← Back to the blog

Personal Data Protection Agency audits: what they'll request (and how to prepare).

From December 1, 2026, the Personal Data Protection Agency can come knocking. The difference between a calm audit and a sanctioning one is almost always the same: being able to demonstrate, with documents, what you're already doing.

Audits · Law 21.719
Short answer

In a Law 21.719 audit in Chile, the Agency may demand any document, book or record needed for its function, under article 30 bis letter c). The first thing reviewed is the information article 14 ter requires you to publish: purposes, lawful basis, recipients, retention periods and security measures.

The essentials in 30 seconds

  • The Personal Data Protection Agency audits and sanctions from December 1, 2026.
  • The principle that frames everything is accountability: it's not enough to comply, you must be able to demonstrate it.
  • The first thing requested is the RoPA and the documentary evidence: policies, consents, agreements, breaches, DPIA and training.
  • An Infringement Prevention Model and a documented program act as a mitigating factor.
  • Obstruction and a complete lack of documentation aggravate liability.

An audit is not an ambush: it's a verification. The authority wants to confirm that the organization processes personal data in accordance with the law and, above all, that it can demonstrate it. That's why preparation isn't about “having everything perfect on the day of the visit,” but about having built —beforehand— a program with traceability. If you want the full picture, start with our guide to the data protection law in Chile.

In this article we cover the Agency's powers, the documents it usually requests, how an inspection unfolds and what you can do today to arrive calm. If the scope of the law isn't clear yet, start with the definitive guide to Law 21.719; and to organize your preparation, use the compliance checklist.

1. What the Agency is and its powers

The Personal Data Protection Agency is the supervisory authority created by Law 21.719. It is the body responsible for overseeing compliance and has powers to audit, open proceedings and apply sanctions. In practice, it concentrates the supervisory power that previously was scattered or simply did not exist with this force.

Its powers include requesting information, conducting inspections, ordering corrective measures and resolving data subject complaints. The sanctions regime behind those powers classifies infringements as minor (up to 5,000 UTM), serious (up to 10,000 UTM) and very serious (up to 20,000 UTM), with aggravation for recidivism. We analyze that regime in detail in fines and sanctions of Law 21.719.

2. When and why you can be audited

An audit can originate in different ways. Knowing them helps understand the risk:

  • A data subject complaint: a person who believes their rights were violated files a complaint.
  • A breach notification: a reported security incident can trigger a review.
  • Ex officio audit: the Agency itself initiates the review, sometimes by sector or by the risk level of the processing.
  • Media coverage or a pattern of complaints: public situations that draw the authority's attention.

The practical message: you don't need to “do something wrong” to be audited. It's enough for someone to complain or for your sector to come into focus. That's why preparation is preventive, not reactive.

3. What documents they'll request

This is the core of the article. When the Agency reviews an organization, it looks for evidence that data processing is under control. This is the “compliance folder” worth having ready:

  • Records of Processing Activities (RoPA): what data you process, for what purpose, on which lawful basis, with whom you share it and how long you keep it. Usually the first thing requested.
  • Policies and procedures: privacy policy, internal data-handling policies and documented procedures.
  • Consent records: proof of when, for what and how consent was obtained, when that is the lawful basis.
  • Processor agreements (DPA): agreements with the third parties that process data on your behalf, with data protection clauses.
  • Breach log: an incident record and evidence of the notifications made on time.
  • Impact assessments (DPIA): for high-risk processing.
  • DPO / owner appointment: who is responsible for data protection and with what mandate.
  • Training evidence: records of who was trained, when and on what.
  • International transfer documentation: what data leaves Chile and under what guarantees.

Pattern to remember: every obligation in the law has a document that proves it. If the document doesn't exist, in the Agency's eyes the obligation wasn't met, even if in practice it was. That is the essence of accountability.

What an audit can request and which Law 21.719 article backs it
Document or evidenceWhat it provesSupporting article
Published processing policy, with date and versionThat the information and transparency duty is live and traceable.Article 14 ter letter a)
Inventory of processing with purpose and lawful basisThat each activity rests on article 12 or 13 and is published.Article 14 ter letter d)
Evidence supporting the lawfulness of processingThat you can hand it over promptly when required.Article 14 letter a)
Record of the consent obtainedThat you can prove consent: the burden falls on the controller.Article 12 final paragraph
Contact channel for data subject requestsThat the channel for notifying requests exists and works.Article 14 ter letter c)
Log of rights requests and their deadlinesThat receipt is acknowledged and replies issued within 30 calendar days.Article 11
Breach register with nature, effects and measuresThat security incidents were documented as the law requires.Article 14 sexies second paragraph
Impact assessments carried out before processingThat high-risk processing was assessed before it started.Article 15 ter
Contracts with processorsThat they set out object, duration, purpose, data types, categories of subjects and the parties' rights.Article 15 bis
Technical and organisational security measuresThat they exist and work: after an incident the burden of proof is yours.Article 14 quinquies
Prevention model certificate, where heldThat the mitigation for fulfilled direction and supervision duties applies.Articles 36 number 5 and 51

4. How an audit unfolds

Although every case is different, an inspection usually follows a recognizable sequence:

  • Initial request: the Agency requests information and documentation within a set deadline.
  • Evidence analysis: what was provided is reviewed and contrasted with the reality of the processing.
  • Additional requests or inspection: clarifications, interviews or a visit may be requested.
  • Findings and responses: if non-compliance is detected, the organization can present its responses and evidence.
  • Resolution: it closes without observations, with corrective measures or with a sanction, depending on the case.

The quality and timeliness of your responses matter. An organization that delivers orderly evidence on time projects a mature program; one that improvises, the opposite.

5. Accountability: the principle that protects you

Accountability is the backbone of Law 21.719. It means the burden of demonstrating compliance falls on whoever processes the data. It's not enough to state “we comply”: you must be able to show it with records, policies and traceability.

Properly understood, this principle is good news. It turns compliance into something you can build: every document you generate today is an argument in your favor tomorrow. That's why the RoPA, consent records and breach log are not bureaucracy, but your best defense.

6. Mitigating factors and the Infringement Prevention Model

The law contemplates circumstances that can mitigate liability. Among the most relevant:

  • Certified Infringement Prevention Model: having one acts expressly as a mitigating factor.
  • Documented, living program: evidence of a serious, sustained compliance effort.
  • Cooperation with the authority: responding on time, providing evidence and remediating.
  • Timely corrective measures: fixing what's detected without delay.

The reverse is also true: recidivism and obstruction aggravate. That's why it's best to treat each finding as a documented improvement opportunity, not a problem to hide.

7. Mistakes that aggravate your situation

  • Not being able to show a RoPA or basic compliance evidence.
  • Not having notified a breach to the Agency without undue delay and by the most expedient means.
  • Not handling data subject rights or doing so late.
  • Obstructing the audit or providing incomplete or late information.
  • Processing data without a lawful basis or with invalid consents.

8. How to prepare today

Don't wait for the request to put your house in order. These actions reduce risk directly:

  • Build and keep the RoPA current; it's your first deliverable.
  • Assemble a compliance folder with all the front-3 documents ready to hand over.
  • Test your breach plan with a drill.
  • Verify that your ARSOP rights process responds on time (see how to respond to ARSOP requests).
  • Formally appoint the owner or DPO and keep a record of training.

Would your company withstand an audit today?

A Law 21.719 assessment simulates the Agency's lens and shows you exactly which evidence you're missing. 30 minutes, no commitment.

Request assessment

Frequently asked questions

What is the Personal Data Protection Agency?

It is the supervisory authority created by Law 21.719 to oversee personal data protection in Chile. It has powers to audit compliance, open proceedings and apply sanctions. It begins exercising its supervisory role from December 1, 2026.

What documents can the Agency request in an audit?

Typically it requests the evidence of accountability: the Records of Processing Activities (RoPA), policies and internal procedures, consent records, processor agreements (DPA), the breach log, impact assessments (DPIA), the DPO appointment and training evidence.

Does having an Infringement Prevention Model help in an audit?

Yes. Having a certified Infringement Prevention Model acts as a mitigating factor. Beyond certification, demonstrating a documented, living program —even if not everything is perfect— evidences accountability and improves the organization's position.

What mistakes aggravate your situation with the Agency?

Not being able to show a RoPA or compliance evidence, not having notified a breach without undue delay, not handling data subject rights, and obstructing the audit. A complete lack of documentation and obstruction aggravate liability.

What can the Agency demand in an audit?

Article 30 bis letter c) of Law 21.719 empowers it to require from anyone processing personal data any document, book or record and all information necessary to discharge its supervisory function. There is no closed list: the power is defined by what the audit needs, not by a prior catalogue.

Can I be summoned to give evidence in the procedure?

Yes. Article 30 bis letter d) of Law 21.719 allows the Agency, on reasoned grounds, to summon the data subject, the legal representatives, managers, advisers and staff of whoever processes data, and anyone who took part in or knew of a relevant fact.

Who must prove the processing was lawful?

The controller. Article 12 of Law 21.719 states that it falls to the controller to prove it obtained consent and that the processing was lawful, fair and transparent. Article 13 adds that the controller must evidence the lawfulness of the processing where another basis is relied on.

And who proves security measures were in place?

The controller as well. Article 14 quinquies of Law 21.719 is explicit: after a security incident, and in any judicial or administrative dispute, it falls to the controller to evidence the existence and operation of the measures adopted given the risk levels and the technology available.

Does a certified prevention model help in an audit?

Yes, as mitigation. Article 36 number 5 of Law 21.719 treats as a mitigating circumstance having diligently fulfilled the duties of direction and supervision, verified through the article 51 certificate. Article 39 also records in the public register those holding certified models in force.

What aggravates liability in a sanctioning procedure?

Article 36 of Law 21.719 lists three aggravating factors: recidivism, meaning having been sanctioned on two or more occasions in the last thirty months; the continuing nature of the infringement; and having put at risk the security of data subjects' rights and freedoms in relation to their data.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You might also be interested in

Enforcement

From complaint to fine: the procedure under articles 42 and 43

Compliance

Law 21.719 compliance checklist: the 10 fronts to close

Sanctions

Fines and sanctions of Law 21.719: what you need to know to avoid them

Rights

How to respond to ARSOP rights requests: process, deadlines and templates

Next step

Is your company ready
for December 2026?

A 30-minute assessment, no commitment.

Request assessment