Yes. Chile's Law 21.719 does not exempt companies that sell to other companies. It protects the data of natural persons, and a B2B business processes that data every day: customer and supplier contacts, legal representatives, employees and job applicants. The law contains no exception for business contact data. What changes is the usual lawful basis, which tends to be legitimate interest.
The essentials in 30 seconds
- The law does not mention B2B, nor does it contain an exception for business contact data.
- A company's data is not personal data; the data of the people who work there is.
- You have no contract with a customer's contact person: the lawful basis is usually legitimate interest, which gives a right to object.
- If your company processes data on behalf of its customers, it is a processor, and article 15 bis imposes duties of its own on it.
- Fines depend on the seriousness of the infringement, not on who you sell to.
The idea that data protection is a matter for retail, banking and consumer apps is common among industrial, professional services, technology and logistics companies. There is some truth in it: a business that sells to consumers processes more data, about more people and with more risk. But going from there to the conclusion that the law does not reach you is a leap the text does not allow. If you want the full picture, start with our guide to the data protection law in Chile.
This article explains why Law 21.719 applies to a B2B business, what personal data it holds even though it may not seem so, why the lawful basis that works for your employees does not work for your customers' contacts, and what changes when you are the one processing data on another company's behalf.
Why does the law apply to a B2B company?
Because the law's criterion is not who you sell to, but what you process. Article 1 makes «all processing of personal data carried out by a natural or legal person, including public bodies» subject to its provisions. It does not distinguish by sector, size or type of customer.
The only exclusions in article 1 are two different ones: processing carried out in the exercise of the freedoms to express opinions and to inform, and processing carried out by natural persons in connection with their personal activities. Neither has anything to do with the business model.
The confusion stems from a statement that is in fact correct: the law protects natural persons, not legal persons. The data subject is, by definition, a «natural person, identified or identifiable» (article 2 letter ñ). Your customer's registered name, its company RUT (tax ID number), its turnover or its business address are not personal data. The name, email address and telephone number of the head of purchasing you speak to every week are.
Reading foreign guides does not help either. Article 19 of Spain's Organic Law 3/2018 presumes that the processing of business contact data is covered by legitimate interest, under certain conditions. Even in Spain that is not an exemption: it is a presumption. And Chilean law has no equivalent rule, so here legitimate interest has to be justified and you have to be able to prove it.
What personal data does a company process if it sells only to companies?
More than comes up in a first conversation. The table runs through the usual categories with the lawful basis that usually corresponds to each. It is general guidance: the basis is decided processing activity by processing activity.
| Category | Examples | Usual lawful basis |
|---|---|---|
| Customer and prospect contacts | Name, job title, email, telephone, history of meetings and proposals. | Legitimate interest (art. 13 letter d). |
| Legal representatives and signatories | Name, national ID number, signature, powers of attorney. | Legitimate interest, or legal obligation where a rule requires them to be identified (art. 13 letters d and b). |
| Employees | Contract, pay, attendance, performance reviews. | Contract with the data subject and legal obligation (art. 13 letters c and b). Sensitive data: art. 16 letter e). |
| Job applicants | CV, references, interview results. | Pre-contractual measures at the data subject's request (art. 13 letter c). |
| Supplier and contractor contacts | Account managers, technicians who come onto your premises. | Legitimate interest (art. 13 letter d). |
| Website visitors | Forms, newsletter subscriptions, cookies. | Consent, pre-contractual measures or legitimate interest, depending on the case. |
| Cameras and access control | Images, visitor log, vehicle number plates. | Legitimate interest (art. 13 letter d). |
| Data you process on behalf of a customer | Payroll records, user databases or support tickets that your customer hands over to you. | You have no basis of your own: you act as a processor (art. 15 bis). |
Two rows deserve a note. Job applicants' data is obtained for pre-contractual measures, and article 14 letter d) requires it to be erased or anonymized: keeping CVs for years without having hired the person needs another basis. And the data of employees tends to be, in a B2B company, the highest-volume processing activity and the one that includes sensitive data.
Which lawful basis works for customer contacts?
This is the point most often overlooked. The natural reaction is to say «we have a contract with the customer». But article 13 letter c) allows data to be processed where that is necessary for a contract «between the data subject and the controller». In a B2B relationship the contract is between two companies. The contact person is not a party to it, so that ground does not cover their data.
The basis that applies is normally the one in article 13 letter d): the processing is necessary to satisfy a legitimate interest of the controller, provided it does not affect the rights and freedoms of the data subject. Maintaining the commercial relationship with the company where that person works is a reasonable legitimate interest. Choosing this basis has three practical consequences:
- You have to declare it. Article 14 ter letter d) requires you to publish the basis of legitimacy of each processing activity and, where it is legitimate interest, what that interest is. A privacy policy that talks only about consent does not describe what you do.
- The person may object at any time. Under article 8 letter a), when the person objects you must stop processing the data, unless you prove compelling legitimate grounds that prevail, or you need the data for a claim.
- The burden of proof is yours. Article 13 ends with a short sentence: «The controller must prove the lawfulness of the data processing». It is advisable to put the analysis in writing: what interest you pursue, why the processing is necessary and why it does not harm the data subject.
Consent is also possible, but it is fragile: it can be withdrawn at any time and without stating a reason (article 12). And there is one case in which the contract ground does apply: when your customer is a natural person, such as a self-employed professional or a sole trader. There the data subject is a party to the contract. The full comparison is in lawful bases and consent.
Can you do B2B sales prospecting by email or on LinkedIn?
The law does not prohibit it, but it attaches three conditions that, in practice, structure the work of the sales team.
The first: the fact that data is public does not take it outside the law. Article 2 letter i) says that the processing of data from publicly accessible sources «shall be subject to the provisions of this law». An email address published on a website or an open professional profile still needs a lawful basis.
The second: the person may object. Article 8 recognizes the right of objection where the processing is carried out exclusively for direct marketing purposes (letter b) and where the data was obtained from a publicly accessible source and there is no other legal ground (letter c). Every commercial communication should offer a simple way to unsubscribe, and that unsubscribe has to be genuinely honoured.
The third: buying a contact database is an assignment of data, governed by article 15. It must be recorded in writing or by a suitable electronic means, identify the parties, the data and the purposes, and rest on one of the grounds in that same article: the data subject's consent, a contract to which the data subject is a party, a legitimate interest of the assignor or the assignee, or a law that provides for it. If the assignment required the data subject's consent and did not have it, it is null and void and the assignee must erase all the data received. Before paying for a list, ask where each record came from. More detail in marketing and personal data.
And what if my company processes data on behalf of its customers?
Then the law reaches you twice over. A software-as-a-service provider, a payroll outsourcing company, a contact centre, a marketing agency or a hosting service all process personal data that is not theirs. For the law they are a «third-party agent or processor»: whoever processes data on behalf of the controller (article 2 letter x).
Article 15 bis sets the rules, and they are not merely contractual:
- Process the data only in accordance with the engagement and the controller's instructions. Using it for another purpose, or assigning it without authorization, makes you a controller for all legal purposes, with joint and several liability for the damage.
- Have a contract that sets out the object of the engagement, its duration, the purpose, the type of data, the categories of data subjects and the rights and obligations of the parties.
- Do not delegate the engagement, not even in part, without specific written authorization from the controller. If you delegate, you remain jointly and severally liable.
- Comply with the duty of secrecy in article 14 bis and the security measures in article 14 quinquies.
- Notify the controller when a security breach occurs.
- Erase or return the data when the service ends.
For a B2B provider this has a commercial reading. Your customers will need to sign that contract with you, they will send you security questionnaires and they will want to know which subcontractors you use. Arriving with the answers prepared shortens sales cycles. And a point for foreign providers: article 1 bis letter b) applies the law to a processor that processes data on behalf of a controller established in Chile, regardless of where it is located. The minimum content of the contract is in contracts with processors.
What fines does a B2B company risk?
The same as any other controller. Article 35 grades the sanctions by the seriousness of the infringement: a written warning or a fine of up to 5,000 UTM (monthly tax units) for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones. The type of customer does not appear in the scale.
The size of the company does matter, in three respects. During the first twelve months in force, the Personal Data Protection Agency may sanction smaller companies (micro, small or medium-sized enterprises) with a written warning (sixth transitory article of Law 21.719). The standards for fulfilling the duties of information and security will be set by the Agency taking into account size and volume of data (article 14 septies). And the alternative cap of 2% or 4% of annual revenue exists only for a company that is not a smaller company and that reoffends in a serious or very serious infringement (article 35). A repeat infringement, by contrast, allows the fine to be tripled for any infringer, including a smaller company.
It is worth checking carefully whether you qualify. Law 20.416 treats as smaller companies those with annual revenue of up to 100,000 UF, but it excludes, among others, those in which companies whose shares are listed on a stock exchange, or subsidiaries of those companies, hold more than 30% of the paid-up capital. A small subsidiary of a listed company may fall outside the more favourable treatment.
There is also a criterion that tends to work in favour of a B2B business and that must not be read as immunity. Article 37 requires the harm caused, and especially the number of data subjects affected, to be considered when setting the fine. Processing the data of fewer people reduces exposure; it does not remove the obligation. The detail is in fines and sanctions.
What must a B2B company have in place before December 2026?
The same as any controller, in an order that takes advantage of the lower volume.
- An inventory of processing activities. What data you hold, whose it is, what for and on what basis. You can start with the RoPA template.
- A privacy policy that tells the truth. With the content of article 14 ter, including the legitimate interest you rely on for business contacts.
- A channel and a procedure for data subject rights. Thirty calendar days to respond, extendable once by a further thirty (article 11). Include how an objection or an unsubscribe request is handled.
- Contracts with your processors. CRM, payroll, email, cloud. And, if you are a provider, your own standard contract for when the customer asks for it.
- Security measures and a plan for security breaches. Where a breach poses a reasonable risk to data subjects, the report to the Agency must be made without undue delay (article 14 sexies), and that cannot be improvised.
- Rules for the sales team. Where contacts may come from, how unsubscribe requests are recorded and how long a prospect who never bought is kept.
If you want to measure where you stand, the compliance checklist goes through the ten fronts, and how we implement Law 21.719 sets out in detail what we leave up and running.
Does your company sell to other companies and not know where to start?
In a 30-minute assessment we review what personal data you actually process, where you act as controller and where as processor, and what your customers are going to ask of you when the law enters into force.
Schedule an assessmentFrequently asked questions
Are B2B companies exempt from Law 21.719?
No. Article 1 makes all processing of personal data carried out by a natural or legal person subject to the law, without distinguishing by type of customer. A B2B company processes data on contacts, legal representatives, employees and job applicants, and all of them are natural persons.
Is a person's corporate email address personal data?
Yes, when it makes it possible to identify a natural person, as with an address such as firstname.lastname@company.cl. The law defines personal data as any information linked or referring to an identified or identifiable natural person (article 2 letter f). A generic mailbox, such as contact@company.cl, does not by itself identify anyone.
Do I need the consent of every one of my customers' contacts?
Not necessarily. The usual basis is the legitimate interest of article 13 letter d). In return, you must state what that interest is, respect the right of objection in article 8 and be able to prove that the processing is lawful.
Is the data of a company's legal representative protected?
Yes. The legal representative is a natural person, and their name, national ID number and signature are personal data. The fact that they appear in a deed or in a public register does not take them outside the law: article 2 letter i) makes the processing of data from publicly accessible sources subject to its provisions.
Why doesn't the contract with my customer work as a lawful basis?
Because article 13 letter c) requires the contract to be between the data subject and the controller. In a relationship between companies, the contact person is not a party to the contract. That ground does apply when the customer is a natural person, such as a self-employed professional.
Can I buy a database of company contacts?
Only if the assignment complies with article 15: it must be recorded in writing or by a suitable electronic means, rest on one of its grounds (consent, a contract to which the data subject is a party, legitimate interest or a law) and respect the purposes for which the data was collected. If it required the data subject's consent and did not have it, the assignment is null and void and you must erase all the data received.
Does a B2B SME also have to comply with the law?
Yes. Size does not exempt you, but the law takes it into account: the Agency will set the information and security standards according to size (article 14 septies), the owner may take on the tasks of data protection officer (article 50) and, during the first year in force, the Agency may apply a written warning to smaller companies.
Does the law apply if all my customers are outside Chile?
Yes, if your company is established or incorporated in Chile. Article 1 bis letter a) applies the law to a controller or processor established in the national territory, regardless of where the data subjects are located.
What do I do if a customer asks me to sign a data processing agreement?
Review it and sign it: that is what article 15 bis requires when you process data on its behalf. It must state the object, the duration, the purpose, the type of data, the categories of data subjects and the rights and obligations of the parties. Pay particular attention to the rules on subcontracting, on notification of security breaches and on return or erasure at the end.
Official sources
- Law 19.628 consolidated with the amendments of Law 21.719 (in force from 1 December 2026)
- Law 21.719 — text as published, with its transitory provisions, Library of the National Congress
- Law 20.416, which sets special rules for smaller companies
- Spain's Organic Law 3/2018, article 19 — Official State Gazette (BOE)
This article is for information purposes only and does not constitute legal advice for a specific case.