Chile's Law 21.719 does not name the "records of processing activities" nor require it as a document. What it does require is article 14 ter: publishing and keeping available which data you process, for what purpose, on which lawful basis, to whom you disclose it and for how long. The RoPA is the tool that lets you answer that.
The essentials in 30 seconds
- The RoPA inventories every activity in which you process personal data.
- Chilean law does not require it under that name: the duty sits in article 14 ter, which requires publishing that same information.
- It is a core piece of accountability and one of the first things an audit requests.
- At a minimum, it must have 9 columns (you'll see them below).
- The hard part is not creating it, but keeping it alive: someone must update it when a process changes.
If you could only do one thing to start complying with Law 21.719, it would be this: knowing what data you process. You cannot protect —or declare to the Agency— what you don't know you have. That inventory, kept orderly and current, is the Records of Processing Activities (RoPA). It is part of the compliance checklist (front no. 2) and is the foundation everything else rests on. If you want the full picture, start with our guide to the data protection law in Chile.
What the RoPA is
The Records of Processing Activities is the document that lists, one by one, the activities in which your organization processes personal data —from the employee payroll to the website contact form— and describes, for each one, what data it involves, for what, on which lawful basis, with whom it is shared and how it is protected. It is, in practice, the map of your data.
Is the RoPA mandatory?
Precision matters here, because this is where Law 21.719 is most often confused with the European regulation. Chilean law does not mention “records of processing activities” and does not impose it as a document. The RoPA under that name and shape comes from article 30 of the GDPR, which does not apply in Chile.
What is mandatory, and rather more demanding than usually reported, is article 14 ter: the controller must provide and keep permanently available to the public, on its website or an equivalent medium, the categories, classes or types of data it processes; a generic description of the universe of persons in its databases; the recipients to whom it expects to communicate or assign the data; the purposes of each processing activity; the basis of legitimacy for each one —and, where it is legitimate interest, what that interest is—; the retention period; the source of the data; international transfers and whether the destination offers an adequate level of protection; and the existence of automated decisions together with the logic applied.
That list is, almost column for column, a RoPA. The difference is direction: article 14 ter requires publishing it outward, not merely filing it. And you cannot publish what you have never inventoried. Article 14 letter a) adds to this, requiring the controller to inform and make available to the data subject the evidence supporting the lawfulness of the processing, and to hand it over promptly on request.
So the honest answer is: the RoPA is not mandatory as a form, but without it there is no way to comply with article 14 ter or to survive an audit. It is the input, not the formality.
Which columns it must have (field template)
A useful RoPA has, at a minimum, these columns. You can start with a spreadsheet using this structure:
| RoPA field | What to record | Legal duty behind it |
|---|---|---|
| Activity or process | Name of the processing, for example "Payroll management" or "Email marketing". | Article 14 ter letter d): purposes of the processing carried out |
| Purpose | What the data is used for in that activity, in specific and explicit terms. | Article 14 letter b) and article 14 ter letter d) |
| Data categories | Which types of data it includes and whether it holds sensitive data under article 2 letter g). | Article 14 ter letter d): categories, classes or types of data |
| Universe of data subjects | Generic description of the people in the database: customers, employees, applicants. | Article 14 ter letter d): generic description of the universe of persons |
| Lawful basis | Consent under article 12 or one of the grounds in article 13, stated one by one. | Article 14 ter letter d): basis of legitimacy of the processing |
| Recipients | Who the data is communicated or assigned to, including processors under article 15 bis. | Article 14 ter letter d): recipients to whom data is expected to be assigned |
| International transfers | Destination country or organisation and whether it offers an adequate level of protection. | Article 14 ter letter h) |
| Retention period | How long the data is kept and what triggers its deletion or anonymisation. | Article 14 ter letter i) |
| Source of the data | Where it comes from and whether it originates in publicly accessible sources. | Article 14 ter letter j) |
| Automated decisions | Whether there is profiling or automated decision-making, with the logic applied and its consequences. | Article 14 ter letter l) |
| Security measures | Technical and organisational controls applied to that database. | Articles 14 quinquies and 14 ter letter e) |
How to build it step by step
- Identify the areas that process data: HR, sales, marketing, finance, support, IT. Interview each one.
- List the activities of each area (one row per activity). Don't aim for perfection: aim for coverage.
- Complete the 9 columns for each activity. Where you don't know the lawful basis, flag it as pending and resolve it later.
- Flag sensitive data and international transfers: they carry the highest risk and demand the most attention.
- Detect the gaps: processing without a basis, without a retention period or with third parties lacking a contract (DPA). That is your remediation list.
- Assign an owner to maintain the RoPA and a review frequency.
Common mistakes
- Doing it once and filing it away. An outdated RoPA is almost as bad as not having one.
- Forgetting the “invisible” processing activities: security cameras, website cookies, spreadsheets on personal computers, old forms.
- Confusing purpose with lawful basis. The purpose is the “what for”; the basis is the “what legally allows it.”
- Not recording the processors (vendors that process data on your behalf): they remain your responsibility.
How to keep it alive
The RoPA is not a one-time deliverable: every time a process is created, a vendor is hired or a campaign is launched, it should be updated. The healthiest approach is to embed it into operations —so that opening a new processing activity includes “update the RoPA” as a step— and to review it periodically. In organizations with many processing activities, a specialized tool helps sustain traceability and generate evidence for the Agency.
Want your RoPA built and gap-free?
We help you build the Records of Processing Activities and close the gaps it reveals. Start with a 30-minute assessment, no commitment.
Request assessmentFrequently asked questions
What are the Records of Processing Activities (RoPA)?
It is the document that inventories every activity in which the organization processes personal data: what data, for what purpose, on which lawful basis, with whom it is shared and with what security measures. It is the foundation on which the entire Law 21.719 compliance program rests.
Is the RoPA mandatory?
Keeping records of processing activities is a core piece of the accountability the law requires. Keeping it current is how you demonstrate to the Agency what data you process and under what conditions, and it is usually one of the first documents requested in an audit.
Which columns must a RoPA have?
At a minimum: activity or process, purpose, data categories, categories of data subjects, lawful basis, recipients and processors, international transfers, retention period and security measures.
Can the RoPA be built in an Excel spreadsheet?
Yes, a spreadsheet works to get started and for small organizations. The challenge is not the format but keeping it alive: it must be updated when a process changes. In organizations with many processing activities, a specialized tool makes traceability and evidence easier.
Does Law 21.719 require records of processing activities?
Not under that name. Law 21.719 does not mention "records of processing activities": that document comes from article 30 of the European GDPR. What Chilean law does impose is the information and transparency duty of article 14 ter, which requires publishing practically the same information.
So why build a RoPA in Chile at all?
To be able to comply with article 14 ter of Law 21.719. That article requires keeping permanently available to the public the detail of data categories, purposes, basis of legitimacy, recipients, retention period and source. You cannot publish an inventory you have never compiled.
What information does article 14 ter require you to publish?
The processing policy with its date and version, the identification of the controller, the contact channel for requests, the categories of data and of data subjects, the recipients, the purposes, the basis of legitimacy, the security measures, international transfers, the retention period, the source of the data and the existence of automated decisions.
Must the RoPA be published or is an internal copy enough?
The RoPA as an internal spreadsheet is not published. What article 14 ter of Law 21.719 requires to be kept permanently available to the public, on the website or an equivalent medium, is the information that inventory contains, written for the data subject. The working document and the publication are separate artefacts.
Is a spreadsheet acceptable for keeping the RoPA?
Yes. Neither Law 21.719 nor its transparency duties impose a format, a tool or a medium. What matters is that the article 14 ter information is complete, current and traceable. For a small organisation a well-maintained spreadsheet is enough; the problem starts when nobody updates it.
What happens if I have not compiled this information?
The breach attaches to the information duty. Article 34 bis letter a) of Law 21.719 classifies failure to comply with the information and transparency duty of article 14 ter as a minor infringement, punishable with a written warning or a fine of up to 5,000 monthly tax units under article 35.
Official sources
- Law 21.719 on the protection and processing of personal data, creating the Personal Data Protection Agency — official text, Library of the National Congress of Chile
- Article 14 ter (information and transparency duty) and article 14 (controller obligations) — consolidated text in force from 1 December 2026
This article is for information purposes only and does not constitute legal advice for a specific case.