The challenge
Carrefour faced significant fragmentation across its digital ecosystem:
- Multiple privacy regulations across more than 30 countries (GDPR, LGPD, regional frameworks).
- Heterogeneous consent systems that fragmented the user experience.
- A lack of centralized visibility into when and how consents were collected.
The solution
A group-wide implementation of OneTrust Consent & Preferences:
- More than 160 websites and 30 mobile apps.
- A unified consent banner, adapted by country and regulation.
- A centralized platform that consolidates consents and preferences for cross-border compliance.
Results
Rolling out the same consent platform across all our business units is key to delivering a consistent experience.
What this means for Chile
The challenge that Carrefour Group faced is not unique to a European giant: any Chilean organization that collects data at scale must manage consent in a way that is traceable, granular, and auditable. Under Law 21.719, published on December 13, 2024 and subject to full enforcement starting December 1, 2026, the Personal Data Protection Agency may require evidence that every processing activity rests on a lawful basis. Consent scattered across channels and vendors is no longer viable and becomes a concrete regulatory risk.
At AlayIAtrust we apply the same approach that underpins OneTrust's international cases, adapted to the Chilean framework. We consolidate consent capture and recording into a single platform, connect that evidence to the RAT, the DPIAs, and the DPO function, and put in place the breach notification the law requires. Faced with fines of up to 5,000, 10,000, or 20,000 UTM depending on the severity of the violation, organizing consent and vendor risk with OneTrust turns compliance into a demonstrable operational capability rather than a reactive effort.
Key takeaway: Key lesson: under Law 21.719, consent only protects when it is traceable and auditable; consolidating it with OneTrust turns a legal obligation into an operational advantage.