The challenge
Iberia managed data flows that were distributed and handled manually across multiple business units (flights, web, apps, customer service), creating obstacles:
- Inconsistent, opaque privacy assessments.
- A lack of clear visibility into personal-data flows.
- Manual cookie and consent management across all platforms.
The solution
Iberia implemented OneTrust through a phased approach:
- Privacy assessment automation (2018) — automated impact assessments.
- Data Mapping (2019) — built an inventory and traceability of personal data.
- Cookie consent management — centralized and automated banners and the consent record.
Results
- Automated assessments that bring greater agility and consistency to risk management.
- Full visibility, with personal-data flows clearly identified and documented.
- Centralized consent management, applied uniformly across web and mobile platforms.
We now have full control over the personal data we process, with an intuitive tool that makes risk assessment and reporting easy.
What this means for Chile
Iberia's challenge (privacy scattered across business units, inconsistent impact assessments, and cookie consent managed by hand) is the same one Chilean organizations face today. Law 21.719 was published on December 13, 2024, and starting December 1, 2026, the Personal Data Protection Agency will assume full enforcement. This pushes companies to put instruments in place such as a Record of Processing Activities (ROPA), conduct Data Protection Impact Assessments (DPIAs), notify security breaches, and handle data subject rights (access, rectification, erasure, objection, and portability) in a traceable way. Doing this in scattered spreadsheets, as Iberia once did, is no longer viable.
AlayIAtrust brings to Chile the same phased approach Iberia adopted with OneTrust. We centralize the data inventory in a living ROPA, make DPIAs consistent and auditable, and unify cookie and consent management across web and applications. As a OneTrust partner, we connect that platform with the DPO role and with breach notification workflows, so that compliance becomes demonstrable before the Agency. This reduces exposure to fines that, depending on the severity of the infringement, can reach 5,000, 10,000, or 20,000 UTM.
Key takeaway: Key lesson: what Iberia solved under the GDPR foreshadows the standard Law 21.719 will bring to Chile from December 2026; centralizing and automating privacy with OneTrust is no longer optional.