← Back to case studies PUMA SE

How PUMA implemented agile vendor risk management with OneTrust

Industry: Multinational sportswear and athletic-goods brand · Solution: OneTrust Vendor Risk Management

International OneTrust reference case — the privacy management platform that AlayIAtrust implements and supports in Chile.

PUMA — OneTrust Vendor Risk Management

The challenge

PUMA needed a standardized framework to assess the risks associated with its vendors, with three clear goals:

  • Identify each vendor's IT risks.
  • Establish a consistent, repeatable process.
  • Reduce the time and resources spent on vendor management.

The solution

PUMA implemented OneTrust Vendor Risk Management with a "Vendor Check" process that incorporates:

  • Standardized risk assessment and monitoring.
  • Collaboration capabilities across teams.
  • Integrated vendor tracking for continuous oversight.

Results

250 vendors assessed after the 2023 launch
17 days average assessment turnaround (80% faster)
80% reduction in total risk-management duration
Using the OneTrust platform, our teams were able to build a clear framework to assess and monitor vendor risks.

Florian Brandner · Director Global Information & Cyber Security, PUMA SE

What this means for Chile

The challenge PUMA faced is not unique to large global brands: any Chilean company that shares personal data with external providers -cloud, logistics, marketing, collections- still has to meet its data protection obligations even when it outsources the operation. Under Law 21.719, published on December 13, 2024 and fully enforceable as of December 1, 2026, duties such as notifying breaches and guaranteeing ARSOP rights do not disappear when working with third parties. A poorly managed failure in the supplier chain can lead to fines from the Personal Data Protection Agency, which for the most serious infractions reach up to 20,000 UTM.

AlayIAtrust applies in Chile the same approach that underpins this case: agile third-party risk management on OneTrust. We inventory your suppliers in the RAT, automate assessments and DPIAs when the processing warrants it, and give the DPO continuous visibility into the risk of each contract and data flow. This way you move from manual, scattered assessments to a living, traceable process that prioritizes the highest-risk suppliers and leaves evidence ready to respond to the Agency. Compliance stops being a one-off event and becomes a permanent operational capability.

Key takeaway: Outsourcing data processing does not outsource your obligations: under Law 21.719, your suppliers' risk remains your risk, and it must be managed continuously.

Next step

Ready for your
success story?

We implement OneTrust in Chile end to end. A 30-minute assessment, no obligation.

Request an assessment