The challenge
With a global user base and an ecosystem of connected devices, Samsung faced critical obstacles to managing consent consistently:
- Implementing consistent consent mechanisms across more than 160 websites and multiple platforms.
- Adapting to evolving regulations, including GDPR and Google's new CMP requirements.
- A lack of centralized visibility into the preferences granted by users.
The solution
Samsung deployed OneTrust Consent & Preferences to:
- Establish uniform consent banners and systems across its main touchpoints (web, mobile apps and TVs).
- Comply quickly with Google's CMP requirements.
- Consolidate user preferences into a single system, improving compliance and transparency.
Results
- International agility: cross-platform rollout across regions with localized adaptations.
- Greater internal control: full visibility into user consents and preferences.
- Better user experience: clearer consent banners that enable informed decisions.
We have given consumers more choice, allowing them to better determine how we manage their data.
What this means for Chile
The challenge Samsung faced is not foreign to Chile. Any organization that operates websites, apps, or digital campaigns must ground its data processing in a lawful basis and, frequently, in valid, granular, and revocable consent. Law 21.719 was published on December 13, 2024, and its full enforcement takes effect on December 1, 2026, under the authority of the Personal Data Protection Agency. Fragmented consent management with no traceability weakens a company's compliance posture and exposes it to penalties that, depending on the severity of the infringement (minor, serious, or very serious), can reach up to 5,000, 10,000, or 20,000 UTM.
In Chile, AlayIAtrust applies the same approach illustrated in this case: implementing OneTrust Consent Management to centralize and audit consent across all digital touchpoints, rather than property by property. We connect that layer with the record of processing activities (ROPA), data protection impact assessments (DPIA), the DPO role, and the duty to notify breaches, while also operationalizing data subject rights (access, rectification, erasure, objection, and portability). In this way, consent ceases to be an isolated cookie and becomes demonstrable evidence of compliance, ready to respond to the Agency and scalable across multiple domains.
Key takeaway: Key lesson: in Chile, consent only protects you when it is granular, revocable, and traceable at scale; with OneTrust it stops being a cookie and becomes evidence of compliance.