The challenge
GDPR compliance requirements exposed manual, fragmented processes at Vanquis:
- No unified repository of data-processing records.
- No automated workflows for data access or deletion requests.
- No centralized visibility into the third parties handling data.
- Difficulty meeting regulatory requirements and managing legal risk.
The solution
Vanquis implemented OneTrust with four key modules, in a project led by its Data Protection Analyst together with the CISO and the compliance team:
- Data Mapping — track personal data across the organization.
- Assessment Automation — automate privacy impact assessments.
- Data Subject Rights Automation — streamline data subject requests.
- Third-Party Risk Management — monitor the vendors handling data.
Results
- Automated, auditable reporting that improves efficiency.
- Full traceability of personal data (customers, employees and vendors).
- Efficient management of data subject rights with clear workflows.
- Centralized impact assessments that reduce risk and inconsistency.
OneTrust was selected for its business focus, intuitive design, adaptability and enterprise-wide auditable transparency.
What this means for Chile
As a bank, Vanquis faced the challenge of governing consent, assessing vendor risk, and documenting privacy decisions at scale. Chilean organizations will experience something similar under Law 21.719: enacted on December 13, 2024, with full enforcement starting December 1, 2026 by the Personal Data Protection Agency. The law requires maintaining a record of processing activities (ROPA), conducting impact assessments (DPIA), appointing a data protection officer (DPO), and complying with the duty to notify breaches, with fines of up to 20,000 UTM for the most serious infringements.
In Chile, AlayIAtrust applies the same approach that underpins international cases like this one: turning privacy into an operational process, not paperwork. With OneTrust we implement the ROPA, automate DPIAs, manage the consent lifecycle and vendor assessment, and enable the workflow to respond to data subject rights (ARSOP) and notify breaches. This way, a Chilean company reaches December 1, 2026 with traceable evidence, third-party risk under control, and a foundation ready to scale as its data processing grows.
Key takeaway: Key takeaway: mature privacy is not proven with scattered documents, but with automated, traceable processes; that is what Law 21.719 will require in Chile.