← Back to case studies Vanquis Banking Group

How Vanquis transformed its privacy strategy with OneTrust

Industry: UK bank specializing in financial inclusion, with more than 2.4 million customers · Solution: OneTrust (4 modules)

International OneTrust reference case — the privacy management platform that AlayIAtrust implements and supports in Chile.

Vanquis Banking Group — OneTrust

The challenge

GDPR compliance requirements exposed manual, fragmented processes at Vanquis:

  • No unified repository of data-processing records.
  • No automated workflows for data access or deletion requests.
  • No centralized visibility into the third parties handling data.
  • Difficulty meeting regulatory requirements and managing legal risk.

The solution

Vanquis implemented OneTrust with four key modules, in a project led by its Data Protection Analyst together with the CISO and the compliance team:

  • Data Mapping — track personal data across the organization.
  • Assessment Automation — automate privacy impact assessments.
  • Data Subject Rights Automation — streamline data subject requests.
  • Third-Party Risk Management — monitor the vendors handling data.

Results

  • Automated, auditable reporting that improves efficiency.
  • Full traceability of personal data (customers, employees and vendors).
  • Efficient management of data subject rights with clear workflows.
  • Centralized impact assessments that reduce risk and inconsistency.
OneTrust was selected for its business focus, intuitive design, adaptability and enterprise-wide auditable transparency.

Mike Dronfield · CISO, Vanquis Banking Group

What this means for Chile

As a bank, Vanquis faced the challenge of governing consent, assessing vendor risk, and documenting privacy decisions at scale. Chilean organizations will experience something similar under Law 21.719: enacted on December 13, 2024, with full enforcement starting December 1, 2026 by the Personal Data Protection Agency. The law requires maintaining a record of processing activities (ROPA), conducting impact assessments (DPIA), appointing a data protection officer (DPO), and complying with the duty to notify breaches, with fines of up to 20,000 UTM for the most serious infringements.

In Chile, AlayIAtrust applies the same approach that underpins international cases like this one: turning privacy into an operational process, not paperwork. With OneTrust we implement the ROPA, automate DPIAs, manage the consent lifecycle and vendor assessment, and enable the workflow to respond to data subject rights (ARSOP) and notify breaches. This way, a Chilean company reaches December 1, 2026 with traceable evidence, third-party risk under control, and a foundation ready to scale as its data processing grows.

Key takeaway: Key takeaway: mature privacy is not proven with scattered documents, but with automated, traceable processes; that is what Law 21.719 will require in Chile.

Next step

Ready for your
success story?

We implement OneTrust in Chile end to end. A 30-minute assessment, no obligation.

Request an assessment