Enforcement begins
Dec 2026
The Data Protection Agency begins enforcement on December 1.
Large volumes of sensitive data, multiple systems and the highest regulatory demands. We take you to compliance with Law 21.719 —legal, operations and technology— to be ready for the December 2026 enforcement.
No obligation · Reply within 24 business hours
Organizations that have trusted Alaya Digital Solutions
We support banks, financial firms and insurers in complex data-governance projects and Law 21.719 compliance.







Dec 2026
The Data Protection Agency begins enforcement on December 1.
Every
company
Public or private, large or SME. If you process personal data, you must comply.
20k UTM
Over CLP 1.39 billion. For the most serious violations, also 4% of annual revenue.
Assessment
Know where you stand. Then: roadmap, implementation and ongoing support.
In banking and financial services, data is not just another record: it is the raw material behind every credit, risk, and fraud-prevention decision. That concentrates personal information, cross-references it across systems, and transfers it to third parties. Law 21.719 looks precisely at that flow.
You process national IDs, income, debts, contracted products, and transactions: information that lets you reconstruct a person's entire financial life. This concentration raises the standard of lawfulness, security, and minimization the law requires, and turns every credit or risk purpose into something you must be able to justify.
Credit profiling decides who gains access to a product and on what terms. Individuals can exercise their ARSOP rights over that processing: accessing which data feeds it, objecting to it, and requesting rectification. If you cannot explain or trace the logic of the scoring, the regulatory and reputational risk is real.
Reporting to credit-rating agencies, sharing with banking affiliates, or outsourcing collections are all data transfers. Each flow needs a lawful basis and a processing arrangement formalized by contract. Operating out of inertia, because it was always reported this way, shifts the risk across the entire chain of financial providers.
Core banking, loan origination, digital channels, antifraud, and CRM: the same data lives in many systems. That dispersion multiplies the exposure surface and makes it harder to respond to a breach. The law sets a duty to notify breaches, and in banking, reaction time is measured in lost trust.
At AlayIAtrust, we start by mapping financial data end to end: where it originates, which systems touch it, which purposes justify it, and to which bureaus, affiliates, or processors it is transferred. With that inventory we build the data processing record, set the lawful basis for each processing activity, and formalize the contracts across the chain, so that credit scoring and collections stop being black boxes when faced with an ARSOP right or an audit by the Personal Data Protection Agency.
On that foundation we organize the highest-risk flows with data protection impact assessments where appropriate, define the DPO's role, and prepare breach response and notification. The goal is not only to be ready by December 1, 2026, when full enforcement begins, but to sustain operable compliance in a banking sector that moves financial data every single day.
The new Data Protection Agency investigates on complaint or on its own initiative. These are the most frequent scenarios in practice.
"I want to know what data you hold about me, how you calculate my score and who you share it with."
You must grant access and explain the processing within deadline. Without traceability across systems, it's a serious violation: up to 10,000 UTM or 2% of revenue.
"We detected unauthorized access to the customer base, but we wanted to contain it quietly."
With financial data the risk is maximal. Not notifying the Agency and data subjects is a most-serious violation: up to 20,000 UTM or 4% of annual revenue + National Sanctions Registry.
"We send data to scoring agencies and affiliates as we always have."
Every transfer needs a lawful basis and a processing contract (DPA). Transferring without grounds is a violation and passes the risk down the whole chain.
Sanctions are published in the National Registry administered by the Agency. The reputational damage —hard to measure, impossible to reverse— often outweighs the financial one.
How do I get ready? →Imagine that tomorrow the Agency requires you to prove that a specific customer authorized the use of their data. How long does it take your team to pull the evidence together?
Without a system: days digging through spreadsheets and folders. Risk of error and a penalty for failing to demonstrate compliance.
With AlayIAtrust: you search the name and the entire trail appears — consents, data subject requests, notice version, date and channel.
We're already implementing Law 21.719 in banking and financial services organizations in Chile. We combine over 20 years of experience in complex projects with our own methodology for diagnosis, prioritization, plan, execution and ongoing operation. These are the components we leave up and running inside your organization.
Records of processing activities (RoPA): which data you process, for what purpose and on what basis.
We define and document the legal basis for every personal-data processing activity.
Processes to handle access, rectification, erasure, objection and portability within deadline.
A procedure to detect, contain and notify incidents to the Agency and to data subjects.
Processing clauses and contracts (DPAs) with vendors and third parties that access data.
Data protection impact assessments (DPIAs) for high-risk processing, when applicable.
Roles, internal policies and team training to sustain compliance over time.
Privacy notices, policies and evidence organized and ready for an audit.
Most organizations don't know what to do first or who should lead it. We hand you a clear roadmap from day one.
30 minutes, no obligation. We assess processing activities, risks and gaps against Law 21.719.
This weekWe rank findings by regulatory risk and business impact.
FocusA prioritized roadmap: what to do first, who on your team leads it and which solution fits.
2 — 4 weeksLegal and operational implementation plus technology enablement: contracts, policies, consents and training.
1 — 6 monthsMonitoring, internal audits and support in the event of an audit.
ContinuousAn enterprise implementation takes 3 — 6 months; an SME solution, 1 — 4 months. It's best to start early so you're ready in time.
Initial assessmentWe are not a startup selling a basic platform, nor a global consultancy operating from abroad. We work as your team in Chile — legal counsel, OneTrust technology and support throughout the process, in a single team and 100% on the ground.
Specialized lawyers + data engineers in a single team. Most firms sell you software only or consulting only — we take you to compliance.
A full team on the ground. We live the Chilean regulatory framework every day — we are no one's branch office.
An Alaya Digital Solutions company, advising large organizations since 2005.
Experience in complex governance, security and digital transformation projects for leading clients in banking, retail, mining and the public sector.
You already know the law, the risks and the way we work. These are the two implementation paths we offer. We help you choose the right one based on the size and maturity of your organization.
Fast implementation
Everything you need to comply with the law without the complexity of an enterprise solution. Simpler, faster, ready in a few months.
For exporters, fisheries, distributors and construction firms.
World-leading technology
For organizations with large data volumes, multiple systems and the highest regulatory demands. A platform used by large organizations worldwide.
For banking, retail, holdings and multinationals.
Not sure which one is right for you? We'll figure it out together in 30 minutes, no obligation. Book an assessment →
Reporting to a rating agency is still possible, but you must now be able to support the lawful basis for that transfer and have it formalized with the third party. Historical continuity does not equal compliance: the law requires you to demonstrate why you process and share each piece of financial data, not just that you have always done so.
ARSOP rights extend to credit profiling. Individuals can access the data used, request its rectification, and object to certain processing. You do not need to reveal your model, but you do need traceability: which data feeds the scoring, for what purpose, and under what lawful basis, so you can respond on solid grounds.
With the inventory. Before any policy, we map where each piece of financial data lives, which systems and providers touch it, and where it is transferred. That data processing record is the basis for establishing lawfulness, prioritizing the highest-risk flows, and responding in an orderly way to an ARSOP rights request or a breach.
To any natural or legal person, public or private, that processes personal data in Chile. It also applies to foreign companies that offer goods or services in the territory.
The initial assessment carries no obligation. We schedule a 30-minute meeting, evaluate your situation and deliver a report with gaps and concrete recommendations.
It depends on size and digital maturity. An SME solution is implemented in 1 to 4 months. An enterprise solution takes 3 to 6 months. That's why we recommend starting now.
We work with both profiles. We have solutions designed specifically for SMEs and mid-market, and enterprise solutions for banking, retail and multinationals.
Three things: we are 100% on the ground in Chile, we combine legal counsel with technology in the same team, and we have 20 years of experience with clients in banking, retail, mining and the public sector.
Each sector processes different data and faces its own risks. See the approach for yours.
Start with an assessment. In 30 minutes you'll know how far —or how close— you are to compliance.