Enforcement begins
Dec 2026
The Data Protection Agency begins enforcement on December 1.
Worker health exams, biometric access control, contractors and site CCTV: more sensitive data than it seems. We implement Law 21.719 to be ready for the December 2026 enforcement.
No obligation · Reply within 24 business hours
Organizations that have trusted Alaya Digital Solutions
We support mining companies and their contractors in protecting workers' data and complying with Law 21.719.







Dec 2026
The Data Protection Agency begins enforcement on December 1.
Every
company
Public or private, large or SME. If you process personal data, you must comply.
20k UTM
Over CLP 1.39 billion. For the most serious violations, also 4% of annual revenue.
Assessment
Know where you stand. Then: roadmap, implementation and ongoing support.
Mining brings together large workforces, dispersed sites, and an extensive chain of suppliers. This multiplies the points where personal data of workers and contractors is generated, copied, and moved. Compliance here is demanding because data rarely stays still: it moves between camps, headquarters, and third parties.
A single person leaves traces in the camp, the plant, headquarters, and rotating shift systems. This geographic and system dispersion makes it hard to know where each piece of data lives, who accesses it, and for what purpose: the first step is to map it in a record of processing activities (RPA).
Managing health and safety at a mining site generates especially sensitive information about the worker, from high-altitude medical exams to exposure to hazards. Processing it requires a solid lawful basis, role-restricted access, and defined retention periods, not shared folders that anyone in the area can open.
Mining contractors, personnel transport, catering, occupational health, and external services form a long chain where data changes hands. Each transfer is a hand-off that must be governed by contract and traceability; the controller remains accountable across the entire chain.
Equipment telemetry, truck geolocation, and per-shift productivity records may seem like mere machine data, but they are often associated with an identifiable operator. When that happens, they become personal data and fall within the scope of the law.
At AlayIAtrust we start from what is specific to a mining operation: where data is generated across the site, how it moves between locations and third parties, and which occupational health and safety information deserves reinforced protection. We build the record of processing activities on that real map, not on a generic office model.
On that basis, we organize the chain of contractors and suppliers with agreements and traceability, and we make ARSOP rights operational for a large workforce with high turnover, so that you can respond on time when a worker or contractor exercises them, and arrive prepared for the full enforcement that begins on December 1, 2026.
The new Data Protection Agency investigates on complaint or on its own initiative. These are the most frequent scenarios in practice.
"We store pre-employment exams and medical leave, but no one controls who accesses them."
Exams and health data are sensitive. Processing or exposing them without a basis or access control is a most-serious violation.
"Site entry is by fingerprint and facial recognition; it's always been that way."
Biometric data is sensitive and requires a lawful basis and, normally, a DPIA. Deploying it without grounds exposes you to penalty.
"Every contractor and subcontractor accesses staff data and there's no data contract."
Every processor needs a processing contract (DPA) and guarantees. Without it, you remain responsible for the whole chain.
Sanctions are published in the National Registry administered by the Agency. The reputational damage —hard to measure, impossible to reverse— often outweighs the financial one.
How do I get ready? →Mining processes far more personal —and sensitive— data than usually assumed, especially on workers and contractors.
Pre-employment exams, leave and fitness: sensitive worker data requiring a reinforced basis and strict access control.
Fingerprint and facial recognition at site entry are sensitive biometric data: they need a lawful basis and, normally, a DPIA.
A broad ecosystem of processors accessing staff data: each needs a processing contract (DPA).
Cameras and site monitoring process personal data: they need a lawful basis, notice and defined retention.
Imagine that tomorrow the Agency requires you to prove that a specific customer authorized the use of their data. How long does it take your team to pull the evidence together?
Without a system: days digging through spreadsheets and folders. Risk of error and a penalty for failing to demonstrate compliance.
With AlayIAtrust: you search the name and the entire trail appears — consents, data subject requests, notice version, date and channel.
We implement Law 21.719 in mining and other sectors with large workforces and sensitive data in Chile. We combine over 20 years of experience in complex projects with our own methodology for diagnosis, prioritization, plan, execution and ongoing operation. These are the components we leave up and running inside your organization.
Records of processing activities (RoPA): which data you process, for what purpose and on what basis.
We define and document the legal basis for every personal-data processing activity.
Processes to handle access, rectification, erasure, objection and portability within deadline.
A procedure to detect, contain and notify incidents to the Agency and to data subjects.
Processing clauses and contracts (DPAs) with vendors and third parties that access data.
Data protection impact assessments (DPIAs) for high-risk processing, when applicable.
Roles, internal policies and team training to sustain compliance over time.
Privacy notices, policies and evidence organized and ready for an audit.
Most organizations don't know what to do first or who should lead it. We hand you a clear roadmap from day one.
30 minutes, no obligation. We assess processing activities, risks and gaps against Law 21.719.
This weekWe rank findings by regulatory risk and business impact.
FocusA prioritized roadmap: what to do first, who on your team leads it and which solution fits.
2 — 4 weeksLegal and operational implementation plus technology enablement: contracts, policies, consents and training.
1 — 6 monthsMonitoring, internal audits and support in the event of an audit.
ContinuousAn enterprise implementation takes 3 — 6 months; an SME solution, 1 — 4 months. It's best to start early so you're ready in time.
Initial assessmentWe are not a startup selling a basic platform, nor a global consultancy operating from abroad. We work as your team in Chile — legal counsel, OneTrust technology and support throughout the process, in a single team and 100% on the ground.
Specialized lawyers + data engineers in a single team. Most firms sell you software only or consulting only — we take you to compliance.
A full team on the ground. We live the Chilean regulatory framework every day — we are no one's branch office.
An Alaya Digital Solutions company, advising large organizations since 2005.
Experience in complex governance, security and digital transformation projects for leading clients in banking, retail, mining and the public sector.
You already know the law, the risks and the way we work. These are the two implementation paths we offer. We help you choose the right one based on the size and maturity of your organization.
Fast implementation
Everything you need to comply with the law without the complexity of an enterprise solution. Simpler, faster, ready in a few months.
For exporters, fisheries, distributors and construction firms.
World-leading technology
For organizations with large data volumes, multiple systems and the highest regulatory demands. A platform used by large organizations worldwide.
For banking, retail, holdings and multinationals.
Not sure which one is right for you? We'll figure it out together in 30 minutes, no obligation. Book an assessment →
With an inventory that spans all sites and headquarters. Before defining controls, you need to know where each piece of data is generated, where it is copied to, and who consults it across camps, the plant, and headquarters. The record of processing activities consolidates that scattered view in a single place and reveals the hand-offs between sites that are not documented today.
The data controller remains accountable across the chain, even when the operation is outsourced on site. That is why every contractor or supplier that accesses data must be governed by a contract setting out purposes, measures, and security obligations, with traceability of what is shared and for what.
When that information is linked to an identifiable worker, such as the operator of a piece of equipment or the driver of a truck, it stops being mere machine data and becomes personal data. In that case it requires a lawful basis, a declared purpose, and retention periods, just like the rest of the processing in the operation.
To any natural or legal person, public or private, that processes personal data in Chile. It also applies to foreign companies that offer goods or services in the territory.
The initial assessment carries no obligation. We schedule a 30-minute meeting, evaluate your situation and deliver a report with gaps and concrete recommendations.
It depends on size and digital maturity. An SME solution is implemented in 1 to 4 months. An enterprise solution takes 3 to 6 months. That's why we recommend starting now.
We work with both profiles. We have solutions designed specifically for SMEs and mid-market, and enterprise solutions for banking, retail and multinationals.
Three things: we are 100% on the ground in Chile, we combine legal counsel with technology in the same team, and we have 20 years of experience with clients in banking, retail, mining and the public sector.
Each sector processes different data and faces its own risks. See the approach for yours.
Start with an assessment. In 30 minutes you'll know how far —or how close— you are to compliance.