Enforcement begins
Dec 2026
The Data Protection Agency begins enforcement on December 1.
Large volumes of customer data, marketing and profiling at scale, cookies and loyalty programs. We take you to compliance with Law 21.719 to be ready for the December 2026 enforcement.
No obligation · Reply within 24 business hours
Organizations that have trusted Alaya Digital Solutions
We support retail, e-commerce and consumer goods companies in their Law 21.719 compliance.







Dec 2026
The Data Protection Agency begins enforcement on December 1.
Every
company
Public or private, large or SME. If you process personal data, you must comply.
20k UTM
Over CLP 1.39 billion. For the most serious violations, also 4% of annual revenue.
Assessment
Know where you stand. Then: roadmap, implementation and ongoing support.
Retail and e-commerce thrive on knowing the customer: every purchase, every click and every visit leaves a trail. That same wealth of data, which fuels sales, is exactly what Law 21.719 requires you to handle with clear legal bases and real control. Here, compliance is not a formality: it is part of daily operations.
Stores accumulate identification, contact, shipping address and order history data from thousands of people. The greater the volume, the greater the exposure: an extensive database concentrates more risk in the event of unauthorized access and requires controlling who has access, for what purpose and how long each purchase record is retained.
The site collects browsing data through cookies and tracking pixels, often before the visitor decides anything. Without a clear legal basis for processing and valid consent for uses such as advertising and analytics, that silent capture becomes one of the most frequent points of noncompliance in an online store.
Points programs and personalization build detailed profiles of purchasing habits, preferences and purchasing power. Cross-referencing that data to predict behavior or segment offers is legitimate only with defined legal bases and transparency toward the customer about how their purchase information is used.
Physical store, app, marketplace, social media and email campaigns move the same data across platforms and external payment, shipping and marketing providers. Each transfer widens the exposure surface and requires knowing, at all times, where the customer's data is and who is accountable for it.
At AlayIAtrust we start from a simple premise: in retail, data moves quickly and through many hands, so compliance has to live within operations, not on the sidelines. We map how data enters and moves between channels, organize the legal bases behind each commercial use, and put web consent and loyalty programs on solid ground.
We also prepare your team to respond swiftly to customers' ARSOP rights, regardless of the channel they write through (store, app, marketplace or social media), and to react to a data breach without improvising. The goal is for you to keep using data to sell better, with the confidence that this use can withstand scrutiny from the Personal Data Protection Agency.
The new Data Protection Agency investigates on complaint or on its own initiative. These are the most frequent scenarios in practice.
"We blast the whole list; the checkboxes were pre-ticked by default."
Consent must be free, informed and unambiguous. Pre-ticked boxes and opt-in-free sends are a violation and expose your entire database.
"There was unauthorized access to the orders system, with data on thousands of customers."
You must notify the Agency and those affected without delay. Failing to do so is a most-serious violation: up to 20,000 UTM or 4% of revenue.
"We get requests to delete data or see what we hold, and we handle them by hand."
At scale, handling ARSOP rights without a process or SLA means deadlines lapse. Non-compliance is a serious violation.
Sanctions are published in the National Registry administered by the Agency. The reputational damage —hard to measure, impossible to reverse— often outweighs the financial one.
How do I get ready? →Imagine that tomorrow the Agency requires you to prove that a specific customer authorized the use of their data. How long does it take your team to pull the evidence together?
Without a system: days digging through spreadsheets and folders. Risk of error and a penalty for failing to demonstrate compliance.
With AlayIAtrust: you search the name and the entire trail appears — consents, data subject requests, notice version, date and channel.
We're already implementing Law 21.719 in retail and consumer companies in Chile. We combine over 20 years of experience in complex projects with our own methodology for diagnosis, prioritization, plan, execution and ongoing operation. These are the components we leave up and running inside your organization.
Records of processing activities (RoPA): which data you process, for what purpose and on what basis.
We define and document the legal basis for every personal-data processing activity.
Processes to handle access, rectification, erasure, objection and portability within deadline.
A procedure to detect, contain and notify incidents to the Agency and to data subjects.
Processing clauses and contracts (DPAs) with vendors and third parties that access data.
Data protection impact assessments (DPIAs) for high-risk processing, when applicable.
Roles, internal policies and team training to sustain compliance over time.
Privacy notices, policies and evidence organized and ready for an audit.
Most organizations don't know what to do first or who should lead it. We hand you a clear roadmap from day one.
30 minutes, no obligation. We assess processing activities, risks and gaps against Law 21.719.
This weekWe rank findings by regulatory risk and business impact.
FocusA prioritized roadmap: what to do first, who on your team leads it and which solution fits.
2 — 4 weeksLegal and operational implementation plus technology enablement: contracts, policies, consents and training.
1 — 6 monthsMonitoring, internal audits and support in the event of an audit.
ContinuousAn enterprise implementation takes 3 — 6 months; an SME solution, 1 — 4 months. It's best to start early so you're ready in time.
Initial assessmentWe are not a startup selling a basic platform, nor a global consultancy operating from abroad. We work as your team in Chile — legal counsel, OneTrust technology and support throughout the process, in a single team and 100% on the ground.
Specialized lawyers + data engineers in a single team. Most firms sell you software only or consulting only — we take you to compliance.
A full team on the ground. We live the Chilean regulatory framework every day — we are no one's branch office.
An Alaya Digital Solutions company, advising large organizations since 2005.
Experience in complex governance, security and digital transformation projects for leading clients in banking, retail, mining and the public sector.
You already know the law, the risks and the way we work. These are the two implementation paths we offer. We help you choose the right one based on the size and maturity of your organization.
Fast implementation
Everything you need to comply with the law without the complexity of an enterprise solution. Simpler, faster, ready in a few months.
For exporters, fisheries, distributors and construction firms.
World-leading technology
For organizations with large data volumes, multiple systems and the highest regulatory demands. A platform used by large organizations worldwide.
For banking, retail, holdings and multinationals.
Not sure which one is right for you? We'll figure it out together in 30 minutes, no obligation. Book an assessment →
The first step is to know which cookies and trackers you actually load, for what purpose, and which third parties are involved. From there, you define the legal basis for each use and adjust the site's consent mechanism so the customer can make an informed decision before advertising or profiling tracking is activated.
Profiling purchasing habits is not prohibited, but it must rest on a valid legal basis and on transparency toward the customer about how their data is used. We help document these uses, review the cross-referencing of information between channels, and make clear to the data subject that they can exercise their ARSOP rights over the profile being built.
Each channel and each external provider, whether for payment, shipping or marketing, adds points where data is copied and shared. The challenge is to have visibility of that flow and to know who is accountable at each stage. We work on that complete map so the same customer receives consistent treatment and you can respond to their requests no matter where they purchased.
To any natural or legal person, public or private, that processes personal data in Chile. It also applies to foreign companies that offer goods or services in the territory.
The initial assessment carries no obligation. We schedule a 30-minute meeting, evaluate your situation and deliver a report with gaps and concrete recommendations.
It depends on size and digital maturity. An SME solution is implemented in 1 to 4 months. An enterprise solution takes 3 to 6 months. That's why we recommend starting now.
We work with both profiles. We have solutions designed specifically for SMEs and mid-market, and enterprise solutions for banking, retail and multinationals.
Three things: we are 100% on the ground in Chile, we combine legal counsel with technology in the same team, and we have 20 years of experience with clients in banking, retail, mining and the public sector.
Each sector processes different data and faces its own risks. See the approach for yours.
Start with an assessment. In 30 minutes you'll know how far —or how close— you are to compliance.