Enforcement begins
Dec 2026
The Data Protection Agency begins enforcement on December 1.
Health data (sensitive), automated underwriting and profiling, reinsurance and claims: the sector with the most sensitive data per policy. We implement Law 21.719 to be ready for the December 2026 enforcement.
No obligation · Reply within 24 business hours
Organizations that have trusted Alaya Digital Solutions
We support insurers, brokers and administrators in handling sensitive data and complying with Law 21.719.







Dec 2026
The Data Protection Agency begins enforcement on December 1.
Every
company
Public or private, large or SME. If you process personal data, you must comply.
20k UTM
Over CLP 1.39 billion. For the most serious violations, also 4% of annual revenue.
Assessment
Know where you stand. Then: roadmap, implementation and ongoing support.
The insurance business runs on people's most intimate data: health, claims histories, and risk profiles. That raw material is precisely what Law 21.719 protects with the highest demands, which makes compliance more challenging here than in almost any other sector.
To price and underwrite policies, insurers process health data, diagnoses, and medical histories. Law 21.719 grants sensitive data stronger protection, so every use must rest on a clear legal basis and on safeguards proportional to its sensitivity.
Handling a claim accumulates medical reports, expert assessments, photographs, and statements. That file concentrates sensitive information that moves between areas and third parties, and demands access controls, minimization, and traceability over who consults each piece of the insured's data and for what purpose.
Brokers, loss adjusters, and reinsurers access policyholder data as part of the chain. Every transfer must be backed by a contract and recorded, because the insurer remains responsible for that data even when it leaves its systems and reaches a third party.
Segmenting and setting premiums through automated profiling means processing policyholder data to decide terms and price. ARSOP rights apply to such processing, so pricing models need transparency, documented criteria, and channels for the insured to access or object to the processing of their data.
At AlayIAtrust, we approach insurance from its most critical point: sensitive data. We map where health and claims data originate and circulate, build the specific RAT for underwriting, claims handling, and reinsurance, and apply a DPIA wherever profiling and pricing justify it because of their impact on people.
We also organize the chain of brokers, loss adjusters, and reinsurers with agreements and records that demonstrate control, prepare the response to policyholders' ARSOP rights, and have breach notification ready. Before December 1, 2026, when full enforcement by the Personal Data Protection Agency begins, your operation is left with demonstrable evidence and processes.
The new Data Protection Agency investigates on complaint or on its own initiative. These are the most frequent scenarios in practice.
"We use medical history to price and renew policies, as always."
Health data is sensitive: it requires specific consent and, often, a DPIA. Processing it without a reinforced basis is a most-serious violation.
"The system rejects or raises prices, but we can't justify each decision."
The data subject can demand information about automated decisions and profiling. Without traceability or basis, it's a serious violation.
"We send records to reinsurers and providers as part of the process."
Every transfer needs a lawful basis and a processing contract (DPA). Transferring without grounds passes the risk down the chain.
Sanctions are published in the National Registry administered by the Agency. The reputational damage —hard to measure, impossible to reverse— often outweighs the financial one.
How do I get ready? →Few industries concentrate so much sensitive data per customer. These are the fronts Law 21.719 watches most closely in insurance.
Medical history, exams and declarations: sensitive data requiring reinforced consent and, often, an impact assessment.
Automated pricing and acceptance: the data subject can request an explanation of decisions that affect them.
Reinsurers, clinics and adjusters are processors: each flow needs a processing contract and guarantees.
Third-party data, beneficiaries and claimants: traceability and a lawful basis across the claim lifecycle.
Imagine that tomorrow the Agency requires you to prove that a specific customer authorized the use of their data. How long does it take your team to pull the evidence together?
Without a system: days digging through spreadsheets and folders. Risk of error and a penalty for failing to demonstrate compliance.
With AlayIAtrust: you search the name and the entire trail appears — consents, data subject requests, notice version, date and channel.
We implement Law 21.719 in insurers and other players in the financial and health sectors in Chile. We combine over 20 years of experience in complex projects with our own methodology for diagnosis, prioritization, plan, execution and ongoing operation. These are the components we leave up and running inside your organization.
Records of processing activities (RoPA): which data you process, for what purpose and on what basis.
We define and document the legal basis for every personal-data processing activity.
Processes to handle access, rectification, erasure, objection and portability within deadline.
A procedure to detect, contain and notify incidents to the Agency and to data subjects.
Processing clauses and contracts (DPAs) with vendors and third parties that access data.
Data protection impact assessments (DPIAs) for high-risk processing, when applicable.
Roles, internal policies and team training to sustain compliance over time.
Privacy notices, policies and evidence organized and ready for an audit.
Most organizations don't know what to do first or who should lead it. We hand you a clear roadmap from day one.
30 minutes, no obligation. We assess processing activities, risks and gaps against Law 21.719.
This weekWe rank findings by regulatory risk and business impact.
FocusA prioritized roadmap: what to do first, who on your team leads it and which solution fits.
2 — 4 weeksLegal and operational implementation plus technology enablement: contracts, policies, consents and training.
1 — 6 monthsMonitoring, internal audits and support in the event of an audit.
ContinuousAn enterprise implementation takes 3 — 6 months; an SME solution, 1 — 4 months. It's best to start early so you're ready in time.
Initial assessmentWe are not a startup selling a basic platform, nor a global consultancy operating from abroad. We work as your team in Chile — legal counsel, OneTrust technology and support throughout the process, in a single team and 100% on the ground.
Specialized lawyers + data engineers in a single team. Most firms sell you software only or consulting only — we take you to compliance.
A full team on the ground. We live the Chilean regulatory framework every day — we are no one's branch office.
An Alaya Digital Solutions company, advising large organizations since 2005.
Experience in complex governance, security and digital transformation projects for leading clients in banking, retail, mining and the public sector.
You already know the law, the risks and the way we work. These are the two implementation paths we offer. We help you choose the right one based on the size and maturity of your organization.
Fast implementation
Everything you need to comply with the law without the complexity of an enterprise solution. Simpler, faster, ready in a few months.
For exporters, fisheries, distributors and construction firms.
World-leading technology
For organizations with large data volumes, multiple systems and the highest regulatory demands. A platform used by large organizations worldwide.
For banking, retail, holdings and multinationals.
Not sure which one is right for you? We'll figure it out together in 30 minutes, no obligation. Book an assessment →
Because Law 21.719 protects health data with a stronger standard, and underwriting and claims depend precisely on that information. Keeping it safeguarded is not enough: you must have a legal basis for each use, limit who has access, and ensure the processing is proportional. That is why the sector's processes require stricter controls than those of other industries.
The insurer remains responsible for its policyholders' data even when it shares them with brokers, loss adjusters, or reinsurers. Every transfer must be backed by a contract, recorded, and limited to what is necessary. At AlayIAtrust, we organize that chain so each party has a defined role and responsibility is documented.
Yes. Profiling to set premiums processes policyholder data to decide their terms, and ARSOP rights, which include the right to object, apply to such processing. This does not prevent pricing, but it requires documented criteria, transparency toward the insured, and mechanisms for them to access their information or object when appropriate.
To any natural or legal person, public or private, that processes personal data in Chile. It also applies to foreign companies that offer goods or services in the territory.
The initial assessment carries no obligation. We schedule a 30-minute meeting, evaluate your situation and deliver a report with gaps and concrete recommendations.
It depends on size and digital maturity. An SME solution is implemented in 1 to 4 months. An enterprise solution takes 3 to 6 months. That's why we recommend starting now.
We work with both profiles. We have solutions designed specifically for SMEs and mid-market, and enterprise solutions for banking, retail and multinationals.
Three things: we are 100% on the ground in Chile, we combine legal counsel with technology in the same team, and we have 20 years of experience with clients in banking, retail, mining and the public sector.
Each sector processes different data and faces its own risks. See the approach for yours.
Start with an assessment. In 30 minutes you'll know how far —or how close— you are to compliance.