Skip to content
DisrupsoftDisrupsoft
Data Protection

Your DS 44 System Also Handles Personal Data: What Law 21.719 Requires

A complete DS 44 system accumulates names, national ID numbers, signatures, and health data for every worker. That is exactly the category of data Law 21.719 regulates most strictly — and both obligations come due almost at the same time.

Your DS 44 System Also Handles Personal Data: What Law 21.719 Requires

When a company builds its IPER Matrix, its IRL, its PPE records, and its accident investigations, it's doing two things at once without necessarily realizing the second one: complying with DS 44, and generating one of the most sensitive worker databases that exists inside the organization. Name, national ID number, signature, job title, risk-exposure history, and — in any accident investigation — health information.

Law 21.719 — whose full effective date currently in force is December 1, 2026, with a bill to postpone it pending — classifies health data as sensitive data, subject to a higher protection standard than ordinary personal data. A DS 44 system isn't a minor footnote to that obligation — it's likely one of the most active repositories of sensitive data a company with physical operations has.

Why this isn't a new problem — it's the same data regulated twice

Complying with Law 21.719 over this data doesn't require a new system — it requires that the system already in place (or being built) for DS 44 also be treated for what it is: a personal-data-processing activity that needs to be entered into the Register of Processing Activities (RAT), with its purpose, its legal basis, its retention periods, and who has access.

The good news is that the legal basis for this specific processing is already settled: it's compliance with a legal obligation (DS 44 and Law 16.744 themselves), not consent. That removes the most complex part of Law 21.719 for other kinds of processing — requesting and being able to prove consent — but it doesn't exempt the rest: security, data minimization, retention periods, and data subject rights still apply just the same.

The three overlaps almost no company has reviewed

1. Registering the activity in the RAT. If the mapping of processing activities done for Law 21.719 didn't explicitly include "DS 44 management" or "accident investigations" as its own activity, with its own analysis, the register is incomplete — and an incomplete register doesn't distinguish being prepared from merely looking prepared.

2. Security proportional to health data. An accident-investigation file containing a medical diagnosis shouldn't live in the same shared folder as the rest of the operational documentation, with the same access level for anyone in the prevention department. Law 21.719 requires security measures proportional to how sensitive the data is — not a single standard applied to all of a company's information.

3. Retention periods and worker rights. A worker who left the company five years ago, whose IPER, IRL, and PPE record are still sitting in the system with no defined retention criteria, is exactly the kind of finding a corporate client questionnaire or an inspection will surface. That worker also keeps access and rectification rights over their own data, even if the company isn't required to delete it because it's a legally mandated record.

One project, not two parallel initiatives

Treating the DS 44 system and Law 21.719 compliance as two separate projects usually ends with each team reviewing its own half and nobody reviewing the overlap between them. The more efficient approach runs the other way: when the DS 44 system is built or brought into order, declare that activity directly in the RAT as part of the same work, with the sensitive-data classification it requires and the security measures already built in from the design stage — not bolted on afterward as a patch.

The two obligations also share more than the data: they share the calendar. DS 44 is already in force and already being inspected; Law 21.719's full effective date currently in force is December 1, 2026 (see the regulatory update). A company that's putting its risk management system in order has, in that same process, the chance to resolve the overlap with data protection once and for all — instead of discovering it later as a separate finding.


If your company already has, or is building, its DS 44 system, Constata's DS 44 diagnostic reviews the state of the eight instruments, and the Law 21.719 diagnostic reviews the state of your processing activities — twelve questions each, immediate results, no contact details required.

Ds 44Ley 21719Proteccion DatosDatos Sensibles

← View more articles