Getting ready for Chile's Law 21.719 on personal data protection
We prepare your team. Then we review the systems where the data actually lives.
Certified training, designated owners, and baseline documentation, with the SENCE subsidy. Then, the part almost nobody does: verifying in your applications and databases that what's declared on paper actually holds up.
How Law 21.719 readiness works: four stages
One roadmap, four stages.
Preparing your people and fixing your systems are different jobs, with different timelines and funding. We run them end to end, in the order that actually holds up.
Organizational readiness
Ten guided hours plus certified e-learning. Leaves designated owners, defined procedures, and the supporting documentation kit.
Technical assessment
We compare what the organization declared against what the databases actually contain. Risk-prioritized gap report.
System fixes
The development work that closes the gaps found: access, audit trails, export and deletion, test environments.
Continuity
Whatever gets built from here on is born compliant, and data subject requests get answered without improvising.
Stages 2 through 4 are software engineering work, and that's where we're different: we're a development company, not a consultancy that outsources the technical part. We run stage 1 together with an OTEC, which is what unlocks the tax subsidy.
Why readiness doesn't end with documentation
Documentation describes intent. Systems show the facts.
Stage 1 leaves the organization orderly and formally backed. It's necessary and it's not enough: the processing activities record gets filled with what each department declares, not with what the databases actually store. Almost the entire market stops right there.
What organizational readiness leaves behind
- Data processing policy and procedure
- Declared processing activities matrix
- Data subject rights procedure
- Incident procedure and access criteria
- Trained team with designated owners
What no document answers
- What personal data does each system store, and in which table?
- Is there a record of who accessed it?
- Can the system export or delete a person's data?
- Are there production copies in development and QA environments?
- Which external vendors receive data, and from where?
A processing activities record verified against the systems is what separates being prepared from just looking prepared.
Free diagnostic: how ready is your company?
How much of your compliance actually lives in your systems.
Twelve questions about the state of your applications and databases. Instant results by area, no contact details required.
—
Get the breakdown by area
We'll send you the breakdown of your answers, the prioritized gaps, and a proposed sequence between preparing your team and working on your systems.
—
Organizational readiness
Ten hours of guided intervention plus a certified e-learning course running in parallel. Every session produces a document: if a session doesn't leave a deliverable, it's not in the program.
- 2 h · in personExecutive kick-offWhat changes, what a data subject can request, and who answers for each area. Closes with the designation of the implementation team.
- 4 h · in personData governanceWorking session: processing activities by area, purpose, legal basis, retention periods, and vendors that receive data.
- 2 h · onlineSecurity and informationAccess and confidentiality criteria. What counts as an incident, how it's detected, and the escalation timeline.
- 2 h · onlineOperations and complianceHow a data subject's request is received and answered, what evidence gets kept, and how a corporate client's questionnaire gets answered.
- AsyncCertified e-learningFor the entire headcount, with assessment, completion tracking, and an individual certificate.
Evidence kit
- Training
Trained staff and individual certificates. - Governance
Policy, procedure, and activities matrix. - Rights
Data subject request procedure. - Security
Incident procedure and access criteria. - Continuity
Implementation plan and final report. - Principals
Backup for answering your clients' requirements.
Technical review of systems and databases
We're a software development company. We do this part with our own team, on the technology your company already has.
Technical assessment
Three weeks to compare what's declared against what the databases actually contain.
- Inventory of systems and personal data
- Review of access, encryption, and audit trails
- Third parties that receive data, and where they're hosted
- Risk-prioritized report with estimated effort
System fixes
The development work that closes the gaps found, in scoped stages.
- Encryption of sensitive fields
- Audit logging and role-based access control
- Export and deletion of a data subject's data
- Anonymization of development and QA environments
- Automated retention and deletion
Continuity
So that whatever gets built from here on is born compliant, without redoing it later.
- Architecture and data model review
- Minimization and retention criteria
- Requirements review before development
- Working with your internal team or your vendor
Independent of the technology
The review criteria is the same in every case; what changes is the implementation. We also work on systems whose original vendor is no longer available.
Articles about Law 21.719
- Real data in test environments and Law 21.719
Almost every company with in-house development has real customer data in QA. What Law 21.719 requires about it and how to fix it at three levels.
Frequently asked questions about Law 21.719 readiness
What people ask us before getting started.
Can we hire just the training, or just the technical part?
Can the training be paid for with the SENCE subsidy?
Our lawyer is already handling this. Where do you fit in?
Does the law apply to small businesses?
Our software vendor says they've got it covered.
Do you only work with Microsoft technologies?
Does this leave us compliant with the law?
Can we be ready before December 1, 2026, the date currently in force?
A 30-minute meeting
We review where your company stands, what systems are behind it, and what sequence makes sense between preparing your team and the technical work. If nothing needs to happen yet, we'll tell you.
—