complianceley-21719

Chile's Law 21.719: what your company should have ready before December

The law takes effect on 1 December 2026. Most companies we have reviewed are not behind on tooling — they are behind on inventory: they don't know what data they hold or where it lives.

By Equipo Arvontec
· 1 min read

Law 21.719 starts applying in a few months, and this year's reviews keep showing the same pattern: the conversation starts with tooling and ends somewhere far more basic. Nobody is clear on what personal data the company processes, where it lives, or who touches it.

It is not a budget problem. The inventory was never done, and without an inventory everything else is guesswork.

The processing register is not paperwork

Registers get a bad reputation because they are usually filled in as a formality. But it is the only thing that lets you answer three questions the regulator will ask, and that your own team cannot answer today:

  • What personal data do you process, for what purpose, and under what legal basis?
  • How long do you keep it, and who decided that period?
  • Which third parties receive it, and what contract backs that up?

If those answers are not written down, you don't have compliance. You have intent.

Nota

The register is also the best technical tool you will get. An honest data inventory exposes forgotten integrations, backups nobody deletes, and access still granted to people who no longer work with you.

Where to start if you are late

Order matters more than speed. Running an impact assessment before you have the inventory means assessing the risk of something you cannot yet describe.

  • Inventory of processing activities, even an imperfect one.
  • Contracts with processors: identify vendors touching data and formalise.
  • Retention policy with concrete periods and a named owner.
  • Data-subject rights procedure, with a measured response time.
  • Only then, impact assessments where the risk warrants one.

If you want a concrete review of where you stand, get in touch. The first conversation is a diagnostic, not a sales pitch.

Equipo Arvontec
Ciberseguridad y cumplimiento

Notas escritas a varias manos por quienes están en los proyectos. Si algo de acá te sirve o te parece discutible, escríbenos.

Does any of this sound familiar?

Let us talk, no strings attached. The first meeting is a diagnostic, not a sales pitch.

Book a diagnostic

Keep reading.

socoperations

Your SOC doesn't need more alerts, it needs fewer

A SIEM firing 4,000 alerts a day isn't monitoring — it's producing noise someone has to ignore in order to work. And what gets ignored by habit also gets ignored on the day it matters.

Equipo Arvontec
July 15, 2026 · 1 min read
Back to the blog