If you use data about clients, employees or suppliers, Law 21,719 already applies to you

Do you keep a client database, employee files or supplier contacts (national ID numbers, emails, phones)? Then you already process personal data, and even if it sits on a third-party platform, you are the one using it. There are 4 months left before the law takes effect, and fines reach over CLP 1.4 billion and, in certain cases, up to 4% of your annual revenue, whichever is higher. We help you get there with defensible evidence before that date.

Law 21,719: in force 1 Dec 2026
Reduce risk (15-min assessment)

Fines • Inspections • Reputation

Does your company process personal data? Almost certainly yes

The law regulates processing, not just storage: if you use data about individuals, even when it lives in a third party's system, you are responsible. It protects any person, not only your clients.

Clients

Client database and marketing

Spreadsheets with ID numbers, emails and phones; email campaigns; web forms; sales records. All of that is processing of personal data.

CRM / ExcelEmail marketing
Employees

Your employees' data

Contracts, payroll, personnel files, performance reviews and health data (sick leave, insurance). These are personal data, several of them sensitive, under your responsibility.

HRSensitive data
Suppliers

Contacts and suppliers

ID numbers, emails and phones of individuals you work with: suppliers, contractors, business contacts. They also count as personal data.

ContactsContractors

You are probably already non-compliant without knowing it

Most SMBs break the law through practices that look harmless. No bad intent is needed: operating as usual is enough. These are the most common cases.

Marketing

Sending emails without consent

Sending campaigns or promotions to contacts who never expressly authorised the use of their data for that purpose.

Consent
Retention

Keeping former employees' data

Holding on to files, contracts or data about people who no longer work with you, with no retention policy or defined period.

Data policy
Transparency

Having no way to exercise rights

Not offering a clear channel for clients or employees to access, correct or delete their data when they ask.

Data subject rights
Third parties

Sharing data without control

Passing data to providers, platforms or contractors with no contract or safeguards on how they use and protect it.

Processors

What is at stake: penalties and consequences

The fine is not a minor cost: it is calculated by severity and can escalate with repeat offences. On top of that, measures can be imposed that halt operations and damage reputation.

Minor

A warning or up to 5,000 UTM (over CLP 350 million)

Formal breaches (for example, minor information or policy failures). It still leaves a record and can escalate if repeated.

Over CLP 350 millionWarning
Serious

Up to 10,000 UTM (over CLP 700 million)

Conduct or omissions that compromise the lawfulness or security of the processing (for example, not answering valid data subject requests).

Over CLP 700 millionGreater impact
Very serious

Up to 20,000 UTM (over CLP 1.4 billion) and, in certain cases, a % of revenue

Systematic or intentional violations, processing without a legal basis or affecting sensitive data. On repeat offences, and if you are not a smaller company (Law 20,416), the penalty can reach 4% of annual sales revenue (as applicable).

Over CLP 1.4 billionUp to 4% of revenue
Escalation

Surcharges and repeat offences (it hurts fast)

The authority can order corrective measures. If they are not adopted in time, a surcharge applies. And with repeat offences, the fine can be multiplied or calculated as a percentage of revenue.

  • A 50% surcharge if you do not adopt the ordered measures within 60 days.
  • Repeat offences: the Agency can apply up to 3 times the amount.
  • If you are not a smaller company and repeat a serious/very serious offence: up to 2% or 4% of annual revenue.
50%x32% / 4%

It is not only a fine: measures that can paralyse you

Beyond the money, corrective measures can be imposed: suspension of processing, an obligation to change practices and publication of the penalty. Individuals can also be held liable in serious cases.

Book an assessment See packages

Getting ready costs a fraction of what you are risking

This is the calculation worth doing before 1 December. The investment in compliance is predictable and bounded; the fine is not.

Getting ready Thousands A preventive audit with evidence: a planned cost that also puts your operation in order.
vs
Staying exposed Millions A single very serious infringement reaches over CLP 1.4 billion, plus surcharges, suspension of operations and reputational damage.

What we do and how long it takes

It is not an endless procedure or a black box. It is a bounded process, with clear deliverables, so you reach 1 December with backing.

Step 1

Assessment

We review how you handle data today and where your gaps are against the law. You leave with a clear map of your real risk.

Week 1
Step 2

Prioritised plan

A 30/60/90 plan that sets out what to fix first by impact and effort, without slowing down your operation.

Weeks 2–3
Step 3

Defensible evidence

We implement controls and leave documented traceability, so that if you are inspected you can demonstrate due diligence.

Ongoing

Getting ready is an expense you control; the fine is a loss you do not. And 1 December is not moving: getting compliant takes months, not days, so starting now is what makes the difference between arriving with backing and arriving late.

Start with an assessment

Who is behind this: multinational standards, applied to your company

We take the standards used to audit large companies and bring them down to SMBs, startups and local businesses, at their scale and budget.

Backing

The standard of an established consultancy

Our training in implementation and regulatory compliance comes from a consultancy with more than 25 years of experience, working with national and international companies applying Law 21,719 alongside ISO/IEC 27701 and GDPR standards. We bring that same level of rigour to companies that normally cannot access it.

25+ yearsISO 27701
Team

Engineers, not just consultants

The team is made up of computer engineers trained in cybersecurity and information security. We understand your systems from the inside, not just the compliance paperwork.

Computer engineersCybersecurity
Certifications

IBM-certified training

We hold IBM certifications in applying ISO standards, data security and the use of compliance frameworks. A recognised methodology, not an improvised one.

IBMISO / Frameworks
Scope

International experience

We have worked in multinational companies, building international experience in compliance and information security. We know what it takes to operate under more than one regulatory framework.

MultinationalInternational

The same technical rigour a multinational demands, without the fees of a large consultancy. Your compliance is handled by a certified engineer, closely and with dedication.

Frequently asked questions

What a business owner usually asks when they hear the word fines.

How much can a Law 21,719 fine cost?
There are three levels: minor (a warning or up to 5,000 UTM, over CLP 350 million), serious (up to 10,000 UTM, over CLP 700 million) and very serious (up to 20,000 UTM, over CLP 1.4 billion). The Agency can order corrective measures; if they are not adopted within 60 days, the fine can carry a 50% surcharge. With repeat offences, it can reach 3 times the amount or be calculated as a percentage of revenue (2% or 4%, as applicable).
Does the law apply to my employees' and suppliers' data?
Yes. Law 21,719 protects the data of any individual, not only your clients. Your employees' data (contracts, payroll, files, reviews, health data) and that of suppliers and contacts (ID numbers, emails, phone numbers of individuals) are also covered. And since the law regulates processing, not just storage, even if the data sits on a third party's platform, you are the one using it and you are responsible. If you have employees, you already process personal data and the law applies to you.
When does it take effect?
Law 21,719 takes effect on 1 December 2026. From that date the Personal Data Protection Agency can inspect and impose penalties. Since getting compliant (assessment, remediation and evidence) takes months, it is worth starting early rather than leaving it to the last month.
What counts as an infringement in practice?
Typical examples: failures to inform the data subject (minor), not answering valid requests (serious) or processing data without a legal basis / affecting sensitive data (very serious). Security breaches, international transfers outside the rules and failure to report incidents when required can also weigh in.
What else can happen besides the fine?
The authority can impose corrective measures: suspending processing activities, requiring practices to be changed or removed, and publishing the penalty. In serious cases, liability can even extend to individuals (directors or officers) for wilful misconduct or gross negligence.
How does Novas Metrics help?
We help you reduce risk with defensible evidence: we implement what you are missing to comply with Law 21,719, with prioritised gaps, a staged plan, controls and traceability. The idea is that, if you are inspected, you have backing and can demonstrate due diligence.

This page is informative and does not replace legal advice. Amounts in pesos are indicative; the UTM is updated monthly.

The cheapest way to lower a fine is to avoid the infringement

The authority takes into account repeat offences, negligence and whether preventive measures exist. Having processes in place and evidence helps you demonstrate due diligence and reduce the risk of penalties.

Get an assessment See packages

Send request

We reply within 24h with a proposal tailored to your company.

Confidential No spam Reply within 24h

By submitting, you accept our Privacy Policy. We use your data only to answer your request.