Client database and marketing
Spreadsheets with ID numbers, emails and phones; email campaigns; web forms; sales records. All of that is processing of personal data.
Do you keep a client database, employee files or supplier contacts (national ID numbers, emails, phones)? Then you already process personal data, and even if it sits on a third-party platform, you are the one using it. There are 4 months left before the law takes effect, and fines reach over CLP 1.4 billion and, in certain cases, up to 4% of your annual revenue, whichever is higher. We help you get there with defensible evidence before that date.
Fines • Inspections • Reputation
The law regulates processing, not just storage: if you use data about individuals, even when it lives in a third party's system, you are responsible. It protects any person, not only your clients.
Spreadsheets with ID numbers, emails and phones; email campaigns; web forms; sales records. All of that is processing of personal data.
Contracts, payroll, personnel files, performance reviews and health data (sick leave, insurance). These are personal data, several of them sensitive, under your responsibility.
ID numbers, emails and phones of individuals you work with: suppliers, contractors, business contacts. They also count as personal data.
Most SMBs break the law through practices that look harmless. No bad intent is needed: operating as usual is enough. These are the most common cases.
Sending campaigns or promotions to contacts who never expressly authorised the use of their data for that purpose.
Holding on to files, contracts or data about people who no longer work with you, with no retention policy or defined period.
Not offering a clear channel for clients or employees to access, correct or delete their data when they ask.
Passing data to providers, platforms or contractors with no contract or safeguards on how they use and protect it.
The fine is not a minor cost: it is calculated by severity and can escalate with repeat offences. On top of that, measures can be imposed that halt operations and damage reputation.
Formal breaches (for example, minor information or policy failures). It still leaves a record and can escalate if repeated.
Conduct or omissions that compromise the lawfulness or security of the processing (for example, not answering valid data subject requests).
Systematic or intentional violations, processing without a legal basis or affecting sensitive data. On repeat offences, and if you are not a smaller company (Law 20,416), the penalty can reach 4% of annual sales revenue (as applicable).
The authority can order corrective measures. If they are not adopted in time, a surcharge applies. And with repeat offences, the fine can be multiplied or calculated as a percentage of revenue.
Beyond the money, corrective measures can be imposed: suspension of processing, an obligation to change practices and publication of the penalty. Individuals can also be held liable in serious cases.
This is the calculation worth doing before 1 December. The investment in compliance is predictable and bounded; the fine is not.
It is not an endless procedure or a black box. It is a bounded process, with clear deliverables, so you reach 1 December with backing.
We review how you handle data today and where your gaps are against the law. You leave with a clear map of your real risk.
A 30/60/90 plan that sets out what to fix first by impact and effort, without slowing down your operation.
We implement controls and leave documented traceability, so that if you are inspected you can demonstrate due diligence.
Getting ready is an expense you control; the fine is a loss you do not. And 1 December is not moving: getting compliant takes months, not days, so starting now is what makes the difference between arriving with backing and arriving late.
We take the standards used to audit large companies and bring them down to SMBs, startups and local businesses, at their scale and budget.
Our training in implementation and regulatory compliance comes from a consultancy with more than 25 years of experience, working with national and international companies applying Law 21,719 alongside ISO/IEC 27701 and GDPR standards. We bring that same level of rigour to companies that normally cannot access it.
The team is made up of computer engineers trained in cybersecurity and information security. We understand your systems from the inside, not just the compliance paperwork.
We hold IBM certifications in applying ISO standards, data security and the use of compliance frameworks. A recognised methodology, not an improvised one.
We have worked in multinational companies, building international experience in compliance and information security. We know what it takes to operate under more than one regulatory framework.
The same technical rigour a multinational demands, without the fees of a large consultancy. Your compliance is handled by a certified engineer, closely and with dedication.
What a business owner usually asks when they hear the word fines.
The authority takes into account repeat offences, negligence and whether preventive measures exist. Having processes in place and evidence helps you demonstrate due diligence and reduce the risk of penalties.
We reply within 24h with a proposal tailored to your company.