Snap Compliance
Contact us

Idioma

Start free
Asociaciones Chile Compliance Gestión de Riesgos Gobierno Corporativo Law 21.719 PYMES

Your customer database and Chile's Law 21.719: how to bring it up to date before December 1

The law also applies to the data your company already holds. Six steps to review, clean up and document your customer database, and the mistake worth avoiding.

By MSc. Alex Siles Loaiza - CEO at Snap Compliance 05 Oct 2026 8 min read

TL;DR

Chile's Law 21.719 takes effect on December 1, 2026, and its transitional provisions grant no special adaptation period for data collected before that date—all processing, including existing customer databases, must comply from day one. Controllers must be able to prove a lawful basis for every use of personal data, not just for each database as a whole, and must delete or anonymize records that no longer serve a documented purpose. The six steps to bring a database into compliance are: inventory sources, assign a lawful basis to each use, decide what to do with uncovered uses, delete or anonymize stale data, update privacy notices, and keep versioned evidence of every decision. Sending a mass 'update your details' email to obtain retroactive consent is itself unlawful processing and has already resulted in regulatory fines in Europe.

Every time we talk about Law 21.719, Chile's new personal data protection law, with compliance, sales or technology teams, the same question comes up: what do I do with the customer database I already have? Thousands of records gathered over the years, with generic consents or none at all, purchased lists, trade show contacts and customers who have not bought anything in a decade.


The short answer: the law has no special regime for that data. Its transitional provisions set the effective date at December 1, 2026, the deadlines for the regulations and the setup of the Personal Data Protection Agency, but none of them gives existing databases a period to adapt. From that day on, all processing of personal data, including data collected before, must comply with the law.


The good news is that bringing a database up to date is a bounded job that can be done in order. We summarize it in six steps.

Why the database you already have is your biggest exposure

Three rules of the law clash with the way most databases were built:

  • The controller must be able to prove that the processing is lawful (arts. 3(a) and 13) and, if it relies on consent, prove that it has it (art. 12). An "I accept the terms" from ten years ago, with no record of what was accepted, is unlikely to prove it.

  • Data may only be used for the purposes disclosed when it was collected, unless the purposes are compatible, a contractual relationship justifies it, the data subject consents again or the law provides for it (art. 3(b), purpose limitation).

  • Data may only be kept for as long as it is needed for those purposes; after that it must be deleted or anonymized (art. 3(c), proportionality).

On top of that comes the duty to inform: the controller must make available to the public, among other things, the categories of data it processes, its purposes, the lawful basis, the retention period and the source of the data (art. 14 ter).

Six steps to bring it up to date

1. Inventory what you have and where it came from

Before deciding anything, you need to know what exists: which databases there are (the CRM, the ERP, spreadsheets, the email marketing tool, the backup nobody checks), which fields each one has, whether it includes sensitive data and, above all, where each record came from: collected by the company, purchased, received from a partner or inherited in a merger. The law requires data to be collected from lawful sources (art. 14(b)) and its source to be disclosed (art. 14 ter (j)).

2. Assign a lawful basis to each use, not to each database

This is the most important shift. The same database is used for several things, and each use needs its own lawful basis. A customer's email address can be processed to invoice them because there is a contract (art. 13(c)) and to meet a tax obligation (art. 13(b)), but that does not cover sending them offers. Doing this exercise splits the database into covered uses and uses that are not.


The bases the law recognizes are consent (art. 12) and those in art. 13: data on economic obligations under Title III, legal obligation, contract or pre-contractual measures, legitimate interest, and the establishment or defense of a right. Sensitive data generally requires express consent (art. 16).

3. Decide what to do with uses that have no basis

For each use left uncovered there are three paths: stop doing it, obtain consent going forward, or rely on legitimate interest. The latter is not a wildcard: it requires that the data subject's rights and freedoms are not affected, it is best documented with a balancing test, and the data subject may object at any time (art. 8(a)). When the processing is for direct marketing, the data subject may also object (art. 8(b)).

4. Clean up: delete or anonymize what no longer has a reason to be there

This is the step with the most impact and the one fewest people want to do. Customers inactive for years, prospects who never bought, fields collected "just in case": if there is no current purpose and no legal obligation to keep them, they are deleted or anonymized (art. 3(c)). The data subject may also request the deletion of data that is no longer needed, outdated or unlawfully obtained (art. 7). Every record deleted is a record that can no longer leak or trigger a request.


Before deleting, reconcile the retention periods required by other rules: tax, employment and, if your company is a reporting entity before Chile's Financial Analysis Unit, Law 19.913.

5. Inform your current customers

The duty to inform does not distinguish between new and old data. Update your privacy policy and notices with what art. 14 ter requires and make them available on your website and in the channels where you already deal with your customers. Informing is not asking for consent: it is telling people what you do with their data and on what basis.

6. Keep evidence of everything

The law rests on the accountability principle (art. 3(e)): what cannot be proven does not count before the Agency. Record the review, with dates and criteria: the inventory, the bases assigned, the balancing tests, what was cleaned up and when, and the version of the current notice. If you rely on consent, keep the date, scope and version of the text disclosed for each one.

If the database was purchased or received from a third party

This deserves its own section. Receiving a database is a transfer of data, and the law requires it to be documented in writing, with the parties, the data and the purposes (art. 15). If the transfer needed the data subjects' consent and did not have it, the transfer is void and whoever received the data must delete all of it (art. 15). Before December 1 it is worth reviewing the contracts under which those lists arrived and, if there is no backing, stop using them.

The mistake worth avoiding: the mass "update your details" email

The most common reaction is to send the whole database an email asking people to accept the new policy or confirm they want to keep receiving information. It seems prudent, but that email is already processing for commercial purposes, sent precisely to people whose consent cannot be proven.


There have already been fines for this in Europe. In 2017, the UK data protection authority fined Flybe £70,000 for sending more than 3.3 million emails titled "Are your details correct?", including to customers who had opted out, and Honda £13,000 for asking "Would you like to hear from Honda?" to contacts with no record of consent. It was a different law, but the logic is the same: you cannot use marketing to ask for permission to do marketing.


The alternative is to ask for consent going forward, in contacts that already happen for another reason: the next purchase, a login to your portal, a contract renewal. In the meantime, do not use that data for anything that has no basis.

What you should have at the end

Step

Document

What it proves

Inventory

Record of processing activities

What data you process, where it comes from and why

Assign bases

Lawful basis matrix

The basis for each use

Decide

Legitimate interest balancing test

That the legitimate interest does not affect the data subject's rights

Clean up

Retention and deletion schedule

How long each piece of data is kept and what happens when the period ends

Inform

Privacy policy and notices by channel

What was disclosed and since when

Keep evidence

Versioned consent log

Who consented, to what and with which text

All six are editable deliverables of the Law 21.719 Toolkit. The documents are in Spanish, the language of the law.

Where to start

If you do not know what state your database is in, start by measuring. The Law 21.719 Self-Assessment is free and asks, among other things, whether you reviewed the source and lawful basis of the databases you already had, whether you defined retention periods and whether you keep evidence of each consent. When you finish, it gives you your findings, a four-wave action plan and the toolkit documents that close each gap. It takes 45 to 90 minutes, you can resume it whenever you want, and it is in Spanish.


Would you rather review it with someone? Talk to a specialist.


Articles cited from Law 19.628 as amended by Law 21.719, and transitional provisions of Law 21.719, verified at the Library of the National Congress of Chile on October 5, 2026. The Flybe and Honda fines were imposed by the UK Information Commissioner's Office in March 2017 under the UK electronic communications rules. Informational content: not legal advice.


Sources: Law 21.719 (BCN) (in Spanish) · Out-Law: ICO fines for Flybe and Honda

Frequently asked questions

Yes. The law has no special regime for existing databases: its transitional provisions set the effective date at December 1, 2026 and give no adaptation period. From that day on, all processing of personal data must comply, regardless of when the data was collected.

Not necessarily. Many uses rely on another lawful basis, such as a contract or a legal obligation (art. 13). Consent is needed for the uses that depend on it and for those where you cannot prove you obtained it. It is best requested going forward, in a contact that already happens for another reason, not through a mass email.

Review the contract under which you received it. The transfer must be documented in writing with the parties, the data and the purposes, and if it needed the data subjects' consent and did not have it, it is void and whoever received the data must delete all of it (art. 15).

Only as long as needed to fulfil the purposes of the processing; after that it must be deleted or anonymized. A longer period requires legal authorization or the data subject's consent (art. 3(c)). Retention obligations under other rules, such as tax law, are reconciled in a retention schedule.

Not for bringing databases up to date. The only transitional rule on sanctions is that, during the first twelve months, the Agency may sanction companies classified as smaller enterprises under Law 20.416 with a written warning (sixth transitional article). It is a power of the Agency, not an exemption.