Every time we talk about Law 21.719, Chile's new personal data protection law, with compliance, sales or technology teams, the same question comes up: what do I do with the customer database I already have? Thousands of records gathered over the years, with generic consents or none at all, purchased lists, trade show contacts and customers who have not bought anything in a decade.
The short answer: the law has no special regime for that data. Its transitional provisions set the effective date at December 1, 2026, the deadlines for the regulations and the setup of the Personal Data Protection Agency, but none of them gives existing databases a period to adapt. From that day on, all processing of personal data, including data collected before, must comply with the law.
The good news is that bringing a database up to date is a bounded job that can be done in order. We summarize it in six steps.
Why the database you already have is your biggest exposure
Three rules of the law clash with the way most databases were built:
The controller must be able to prove that the processing is lawful (arts. 3(a) and 13) and, if it relies on consent, prove that it has it (art. 12). An "I accept the terms" from ten years ago, with no record of what was accepted, is unlikely to prove it.
Data may only be used for the purposes disclosed when it was collected, unless the purposes are compatible, a contractual relationship justifies it, the data subject consents again or the law provides for it (art. 3(b), purpose limitation).
Data may only be kept for as long as it is needed for those purposes; after that it must be deleted or anonymized (art. 3(c), proportionality).
On top of that comes the duty to inform: the controller must make available to the public, among other things, the categories of data it processes, its purposes, the lawful basis, the retention period and the source of the data (art. 14 ter).
Six steps to bring it up to date
1. Inventory what you have and where it came from
Before deciding anything, you need to know what exists: which databases there are (the CRM, the ERP, spreadsheets, the email marketing tool, the backup nobody checks), which fields each one has, whether it includes sensitive data and, above all, where each record came from: collected by the company, purchased, received from a partner or inherited in a merger. The law requires data to be collected from lawful sources (art. 14(b)) and its source to be disclosed (art. 14 ter (j)).
2. Assign a lawful basis to each use, not to each database
This is the most important shift. The same database is used for several things, and each use needs its own lawful basis. A customer's email address can be processed to invoice them because there is a contract (art. 13(c)) and to meet a tax obligation (art. 13(b)), but that does not cover sending them offers. Doing this exercise splits the database into covered uses and uses that are not.
The bases the law recognizes are consent (art. 12) and those in art. 13: data on economic obligations under Title III, legal obligation, contract or pre-contractual measures, legitimate interest, and the establishment or defense of a right. Sensitive data generally requires express consent (art. 16).
3. Decide what to do with uses that have no basis
For each use left uncovered there are three paths: stop doing it, obtain consent going forward, or rely on legitimate interest. The latter is not a wildcard: it requires that the data subject's rights and freedoms are not affected, it is best documented with a balancing test, and the data subject may object at any time (art. 8(a)). When the processing is for direct marketing, the data subject may also object (art. 8(b)).
4. Clean up: delete or anonymize what no longer has a reason to be there
This is the step with the most impact and the one fewest people want to do. Customers inactive for years, prospects who never bought, fields collected "just in case": if there is no current purpose and no legal obligation to keep them, they are deleted or anonymized (art. 3(c)). The data subject may also request the deletion of data that is no longer needed, outdated or unlawfully obtained (art. 7). Every record deleted is a record that can no longer leak or trigger a request.
Before deleting, reconcile the retention periods required by other rules: tax, employment and, if your company is a reporting entity before Chile's Financial Analysis Unit, Law 19.913.
5. Inform your current customers
The duty to inform does not distinguish between new and old data. Update your privacy policy and notices with what art. 14 ter requires and make them available on your website and in the channels where you already deal with your customers. Informing is not asking for consent: it is telling people what you do with their data and on what basis.
6. Keep evidence of everything
The law rests on the accountability principle (art. 3(e)): what cannot be proven does not count before the Agency. Record the review, with dates and criteria: the inventory, the bases assigned, the balancing tests, what was cleaned up and when, and the version of the current notice. If you rely on consent, keep the date, scope and version of the text disclosed for each one.
If the database was purchased or received from a third party
This deserves its own section. Receiving a database is a transfer of data, and the law requires it to be documented in writing, with the parties, the data and the purposes (art. 15). If the transfer needed the data subjects' consent and did not have it, the transfer is void and whoever received the data must delete all of it (art. 15). Before December 1 it is worth reviewing the contracts under which those lists arrived and, if there is no backing, stop using them.
The mistake worth avoiding: the mass "update your details" email
The most common reaction is to send the whole database an email asking people to accept the new policy or confirm they want to keep receiving information. It seems prudent, but that email is already processing for commercial purposes, sent precisely to people whose consent cannot be proven.
There have already been fines for this in Europe. In 2017, the UK data protection authority fined Flybe £70,000 for sending more than 3.3 million emails titled "Are your details correct?", including to customers who had opted out, and Honda £13,000 for asking "Would you like to hear from Honda?" to contacts with no record of consent. It was a different law, but the logic is the same: you cannot use marketing to ask for permission to do marketing.
The alternative is to ask for consent going forward, in contacts that already happen for another reason: the next purchase, a login to your portal, a contract renewal. In the meantime, do not use that data for anything that has no basis.
What you should have at the end
Step | Document | What it proves |
|---|---|---|
Inventory | Record of processing activities | What data you process, where it comes from and why |
Assign bases | Lawful basis matrix | The basis for each use |
Decide | Legitimate interest balancing test | That the legitimate interest does not affect the data subject's rights |
Clean up | Retention and deletion schedule | How long each piece of data is kept and what happens when the period ends |
Inform | Privacy policy and notices by channel | What was disclosed and since when |
Keep evidence | Versioned consent log | Who consented, to what and with which text |
All six are editable deliverables of the Law 21.719 Toolkit. The documents are in Spanish, the language of the law.
Where to start
If you do not know what state your database is in, start by measuring. The Law 21.719 Self-Assessment is free and asks, among other things, whether you reviewed the source and lawful basis of the databases you already had, whether you defined retention periods and whether you keep evidence of each consent. When you finish, it gives you your findings, a four-wave action plan and the toolkit documents that close each gap. It takes 45 to 90 minutes, you can resume it whenever you want, and it is in Spanish.
Would you rather review it with someone? Talk to a specialist.
Articles cited from Law 19.628 as amended by Law 21.719, and transitional provisions of Law 21.719, verified at the Library of the National Congress of Chile on October 5, 2026. The Flybe and Honda fines were imposed by the UK Information Commissioner's Office in March 2017 under the UK electronic communications rules. Informational content: not legal advice.
Sources: Law 21.719 (BCN) (in Spanish) · Out-Law: ICO fines for Flybe and Honda