Law 21719 — Personal Data Protection

Prove you comply with Law 21719.
All-in-one platform for managing ARCO+ requests, consents and your RAT. Assisted Compliance with legal basis documented at every step.

SaaS platform that lets you:

  • Spot compliance gaps before the Agency does
  • Answer ARCO+ requests in days, not weeks
  • Collect consent with legal basis at every step
No commitmentDemo scheduled within 24 hours
ISO/IEC 27001Information Security

Does your company already know how to respond when the first ARCO+ request arrives?

An ARCO+ request is the legal mechanism by which a data subject exercises their rights of Access, Rectification, Cancellation, Opposition, Portability and Blocking against an organisation.

Law 21719 requires every company that processes personal data in Chile to maintain a formal process for receiving and responding to such requests within 30 calendar days, or risks fines from the Personal Data Protection Agency.

Retail
Healthcare
Fintech
Education
SaaS
Logistics

From the makers of23peopleChilean software engineering studio specialized in SaaS platforms for regulated markets.

The problem isn't the law.
It's proving you comply — to the Agency and to your principals.

How many systems in your company hold personal data today? When that first ARCO+ request arrives, you'll have 30 days to find it all, justify your legal basis for processing it, and respond properly. And that's just the beginning.

01
Regulatory riskThe Agency audits and fines

Who receives ARCO+ requests at your company?

The request lands in email, WhatsApp or the general contact form. Nobody sees it. The 30-day legal clock is already ticking — and the inbox owner is on vacation.

Do you know where the personal data you process is stored?

Your team hunts through the CRM, Buk, Google Drive — and spreadsheets scattered everywhere. Zero traceability. Hours of manual search. Risk of an incomplete answer.

Do you have your RAT, EIPD, and DPAs up to date?

Answering the request isn't enough. The law requires your RAT, Impact Assessments, DPA contracts with providers, and published privacy policies. Without them, the Agency will fine you regardless — starting at 5,000 UTM.

02
Commercial riskYour principals demand evidence

Your contracts depend on it

Large corporations are already auditing their suppliers. If your principal asks whether you're compliant with Law 21719, can you provide evidence? Your contract renewals and access to new bids depend on it.

The platform to comply with the law.
And prove it.

Six modules. Every legal obligation with its owner, its deadline and its evidence.

01

ARCO+ Request Management

Centralised panel to receive, assign and respond to Access, Rectification, Cancellation, Opposition, Portability and Blocking requests — with deadlines calculated in calendar days and alerts before each one expires.

  • Public URL ready for data subjects to submit requests 24/7.
  • Operate as Controller and Processor from a single account — ideal for holding groups and external DPOs.
  • Response templates parameterised by the legal grounds of Law 21719 — no need to draft each case.

Initial setup: less than 10 minutes. That same day, data subjects can already start submitting requests.

ARCO+ REQUEST TYPES
  • A
    Access
    Know which data is processed
    18
  • R
    Rectification
    Correct inaccurate data
    7
  • C
    Cancellation
    Delete or erase data
    14
  • O
    Opposition
    Object to processing
    9
  • P
    Portability
    Receive data in reusable format
    4
  • B
    Blocking
    Suspend processing
    2
02

Audit

Every action is logged with timestamp, owner and an immutable trail. When an auditor or the Agency asks for proof, you generate a certificate comparable to the F-30-1 previsional document.

  • Immutable log of every action with timestamp, actor and result.
  • Read-only access for external auditors — without compromising data integrity.
  • Monthly compliance certificate, analogous to the F-30-1 previsional document, ready to deliver to corporate principals.

Export in standard formats for regulatory inspection or supplier audits.

VERIFIED

Compliance Certificate

Law 21719 · Period December 2026

EmpresaYour Company S.A.
RUT76.123.456-7
  • Record of Processing Activities (RAT) current
  • 0 ARCO+ requests answered out of time
  • Consents captured with timestamp
  • Data Protection Impact Assessment (DPIA) signed
  • Encrypted backups verified
03

Structural Compliance

Map which personal data you process, where it lives, under which legal basis and when it must be erased — your RAT always ready to present.

  • Personal data mapping: what you collect, where it lives, who processes it and under which legal basis.
  • Record of Processing Activities (RAT) documented with every field required by law.
  • AI-assisted Data Protection Impact Assessments (DPIAs), plus DPA management with vendors like Buk or Google Drive.

Privacy policies generated aligned with your RAT — no drafting from scratch.

Record of Processing Activities
DataSystemLegal basisRetention
Customer emailSalesforce CRMConsentUntil withdrawal
Employee RUTBuk HREmployment contract5 years
Access logsAuth0Legitimate interest12 months
Health dataClinical systemConsent15 years
04

Consents

Every consent is captured with timestamp, document version and mechanism — and stays available for the data subject to review or revoke whenever they want, without going through your team.

  • Forms generated for cookies, RAT or DPIA with individual checkboxes per purpose (explicit opt-in, not pre-ticked).
  • Data Subject Portal so each person can review and revoke their consents autonomously.
  • Full traceability: timestamp, version of the accepted document, capture mechanism and link to the RAT.

Dual capture mechanism (API + email validation) — the cryptographic proof the Agency demands.

Consent Management
  • Analytics cookies
    Google Analytics
    Captured 12 Mar 2026
  • Marketing email
    Monthly newsletter
    Revoked 03 May 2026
  • Share with partners
    Commercial partners
    Not captured
  • Biometric processing
    Physical access
    Captured 02 Jan 2026
05

Integrations

Connect the systems where your data already lives — Buk for HR, Google Drive for documents — and add your internal sources via API and webhooks. Answering a request no longer means opening five tabs.

  • Native integrations with Buk (HR) and Google Drive (documents and evidence).
  • Events API for your dev team to connect internal sources and proprietary CRMs.
  • Automatic webhooks on request reception, deadline and closure — without checking the panel constantly.

Custom integration service available — evaluated case by case by 23people Engineering.

AVAILABLE INTEGRATIONS
  • Buk
    HR
    Sync to map processing activities for employee personal data
  • Google Drive
    Documents
    Attach evidence with traceability on where each document lives
  • REST API
    Events
    Connect proprietary data sources not covered by predefined integrations
  • Webhooks
    Automation
    Automatic notifications on request reception, deadline and closure
06

AI Assistant

An assistant trained on Law 21719 answers questions about deadlines, obligations, legal bases and rejection grounds. It validates your compliance documents and logs every interaction.

  • Conversational agent trained on Law 21719 — deadlines, obligations, legal bases and rejection grounds.
  • Automatic validation of RAT, DPIA and consents: detects incomplete processing activities or unmitigated risks.
  • Every interaction logged with the role of the user who made it — auditable evidence ready for inspection.

Available 24/7 — no ticket, no scheduling, no waiting for a law firm.

ARCO Legal AssistantOnline · Law 21719
How do I answer a cancellation request from a former employee?
AI
To respond to a cancellation: 1) Verify identity with RUT, 2) Confirm any legal retention obligation (e.g. 5 years for social security records), 3) Delete from all systems (HR, backups, CRM) and 4) Issue a timestamped receipt. Should I generate the response template?

Granular Roles with Dual-Role Support

Assign permissions by role: Controller, Processor, DPO or external auditor. Includes read-only view so the Agency or your clients can review evidence without touching records.

Multi-Company Console

Manage multiple RUTs from a single master account. Full physical and logical isolation between entities. Ideal for holding groups and external DPOs.

Adaptive Legal Configuration

Response templates, rejection grounds and legal texts parameterized to the current version of Chilean data protection law. Your platform doesn't become obsolete when the law changes.

Exportable Operational Reports

Metrics on requests, rights exercised, rejection rates and response times. Exportable as PDF or Excel to present to your board, principals or the Agency.

December 2026: your company must be ready.

Updated:

Chile's Law 21719 on Personal Data Protection requires every organization processing personal data of individuals to have a mechanism to receive and manage ARCO+ requests. Full enforcement takes effect on 1 de diciembre de 2026 (Art. 1 trans.).

Infractions are classified by severity: minor up to 5,000 UTM, serious up to 10,000 UTM, very serious up to 20,000 UTM (~$1,400M CLP). Repeat offenders can be sanctioned with 2–4% of annual revenue (Art. 52). The supervising body is the Personal Data Protection Agency, autonomous and independent, with sanctioning powers from day one. Don't wait to be audited.

Request your demo
Law 21719 publishedDecember 13, 2024
Adjustment periodWe are here — months left to prepare
Full enforcement — ARCO+ rights enforceableDecember 1, 2026
Fines active from day 1Minor: 5,000 UTM · Serious: 10,000 UTM · Most serious: 20,000 UTM

What you need to know
before you start.

What is an ARCO+ request?

An ARCO+ request is the legal mechanism by which a person exercises their rights of Access, Rectification, Cancellation, Opposition, Portability and Blocking over their personal data. Law 21719 requires every organization processing personal data of individuals in Chile to have a formal process to receive and respond to them.

Which companies must comply with Law 21719?

Every organization processing personal data of individuals in Chile is required, regardless of size or sector: retail, healthcare, fintech, education, logistics, SaaS, and any business that collects emails, RUTs, phone numbers or other identifying data.

What is the deadline to respond to an ARCO+ request?

Law 21719 sets a maximum of 30 calendar days from receipt of the request. Missing this deadline can be considered an infraction and lead to administrative sanctions.

What fines does Law 21719 impose for non-compliance?

Law 21719 sets a scale by severity: minor offenses up to 5,000 UTM (~$350M CLP), serious up to 10,000 UTM (~$700M CLP), and very serious up to 20,000 UTM (~$1,400M CLP). Repeat offenders can be sanctioned with 2–4% of annual revenue. Each request not answered in time is an independent infraction.

How long does it take to set up ARCO Legal?

Initial setup takes less than 10 minutes: enter your company details, define the responsible users and get the public form URL. That same day, data subjects can start submitting requests.

I already have a lawyer — why would I need ARCO Legal?

The platform doesn't replace your lawyer: it accelerates them. Your lawyer defines the legal strategy and reviews complex cases; ARCO Legal runs the day-to-day — request intake, deadline tracking, task assignment and evidence logging. Your lawyer gets time back for what actually matters.

Where is requester data stored?

Data is stored on cloud servers with encryption in transit and at rest. For companies in regulated sectors (banking, healthcare, government) that require data to reside in their own infrastructure, ARCO Legal offers on-premise deployment as part of the Enterprise plan.

Who enforces compliance with Law 21719?

The Personal Data Protection Agency is the autonomous and independent body in charge of supervising and sanctioning non-compliance with Law 21719. It has sanctioning powers from the first day of enforcement and may initiate investigations on its own or following data subject complaints.

What if the law changes?

Legal templates, response deadlines and consent settings are configurable. If Law 21719 or its regulations are amended, parameters are updated without touching code or migrating data. Your platform doesn't become obsolete with regulatory changes.

Can I change plans after signing up?

Yes. You can upgrade or downgrade your plan at any time from the admin panel. The price adjustment is applied immediately and prorated on your next invoice.

How long is the demo and what's included?

20 minutes with a Personal Data Protection Law 21719 specialist. Includes practical guidance on how the law applies to your business, a platform walkthrough focused on ARCO+ requests and consent management, and answers to your technical questions. No commercial commitment.

What are ARCO and ARCO+ rights?

ARCO rights cover Access, Rectification, Cancellation and Opposition over your personal data. Law 21719 extends them to ARCO+ rights by adding Portability and Blocking. In Chile any individual can exercise them against the company processing their data, and the company has 30 calendar days to respond.

What is a compliance platform like ARCO Legal?

It's software built specifically so a Chilean company can comply with Law 21719 without rebuilding its operations. It centralizes the Record of Processing Activities (RAT), ARCO+ request handling, consent management and traceability for the Personal Data Protection Agency. ARCO Legal is a SaaS platform ready in under 10 minutes.

What is Chile's Personal Data Protection Law 21719?

It is Chilean law (Law N°21.719, published on December 13, 2024) regulating how companies and entities process personal data of individuals. It replaces the previous framework of Law 19.628 and entered full effect on December 1, 2026. Its regulator is the Personal Data Protection Agency.

A plan for every
company size.

Early-access pricing — locked for life for customers who join before October 1, 2026. Pricing rises when Law 21719 comes into force.
Founders' pricing

Essential

0.5UF/month+ VAT

For small companies that need to comply with Law 21719 from day one.

  • Module 01 · ARCO+ Request Management
  • Module 02 · Audit
Request your demo

Enterprise

Custom pricing

For companies in regulated sectors (banking, healthcare, government) that cannot host data outside their own infrastructure. On-premise deployment with custom integrations.

  • Module 01 · ARCO+ Request Management
  • Module 02 · Audit
  • Module 03 · Structural Compliance
  • Module 04 · Consents
  • Module 05 · Integrations
  • Module 06 · AI Assistant
  • On-premise or in your own infrastructure
Contact sales team

Complementary professional services

Compliance advisory

Initial compliance assessment, drafting or completion of structural documents —RAT, DPIA, DPA and policies— and legal review by a lead attorney from 23people together with their network of allied firms.

Per-project fee in UF. After the project ends, you can subscribe to Essential or Pro independently to maintain your compliance.

Request assessment

Custom integrations

Implementation of integrations with data sources or internal systems that are not covered by the predefined connections (Buk, Google Drive).

Quoted on a case-by-case basis by the 23people Engineering team.

Request quote

Custom demo · Guidance included · No commitment

20-min demo · Guidance included

Request your demo.
Get practical guidance on compliance

Law 21719 comes into full effect on December 1, 2026 — and getting ready takes weeks.

Request a 20-minute demo and get practical guidance on compliance and consent under Chile's Personal Data Protection Law 21719. We'll reach out within 24 hours to schedule it.

Customers who join before Oct 1, 2026 get founders' pricing.