Prove you comply with Law 21719.
All-in-one platform for managing ARCO+ requests, consents and your RAT. Assisted Compliance with legal basis documented at every step.
SaaS platform that lets you:
- Spot compliance gaps before the Agency does
- Answer ARCO+ requests in days, not weeks
- Collect consent with legal basis at every step
The problem isn't the law.
It's proving you comply — to the Agency and to your principals.
How many systems in your company hold personal data today? When that first ARCO+ request arrives, you'll have 30 days to find it all, justify your legal basis for processing it, and respond properly. And that's just the beginning.
Who receives ARCO+ requests at your company?
The request lands in email, WhatsApp or the general contact form. Nobody sees it. The 30-day legal clock is already ticking — and the inbox owner is on vacation.
Do you know where the personal data you process is stored?
Your team hunts through the CRM, Buk, Google Drive — and spreadsheets scattered everywhere. Zero traceability. Hours of manual search. Risk of an incomplete answer.
Do you have your RAT, EIPD, and DPAs up to date?
Answering the request isn't enough. The law requires your RAT, Impact Assessments, DPA contracts with providers, and published privacy policies. Without them, the Agency will fine you regardless — starting at 5,000 UTM.
Your contracts depend on it
Large corporations are already auditing their suppliers. If your principal asks whether you're compliant with Law 21719, can you provide evidence? Your contract renewals and access to new bids depend on it.
The platform to comply with the law.
And prove it.
Six modules. Every legal obligation with its owner, its deadline and its evidence.
ARCO+ Request Management
Centralised panel to receive, assign and respond to Access, Rectification, Cancellation, Opposition, Portability and Blocking requests — with deadlines calculated in calendar days and alerts before each one expires.
- Public URL ready for data subjects to submit requests 24/7.
- Operate as Controller and Processor from a single account — ideal for holding groups and external DPOs.
- Response templates parameterised by the legal grounds of Law 21719 — no need to draft each case.
Initial setup: less than 10 minutes. That same day, data subjects can already start submitting requests.
- A18
- R7
- C14
- O9
- P4
- B2
Audit
Every action is logged with timestamp, owner and an immutable trail. When an auditor or the Agency asks for proof, you generate a certificate comparable to the F-30-1 previsional document.
- Immutable log of every action with timestamp, actor and result.
- Read-only access for external auditors — without compromising data integrity.
- Monthly compliance certificate, analogous to the F-30-1 previsional document, ready to deliver to corporate principals.
Export in standard formats for regulatory inspection or supplier audits.
Compliance Certificate
Law 21719 · Period December 2026
- Record of Processing Activities (RAT) current
- 0 ARCO+ requests answered out of time
- Consents captured with timestamp
- Data Protection Impact Assessment (DPIA) signed
- Encrypted backups verified
Structural Compliance
Map which personal data you process, where it lives, under which legal basis and when it must be erased — your RAT always ready to present.
- Personal data mapping: what you collect, where it lives, who processes it and under which legal basis.
- Record of Processing Activities (RAT) documented with every field required by law.
- AI-assisted Data Protection Impact Assessments (DPIAs), plus DPA management with vendors like Buk or Google Drive.
Privacy policies generated aligned with your RAT — no drafting from scratch.
| Data | System | Legal basis | Retention |
|---|---|---|---|
| Customer email | Salesforce CRM | Consent | Until withdrawal |
| Employee RUT | Buk HR | Employment contract | 5 years |
| Access logs | Auth0 | Legitimate interest | 12 months |
| Health data | Clinical system | Consent | 15 years |
Consents
Every consent is captured with timestamp, document version and mechanism — and stays available for the data subject to review or revoke whenever they want, without going through your team.
- Forms generated for cookies, RAT or DPIA with individual checkboxes per purpose (explicit opt-in, not pre-ticked).
- Data Subject Portal so each person can review and revoke their consents autonomously.
- Full traceability: timestamp, version of the accepted document, capture mechanism and link to the RAT.
Dual capture mechanism (API + email validation) — the cryptographic proof the Agency demands.
Integrations
Connect the systems where your data already lives — Buk for HR, Google Drive for documents — and add your internal sources via API and webhooks. Answering a request no longer means opening five tabs.
- Native integrations with Buk (HR) and Google Drive (documents and evidence).
- Events API for your dev team to connect internal sources and proprietary CRMs.
- Automatic webhooks on request reception, deadline and closure — without checking the panel constantly.
Custom integration service available — evaluated case by case by 23people Engineering.
AI Assistant
An assistant trained on Law 21719 answers questions about deadlines, obligations, legal bases and rejection grounds. It validates your compliance documents and logs every interaction.
- Conversational agent trained on Law 21719 — deadlines, obligations, legal bases and rejection grounds.
- Automatic validation of RAT, DPIA and consents: detects incomplete processing activities or unmitigated risks.
- Every interaction logged with the role of the user who made it — auditable evidence ready for inspection.
Available 24/7 — no ticket, no scheduling, no waiting for a law firm.
Granular Roles with Dual-Role Support
Assign permissions by role: Controller, Processor, DPO or external auditor. Includes read-only view so the Agency or your clients can review evidence without touching records.
Multi-Company Console
Manage multiple RUTs from a single master account. Full physical and logical isolation between entities. Ideal for holding groups and external DPOs.
Adaptive Legal Configuration
Response templates, rejection grounds and legal texts parameterized to the current version of Chilean data protection law. Your platform doesn't become obsolete when the law changes.
Exportable Operational Reports
Metrics on requests, rights exercised, rejection rates and response times. Exportable as PDF or Excel to present to your board, principals or the Agency.
December 2026: your company must be ready.
Updated:
Chile's Law 21719 on Personal Data Protection requires every organization processing personal data of individuals to have a mechanism to receive and manage ARCO+ requests. Full enforcement takes effect on 1 de diciembre de 2026 (Art. 1 trans.).
Infractions are classified by severity: minor up to 5,000 UTM, serious up to 10,000 UTM, very serious up to 20,000 UTM (~$1,400M CLP). Repeat offenders can be sanctioned with 2–4% of annual revenue (Art. 52). The supervising body is the Personal Data Protection Agency, autonomous and independent, with sanctioning powers from day one. Don't wait to be audited.
Request your demoWhat you need to know
before you start.
What is an ARCO+ request?
An ARCO+ request is the legal mechanism by which a person exercises their rights of Access, Rectification, Cancellation, Opposition, Portability and Blocking over their personal data. Law 21719 requires every organization processing personal data of individuals in Chile to have a formal process to receive and respond to them.
Which companies must comply with Law 21719?
Every organization processing personal data of individuals in Chile is required, regardless of size or sector: retail, healthcare, fintech, education, logistics, SaaS, and any business that collects emails, RUTs, phone numbers or other identifying data.
What is the deadline to respond to an ARCO+ request?
Law 21719 sets a maximum of 30 calendar days from receipt of the request. Missing this deadline can be considered an infraction and lead to administrative sanctions.
What fines does Law 21719 impose for non-compliance?
Law 21719 sets a scale by severity: minor offenses up to 5,000 UTM (~$350M CLP), serious up to 10,000 UTM (~$700M CLP), and very serious up to 20,000 UTM (~$1,400M CLP). Repeat offenders can be sanctioned with 2–4% of annual revenue. Each request not answered in time is an independent infraction.
How long does it take to set up ARCO Legal?
Initial setup takes less than 10 minutes: enter your company details, define the responsible users and get the public form URL. That same day, data subjects can start submitting requests.
I already have a lawyer — why would I need ARCO Legal?
The platform doesn't replace your lawyer: it accelerates them. Your lawyer defines the legal strategy and reviews complex cases; ARCO Legal runs the day-to-day — request intake, deadline tracking, task assignment and evidence logging. Your lawyer gets time back for what actually matters.
Where is requester data stored?
Data is stored on cloud servers with encryption in transit and at rest. For companies in regulated sectors (banking, healthcare, government) that require data to reside in their own infrastructure, ARCO Legal offers on-premise deployment as part of the Enterprise plan.
Who enforces compliance with Law 21719?
The Personal Data Protection Agency is the autonomous and independent body in charge of supervising and sanctioning non-compliance with Law 21719. It has sanctioning powers from the first day of enforcement and may initiate investigations on its own or following data subject complaints.
What if the law changes?
Legal templates, response deadlines and consent settings are configurable. If Law 21719 or its regulations are amended, parameters are updated without touching code or migrating data. Your platform doesn't become obsolete with regulatory changes.
Can I change plans after signing up?
Yes. You can upgrade or downgrade your plan at any time from the admin panel. The price adjustment is applied immediately and prorated on your next invoice.
How long is the demo and what's included?
20 minutes with a Personal Data Protection Law 21719 specialist. Includes practical guidance on how the law applies to your business, a platform walkthrough focused on ARCO+ requests and consent management, and answers to your technical questions. No commercial commitment.
What are ARCO and ARCO+ rights?
ARCO rights cover Access, Rectification, Cancellation and Opposition over your personal data. Law 21719 extends them to ARCO+ rights by adding Portability and Blocking. In Chile any individual can exercise them against the company processing their data, and the company has 30 calendar days to respond.
What is a compliance platform like ARCO Legal?
It's software built specifically so a Chilean company can comply with Law 21719 without rebuilding its operations. It centralizes the Record of Processing Activities (RAT), ARCO+ request handling, consent management and traceability for the Personal Data Protection Agency. ARCO Legal is a SaaS platform ready in under 10 minutes.
What is Chile's Personal Data Protection Law 21719?
It is Chilean law (Law N°21.719, published on December 13, 2024) regulating how companies and entities process personal data of individuals. It replaces the previous framework of Law 19.628 and entered full effect on December 1, 2026. Its regulator is the Personal Data Protection Agency.
A plan for every
company size.
Essential
For small companies that need to comply with Law 21719 from day one.
- Module 01 · ARCO+ Request Management
- Module 02 · Audit
Pro
For mid-sized companies that need their own domain and unlimited operations.
- Module 01 · ARCO+ Request Management
- Module 02 · Audit
- Module 03 · Structural Compliance
- Module 04 · Consents
- Module 05 · Integrations
- Module 06 · AI Assistant
Enterprise
For companies in regulated sectors (banking, healthcare, government) that cannot host data outside their own infrastructure. On-premise deployment with custom integrations.
- Module 01 · ARCO+ Request Management
- Module 02 · Audit
- Module 03 · Structural Compliance
- Module 04 · Consents
- Module 05 · Integrations
- Module 06 · AI Assistant
- On-premise or in your own infrastructure
Complementary professional services
Compliance advisory
Initial compliance assessment, drafting or completion of structural documents —RAT, DPIA, DPA and policies— and legal review by a lead attorney from 23people together with their network of allied firms.
Per-project fee in UF. After the project ends, you can subscribe to Essential or Pro independently to maintain your compliance.
Request assessmentCustom integrations
Implementation of integrations with data sources or internal systems that are not covered by the predefined connections (Buk, Google Drive).
Quoted on a case-by-case basis by the 23people Engineering team.
Request quoteCustom demo · Guidance included · No commitment
Request your demo.
Get practical guidance on compliance
Law 21719 comes into full effect on December 1, 2026 — and getting ready takes weeks.
Request a 20-minute demo and get practical guidance on compliance and consent under Chile's Personal Data Protection Law 21719. We'll reach out within 24 hours to schedule it.
Customers who join before Oct 1, 2026 get founders' pricing.
Done! We'll review your request.
Check your inbox — we'll email you within 24 hours to schedule your demo.
In the meantime, you can review the plans or read the frequently asked questions.