Prove you comply with Law 21719. Simple.
SaaS platform that lets you:
- Spot compliance gaps before the Agency does
- Answer ARCO+ requests in legal time and form
- Collect consent with legal basis at every step
The problem isn't the law.
It's proving you comply — to the Agency and to your principals.
How many systems in your company hold personal data today? When that first ARCO+ request arrives, you'll have 30 days to find it all, justify your legal basis for processing it, and respond properly. And that's just the beginning.
Who receives ARCO+ requests at your company?
The request lands in email, WhatsApp or the general contact form. Nobody sees it. The 30-day legal clock is already ticking — and the inbox owner is on vacation.
Do you know where the personal data you process is stored?
Your team hunts through the CRM, Buk, Google Drive — and spreadsheets scattered everywhere. Zero traceability. Hours of manual search. Risk of an incomplete answer.
Do you have your RAT, EIPD, and DPAs up to date?
Answering the request isn't enough. The law requires your RAT, Impact Assessments, DPA contracts with providers, and published privacy policies. Without them, the Agency will fine you regardless — starting at 5,000 UTM.
Your contracts depend on it
Large corporations are already auditing their suppliers. If your principal asks whether you're compliant with Law 21719, can you provide evidence? Your contract renewals and access to new bids depend on it.
“Losing the contract is the biggest risk, not the Agency's fine”
ARCO Legal customer · B2B provider
The platform to comply with the law.
And prove it.
Six modules. Every legal obligation with its owner, its deadline and its evidence.
ARCO+ Request Management
Centralised panel to receive, assign and respond to Access, Rectification, Cancellation, Opposition, Portability and Blocking requests — with deadlines calculated in calendar days and alerts before each one expires.
- Public URL ready for data subjects to submit requests 24/7.
- Operate as Controller and Processor from a single account — ideal for holding groups and external DPOs.
- Response templates parameterised by the legal grounds of Law 21719 — no need to draft each case.
Initial setup: less than 10 minutes. That same day, data subjects can already start submitting requests.
- A18
- R7
- C14
- O9
- P4
- B2
Audit
Every action is logged with timestamp, owner and an immutable trail. When an auditor or the Agency asks for proof, you export auditable evidence in minutes — not days.
- Immutable log of every action with timestamp, actor and result.
- Read-only access for external auditors — without compromising data integrity.
- Export auditable evidence in standard formats for regulatory inspection or supplier audits.
- j.rodriguez@yourcompany.com12 Mar 2026 · 14:03Responded to ARCO+ request A-18 (Access) within the deadline.
- external.auditor@firm.com11 Mar 2026 · 09:47Accessed the audit trail in read-only mode.
- m.perez@yourcompany.com10 Mar 2026 · 16:22Updated the legal basis of processing RAT-07.
- system08 Mar 2026 · 11:05Verified the encrypted backup for the period.
- j.rodriguez@yourcompany.com05 Mar 2026 · 08:31Exported the period's auditable evidence (PDF).
Compliance
Document which personal data you process, where it lives, under which legal basis and when it must be erased. Two scopes: Basic automatically generates the minimum records the law requires; Complete structures the full RAT and its assessments before the first inspection.
Basic Compliance (Essential plan)
- Automatic ARCO+ RAT: every request generates its processing record with no manual work.
- Employee RAT generated during onboarding through a guided question wizard.
- RAT and DPIA for direct customers (e.g. shipping addresses) when the company processes that data directly.
Complete Compliance (Pro and Enterprise plans)
- Full structured RAT with every field required by law.
- AI-assisted Data Protection Impact Assessments (DPIAs) for high-risk processing.
- DPA management with vendors and processors (Buk, Google Drive).
- Privacy policies and terms generated and aligned with your RAT.
- Legal basis mapping per processing (consent, contract, legal obligation, legitimate interest).
- AI validation of RAT, DPIA and existing consents.
- Monthly compliance certificate, analogous to the F-30-1 previsional document, ready to deliver to corporate principals.
Privacy policies generated aligned with your RAT — no drafting from scratch.
| Data | System | Legal basis | Retention |
|---|---|---|---|
| Customer email | Salesforce CRM | Consent | Until withdrawal |
| Employee RUT | Buk HR | Employment contract | 5 years |
| Access logs | Auth0 | Legitimate interest | 12 months |
| Health data | Clinical system | Consent | 15 years |
Consents
Every consent is captured with timestamp, document version and mechanism — and stays available for the data subject to review or revoke whenever they want, without going through your team.
- Forms generated for cookies, RAT or DPIA with individual checkboxes per purpose (explicit opt-in, not pre-ticked).
- Data Subject Portal so each person can review and revoke their consents autonomously.
- Full traceability: timestamp, version of the accepted document, capture mechanism and link to the RAT.
Dual capture mechanism (API + email validation) — the cryptographic proof the Agency demands.
Integrations
Connect the systems where your data already lives — Buk for HR, Google Drive for documents — and add your internal sources via API and webhooks. Answering a request no longer means opening five tabs.
- Native integrations with Buk (HR) and Google Drive (documents and evidence).
- Events API for your dev team to connect internal sources and proprietary CRMs.
- Automatic webhooks on request reception, deadline and closure — without checking the panel constantly.
Custom integration service available — evaluated case by case by 23people Engineering.
AI Assistant
An assistant trained on Law 21719 answers questions about deadlines, obligations, legal bases and rejection grounds, and guides you to complete your documentation. Within a monthly pack, it validates your RAT, DPIA and consents and logs every interaction.
- Conversational agent trained on Law 21719 — deadlines, obligations, legal bases and rejection grounds.
- Validation of RAT, DPIA and consents within a monthly pack of documents: flags incomplete processing activities or unmitigated risks.
- Every interaction logged with the role of the user who made it — auditable evidence ready for inspection.
Available 24/7 — no ticket, no scheduling, no waiting for a law firm.
Granular Roles with Dual-Role Support
Assign permissions by role: Controller, Processor, DPO or external auditor. Includes read-only view so the Agency or your clients can review evidence without touching records.
Multi-Company Console
Manage multiple RUTs from a single master account. Full physical and logical isolation between entities. Ideal for holding groups and external DPOs.
Adaptive Legal Configuration
Response templates, rejection grounds and legal texts parameterized to the current version of Chilean data protection law. Your platform doesn't become obsolete when the law changes.
Exportable Operational Reports
Metrics on requests, rights exercised, rejection rates and response times. Exportable as PDF or Excel to present to your board, principals or the Agency.
December 2026: your company must be ready.
Updated:
Chile's Law 21719 on Personal Data Protection requires every organization processing personal data to manage ARCO+ requests. Full enforcement takes effect on December 1, 2026 (Art. 1 trans.). The Executive branch submitted a bill to postpone it to December 1, 2027, still pending in Congress; until approved, the legal date does not change. No matter when the Agency audits, your clients won't wait.
Infractions by severity: minor up to 5,000 UTM, serious up to 10,000 UTM, very serious up to 20,000 UTM (~$1,400M CLP). Recidivism: 2–4% of annual revenue (Art. 52). Enforcement falls to the Personal Data Protection Agency. Don't wait to be audited.
Banks, retailers and insurers are already auditing their suppliers.
Already working on your law compliance? If not, request your demo and move forward now.
Request your demoNo-commitment demo · reply within one business day
What you need to know
before you start.
Was Law 21719's enforcement postponed?
No. Law 21719's full enforcement is still December 1, 2026. On September 1, 2026 the Executive submitted a bill to postpone it to December 1, 2027, but it is still pending in Congress: until approved, the legal date does not change.
What is the Early-mover discount and when can I sign up with it?
The Early-mover discount is 30% off the regular price of the Essential and Pro plans, available for plans contracted before October 1, 2026. The discounted price is locked for life while the customer remains active, including automatic Essential to Pro upgrades that happen after that date. Customers contracting after October 1, 2026 pay the regular price.
Do prices include VAT?
No. All prices are quoted in UF (Unidad de Fomento) and exclude VAT: the applicable VAT is added at billing time.
Do you offer an annual-billing discount?
Not yet. Monthly billing is currently the only option. Annual billing is under evaluation and will be announced if confirmed.
What is an ARCO+ request?
An ARCO+ request is the legal mechanism by which a person exercises their rights of Access, Rectification, Cancellation, Opposition, Portability and Blocking over their personal data. Law 21719 requires every organization processing personal data of individuals in Chile to have a formal process to receive and respond to them.
Which companies must comply with Law 21719?
Every organization processing personal data of individuals in Chile is required, regardless of size or sector: retail, healthcare, fintech, education, logistics, SaaS, and any business that collects emails, RUTs, phone numbers or other identifying data.
What is the deadline to respond to an ARCO+ request?
Law 21719 sets a maximum of 30 calendar days from receipt of the request. Missing this deadline can be considered an infraction and lead to administrative sanctions.
What fines does Law 21719 impose for non-compliance?
Law 21719 sets a scale by severity: minor offenses up to 5,000 UTM (~$350M CLP), serious up to 10,000 UTM (~$700M CLP), and very serious up to 20,000 UTM (~$1,400M CLP). Repeat offenders can be sanctioned with 2–4% of annual revenue. Each request not answered in time is an independent infraction.
How long does it take to set up ARCO Legal?
Initial setup takes less than 10 minutes: enter your company details, define the responsible users and get the public form URL. That same day, data subjects can start submitting requests.
I already have a lawyer — why would I need ARCO Legal?
The platform doesn't replace your lawyer: it accelerates them. Your lawyer defines the legal strategy and reviews complex cases; ARCO Legal runs the day-to-day — request intake, deadline tracking, task assignment and evidence logging. Your lawyer gets time back for what actually matters.
Where is requester data stored?
Data is stored on cloud servers with encryption in transit and at rest. For companies in regulated sectors (banking, healthcare, government) that require data to reside in their own infrastructure, ARCO Legal offers on-premise deployment as part of the Enterprise plan.
Who enforces compliance with Law 21719?
The Personal Data Protection Agency is the autonomous and independent body in charge of supervising and sanctioning non-compliance with Law 21719. It has sanctioning powers from the first day of enforcement and may initiate investigations on its own or following data subject complaints.
What if the law changes?
Legal templates, response deadlines and consent settings are configurable. If Law 21719 or its regulations are amended, parameters are updated without touching code or migrating data. Your platform doesn't become obsolete with regulatory changes.
Can I change plans after signing up?
Yes. You can upgrade or downgrade your plan at any time from the admin panel. The price adjustment is applied immediately and prorated on your next invoice.
How long is the demo and what's included?
20 minutes with a Personal Data Protection Law 21719 specialist. Includes practical guidance on how the law applies to your business, a platform walkthrough focused on ARCO+ requests and consent management, and answers to your technical questions. No commercial commitment.
What are ARCO and ARCO+ rights?
ARCO rights cover Access, Rectification, Cancellation and Opposition over your personal data. Law 21719 extends them to ARCO+ rights by adding Portability and Blocking. In Chile any individual can exercise them against the company processing their data, and the company has 30 calendar days to respond.
What is a compliance platform like ARCO Legal?
It's software built specifically so a Chilean company can comply with Law 21719 without rebuilding its operations. It centralizes the Record of Processing Activities (RAT), ARCO+ request handling, consent management and traceability for the Personal Data Protection Agency. ARCO Legal is a SaaS platform ready in under 10 minutes.
What is Chile's Personal Data Protection Law 21719?
It is Chilean law (Law N°21.719, published on December 13, 2024) regulating how companies and entities process personal data of individuals. It replaces the previous framework of Law 19.628 and its full effect date is December 1, 2026. The Executive submitted a bill to postpone it to December 1, 2027, still pending in Congress. Its regulator will be the Personal Data Protection Agency.
A plan for every
company size.
Essential
For small companies that need to comply with Law 21719 from day one.
- ARCO+ Request Management
- Basic Compliance (automatic ARCO+ RAT, employees and direct customers)
- Audit
Up to 3 users · 10 admissible ARCO+ requests/month included · Billing cap: 7 UF/month · Automatic upgrade to Pro after 2 months at the cap
Request your demoPro
For mid-sized companies that need their own domain and unlimited operations.
- Everything in the Essential plan
- Complete Compliance (full RAT, DPIA, DPAs, policies and monthly certificate)
- Consent Management
- Native integrations
- AI Assistant
Per-company (RUT) base · up to 5 users included · 50 admissible ARCO+ requests and 1,000 consents/month included
Request your demoEnterprise
For companies in regulated sectors (banking, healthcare, government, retail, education) that cannot host data outside their own infrastructure. On-premise deployment with custom integrations.
- Everything in the Pro plan
- On-premise or in your own infrastructure
Complementary professional services
Compliance advisory
Initial compliance assessment, drafting or completion of structural documents —RAT, DPIA, DPA and policies— and legal review by a lead attorney from 23people together with their network of allied firms.
Per-project fee in UF. After the project ends, you can subscribe to Essential or Pro independently to maintain your compliance.
Request assessmentCustom integrations
Implementation of integrations with data sources or internal systems that are not covered by the predefined connections (Buk, Google Drive).
Quoted on a case-by-case basis by the 23people Engineering team.
Request quoteCustom demo · Guidance included · No commitment
Get ready for Law 21719.
Law 21719 comes into full effect on December 1, 2026 — and getting ready takes months.
We'll reach out within one business day to schedule it.
A specialist will write to you within one business day to schedule your demo. No commitment.
Done! We'll review your request.
Check your inbox — we'll write to you within one business day to coordinate your demo.
In the meantime, you can review the plans or read the frequently asked questions.