Chile's Law 21,719: What Your Company Must Do Before December

On December 1, your site's contact form becomes a legal risk. That sounds like a salesperson's headline scaring people, so let me start with the…

Chile's Law 21,719: What Your Company Must Do Before December

On December 1, your site’s contact form becomes a legal risk. That sounds like a salesperson’s headline scaring people, so let me start with the reassuring part: it’s not the end of the world and it can be fixed in a couple of afternoons. But it has to be done.

That day Law 21.719 takes full effect, Chile’s new personal data protection law. Here’s the simple version: what applies to you, what your site should have, and what we’re doing about it.

What it is, in short

The law was published in December 2024 and replaced Law 19.628, which dated back to 1999 and didn’t enforce anything. What opened then was a two-year window to get up to speed, and that window ends on December 1, 2026.

From that date, the Personal Data Protection Agency is up and running. It can investigate on its own, receive complaints from anyone, order you to stop using the data, issue fines, and publish a registry of sanctioned companies. That registry is public, and for many businesses that part weighs more than the fine.

Who it applies to

Everyone. There’s no minimum size or revenue threshold: if you store people’s data, it applies to you just like it does to a bank. What changes is the size of the penalty, not the obligation.

And «personal data» covers a lot more than you’d think. If you have any of these, you’re already processing data:

  • Your site’s contact or quote request form.
  • The client or prospect spreadsheet in Sheets or Excel, and the inbox full of quotes from years back.
  • The subscriber list in Brevo, Mailchimp, or your CRM.
  • The WhatsApp chats on your business number.
  • Google Analytics and the Meta Pixel, which send every visitor’s behavior to servers outside Chile.

Sensitive data is a separate case: health, union membership, criminal records, biometrics. The rules there are stricter and require express consent. If your form asks about a medical leave or a workplace accident, you’re in that category even if you didn’t know it.

What’s at stake, without the drama

The law reaches up to 20,000 UTM in the most serious tier — about CLP 1.434 billion with the September UTM — and drops to 10,000 and 5,000 UTM in the serious and minor tiers. But those are maximum caps: the Agency grades according to severity, company size, and whether there was intent. A ten-person small business isn’t going to get hit with 1.4 billion.

The real risk is more boring than that. Someone files a complaint — an angry customer, a former employee, a competitor — and you have to explain what data you have, where it came from, what you use it for, and who you shared it with. If that isn’t in order, the cost isn’t the fine: it’s putting together in three weeks and in a rush what you could have done calmly in October.

What your site should have

  • A real privacy policy, written for your case and with a working footer link. A legal link that goes nowhere is worse than not having one.
  • A consent checkbox on every form, unchecked by default and stating what you’ll use that email and phone number for.
  • A cookie banner that actually blocks. The little notice that pops up after Analytics and the Pixel have already fired is useless.
  • A channel to exercise rights. People can ask you for access to their data, to correct it, delete it, or take it with them. You need a visible email to receive those requests and someone to answer them.
  • A record of what data you have and where. A spreadsheet is enough: what data, where it lives, who sees it. And get rid of what no longer has a reason to exist — that database you bought in 2018 can’t be used anymore.
  • A plan for when something leaks. You have to notify the Agency without delay and, if the risk is high, the affected people too. That’s defined beforehand, not the day it happens.

A detail that always gets forgotten: whoever runs your site, hosting, or mailing is a data processor, and that relationship should be in writing.

What we’re doing at Boostify

We don’t want to reach December improvising, so we started with our own. We’ve already gone through the sites we manage one by one — forms, fields they ask for, third-party scripts, privacy policy, cookies — and every client will receive their diagnosis: what’s missing, ordered by urgency, and the plan to get it up to date before December 1.

We also put together the compliance package: a privacy policy drafted for each company’s real case, consent checkboxes on forms, a banner that blocks scripts until the person accepts, a rights channel, and the data record.

And we started at home: boostify.cl gets up to date first. We’re not going to recommend anything we haven’t tested on our own site.

If you’re a client of ours, for now you don’t have to lift a finger: we’ll come to you with your diagnosis.

Three things you can do this week

  • Open your site and look for the privacy link in the footer. If it doesn’t exist or goes nowhere, that’s point one.
  • Fill out your own contact form and check whether at any point they told you what your data would be used for.
  • Make a list of where you have people’s data: spreadsheets, email, WhatsApp, CRM, mailing. Just the list — with that you’ve already made a lot of progress.

Two honest notes to close

First: we’re not lawyers and this isn’t legal advice. Our part is the technical side — the site, the forms, the scripts, the consents, keeping data in order — which is where any audit starts. If you handle sensitive data or high volume, add a lawyer to that.

Second: nothing spectacular is going to happen on December 1. The internet won’t go down and no one will show up at your office. It’s just that from that day on, what you didn’t do becomes enforceable and anyone can file a claim. Sorting it out in October costs less and gets done calmly.

If you want to know where your site stands, message me on WhatsApp and I’ll tell you what you’re missing, even if you later fix it on your own or with someone else. And if you’d rather leave it for later, that’s fine too: at least now you know what’s coming.

Share

Daniel Camus

Founder & CEO

Digital strategist with 20+ years in B2B marketing. Founder of Boostify, helping companies scale with Google Ads, automation and digital positioning.

439 Articles Since Jul 2025 Latest post: Sep 18, 2026
Daniel Camus
Daniel Camus
Artículos: 439
Any questions? Message me

Stay ahead of what matters 🚀

Receive weekly insights on marketing, technology, and business in Latin America.

🔒 0% Spam. High-value content only.