{"id":1596,"date":"2026-09-18T20:43:08","date_gmt":"2026-09-18T20:43:08","guid":{"rendered":"https:\/\/boostify.cl\/blog\/chiles-law-21719-what-your-company-must-do-before-december\/"},"modified":"2026-09-18T20:43:08","modified_gmt":"2026-09-18T20:43:08","slug":"chiles-law-21719-what-your-company-must-do-before-december","status":"publish","type":"post","link":"https:\/\/boostify.cl\/blog\/chiles-law-21719-what-your-company-must-do-before-december\/","title":{"rendered":"Chile&#039;s Law 21,719: What Your Company Must Do Before December"},"content":{"rendered":"<p>On December 1, your site&#8217;s contact form becomes a legal risk. That sounds like a salesperson&#8217;s headline scaring people, so let me start with the reassuring part: it&#8217;s not the end of the world and it can be fixed in a couple of afternoons. But it has to be done.<\/p>\n<p>That day <strong>Law 21.719<\/strong> takes full effect, Chile&#8217;s new personal data protection law. Here&#8217;s the simple version: what applies to you, what your site should have, and what we&#8217;re doing about it.<\/p>\n<h2>What it is, in short<\/h2>\n<p>The law was published in December 2024 and replaced Law 19.628, which dated back to 1999 and didn&#8217;t enforce anything. What opened then was a two-year window to get up to speed, and that window <strong>ends on December 1, 2026<\/strong>.<\/p>\n<p>From that date, the Personal Data Protection Agency is up and running. It can investigate on its own, receive complaints from anyone, order you to stop using the data, issue fines, and publish a registry of sanctioned companies. That registry is public, and for many businesses that part weighs more than the fine.<\/p>\n<h2>Who it applies to<\/h2>\n<p>Everyone. There&#8217;s no minimum size or revenue threshold: if you store people&#8217;s data, it applies to you just like it does to a bank. What changes is the size of the penalty, not the obligation.<\/p>\n<p>And \u00abpersonal data\u00bb covers a lot more than you&#8217;d think. If you have any of these, you&#8217;re already processing data:<\/p>\n<ul>\n<li>Your site&#8217;s contact or quote request form.<\/li>\n<li>The client or prospect spreadsheet in Sheets or Excel, and the inbox full of quotes from years back.<\/li>\n<li>The subscriber list in Brevo, Mailchimp, or your CRM.<\/li>\n<li>The WhatsApp chats on your business number.<\/li>\n<li>Google Analytics and the Meta Pixel, which send every visitor&#8217;s behavior to servers outside Chile.<\/li>\n<\/ul>\n<p><strong>Sensitive data<\/strong> is a separate case: health, union membership, criminal records, biometrics. The rules there are stricter and require express consent. If your form asks about a medical leave or a workplace accident, you&#8217;re in that category even if you didn&#8217;t know it.<\/p>\n<h2>What&#8217;s at stake, without the drama<\/h2>\n<p>The law reaches up to 20,000 UTM in the most serious tier \u2014 about CLP 1.434 billion with the September UTM \u2014 and drops to 10,000 and 5,000 UTM in the serious and minor tiers. But those are <strong>maximum caps<\/strong>: the Agency grades according to severity, company size, and whether there was intent. A ten-person small business isn&#8217;t going to get hit with 1.4 billion.<\/p>\n<p>The real risk is more boring than that. Someone files a complaint \u2014 an angry customer, a former employee, a competitor \u2014 and you have to explain what data you have, where it came from, what you use it for, and who you shared it with. If that isn&#8217;t in order, the cost isn&#8217;t the fine: it&#8217;s putting together in three weeks and in a rush what you could have done calmly in October.<\/p>\n<h2>What your site should have<\/h2>\n<ul>\n<li><strong>A real privacy policy<\/strong>, written for your case and with a working footer link. A legal link that goes nowhere is worse than not having one.<\/li>\n<li><strong>A consent checkbox on every form<\/strong>, unchecked by default and stating what you&#8217;ll use that email and phone number for.<\/li>\n<li><strong>A cookie banner that actually blocks.<\/strong> The little notice that pops up after Analytics and the Pixel have already fired is useless.<\/li>\n<li><strong>A channel to exercise rights.<\/strong> People can ask you for access to their data, to correct it, delete it, or take it with them. You need a visible email to receive those requests and someone to answer them.<\/li>\n<li><strong>A record of what data you have and where.<\/strong> A spreadsheet is enough: what data, where it lives, who sees it. And get rid of what no longer has a reason to exist \u2014 that database you bought in 2018 can&#8217;t be used anymore.<\/li>\n<li><strong>A plan for when something leaks.<\/strong> You have to notify the Agency without delay and, if the risk is high, the affected people too. That&#8217;s defined beforehand, not the day it happens.<\/li>\n<\/ul>\n<p>A detail that always gets forgotten: whoever runs your site, hosting, or mailing is a <em>data processor<\/em>, and that relationship should be in writing.<\/p>\n<h2>What we&#8217;re doing at Boostify<\/h2>\n<p>We don&#8217;t want to reach December improvising, so we started with our own. We&#8217;ve already gone through the sites we manage one by one \u2014 forms, fields they ask for, third-party scripts, privacy policy, cookies \u2014 and every client will receive their diagnosis: what&#8217;s missing, ordered by urgency, and the plan to get it up to date before December 1.<\/p>\n<p>We also put together the compliance package: a privacy policy drafted for each company&#8217;s real case, consent checkboxes on forms, a banner that blocks scripts until the person accepts, a rights channel, and the data record.<\/p>\n<p>And we started at home: boostify.cl gets up to date first. We&#8217;re not going to recommend anything we haven&#8217;t tested on our own site.<\/p>\n<p>If you&#8217;re a client of ours, for now you don&#8217;t have to lift a finger: we&#8217;ll come to you with your diagnosis.<\/p>\n<h2>Three things you can do this week<\/h2>\n<ul>\n<li>Open your site and look for the privacy link in the footer. If it doesn&#8217;t exist or goes nowhere, that&#8217;s point one.<\/li>\n<li>Fill out your own contact form and check whether at any point they told you what your data would be used for.<\/li>\n<li>Make a list of where you have people&#8217;s data: spreadsheets, email, WhatsApp, CRM, mailing. Just the list \u2014 with that you&#8217;ve already made a lot of progress.<\/li>\n<\/ul>\n<h2>Two honest notes to close<\/h2>\n<p>First: we&#8217;re not lawyers and this isn&#8217;t legal advice. Our part is the technical side \u2014 the site, the forms, the scripts, the consents, keeping data in order \u2014 which is where any audit starts. If you handle sensitive data or high volume, add a lawyer to that.<\/p>\n<p>Second: nothing spectacular is going to happen on December 1. The internet won&#8217;t go down and no one will show up at your office. It&#8217;s just that from that day on, what you didn&#8217;t do becomes enforceable and anyone can file a claim. Sorting it out in October costs less and gets done calmly.<\/p>\n<p>If you want to know where your site stands, <a href=\"https:\/\/wa.me\/56934102467?text=Hi%20Boostify%21%20I%20came%20from%20the%20blog%20and%20I%27d%20like%20to%20talk%20about%20my%20B2B%20business.\" rel=\"noopener noreferrer\" target=\"_blank\">message me on WhatsApp<\/a> and I&#8217;ll tell you what you&#8217;re missing, even if you later fix it on your own or with someone else. And if you&#8217;d rather leave it for later, that&#8217;s fine too: at least now you know what&#8217;s coming.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On December 1, your site&#8217;s contact form becomes a legal risk. That sounds like a salesperson&#8217;s headline scaring people, so let me start with the\u2026<\/p>\n","protected":false},"author":1,"featured_media":1593,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[64,167,63],"tags":[239,237,238,166,154],"class_list":["post-1596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-en","category-marketing-digital-b2b","category-tecnologia","tag-cumplimiento","tag-ley-21719","tag-proteccion-de-datos","tag-pymes-b2b","tag-sitios-web"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"_links":{"self":[{"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/posts\/1596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/comments?post=1596"}],"version-history":[{"count":0,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/posts\/1596\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/media\/1593"}],"wp:attachment":[{"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/media?parent=1596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/categories?post=1596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/boostify.cl\/blog\/wp-json\/wp\/v2\/tags?post=1596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}