Law 21.719: a step-by-step guide to making your eCommerce compliant
Chile's new personal data law comes into force on 1 December 2026. If your store collects data —and they all do— this is your roadmap to comply without getting tangled up.

Law 21.719 modernises personal data protection in Chile, taking its cue from the European GDPR. It comes into force on 1 December 2026, creates the Personal Data Protection Agency (APDP) —which does enforce— and sets fines of up to 20,000 UTM. The good news: complying does not require a team of lawyers. If the general picture is not clear yet, start with what Law 21.719 is and what changes for your eCommerce. If it is already clear, this is your roadmap.
Step 1 · Data inventory: what you collect and where it lives
Before changing anything, answer four questions: what data you collect (name, national ID, email, phone, browsing behaviour), where you store it, who has access and how long you keep it. Without this map, everything else is guesswork.
Step 2 · Consent in forms: freely given, informed and unambiguous
Every form where you ask for data must tell the user what you use it for. "To improve your experience" is not enough: be specific. The consent the law requires is freely given, informed and unambiguous — and the user must be able to withdraw it.
Step 3 · Privacy policy: bring it up to date with Law 21.719
If you have not reviewed it in more than two years, it is out of date. It must align with Law 21.719: what data you process, on what legal basis, for how long, and how the user exercises their rights. If you want to see how one is structured in practice, take a look at Clicomy's privacy policy: data controller, what is collected, who it is shared with and how to exercise your rights, section by section.
Step 4 · Legal basis: why you may process each piece of data
You can no longer keep data "just because". The law requires a legal basis for each use: consent, performance of a contract, legal obligation, among others. Without a basis, it is an infringement.
Step 5 · Cookies and trackers: consent before loading
The Meta pixel, Google Analytics and other trackers process personal data. They must load after the user's consent, not before. A properly configured cookie banner stops being decoration and becomes a requirement.
Step 6 · Data breaches: a notification protocol
If a data leak occurs, the law requires notification. Define the procedure before you need it: who responds, who is notified and within what timeframe.
The Agency does not audit good intentions, it audits evidence. Having the policies written down is not enough if you cannot show that you follow them.
Your customers' rights —access, rectification, erasure, objection and portability— are now enforceable before the Agency. Complying does not only avoid fines: it builds trust, and trust sells. At Clicomy we help stores do marketing that complies and converts: if you want to get your store's data capture in order before December, start with a marketing consultancy for eCommerce. This note is an example of Clicomy Notes.


