We are sharing this article from El Mercurio in which our Director of New Technologies and AI, Juan Pablo González, was asked about the main challenge companies face as the Personal Data Law takes effect.
In this edition, we invited compliance, data, and privacy leaders from 25 FGE partner organizations to share their perspectives on the main challenges posed by the new law and how prepared companies are for its implementation.
Average rating: 3.96
On a scale of 1 to 7, how prepared do you think companies in Chile are today for the implementation of Law No. 21,719?
QUESTION 1
What is the main gap companies currently face in preparing for the implementation of Law No. 21,719 on personal data protection?
“The main challenge is cultural. Personal data protection is still perceived as an issue rooted in legal or IT departments, rather than as a cross-functional responsibility.”
Felipe Encina,
compliance officer, Viña Concha y Toro.
“The main challenge lies in shifting from viewing data protection as a legal or technological issue to managing it as a cross-functional risk, with clear responsibilities, effective controls, and the ability to demonstrate how data is protected.”
Paula Millar,
audit director, Coordinador Eléctrico Nacional.
“The main challenge is moving from statements to evidence. The new law requires companies to understand their data, properly manage risks, and be able to demonstrate—on an ongoing basis—how they protect people’s information.”
Claudia Blazquez,
Corporate Manager of Risk, Compliance, and Internal Audit, Empresas Iansa.
“From my perspective, the challenge lies in not knowing the location of the personal data used in certain processes; therefore, mapping personal data is a valuable tool that will help identify risks associated with the use of this information across various departments.”
Juan Pablo González,
Director of New Technologies and AI, az.
“There is a gap in organizational culture regarding data management and protection, evidenced by the need to strengthen the incorporation of privacy by default and by design into processes, products, and services.”
Sandra Ferrada Bórquez,
Risk Manager, Klap.
“The main gap is that companies do not know what data they process, for what purpose, and with whom they share it. Without that assessment, there is no basis for lawfulness, no contract, and no possible retention periods—and that is not a legal problem or one of interpreting the law, but rather a matter of understanding their own operations.”
Martín Aylwin,
Partner, Ayhwin Matta.
QUESTION 2
Beyond regulatory compliance and technological aspects, what do you consider to be the main changes that companies will need to address to adapt to the new law, both culturally and organizationally?
“The Data Law sets a new standard of trust in Chile. Its greatest challenge is operational and cultural: mapping data, implementing Privacy by Design, and enabling ARCO+ rights.”
Francisco Smith,
Director of Compliance, Caja Los Andes.
“This requires visible leadership, clear responsibilities, coordination across departments, ongoing training, and embedding privacy into every process, with a focus on the individual.”
Margarita Walker,
Compliance Manager & DPO, Entel S.A.
“Culturally, it means understanding privacy as a key element in building trust with customers and various stakeholders.”
Jorge Vita Hausser,
Manager of Internal Audit and Corporate Affairs, GTD.
“I believe the main change involves establishing a culture of accountability regarding personal data. This entails defining clear roles, strengthening decision-making, training teams, and incorporating privacy as a cross-cutting criterion in business processes.”
Valentina Uribe,
Compliance Officer, Consorcio Kimal-Lo Aguirre S.A.
“There needs to be data governance that establishes responsibilities. All of this must be accompanied by proper change management to ensure that all employees and third parties associated with the company implement the necessary changes.”
Paula Jervis,
Manager of Legal, Corporate Affairs, and Sustainability, Abastible.
“The biggest challenge will be establishing a culture of data protection throughout the organization. This requires leadership, clear responsibilities, and proactive privacy management, integrating it into business processes, decision-making, and risk management.”
Macarena Escobedo,
Attorney, GNL Quintero S.A.
The Path to Effective Management
The companies’ responses converge on four key dimensions
01 | VISIBILITY
“Today, companies are navigating blindly with their data; they lack visibility into what data they handle or where it is stored. That is why the main gap lies in the absence of a comprehensive record of processing activities. This is key to building an adequate prevention model.”
Juan Enrique Joannon,
Head of Legal Compliance & Public Affairs, Samsung Electronics Chile.
02 | GOVERNANCE
“The biggest gap today is in governance and accountability. To comply with the law, it’s essential to have complete visibility into the data being handled—a challenge that’s especially difficult when information is scattered across different systems, processes, and business units.”
Javier Aguiló Gelerstein,
Head of Compliance and DPO, Enex.
03 | CULTURE
“Incorporating an awareness of care into the culture of all employees will undoubtedly be a slow process, and in that regard, establishing new controls, procedures, and policies—along with training—should be the way to address it.”
Claudia Avendaño Rozas,
Corporate VP of Compliance and Risk, Molymet.
04 | EVIDENCE
“The main gap is not regulatory, but one of implementation. Many companies still fail to translate Law 21,719 into permanent operational capabilities: identifying data processing activities, assigning responsible parties, managing risks, demonstrating compliance, and fostering a genuine culture of privacy.”
Sebastián González Gálvez,
Data Governance & AI Leader, Garcés Fruit.
“Properly protecting the data that others entrust to us is also a concrete way to build trust. If organizations view this change as a cultural transformation—and not merely as a legal obligation—we can move toward institutions that are more responsible, transparent, and aware of the impact of their decisions.”
JANET AWAD
President, Fundación Generación Empresarial (FGE)
ALSO IN ATTENDANCE WERE
Matías Valencia, DPO, Sodimac; Jessica Gómez, Compliance Officer, Grupo Sendero; Paola Hermosilla, DPO for Compliance and Privacy at Sonda S.A.; Paola Quijón, Assistant Manager of Regulatory Compliance and Operational Risk, BancoEstado Microempresas; Orietta Araya, Corporate Risk and Compliance Coordinator, Enaex S.A.; Valeria Martinez, Corporate Internal Auditor, Grupo Emaresa; Juan Carlos Hayes, Executive Director, Hayes & Corp; and Carolina Orrego, Manager of Corporate Affairs and Compliance, Cemento Melón.



