Skip to content

Evidence request lists

Chile Personal Data Protection Law (Law No. 21.719)

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Chile Law 21.719: Controller and Processor Obligations

CL21719-A14quater
Privacy by Design and by Default (Art. 14 quater)

Obligation to implement data protection by design and by default.

Artefacts an auditor will ask for
  • policy/records evidencing privacy by design/default
  • evidence the obligation is met in processing operations
Where this commonly fails
  • privacy by design/default not implemented or evidenced
CL21719-A14quinquies
Security of Processing (Art. 14 quinquies)

Obligation to adopt technical and organisational security measures appropriate to the risk.

Artefacts an auditor will ask for
  • policy/records evidencing security measures
  • evidence the obligation is met in processing operations
Where this commonly fails
  • security measures not implemented or evidenced
CL21719-A14sexies
Breach Notification (Art. 14 sexies)

Obligation to notify the Agency (and, where required, data subjects) of personal data breaches without undue delay.

Artefacts an auditor will ask for
  • policy/records evidencing breach notification
  • evidence the obligation is met in processing operations
Where this commonly fails
  • breach notification not implemented or evidenced
CL21719-A14ter
Lawfulness Documentation and Transparency (Art. 14 ter)

Obligation to document the lawful basis and to provide the data subject with the prescribed information (transparency).

Artefacts an auditor will ask for
  • policy/records evidencing transparency / lawfulness documentation
  • evidence the obligation is met in processing operations
Where this commonly fails
  • transparency / lawfulness documentation not implemented or evidenced
CL21719-A15
Processor Obligations and Contracts (Art. 15)

Obligations of processors and the requirement for a contract governing processing on behalf of a controller.

Artefacts an auditor will ask for
  • policy/records evidencing processor contracts
  • evidence the obligation is met in processing operations
Where this commonly fails
  • processor contracts not implemented or evidenced
CL21719-A15bis
Records of Processing Activities (Art. 15 bis)

Obligation to maintain a register of processing activities.

Artefacts an auditor will ask for
  • policy/records evidencing records of processing
  • evidence the obligation is met in processing operations
Where this commonly fails
  • records of processing not implemented or evidenced
CL21719-A15ter
Data Protection Impact Assessment (Art. 15 ter)

Obligation to carry out a DPIA for high-risk processing.

Artefacts an auditor will ask for
  • policy/records evidencing DPIA
  • evidence the obligation is met in processing operations
Where this commonly fails
  • DPIA not implemented or evidenced
CL21719-A17
Credit and Financial Data (Art. 17-18)

Specific rules for the processing of economic, financial, banking and commercial (credit) data.

Artefacts an auditor will ask for
  • policy/records evidencing credit/financial data
  • evidence the obligation is met in processing operations
Where this commonly fails
  • credit/financial data not implemented or evidenced
CL21719-A49
Data Protection Officer (Art. 49)

Designation and role of a data protection officer where required.

Artefacts an auditor will ask for
  • policy/records evidencing DPO
  • evidence the obligation is met in processing operations
Where this commonly fails
  • DPO not implemented or evidenced

Chile Law 21.719: International Transfers

CL21719-A27
International Data Transfers (Art. 27-28 bis)

Conditions for transferring personal data internationally, including safeguards.

Artefacts an auditor will ask for
  • policy/records evidencing international transfers
  • evidence the obligation is met in processing operations
Where this commonly fails
  • international transfers not implemented or evidenced
CL21719-A28
Adequacy Determinations (Art. 28)

Transfers to countries/territories recognised as providing an adequate level of protection.

Artefacts an auditor will ask for
  • policy/records evidencing adequacy
  • evidence the obligation is met in processing operations
Where this commonly fails
  • adequacy not implemented or evidenced

Chile Law 21.719: Principles and Lawful Basis

CL21719-A12
Lawful Bases for Processing (Art. 12)

The sources of lawfulness for processing personal data (consent, contract, legal obligation, legitimate interest, etc.).

Artefacts an auditor will ask for
  • policy/records evidencing lawful basis
  • evidence the obligation is met in processing operations
Where this commonly fails
  • lawful basis not implemented or evidenced
CL21719-A14
Consent (Art. 13-14)

Requirements for valid consent - free, informed, specific and unequivocal - and the rules for obtaining and withdrawing it.

Artefacts an auditor will ask for
  • policy/records evidencing consent
  • evidence the obligation is met in processing operations
Where this commonly fails
  • consent not implemented or evidenced
CL21719-A3
Definitions and Scope (Art. 1-3)

Law 21.719 (amending Law 19.628): material and territorial scope and the definitions of personal data, sensitive data, controller, processor, consent and the data subject.

Artefacts an auditor will ask for
  • policy/records evidencing scope and definitions
  • evidence the obligation is met in processing operations
Where this commonly fails
  • scope and definitions not implemented or evidenced
CL21719-A4
Principles of Processing (Art. 3-4)

The principles governing processing: lawfulness, purpose limitation, proportionality/minimisation, data quality, transparency and information, security, confidentiality and accountability.

Artefacts an auditor will ask for
  • policy/records evidencing processing principles
  • evidence the obligation is met in processing operations
Where this commonly fails
  • processing principles not implemented or evidenced

Chile Law 21.719: Rights of Data Subjects

CL21719-A5a
Right of Access (Art. 5 lit a)

The data subjects right to access their personal data and information about its processing.

Artefacts an auditor will ask for
  • policy/records evidencing right of access
  • evidence the obligation is met in processing operations
Where this commonly fails
  • right of access not implemented or evidenced
CL21719-A5b
Right of Rectification (Art. 5 lit b)

The right to rectify inaccurate, outdated or incomplete personal data.

Artefacts an auditor will ask for
  • policy/records evidencing rectification
  • evidence the obligation is met in processing operations
Where this commonly fails
  • rectification not implemented or evidenced
CL21719-A5c
Right of Cancellation/Erasure (Art. 5 lit c)

The right to cancellation (suppression/erasure) of personal data where the legal grounds apply.

Artefacts an auditor will ask for
  • policy/records evidencing erasure
  • evidence the obligation is met in processing operations
Where this commonly fails
  • erasure not implemented or evidenced
CL21719-A5d
Right of Opposition (Art. 5 lit d)

The right to object to the processing of personal data.

Artefacts an auditor will ask for
  • policy/records evidencing objection
  • evidence the obligation is met in processing operations
Where this commonly fails
  • objection not implemented or evidenced
CL21719-A5e
Right of Portability (Art. 5 lit e)

The right to data portability - to obtain and transfer personal data in a structured, commonly used format.

Artefacts an auditor will ask for
  • policy/records evidencing portability
  • evidence the obligation is met in processing operations
Where this commonly fails
  • portability not implemented or evidenced
CL21719-A8bis
Rights Regarding Automated Decisions (Art. 8 bis)

The right not to be subject to decisions based solely on automated processing that produce significant effects, and to obtain human intervention.

Artefacts an auditor will ask for
  • policy/records evidencing automated decisions
  • evidence the obligation is met in processing operations
Where this commonly fails
  • automated decisions not implemented or evidenced
CL21719-A8ter
Right to Block Processing (Art. 8 ter)

The right to request blocking (restriction) of processing in defined circumstances.

Artefacts an auditor will ask for
  • policy/records evidencing restriction
  • evidence the obligation is met in processing operations
Where this commonly fails
  • restriction not implemented or evidenced

Chile Law 21.719: Special Categories of Data

CL21719-A16
Sensitive Personal Data (Art. 16)

Special protection and restricted grounds for processing sensitive personal data.

Artefacts an auditor will ask for
  • policy/records evidencing sensitive data
  • evidence the obligation is met in processing operations
Where this commonly fails
  • sensitive data not implemented or evidenced
CL21719-A16bis
Health Data (Art. 16 bis)

Specific conditions for processing health-related personal data.

Artefacts an auditor will ask for
  • policy/records evidencing health data
  • evidence the obligation is met in processing operations
Where this commonly fails
  • health data not implemented or evidenced
CL21719-A16quater
Children's Data (Art. 16 quater)

Enhanced protection for the personal data of children and adolescents, including consent rules.

Artefacts an auditor will ask for
  • policy/records evidencing children's data
  • evidence the obligation is met in processing operations
Where this commonly fails
  • children's data not implemented or evidenced
CL21719-A16ter
Biometric Data (Art. 16 ter)

Specific conditions for processing biometric personal data.

Artefacts an auditor will ask for
  • policy/records evidencing biometric data
  • evidence the obligation is met in processing operations
Where this commonly fails
  • biometric data not implemented or evidenced

Chile Law 21.719: Supervision, Enforcement and Transition

CL21719-A26
Certification and Compliance Models (Art. 26)

Voluntary certification and compliance/prevention models that evidence compliance.

Artefacts an auditor will ask for
  • policy/records evidencing certification / compliance model
  • evidence the obligation is met in processing operations
Where this commonly fails
  • certification / compliance model not implemented or evidenced
CL21719-A36
Personal Data Protection Agency (Art. 30/36)

Establishment, powers and functions of the Agencia de Proteccion de Datos Personales (APDP) as the supervisory authority.

Artefacts an auditor will ask for
  • policy/records evidencing supervisory authority / cooperation
  • evidence the obligation is met in processing operations
Where this commonly fails
  • supervisory authority / cooperation not implemented or evidenced
CL21719-A45
Sanctions Regime (Art. 34 quinquies / Art. 45)

Administrative infringements and sanctions (fines graduated by seriousness) enforced by the Agency.

Artefacts an auditor will ask for
  • policy/records evidencing sanctions / enforcement exposure
  • evidence the obligation is met in processing operations
Where this commonly fails
  • sanctions / enforcement exposure not implemented or evidenced
CL21719-A50
Effective Date and Transition

Entry into force and the transition period for compliance with Law 21.719 (in force approximately December 2026).

Artefacts an auditor will ask for
  • policy/records evidencing transition / readiness
  • evidence the obligation is met in processing operations
Where this commonly fails
  • transition / readiness not implemented or evidenced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.