Glossary

Glossary

The terminology we use at Auda Systems, explained simply. From connectors to Law 21.719 compliance.

01

Connectors

Connectors are a set of AI-managed integration systems that let our clients connect our platform to the systems they already use, whether third-party or built in-house. The number of connectors available in Auda Systems grows day by day, enabling accelerated growth for our clients.

Auda Systems also offers custom connectors, which let you connect systems built in-house at each company.

Connect your systems in minutes. AI maps which personal data you process and keeps your ROPA always up to date.


02

RAT / ROPA

It is a Record of Processing Activities. It is the evidentiary record of what has been done with people’s information. It must be complete and auditable, and every process must be documented. Auda Systems has ready-to-use Chilean templates, pre-loaded according to Law 21.719.


03

ARCO+ & DSR Portal

It is a web portal that lets people exercise their rights over their personal information. Users or individuals can request changes to the information companies hold about them. These changes include editing, deleting, expanding, cancelling or rectifying data.

A free public portal for your data subjects to exercise their rights, with identity verification. Internal management saves you time and money — and logs every step.


04

DPIA

It is a module that helps assess and quantify the impact of breaches. It helps identify, analyze and mitigate risks. It must also notify breaches within 72 hours of their occurrence.


05

Evidence Vault

Encrypted module that securely stores the information and evidence of the many processing operations and actions that have been carried out.

Compliance checklist

What key features should software have to comply with Law 21.719?

Data catalogs and inventories (RAT)

Build a complete, auditable Record of Processing Activities, documenting what data is processed, for what purpose, legal basis, categories, retention periods and recipients (arts. 16 and 17). It must be kept dynamically up to date.

Consent automation

Engines to obtain, manage and record express, free, specific, informed and unambiguous consent. It logs the date, the privacy-notice version and a full history, including revocation at any time.

ARCO+ rights portal (ARCOP)

Automated digital channel to manage Access, Rectification, Cancellation, Objection and Portability requests. It assigns deadlines (e.g. 30 days), sends alerts, keeps full traceability and guarantees free, interoperable responses.

Impact assessments (DPIA)

Carry out Data Protection Impact Assessments, especially for "high-risk" processing (AI, biometrics, mass surveillance), with workflows to identify, analyze and mitigate risks, documenting the whole process.

Security breach response

A system that logs and manages incidents, enabling notification of the Data Protection Agency and data subjects within legal deadlines. It documents severity and corrective measures and generates the official report.

Technical security measures

Strong encryption in transit and at rest, role-based access control (RBAC), pseudonymization, anonymization and audit logs that show who accessed, modified or deleted personal data, and when.

Third-party compliance

Manage and monitor vendors and processors: due diligence, standard contractual clauses (DPA) and compliance verification for international transfers to countries with an adequate level of protection.

Policy and evidence management

Centralize privacy and security policies, with version control and generation of concrete evidence of their application: the law requires proving compliance with facts, not just documents.

Infringement-prevention model

A risk-management system that periodically identifies, assesses and mitigates potential legal breaches, keeping a record of staff training and internal audits carried out.

Legal framework

Law 21.719 summary

Law 21.719 modernizes Chile's personal-data protection regime, substantially amending Law 19.628. It aligns the country with international standards — especially the European GDPR — strengthens data-subject rights, sets binding principles for lawful processing, creates an independent Personal Data Protection Agency (APDP) with enforcement powers, and introduces obligations such as data protection by design and by default, breach notification, proactive accountability, and stricter rules for sensitive data and international transfers.

Published

Dec 13, 2024

In force

Dec 1, 2026

Amends

Ley 19.628

The 6 data-subject rights (ARCO+)

Article 4 expressly recognizes six personal, inalienable and non-waivable rights. Data subjects may exercise them directly before the controller, with recourse to the Agency. Responses are generally provided within 30 days (extendable in complex cases).

01

Access

Obtain confirmation of whether your data is being processed and, if so, access it along with the key details: purposes, recipients and the logic of automated decisions.

02

Rectification

Request the correction, updating or completion of inaccurate, outdated or incomplete data.

03

Erasure or cancellation

The "right to be forgotten": request deletion when the data is no longer necessary, consent is withdrawn (with no other legal basis), it has been unlawfully processed, or on other grounds.

04

Objection

Object to specific processing, for example that based on legitimate interest, direct marketing or data from public sources.

05

Portability

Receive a copy of your data in a structured, commonly used, machine-readable format, and transmit it — or have it transmitted — to another controller when processing is automated and based on consent or a contract.

06

Blocking or suspension

Request the temporary suspension of processing — for example, while a rectification, erasure or objection is resolved. The data may remain stored.

Automated decisions: the law also establishes safeguards against decisions based solely on automated processing — including profiling — with significant effects, with the right to an explanation, human intervention and to contest them.

The 8 guiding principles (Article 3)

They are mandatory for all processing carried out by controllers and processors. They form the basis of compliance, documentation and proactive accountability.

1 · Lawfulness & fairness

Processing must have a valid legal basis (consent, contract, legal obligation, legitimate interest, etc.) and be carried out fairly and transparently. The controller must be able to prove its lawfulness.

2 · Purpose

Data is collected for specific, explicit and lawful purposes, and not further processed in a way incompatible with them (with limited exceptions).

3 · Proportionality & minimization

Data must be limited to what is strictly necessary, adequate and relevant to the stated purposes. This includes limiting the retention period.

4 · Quality

Data must be accurate, complete, up to date and relevant to the purposes of processing.

5 · Accountability

The controller guarantees compliance and must be able to demonstrate it proactively through records, policies and assessments (accountability).

6 · Security

Implement appropriate technical and organizational measures to protect data against unauthorized processing, loss or breaches. Breaches must be notified to the Agency and, where applicable, to data subjects.

7 · Transparency & information

Provide data subjects with clear, accessible and accurate information about processing activities, their rights and related policies.

8 · Confidentiality

Anyone with access to personal data must maintain confidentiality and secrecy — even after the relationship ends — with appropriate controls.

Key structural elements

Lawful bases for processing

Expanded beyond consent: performance of a contract, legal obligations, vital interests, tasks in the public interest, and legitimate interest (with a balancing test and right to object).

Personal Data Protection Agency (APDP)

An independent supervisory authority empowered to issue regulations, investigate, impose sanctions and resolve complaints.

Controller obligations

Data protection by design and by default, a record of processing activities (RAT/ROPA), a data protection officer (DPO) in high-risk cases, impact assessments (DPIA), reinforced security and breach notification (typically within 72 hours).

Sensitive data

Stricter rules for special categories: health, biometric data, racial or ethnic origin, political or religious beliefs and sexual orientation, among others.

Sanctions

Significant fines (up to 20,000 UTM — approximately US$1.5M or more depending on severity) and other administrative measures. Prevention models can mitigate liability.

International transfers

Regulated through adequacy decisions, appropriate safeguards or specific exceptions for sending data outside Chile.

Ready to comply without the hassle?

Start free and get your first compliance report in 30 minutes.