Law 21,719
Personal Data
-
Gap assessment Gap assessment
-
Regulatory implementation Gap closure and evidence
-
Gap assessment + implementation Both services, together−15%
Specialist consultancy in ISO/IEC 27001:2022, Cybersecurity Framework Law (21,663) and Personal Data Protection Law (21,719). Choose the service you need:
Click the service that best fits your current situation.
You do not know exactly what you are missing in order to comply. The gap assessment gives you a clear picture of gaps, priorities and the way forward — before investing in implementation.
You already know what you need and are ready to do it. We implement ISO 27001, Law 21,663 or Law 21,719 alongside your team, with complete documentation and audit preparation.
The gap assessment compares your current situation —documentation, controls, processes and governance— against the exact requirements of the regulation you need to comply with. The result is not a generic list: it is a a compliance matrix, requirement by requirement with maturity scoring by domain and a roadmap prioritised by risk.
For ISO 27001 we assess clauses 4–10 and the 93 Annex A controls. For Law 21,663, the duties that follow from your designation (Operator of Vital Importance or essential service). For Law 21,719, principles, lawful bases, rights and security obligations.
Price a gap assessmentAll in editable DOCX format, ready to present to the board, auditors or regulators.
End-to-end support alongside your team, with complete documentation and preparation for audit or inspection.
We design and implement your Information Security Management System (ISMS) in line with clauses 4–10 of ISO 27001:2022 and the 93 Annex A controls organised into 4 domains: organisational (37), people (8), physical (14) and technological (34). At the close, your organisation is ready to certify with an accredited body.
Law 21,663 created the ANCI and established mandatory duties for Operators of Vital Importance and providers of essential services. Incident reporting with the strict deadlines of article 9: early alert within 3 hours, a second report within 72 hours —or within 24 if an Operator of Vital Importance sees the delivery of its essential service affected— and a final report within 15 days. Operators of Vital Importance must also submit a action plan within 7 calendar days. Fines of up to 20,000 UTM (40.000 UTM for Operators of Vital Importance in very serious infringements).
Law 21,719 brings the Chilean privacy regime up to GDPR level: it creates the Data Protection Agency, recognises the rights of access, rectification, erasure, objection, portability and blocking and sets fines of up to 20,000 UTM for very serious infringements. For companies that are not small businesses and that reoffend, the fine can reach 2% or 4% of annual revenue from the business, depending on whether the infringement is serious or very serious. It applies to every organisation that processes data in Chile, whatever its size.
Think of the specific regulation you are interested in (ISO 27001, Law 21,663 or Law 21,719).
Whether internal, with an external consultant, or through Ziemtinel's free assessment.
For example, a process with a corporate client, an ANCI audit, or Law 21,719 coming into force.
We do not start from scratch: our catalogue covers all three regulations with professional documentation that we adapt to your reality. That saves months of work.
Whoever works with you knows the Chilean regulatory landscape and has defended documentation before auditors. Regulatory judgement cannot be improvised.
ISO 27001, Law 21,663 and Law 21,719 share many requirements. We implement them together so that one effort satisfies all three.
Every document and piece of evidence we deliver can be defended before auditors, the ANCI and the Data Protection Agency. Real compliance, not paper compliance.
We work with organisations in Chile and across Latin America: the ISO standards are the same in every country. Each scope can be engaged as an assessment, as a full implementation, or as both together, with the detailed scope and deliverables set out in the proposal.
Personal Data
Cybersecurity Framework
Information Security
One single project, not 3 por separado
How the value is determined
Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.
The management system the standard certifies is the same one that article 8(a) of Law 21,663 requires of an Operator of Vital Importance. The five phases, the four deadlines of article 9, and which legal duty each stage covers.
See the programmeThey all share the same management system structure, so the context, the roles, document control and the internal audit are built once and serve all of them. Each programme is contracted separately, but implementing them as one integrated management system avoids duplicating what is already done.
ISO 27701
ISO 42001
ISO 9001
ISO 22301
ISO 20000-1
One single project, not 2 por separado
How the value is determined
Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.
ISO/IEC 27001:2022 with Law 21,663 built in and the personal data layer Law 21,719 requires. One management system for all three.
See the programmeISO/IEC 27701:2025 as a privacy management system, with a single matrix covering Law 21,719 and the GDPR. For those who process personal data and need to prove it.
See the programmeISO/IEC 42001:2023, the first certifiable AI management standard. For those already using models who need to govern them before they are required to.
See the programmeISO 9001, the standard most often required in tenders and in contracts with large companies. For those who need to certify without ending up with a folder nobody uses.
See the programmeISO 22301, to keep operating when something goes down. With the impact analysis and, above all, with exercises that are actually run.
See the programmeISO/IEC 20000-1, a Chilean standard cited in government IT tenders. To answer for the services you provide, with figures.
See the programmeBuild your quote in two minutes: choose the regulations and the service you need, indicate the size of your organisation and see the reference figure on screen. A senior consultant contacts you within 24 business hours with the formal proposal.
Regulations, service and the size of your organisation. The reference figure appears instantly, with no waiting for a reply.
A 30-minute video call, at no cost, to understand your context and your urgency.
You receive scope, phases, deliverables, timelines and figures. No hidden commitments.
It takes two minutes and commits you to nothing.
Would you rather write to us directly? contacto@ziemtinel.cl
Your basket is empty
Add regulatory documentation packs or plans