ISO/IEC 27701:2025 · Privacy governance

Privacy
Governance

A privacy management system built on ISO/IEC 27701:2025, aligned with Law 21,719 and the GDPR at the same time.

Why this programme

The standard no longer requires a pre-existing ISMS

The 2025 revision turned ISO/IEC 27701 into a standalone standard: it is no longer an extension that requires ISO 27001 certification first. That puts it within reach of organisations that need to demonstrate privacy governance without first building a full security management system.

 Mandatory transition until October 2028

The transition has a date: anyone already certified under the 2019 edition must move to the 2025 one before October 2028 — current certificates are valid until they expire or until that deadline, whichever comes first. And the accredited circuit is now complete: ISO/IEC 27706:2025 replaced ISO/IEC TS 27006-2:2021 as the standard for certification bodies, so certifying the privacy system on its own is auditable today, not an expectation.

And there is a local reason with a date on it: Law 21,719 comes into force on 1 December 2026 —with 92 days— to go, and it reaches any organisation that processes personal data, not just critical operators. A serious implementation takes three to six months. Anyone who also has clients or suppliers in Europe needs to answer to the GDPR with the same evidence. This programme produces a single set of documentation that serves all three frameworks, instead of three projects that nobody reconciles afterwards.

Standards that integrate

The standard and its reference

ISO/IEC 27701:2025 — privacy management system
ISO/IEC 29100 — privacy framework, its only normative reference
ISO/IEC 27706:2025 — PIMS certification (bodies)

Mappings the standard itself provides

GDPR — annex D
ISO/IEC 27018 and ISO/IEC 29151 — annex E
ISO/IEC 27701:2019 — annex F, for anyone coming from the previous edition

Methodology we bring

ISO/IEC 29134 — privacy impact assessment
ISO 31000 — risk management
ISO/IEC 27002 — security controls

The Chilean law

Law 21,719, Without Embellishment

Everything in this section is cited by article and verified against the consolidated text. If the law does not require it, it does not appear here as mandatory — and what it does require and is usually left out is flagged.

30días corridos

To rule on a data subject request

Art. 11
+30días corridos

Of extension, and it can only be used once

Art. 11
2días hábiles

To answer a temporary blocking request

Art. 11
0de margen

Breaches are reported «without undue delay»

Art. 14 sexies

14 duties grouped by topic. Tap one to open it.

Towards individuals Six rights that cannot be limited by contract, and a clock that starts running the moment the request comes in. 2
Art. 4°

Six rights, not four

Access, rectification, erasure, objection, portability and blocking. They are personal, non-transferable and cannot be waived, and they cannot be limited by any act or agreement.

A procedure with the six channels, identity authentication of the requester and criteria for reasoned refusal.

Art. 11

Thirty days, and you have to be able to prove it

Acknowledge receipt and rule within 30 calendar days, extendable only once by another 30. You have to store the record that proves the response was sent, its date and its full content. A temporary blocking request is answered within 2 working days, and until it is resolved that data cannot be processed.

A register of requests with deadline tracking, response templates and an evidence file for each request.

What must be published The heaviest documentary obligation in the law, and the only one an inspector can review without having to ask anyone for anything. 1
Art. 14 ter

Twelve items, permanently on show

The website must keep «at least» twelve items, from letter a) to letter l): the processing policy with its date and version; the controller and its legal representative; the contact channel; the categories of data, the universe of data subjects, the recipients, the purposes and the basis of legitimacy; the security measures; the data subject's rights; the right to appeal to the Agency; international transfers and their safeguards; the retention period; the source of the data; the right to withdraw consent; and the existence of automated decisions with information about the logic applied.

A public policy drafted against the twelve letters, versioned and published. It is a superset of the record of processing activities of article 30 of the GDPR, and public on top of that.

How the data has to be processed Three duties that do not produce a document, but a way of operating that you then have to be able to prove. 3
Art. 14

Prove lawfulness, do not declare it

Inform the data subject and make available the records that prove the lawfulness of the processing, and hand them over promptly when asked for them. Collect from lawful sources for specific and explicit purposes. Communicate accurate, complete and up-to-date information. Delete or anonymise what was obtained for pre-contractual measures.

An inventory of processing operations with the purpose and lawful basis declared for each one, and deletion rules for when the purpose ends.

Art. 14 bis

Secrecy outlives the relationship

The duty of confidentiality survives even after the relationship has ended with the data subject. And there is a common trap: if data is taken from public sources and then organised, classified, combined or supplemented, the result is protected by the same duty.

Confidentiality clauses in employment and processing contracts, role-based access control, and treating public sources as what they become once you enrich them.

Art. 14 quáter

By design and by default

Technical and organisational measures applied before and during the processing, taking into account the state of the art, the costs, the nature and the risks. And by default, processing only the data that is strictly necessary, having regard to the amount of data, its extent, the retention period and its accessibility.

Privacy controls built into the processes and systems that already exist, not into a separate annex.

Security and breaches Here the law reverses the burden of proof, and that single subsection changes the value of the whole file. 3
Art. 14 quinquies

If there is an incident, you prove you were protected

The measures must ensure confidentiality, integrity, availability and resilience, and include «among others» pseudonymisation and encryption, the ability to restore access quickly after an incident and a process of regular verification of their effectiveness. In an incident and in judicial or administrative proceedings, it falls to the controller to prove that they existed and worked.

Annex A controls with dated evidence that they operate. It is that reversed burden of proof that makes the file the only defence available.

Art. 14 sexies

It is not 72 hours: it is «without undue delay»

Report to the Agency «by the most expeditious means possible and without undue delay» whenever there is a reasonable risk to the rights of the data subjects, and keep a record of those notifications. If the data is sensitive, belongs to children under fourteen or is economic, financial, banking or commercial in nature, it must also be communicated to each affected data subject, in clear and simple language; if that is not possible, by notice in a mass medium with national reach.

A breach procedure with a decision tree, notification templates for the Agency and for the data subjects, and a register of security breaches.

Art. 14 septies

The standard is not the same for everyone

The minimum standards for the duties of information and security are graded by type of data, by whether the controller is a natural or legal person, by the size of the company under Law 20,416, by the activity and by the volume and the purposes of the data. The Agency will set them by general instruction, which does not yet exist.

Scope and depth sized to the organisation, with the grading criterion documented so that it can be defended.

Third parties and risk Whoever processes data on your behalf can become a controller, and be jointly and severally liable, for signing a contract badly. 2
Art. 15 bis

Six mandatory items in every contract

Every processing engagement is governed by a contract, and the contract must set out the subject matter, duration, purpose of the processing, type of data, categories of data subjects and the rights and obligations of the parties. The processor cannot sub-delegate without specific written authorisation. If it processes the data for a different purpose or transfers it without authorisation, it is deemed a controller for all legal purposes and is jointly and severally liable for the damages. Once the service ends, the data is deleted or returned.

Processing contracts with the six required contents, sub-processing clauses and a processor matrix cross-checked against the inventory. The Agency will publish model contracts; we review them so that they are not signed blind.

Art. 15 ter

Impact assessment before, not after

Mandatory before the start of the processing whenever a high risk is likely, and always in four cases: profiling with significant legal effects, mass or large-scale processing, systematic monitoring of publicly accessible areas, and sensitive data processed under an exception to consent.

A methodology based on ISO/IEC 29134 and the assessments of the processing operations that fall within the four cases, with prior consultation of the Agency when the result advises it.

Prevention and certification Prevention is mandatory. Formalising it in a certified model is not, but it is the only thing the law expressly recognises as a mitigating factor. 3
Art. 48

Prevenir sí es obligatorio

Controllers, whether natural or legal persons, public or private, shall adopt actions aimed at preventing the commission of the infringements in articles 34 bis, 34 ter and 34 quáter. The verb is «shall»: this is not voluntary.

An infringement risk analysis by process and a preventive action plan traceable to each type of infringement.

Art. 49 y 50

The model and the officer are indeed voluntary

The prevention model is adopted voluntarily and, if it is adopted, it must contain seven minimum elements —starting with appointing an officer and defining their means and powers—. The officer on their own is also optional: the controller «may» appoint one, it must be done by the highest authority, and in micro, small and medium-sized companies the owner can personally take on those tasks.

A compliance programme with the seven elements, a job description for the officer and its incorporation into the employment contracts or the internal rules, as article 49 itself requires.

Art. 51 y 52

The Agency certifies, and it lasts three years

It is the Agency itself that certifies the model, not a third party, and that supervises it. The certificate is valid for three years and lapses through revocation, dissolution, court order or cessation of the activity. Valid certificates are published in the National Register of Sanctions and Compliance.

Preparation of the certification file and of the supervision cycle, plus tracking the renewal before it expires.

What non-compliance costs

Leves up to 5.000 UTM
Written warning or fine
Graves up to 10.000 UTM
Multa
Gravísimas up to 20.000 UTM
Multa

If the corrective measures are not adopted within 60 days, the fine carries a 50% surcharge. With a repeat offence the amount can reach three times.

The 2% or 4% of annual revenue is an exceptional ceiling: it only reaches companies that are not small businesses and that reoffend in serious or very serious infringements. Reoffending means having been sanctioned two or more times in thirty months, with the resolutions final.

Everything is published in the National Register of Sanctions and Compliance, free and public, and the entries stay visible five years. It also shows who holds a valid certified model.

During the first twelve months, the Agency may issue small businesses with a written warning instead of the penalty. May, not must — and the warning is also entered in the public register.

Three things that get sold and the law does not require

You have to register in a public register

There is no such register. The third transitional article orders the elimination of the data bank register kept by the Registro Civil under article 22 of Law 19,628, and creates none in its place. What is mandatory is publishing the content, under article 14 ter.

You have to appoint a data protection officer

Article 50 says that the controller «may» appoint one, and 14 ter b) refers to the prevention officer «if one exists». In micro, small and medium-sized companies the owner can take on those tasks. What is mandatory, under article 48, is adopting prevention actions.

Breaches are notified within 72 hours

That deadline is the GDPR's. Article 14 sexies requires reporting «by the most expeditious means possible and without undue delay», which in practice is more demanding: it grants nobody three days of leeway.

How we work

Seven Phases, Concrete Deliverables

They run through clauses 4 to 10 of the standard and the controls of its Annex A. Estimated duration of 4 to 7 months depending on the size and complexity of the organisation.

  1. Fase 1 of 7 Diagnosis and scope

    A gap assessment against ISO 27701, Law 21,719 and the GDPR in a single matrix. A defined system scope, with the role declared —controller, processor or both, because the standard requires different controls for each— and an executive report for top management.

  2. Fase 2 of 7 Governance

    A public processing policy with the contents of article 14 ter, an internal privacy policy, named assignment of responsibility for the system —ISO 27701 requires a point of contact, Law 21,719 does not require appointing a data protection officer—, a committee and measurable privacy objectives.

  3. Fase 3 of 7 Inventory and mapping

    The Record of Processing Activities, the source of the twelve lettered items that article 14 ter requires you to publish, the details that article 15 bis requires to be stated in every processing contract and the proof of lawfulness under article 14, letter a). With it: data flows, purpose and legal basis for each processing operation, and an inventory of international transfers with the destination countries and their safeguards.

  4. Fase 4 of 7 Risk and impact

    Privacy risk methodology, impact assessments for high-risk processing and the statement of applicability: the document that justifies every annex A control that is excluded, and without which there is no certification.

  5. Fase 5 of 7 Controls and procedures

    Data subject rights —including a copy of their data and automated decisions—, breach notification with the deadlines of both frameworks, contracts with processors, retention, secure deletion and de-identification once the purpose ends.

  6. Fase 6 of 7 Privacy by design

    The controls the standard requires you to apply before collecting: minimisation, purpose limitation, accuracy and handling of temporary files. They are built into the processes and systems that already exist, not into a separate document.

  7. Fase 7 of 7 Implementation and verification

    Supported rollout, role-based training, an evidence file, internal audit, management review and preparation for certification.

What you can engage

Scopes of the Programme

The gap assessment can be engaged on its own. Below, the option of integrating it with AI Governance into a single management system, which costs less than running them apart.

Privacy Governance

ISO 27701

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%
Promotion

ISO 27701 + ISO 42001, integrated

One single project, not 2 por separado

  • Gap assessment Gap assessment
    −20%
  • Regulatory implementation Gap closure and evidence
    −20%
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.

Build my quote
Next step

Let Us Discuss Your Scope

A 30-minute call, at no cost, to understand your situation and tell you frankly whether this programme is what you need.

Request a proposal See AI Governance
Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?