By Maritza Marchant, Director of Consulting at CCL Auditores Consultores.
Read the opinion column in Diario Financiero.
The new amendments to Law 20.393, reflected in the Economic and Environmental Crimes Law, and now with the passage in Congress of the Personal Data Protection Law, raise the standard for the protection of individuals’ rights.
This latest amendment will allow Chile to be recognized by the European Commission as a country with an adequate level of personal data protection, facilitating international data transfers between our country and the European Union, a key trading partner of Chile.
The new law will enter into force 24 months after its publication, allowing all data controllers to adapt to this new framework, which follows the principle of establishing protection systems or models that include, among others: the designation of a data protection officer (individual(s) responsible for managing risks), internal and external control reports to the data protection authority (vulnerabilities), and the implementation of a system for preventing violations of data protection laws.
Consequently, under these new standards, it is imperative to establish comprehensive prevention models within organizations, which must evolve toward a global risk management approach, ideally aligned with the principles of the ISO 31.000 family of standards. This means they should be integrated, structured, comprehensive, adaptable, inclusive, dynamic, supported by better available information, consider human and cultural factors, and incorporate continuous improvement.
Otherwise, fragmented structures will emerge within organizations, leading to limited cooperation between departments, poor communication, weakened interdepartmental relationships, increased internal division, and team burnout, all of which will hinder decision-making and operational efficiency.