logo Lawwwing

Prepare Your Ecommerce Business for Law 21.719: Key Steps to Ensure Compliance

The entry into force of the new legislation means that ecommerce businesses must review and update various aspects of their websites to comply with the new legal requirements, avoid potential penalties, and provide a better customer experience. In this article, we outline the key measures companies should implement to adapt their ecommerce operations to Law […]
Legal Lawwwing
July 30, 2026

The entry into force of the new legislation means that ecommerce businesses must review and update various aspects of their websites to comply with the new legal requirements, avoid potential penalties, and provide a better customer experience.

In this article, we outline the key measures companies should implement to adapt their ecommerce operations to Law 21.719, explaining the changes that are required and how to address them.

1. Information and Transparency: Update Your Data Processing Policy

The new legislation requires data controllers to make available on their website a data processing policy that is accurate, clear, unambiguous, easily accessible, and free of charge.

The data processing policy must include:

  • The personal data processing policy adopted by the organisation, including its version number and date of publication.
  • Identification of the data controller and its legal representative, as well as the designated data protection officer or compliance officer, where applicable.
  • The postal address, email address, and contact form through which data subjects may submit requests.
  • The categories or types of personal data processed, the recipients of the data, the purposes of processing, the legal basis for processing, and, where applicable, the legitimate interests relied upon.
  • The security policy and the technical and organisational security measures implemented.
  • The rights of data subjects.
  • Information on transfers of personal data to third countries or international organisations, including whether they provide an adequate level of data protection.
  • The applicable data retention period.
  • The source from which the personal data was obtained.
  • Information on the right to withdraw consent at any time.
  • Information on the existence of automated decision-making, including profiling.

A well-drafted privacy policy not only helps ensure compliance with the legislation but also strengthens customer trust by demonstrating transparency and accountability.

2. Consent Management: Your Cookie Banner

One of the most significant changes for any ecommerce business is that consent must be freely given, informed, specific, unambiguous, and obtained prior to processing. In practice, this means that consent must be expressed through a clear affirmative action. As a result, cookie banners can no longer include pre-ticked boxes; instead, users must actively choose to tick the relevant box to provide their consent.

Under this new requirement, consent can no longer be implied, as was possible under the previous legislation, nor can it be inferred from a user's inactivity or continued browsing of the website.

In addition, Law 21.719 establishes that withdrawing consent must be as easy as giving it. Your ecommerce website must therefore provide permanent and easily accessible mechanisms that allow users to withdraw their consent at any time, using a process that is as straightforward as the one through which consent was originally given.

3. Provide a Channel for Exercising Data Subject Rights

Your customers have the right to access, rectify, erase, object to the processing of, and request the portability of their personal data, as well as to request the temporary restriction of its processing.

To enable customers to exercise these rights, your ecommerce website must provide an email address, contact form, or equivalent electronic channel through which they can submit their requests. You should also bear in mind that requests must be answered within 30 calendar days, with the possibility of a one-time extension of an additional 30 calendar days where applicable.

4. Security and Data Protection by Design and by Default

Your ecommerce website must be designed in accordance with the principles of privacy by design and privacy by default. This means that data protection must be embedded into the website from the outset and integrated into every data processing activity.

In practice, this requires implementing the principle of data minimisation, ensuring that only the personal data strictly necessary for each specific purpose is collected and processed.

The website must also implement security measures that are appropriate to the level of risk involved, such as pseudonymisation and encryption of personal data.

In addition, the system must ensure the confidentiality, integrity, and availability of personal data at all times.

5. Protection of Children's Personal Data

If your website may be used by children or minors, particular care must be taken when processing their personal data.

To process the personal data of children under the age of 14, your website must obtain the consent of their parents or legal guardians. For teenagers between the ages of 14 and 18, parental consent is required for the processing of sensitive personal data where the individual is under the age of 16.
In practice, this means that businesses should review their registration forms, sign-up processes, and age verification mechanisms to ensure compliance with these requirements.

6. Geolocation and Tracking Cookies

More and more ecommerce businesses are using geolocation tools and profiling technologies to personalise the shopping experience and optimise their marketing campaigns.

However, the new legislation requires that users be clearly and timely informed about the type of data being processed, how long it will be retained, and whether it will be shared with third parties. The law considers it a serious infringement to process personal data for marketing or profiling purposes without respecting the data subject's right to object.

What Happens If You Fail to Comply?

Failure to comply with Law 21.719 may result in a range of consequences, from financial penalties, whose amount will depend on the seriousness of the infringement and whether it is a repeated offence, to the suspension of your ecommerce operations.

Tipo de infracciónSanciónCasos
Minor infringementWritten warning or a fine of up to 5,000 UTMFailure to comply with website information requirements, responding to data subject requests after the statutory deadline, or failing to keep the data controller's contact details updated.
Serious infringementFine of up to 10,000 UTM Processing personal data without valid consent or another legal basis, preventing data subjects from exercising their rights, or carrying out unlawful international data transfers.
Very serious infringementFine of up to 20,000 UTM Fraudulent processing of personal data, intentionally using personal data for purposes other than those consented to, or breaching the confidentiality of sensitive personal data.
Repeat infringement by a large companyFine of up to 2% or 4% of annual sales revenue
Failure to remedy non-compliance within the prescribed period50% surcharge on the imposed fine
Repeat infringement (general rule)Fine of up to three times the applicable amount
Repeat very serious infringementSuspension of data processing operations for up to 30 days

In addition, you should be aware that sanctions remain recorded for five years in the National Register of Sanctions and Compliance, a public register that is freely accessible. This means that anyone—including your customers and competitors—can check whether your company has been sanctioned, potentially causing significant reputational damage.

But that's not all. Regardless of any administrative fine imposed, if a breach causes material or non-material damage to a data subject, that individual may bring a claim for compensation once the decision of the Data Protection Agency becomes final.

💡 Want to learn more about Law 21.719? Read our article.

How Can I Comply with Law 21.719?

To comply with the new legislation, you will need to review your data processing policy, redesign your consent management system, embed security into your website by design, implement safeguards for children's personal data, and provide transparent information about the use of geolocation technologies and cookies.

Implementing all of these changes can become a complex process, particularly if your ecommerce business processes large volumes of personal data or carries out multiple types of data processing activities. Ensuring that every new legal requirement is properly implemented requires time, expertise, and ongoing monitoring of legislative developments.

That's why, at Lawwwing, we make compliance simple. We provide an easy solution to help you adapt your ecommerce business to Law 21.719 by automatically generating and keeping your data processing policy up to date, as well as providing a fully customisable cookie banner that complies with the new legal requirements.

Don't wait until it's too late and adapt your ecommerce to Law 21.719 with Lawwwing.

How can we help you?
If you have any questions, our specialists are here to assist you whenever you need it.
Live Chat
Share this article
Blog

Related Articles

Businesses trust Lawwwing to ensure their legal compliance, keeping their documents up-to-date and avoiding penalties.
cross