

The entry into force of the new legislation means that ecommerce businesses must review and update various aspects of their websites to comply with the new legal requirements, avoid potential penalties, and provide a better customer experience.
In this article, we outline the key measures companies should implement to adapt their ecommerce operations to Law 21.719, explaining the changes that are required and how to address them.
The new legislation requires data controllers to make available on their website a data processing policy that is accurate, clear, unambiguous, easily accessible, and free of charge.
The data processing policy must include:
A well-drafted privacy policy not only helps ensure compliance with the legislation but also strengthens customer trust by demonstrating transparency and accountability.
One of the most significant changes for any ecommerce business is that consent must be freely given, informed, specific, unambiguous, and obtained prior to processing. In practice, this means that consent must be expressed through a clear affirmative action. As a result, cookie banners can no longer include pre-ticked boxes; instead, users must actively choose to tick the relevant box to provide their consent.
Under this new requirement, consent can no longer be implied, as was possible under the previous legislation, nor can it be inferred from a user's inactivity or continued browsing of the website.
In addition, Law 21.719 establishes that withdrawing consent must be as easy as giving it. Your ecommerce website must therefore provide permanent and easily accessible mechanisms that allow users to withdraw their consent at any time, using a process that is as straightforward as the one through which consent was originally given.
Your customers have the right to access, rectify, erase, object to the processing of, and request the portability of their personal data, as well as to request the temporary restriction of its processing.
To enable customers to exercise these rights, your ecommerce website must provide an email address, contact form, or equivalent electronic channel through which they can submit their requests. You should also bear in mind that requests must be answered within 30 calendar days, with the possibility of a one-time extension of an additional 30 calendar days where applicable.
Your ecommerce website must be designed in accordance with the principles of privacy by design and privacy by default. This means that data protection must be embedded into the website from the outset and integrated into every data processing activity.
In practice, this requires implementing the principle of data minimisation, ensuring that only the personal data strictly necessary for each specific purpose is collected and processed.
The website must also implement security measures that are appropriate to the level of risk involved, such as pseudonymisation and encryption of personal data.
In addition, the system must ensure the confidentiality, integrity, and availability of personal data at all times.
If your website may be used by children or minors, particular care must be taken when processing their personal data.
To process the personal data of children under the age of 14, your website must obtain the consent of their parents or legal guardians. For teenagers between the ages of 14 and 18, parental consent is required for the processing of sensitive personal data where the individual is under the age of 16.
In practice, this means that businesses should review their registration forms, sign-up processes, and age verification mechanisms to ensure compliance with these requirements.
More and more ecommerce businesses are using geolocation tools and profiling technologies to personalise the shopping experience and optimise their marketing campaigns.
However, the new legislation requires that users be clearly and timely informed about the type of data being processed, how long it will be retained, and whether it will be shared with third parties. The law considers it a serious infringement to process personal data for marketing or profiling purposes without respecting the data subject's right to object.
Failure to comply with Law 21.719 may result in a range of consequences, from financial penalties, whose amount will depend on the seriousness of the infringement and whether it is a repeated offence, to the suspension of your ecommerce operations.
| Tipo de infracción | Sanción | Casos |
| Minor infringement | Written warning or a fine of up to 5,000 UTM | Failure to comply with website information requirements, responding to data subject requests after the statutory deadline, or failing to keep the data controller's contact details updated. |
| Serious infringement | Fine of up to 10,000 UTM | Processing personal data without valid consent or another legal basis, preventing data subjects from exercising their rights, or carrying out unlawful international data transfers. |
| Very serious infringement | Fine of up to 20,000 UTM | Fraudulent processing of personal data, intentionally using personal data for purposes other than those consented to, or breaching the confidentiality of sensitive personal data. |
| Repeat infringement by a large company | Fine of up to 2% or 4% of annual sales revenue | |
| Failure to remedy non-compliance within the prescribed period | 50% surcharge on the imposed fine | |
| Repeat infringement (general rule) | Fine of up to three times the applicable amount | |
| Repeat very serious infringement | Suspension of data processing operations for up to 30 days | |
In addition, you should be aware that sanctions remain recorded for five years in the National Register of Sanctions and Compliance, a public register that is freely accessible. This means that anyone—including your customers and competitors—can check whether your company has been sanctioned, potentially causing significant reputational damage.
But that's not all. Regardless of any administrative fine imposed, if a breach causes material or non-material damage to a data subject, that individual may bring a claim for compensation once the decision of the Data Protection Agency becomes final.
💡 Want to learn more about Law 21.719? Read our article.
To comply with the new legislation, you will need to review your data processing policy, redesign your consent management system, embed security into your website by design, implement safeguards for children's personal data, and provide transparent information about the use of geolocation technologies and cookies.
Implementing all of these changes can become a complex process, particularly if your ecommerce business processes large volumes of personal data or carries out multiple types of data processing activities. Ensuring that every new legal requirement is properly implemented requires time, expertise, and ongoing monitoring of legislative developments.
That's why, at Lawwwing, we make compliance simple. We provide an easy solution to help you adapt your ecommerce business to Law 21.719 by automatically generating and keeping your data processing policy up to date, as well as providing a fully customisable cookie banner that complies with the new legal requirements.
Don't wait until it's too late and adapt your ecommerce to Law 21.719 with Lawwwing.