Argentine Personal Data Protection Act (Ley 25.326)

Latin AmericaPrivacy2000
ByDecipherU Editorial

Argentina's PDPA is one of Latin America's oldest cybersecurity and data protection laws, influenced by EU data protection standards. Argentina holds an EU adequacy determination (from 2003), enabling free data flows with the EU. The law requires registration of databases with the AAIP (Access to Public Information Agency) and consent before processing personal data. A reform bill has been under discussion since 2018.

Quick Reference

EnactedNovember 2, 2000
Last AmendedRegulatory updates via Decree 1558/2001; reform pending
Enforcement BodyAgencia de Acceso a la Información Pública (AAIP)
PenaltiesAdministrative sanctions including warnings, suspension, fines, and closure of databases
Applicable ToPublic and private entities processing personal data registered in databases in Argentina

Key Requirements

Article 9 (Security of data)

The data controller must adopt technical and organizational measures necessary to guarantee the security and confidentiality of personal data

Article 21 (Registration of databases)

Every database that exceeds private use must be registered with the AAIP, declaring purpose, nature of data, and security measures

Article 12 (Cross-border data transfer)

Transfer of personal data to countries or international organizations that do not provide adequate levels of protection is generally prohibited

How Does Argentina PDPA Affect Cybersecurity Careers?

Argentina's EU adequacy status makes it a preferred location for data processing operations serving European companies. Cybersecurity professionals in Argentina operate under an established but aging legal framework. The pending reform means professionals should prepare for updated requirements aligned more closely with GDPR.

Cybersecurity Roles That Work With Argentina PDPA

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of Argentina PDPA at the official source: https://www.argentina.gob.ar/aaip/datospersonales/ley-25326

Frequently Asked Questions

What is Argentina PDPA in cybersecurity?

Argentina's PDPA is one of Latin America's oldest cybersecurity and data protection laws, influenced by EU data protection standards. Argentina holds an EU adequacy determination (from 2003), enabling free data flows with the EU. The law requires registration of databases with the AAIP (Access to Public Information Agency) and consent before processing personal data. A reform bill has been under discussion since 2018.

How does Argentina PDPA affect cybersecurity careers?

Argentina's EU adequacy status makes it a preferred location for data processing operations serving European companies. Cybersecurity professionals in Argentina operate under an established but aging legal framework. The pending reform means professionals should prepare for updated requirements aligned more closely with GDPR.

What are the penalties for Argentina PDPA non-compliance?

Administrative sanctions including warnings, suspension, fines, and closure of databases

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?