Everything you need to know about Ley 25.326 compliance, data security requirements, and secure data disposal.
Argentina's Personal Data Protection Law — Ley 25.326 — was one of the earliest comprehensive data protection statutes in Latin America and remains the country's principal privacy framework today. Enacted in 2000, it was notably influenced by European data protection standards, which later helped Argentina become one of the few Latin American countries recognized by the European Commission as providing an adequate level of data protection under EU law.
Background
Ley 25.326 was enacted in October 2000, grounded in Section 43 of the Argentine Constitution, which explicitly recognizes a right of habeas data — allowing individuals to access, know the purpose of, and, where necessary, request the suppression or correction of information about themselves held in public or private data registries. The law's regulatory authority, now known as the Agencia de Acceso a la Información Pública (AAIP), oversees enforcement and has continued to issue updated guidance, including on international data transfers and biometric data.
Who Must Comply
Ley 25.326 applies to any natural or legal person, public or private, that owns or is responsible for a personal data file, register, database, or bank located in Argentina. Cross-border transfer provisions also affect any foreign entity seeking to receive personal data originating in Argentina.
Core Principles
The law establishes several foundational principles for lawful data processing:
- Consent – data subjects must generally consent to the collection and processing of their personal data, with narrower exceptions than many newer laws
- Quality of data – data must be accurate, relevant, and not excessive relative to the purpose for which it was collected
- Purpose limitation – data may only be used for the purpose for which it was collected
- Data security – data controllers must adopt technical and organizational measures to guarantee the security and confidentiality of personal data
- Confidentiality – data controllers and anyone involved in processing are bound by a duty of professional secrecy regarding the data
Sensitive Data
Argentine law defines sensitive data to include information revealing racial or ethnic origin, political opinions, religious, philosophical, or moral beliefs, trade union membership, and health or sex life information. No one may be compelled to provide sensitive data, and this category can only be collected or processed for reasons of general interest authorized by law, or with the data subject's consent.
Habeas Data Rights
Reflecting its constitutional origins, Argentine law gives individuals the right to:
- Access their personal data held in any public or private registry
- Request rectification of inaccurate data
- Request updating of outdated data
- Request suppression (deletion) of data that is inaccurate, unlawfully collected, or no longer necessary
- Request confidentiality treatment of specific data in appropriate circumstances
The habeas data action can be brought directly in court, giving individuals a constitutionally grounded remedy beyond ordinary regulatory complaint processes.
Cross-Border Data Transfers
Ley 25.326 restricts transferring personal data to countries or international organizations that do not provide adequate levels of protection, subject to exceptions such as international judicial cooperation, medical data transfers necessary for treatment, bank or stock exchange transfers within their normal scope of activity, or transfers agreed upon under a contract that guarantees adequate protection levels.
Enforcement and Penalties
The AAIP can conduct inspections, issue sanctions, and impose administrative fines for violations of the law, with amounts periodically updated. Serious violations — particularly those involving the unlawful use of sensitive data or fraudulent data collection — can also give rise to criminal liability under related provisions of Argentina's criminal code.
Secure Data Suppression
The right to suppression under Ley 25.326 requires that personal data be permanently and effectively removed once it is inaccurate, unlawfully obtained, or no longer necessary for its original purpose. Argentine regulatory guidance reflects the broader principle that "suppression" must mean genuine, irreversible removal — not data that remains recoverable through basic file recovery techniques. Organizations retiring computers, servers, or storage media that held personal data governed by Ley 25.326 should apply standards-based, verifiable data erasure and retain destruction records to support their security and confidentiality obligations under the law.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
As one of Latin America's most established privacy frameworks — and one with EU adequacy recognition — Ley 25.326 sets a meaningful compliance bar. Organizations processing personal data connected to Argentina need strong consent practices, clear handling of sensitive data, and secure, documented data suppression processes to satisfy both the letter of the law and its constitutional habeas data foundation.
No comments yet. Be the first to comment.