Everything you need to know about Ley 29733 compliance, data security requirements, and secure data disposal.
Peru's Personal Data Protection Law — Ley de Protección de Datos Personales, Ley No. 29733 — is the country's foundational data privacy statute, governing how public and private entities collect, process, and store personal data. Enacted in 2011 and later strengthened through amendment, the law reflects Peru's alignment with broader Latin American and international data protection standards.
Background
Ley No. 29733 was enacted in July 2011, with its implementing regulations (Supreme Decree No. 003-2013-JUS) following in 2013 to provide operational detail. The law was significantly updated through Legislative Decree No. 1353 in 2017, which, among other changes, created the Autoridad Nacional de Protección de Datos Personales (National Data Protection Authority) as an independent body to oversee enforcement, having previously been housed within the Ministry of Justice.
Who Must Comply
The law applies to personal data contained or intended to be contained in databases administered by public or private entities, whether the data is processed in Peru or the databases are managed from abroad but relate to individuals in Peru. This gives the law meaningful extraterritorial reach for organizations processing Peruvian residents' data from outside the country.
Core Principles
Peru's law establishes several guiding principles for lawful processing, including:
- Legality – processing must not involve unlawful or fraudulent collection methods
- Consent – processing generally requires the data subject's free, prior, informed, express, and unambiguous consent
- Purpose specification – data may only be collected for a specific, explicit, and lawful purpose
- Proportionality – data processing must be adequate, relevant, and not excessive relative to the stated purpose
- Data quality – personal data must be accurate and kept up to date
- Security – data controllers must adopt necessary technical, organizational, and legal measures to protect personal data
- Confidentiality – personal data may not be disclosed for purposes incompatible with the purpose for which it was collected, without the consent of the data subject
Sensitive Data
The law defines sensitive personal data to include information related to racial or ethnic origin, income, political or religious beliefs, philosophical convictions, union affiliation, health, and sex life, as well as biometric data that could uniquely identify a person. Processing sensitive data requires explicit written consent, subject to narrow statutory exceptions.
Individual (ARCO) Rights
Peruvian data subjects hold rights closely modeled on the ARCO framework common across Latin America: the right to access their personal data, the right to update or rectify inaccurate data, the right to have data included where legally required, and the right to oppose or cancel (delete) the processing of their data under specified circumstances, such as when data was unlawfully collected or is no longer necessary for its original purpose.
Registration of Databases
A distinctive feature of Peruvian law is the requirement for data controllers to register their personal data databases with the National Data Protection Authority, providing transparency about what databases exist and who administers them — a registration obligation not commonly found in many other privacy frameworks.
Enforcement and Penalties
The National Data Protection Authority can investigate complaints, conduct audits, and impose administrative sanctions for violations, with fines calibrated according to the severity of the infringement — ranging from minor infractions to serious and very serious violations, the latter carrying the most substantial financial penalties under the law's sanctioning framework.
Secure Data Cancellation
The right to cancellation under Peruvian law requires that personal data be genuinely and permanently removed once a valid cancellation request is made or once the data is no longer necessary for its original purpose. Consistent with the law's security principle, this means data controllers retiring servers, computers, or storage devices that held personal data should apply standards-based erasure methods that render the data unrecoverable, rather than relying on basic deletion, and should maintain documentation of destruction to support compliance in the event of an audit by the National Data Protection Authority.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
Peru's data protection law combines strong ARCO-style individual rights with a distinctive database registration requirement, giving the National Data Protection Authority meaningful oversight of how personal data is organized and processed across the country. Organizations handling Peruvian residents' personal data need robust consent practices, timely handling of individual rights requests, and secure, verifiable data disposal procedures to remain compliant.
No comments yet. Be the first to comment.