Latin America Argentina / EU

Argentina EU Adequacy: Using and Keeping the Status

Argentina's EU adequacy decision (2003, reaffirmed 2024): what it lets you do with EU data, onward-transfer limits, and how it interacts with Law 25.326 duties.

Regulation

Commission Decision 2003/490/EC; GDPR Article 45; Law No. 25.326

Max Penalty

Loss or suspension of adequacy would force SCCs onto all EU-Argentina flows; domestic violations sanctioned by the AAIP

Enforcing Authority

European Commission (adequacy review); AAIP (domestic enforcement)

Official Source

www.argentina.gob.ar

Executive Summary

  • The European Commission found Argentina adequate in 2003 (Decision 2003/490/EC), one of the first such decisions worldwide, allowing EU/EEA personal data to flow to Argentina without SCCs, BCRs, or derogations.
  • The Commission's January 2024 review of the eleven pre-GDPR adequacy decisions confirmed Argentina's continues in force, citing Law 25.326, the constitutional habeas data framework, AAIP oversight, and Convention 108+ ratification.
  • Adequacy covers the inbound leg only: EU data received in Argentina remains subject to Argentine law, and onward transfers from Argentina to third countries need their own safeguards.
  • For LATAM regional architectures, Argentina is the natural EU data hub: the only major economy in the region with adequacy (Uruguay being the other holder).
  • Keeping the benefit means honoring the framework that justifies it: registration, consent rules, the 10-day/5-day habeas data clocks, and AAIP guidance, plus monitoring the pending reform bill that would modernize the regime.

Adequacy is the rarest asset in data-transfer law, only around fifteen jurisdictions hold it, and Argentina has held it since 2003, reaffirmed when Brussels reviewed all legacy decisions in January 2024. For EU-facing businesses this is a straightforward commercial advantage: an Argentine data operation receives EU personal data with none of the SCC and transfer-impact-assessment machinery Brazil or Mexico require. The discipline is in the details adequacy does not cover: domestic Law 25.326 compliance and, above all, onward transfers, where the frictionless inbound leg meets Argentine transfer restrictions on the way out.

Decision2003/490/EC, confirmed by the Commission’s 2024 review
EffectEU/EEA data flows to Argentina without SCCs
Domestic lawLey 25.326, AAIP oversight
Onward transfersArgentine safeguards required (Disp. 60-E/2016 clauses)
Regional peersUruguay adequate; Brazil and Mexico not

Operating an adequacy-backed data flow

Use it where it pays. EU client data hosted or processed in Argentina skips Chapter V entirely; position Argentine entities as the EU landing zone in regional architectures instead of routing through non-adequate hubs.

Guard the onward legs. Every export from Argentina, to Brazil, the US, or a cloud region elsewhere, needs its own Argentine-law instrument; reconcile with Brazilian transfer rules when the chain continues south.

Maintain the domestic base. Registration, consent, and the habeas data clocks in the Law 25.326 guide are what the Commission’s reviews actually examine; treat them as the price of the asset.

Plan for the reform. The pending modernization bill would align Argentina with GDPR-grade practice; building to that standard now de-risks both the reform and future adequacy reviews.

EU-facing sites still need compliant consent and tracker behavior regardless of adequacy: check yours with a free scan.

Frequently Asked Questions

What does adequacy actually permit?

Under GDPR Article 45, transfers from the EU/EEA to Argentina are treated like intra-EU transfers: no SCCs, no transfer impact assessments, no derogations. An EU controller can host data with an Argentine processor, share with an Argentine subsidiary, or serve EU customers from Buenos Aires operations with no Chapter V paperwork. What adequacy does not remove is everything else: the EU controller still needs an Article 28 processing agreement, and the Argentine recipient must comply with Law 25.326 domestically.

Is the adequacy decision at risk?

The January 2024 Commission review concluded Argentina (with the other ten legacy adequacy holders) continues to provide adequate protection, the concrete evidence being Law 25.326, habeas data enforcement, an independent AAIP, and Convention 108+ ratification (2023). The Commission monitors continuously and can suspend or repeal a decision (as Schrems II showed for the US Privacy Shield). The realistic risk factors are institutional, weakening of the AAIP's independence or budget, rather than statutory; passage of the modernization bill would strengthen the case further.

Can we forward EU data from Argentina to other countries?

Only with safeguards. Onward transfers are the classic adequacy leak: Law 25.326 Article 12 prohibits transfers to countries without adequate protection, subject to consent and treaty exceptions, and AAIP Disposition 60-E/2016 provides model contract clauses for transfers to non-adequate destinations. An EU-to-Argentina-to-Brazil pipeline therefore needs an Argentine-law instrument on the second leg (Brazil is not on Argentina's adequacy view either), plus the EU exporter's visibility into the full chain. Map the chain before promising EU clients an Argentine hub.

How does Argentina's adequacy compare with how Brazil and Mexico handle EU data?

Brazil has no EU adequacy decision, so EU-to-Brazil flows need EU SCCs, and Brazil-side exports need Brazilian SCCs under ANPD Resolution 19/2024, double paper. Mexico likewise lacks adequacy, and its 2025 law reorganized the regulator, which does not help a near-term application. Uruguay holds adequacy (2012). So in a LATAM regional design, Argentina and Uruguay are the frictionless EU entry points; every other route pays the SCC toll on the EU leg.

What should an Argentine company do to stay on the right side of the decision?

Treat domestic compliance as adequacy maintenance: keep database registrations current, run consent-based processing with the statutory notices, hit the 10-day access and 5-business-day rectification clocks, apply AAIP security resolutions, and use Disposition 60-E/2016 clauses for onward transfers. Document all of it, EU counterparties increasingly audit Argentine vendors against the adequacy framework in procurement, and the Commission's periodic reviews look at enforcement practice, not just statute text.

Regulatory Crosswalk

GDPR Chapter VConvention 108+LGPD transfers

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.