Adequacy is the rarest asset in data-transfer law, only around fifteen jurisdictions hold it, and Argentina has held it since 2003, reaffirmed when Brussels reviewed all legacy decisions in January 2024. For EU-facing businesses this is a straightforward commercial advantage: an Argentine data operation receives EU personal data with none of the SCC and transfer-impact-assessment machinery Brazil or Mexico require. The discipline is in the details adequacy does not cover: domestic Law 25.326 compliance and, above all, onward transfers, where the frictionless inbound leg meets Argentine transfer restrictions on the way out.
| Decision | 2003/490/EC, confirmed by the Commission’s 2024 review |
|---|---|
| Effect | EU/EEA data flows to Argentina without SCCs |
| Domestic law | Ley 25.326, AAIP oversight |
| Onward transfers | Argentine safeguards required (Disp. 60-E/2016 clauses) |
| Regional peers | Uruguay adequate; Brazil and Mexico not |
Operating an adequacy-backed data flow
Use it where it pays. EU client data hosted or processed in Argentina skips Chapter V entirely; position Argentine entities as the EU landing zone in regional architectures instead of routing through non-adequate hubs.
Guard the onward legs. Every export from Argentina, to Brazil, the US, or a cloud region elsewhere, needs its own Argentine-law instrument; reconcile with Brazilian transfer rules when the chain continues south.
Maintain the domestic base. Registration, consent, and the habeas data clocks in the Law 25.326 guide are what the Commission’s reviews actually examine; treat them as the price of the asset.
Plan for the reform. The pending modernization bill would align Argentina with GDPR-grade practice; building to that standard now de-risks both the reform and future adequacy reviews.
EU-facing sites still need compliant consent and tracker behavior regardless of adequacy: check yours with a free scan.