Argentina’s law is the elder statesman of Latin American privacy: enacted in 2000, adequacy-approved by Brussels in 2003, and still running on consent, database registration, and habeas data clocks measured in days. Its age cuts both ways. The mechanics feel dated next to the LGPD, but the EU adequacy decision, reaffirmed in the Commission’s 2024 review, makes Argentina one of the few places on the continent where EU data flows in without extra paperwork, an asset the AAIP protects by steadily modernizing through resolutions while Congress sits on the reform bill.
| Law | Ley 25.326 (2000) |
|---|---|
| Regulator | AAIP |
| EU adequacy | Since 2003 (Decision 2003/490/EC), reaffirmed 2024 |
| Access clock | 10 calendar days |
| Rectify/delete | 5 business days |
Making the 2000-era mechanics work today
Register the databases. The National Registry filing is the unique Argentine step; inventory databases the way you would a RoPA and keep registrations current, unregistered processing taints everything else.
Run consent-first flows. Unlike Brazil’s ten bases, Argentina defaults to express consent with narrow exceptions; marketing and trackers need affirmative opt-in, with the statutory information given up front.
Honor the short clocks. 10 days for access and 5 business days for corrections beat every neighboring regime; wire Argentina into the DSAR pipeline at its own speed, since blown deadlines invite habeas data suits, not just AAIP complaints.
Protect the adequacy dividend. EU data received under Argentina’s adequacy must stay within the protections that justify it, especially for onward transfers to non-adequate countries, and regional programs should reconcile Argentina with Brazil and Mexico rather than assume one Latin American template.
Consent collection and tracker behavior on your Argentine traffic are visible from outside: verify them with a free scan.