Latin America Argentina

Argentina Data Protection Law 25.326: Compliance Guide

Argentina's Personal Data Protection Act: AAIP enforcement, registration duties, habeas data rights, sensitive-data rules, and the pending modernization bill.

Regulation

Personal Data Protection Act, Law No. 25.326 (2000), Decree 1558/2001, and AAIP resolutions

Max Penalty

Administrative fines under AAIP's graduated sanctions regime (updated by resolution), plus closure of databases and criminal liability for specific offenses

Enforcing Authority

Agencia de Acceso a la Informacion Publica (AAIP)

Official Source

www.argentina.gob.ar

Executive Summary

  • Law 25.326 (2000) is Latin America's oldest comprehensive data protection law, rooted in the constitutional habeas data action (Article 43 of the Constitution) and modeled on the EU's 1995 Directive.
  • It earned an EU adequacy decision in 2003 (Decision 2003/490/EC), which Argentina retains and which the European Commission reaffirmed in its 2024 adequacy review, still the regime's biggest commercial asset.
  • Core duties: consent as the default basis, registration of databases with the AAIP's national registry, quality and proportionality principles, and habeas data rights (access within 10 days, rectification/deletion within 5 business days).
  • The AAIP enforces through a graduated sanctions regime updated by resolution, and has modernized around the statute with resolutions on binding guidance, biometric data, and AI.
  • A GDPR-style modernization bill has been pending in Congress for years (most recently the 2023 draft); it has not passed, so the 2000 law plus AAIP resolutions remain the binding framework.

Argentina’s law is the elder statesman of Latin American privacy: enacted in 2000, adequacy-approved by Brussels in 2003, and still running on consent, database registration, and habeas data clocks measured in days. Its age cuts both ways. The mechanics feel dated next to the LGPD, but the EU adequacy decision, reaffirmed in the Commission’s 2024 review, makes Argentina one of the few places on the continent where EU data flows in without extra paperwork, an asset the AAIP protects by steadily modernizing through resolutions while Congress sits on the reform bill.

LawLey 25.326 (2000)
RegulatorAAIP
EU adequacySince 2003 (Decision 2003/490/EC), reaffirmed 2024
Access clock10 calendar days
Rectify/delete5 business days

Making the 2000-era mechanics work today

Register the databases. The National Registry filing is the unique Argentine step; inventory databases the way you would a RoPA and keep registrations current, unregistered processing taints everything else.

Run consent-first flows. Unlike Brazil’s ten bases, Argentina defaults to express consent with narrow exceptions; marketing and trackers need affirmative opt-in, with the statutory information given up front.

Honor the short clocks. 10 days for access and 5 business days for corrections beat every neighboring regime; wire Argentina into the DSAR pipeline at its own speed, since blown deadlines invite habeas data suits, not just AAIP complaints.

Protect the adequacy dividend. EU data received under Argentina’s adequacy must stay within the protections that justify it, especially for onward transfers to non-adequate countries, and regional programs should reconcile Argentina with Brazil and Mexico rather than assume one Latin American template.

Consent collection and tracker behavior on your Argentine traffic are visible from outside: verify them with a free scan.

Frequently Asked Questions

Who must comply with Law 25.326?

Any person or entity, public or private, that processes personal data in databases (archivos, registros, bancos de datos) located in Argentina or used for providing reports. The concept is database-centric, a 2000-era design, but the AAIP applies it functionally to modern processing. Foreign companies processing Argentines' data through local operations, subsidiaries, or databases in Argentina are covered; purely offshore processing sits in a gray zone the modernization bill would close with GDPR-style extraterritoriality.

What does the database registration duty require?

Controllers must register their databases containing personal data with the AAIP's National Registry of Databases: identifying the controller, data categories, purposes, security measures, and transfers. Registration is done online and renewed as required by AAIP resolutions. It is the compliance item foreign practitioners most often miss because GDPR abolished its equivalent in 2018; in Argentina, an unregistered database processing personal data is itself an infraction and an aggravating factor in any other proceeding.

How does consent work, and what are the exceptions?

Consent is the default lawful basis: free, express, informed, and in writing or by an equivalent means, with prior information about purpose, recipients, the registry, and rights. Exceptions cover data from public sources, state functions, basic contact data (name, ID, tax ID, occupation, birth date, address, phone), contractual necessity, and financial-system operations. Sensitive data (racial/ethnic origin, political opinions, religious or moral beliefs, union membership, health, sex life) gets stronger protection: no one can be compelled to disclose it, and processing generally requires a public-interest law or statistical/scientific purposes with dissociation.

What are the habeas data rights and deadlines?

Access: any person can demand information about their data from a registry, answered within 10 calendar days, free of charge at intervals of six months or less unless a legitimate interest justifies more. Rectification, update, deletion, or confidentiality: within 5 business days of the request. Non-response opens the constitutional habeas data action in court, a fast-track remedy that predates the statute itself. These deadlines are shorter than GDPR's month and are enforced through both the AAIP and the courts.

Is the modernization reform going to pass, and what would change?

A full replacement bill (GDPR-aligned: extraterritorial scope, lawful bases beyond consent, breach notification, DPOs, fines scaled to revenue, no database registration) was submitted to Congress in 2023 and has not been enacted; earlier attempts (2017, 2018) also lapsed. Argentina remains party to Convention 108+ (ratified 2023), and the AAIP fills gaps by resolution, including guidance on biometrics and AI. Companies should comply with the current law's mechanics, registration, consent, habeas data clocks, while building toward GDPR-grade practices the reform would demand and the EU adequacy review already rewards.

Regulatory Crosswalk

GDPRLGPDConvention 108+

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.