Data Protection & Privacy
DETAIL

Argentina Personal Data Protection Law (Law No. 25,326)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

Argentina Personal Data Protection Law — Bill 1,024 (proposed update to Law 25,326) represents Argentina’s modernization effort to update its data protection framework aligning with contemporary privacy standards including the EU GDPR. The bill proposes significant expansions of data subject rights, new obligations for data controllers, and updated cross-border transfer mechanisms.

Developed through the Argentine legislative process, Bill 1,024 builds on the foundation of Law 25,326 while introducing GDPR-aligned concepts including data protection officers, privacy impact assessments, privacy by design, and enhanced breach notification requirements. It aims to modernize Argentina’s privacy framework supporting continued international adequacy recognition.

Organizations preparing for the updated law are assessing gaps against proposed requirements, updating privacy programs, and planning for new obligations that would expand data subject rights and strengthen accountability requirements.

Why it Matters

Argentina’s PDPL modernization aligns the country’s data protection framework with international standards supporting continued participation in the global digital economy.

Key benefits include:

  • Align with international standards

Update compliance programs to reflect GDPR-aligned requirements supporting international data transfer recognition.

  • Expand data subject rights

Implement enhanced rights including data portability and strengthened erasure rights under the updated framework.

  • Strengthen accountability

Establish DPO roles, privacy impact assessments, and privacy by design requirements enhancing governance.

  • Improve breach response

Implement enhanced breach notification requirements aligned with international standards.

  • Support market access

Maintain and strengthen Argentina’s data protection adequacy enabling international data flows.

How it Works

Bill 1,024 proposes updating Law 25,326 with new obligations for DPOs in high-risk processing activities, PIAs for high-risk processing, privacy by design principles, enhanced breach notification timelines, new data subject rights, and updated cross-border transfer mechanisms aligned with international standards.

Organizations prepare by gap-assessing current compliance against proposed requirements, updating privacy governance structures, developing PIA processes, and training staff on new obligations expected under the modernized framework.

Key Elements

  • Data Protection Officers

Proposed requirement for DPOs in organizations conducting high-risk processing activities.

  • Privacy Impact Assessments

Mandated PIAs for high-risk data processing activities under the modernized framework.

  • Enhanced Data Subject Rights

Expanded rights including data portability and strengthened erasure and restriction rights.

  • Breach Notification Updates

Enhanced breach notification requirements with defined timelines for AAIP and data subject notification.

Framework Scope

The proposed update applies to entities processing personal data in Argentina, building on existing Law 25,326 scope with expanded obligations for larger processors and high-risk activities.

Framework Objectives

Argentina’s PDPL modernization strengthens data protection aligning with international standards.

  • Modernize Argentine data protection framework with GDPR-aligned requirements
  • Expand data subject rights supporting individual privacy control
  • Strengthen organizational accountability through DPOs and PIAs
  • Maintain international adequacy enabling cross-border data flows
  • Align Argentine privacy law with evolving global standards

Common Framework Mappings

Mapped frameworks include:

EU General Data Protection Regulation (GDPR)

ISO/IEC 27001

ISO/IEC 27701

NIST Privacy Framework

At a Glance
Argentina Personal Data Protection Law No. 25,326
  • checklist
    Classicifation
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    Global Privacy Regulations
  • info
    Regulatory Context
    Type
    info
    Framework
    Legal Instrument
    info
    Law
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Latin America
    Region Detail
    info
    Argentina
    Publisher
    info
    Agencia de Acceso a la Información Pública (AAIP)
  • published_with_changes
    Versioning
    Version
    info
    2000
    Effective Date
    info
    October 28, 2000
    Issue Date
    info
    October 28, 2000
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    Moderate
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

Argentina's Personal Data Protection Law is publicly available as national legislation and can be accessed through official government sources.

Official Resources
Argentina Personal Data Protection Law Text
Provides the official legal text of Argentina's Personal Data Protection Law (Law No. 25,326).
chevron_forward
AAIP Guidance on Personal Data Protection
Outlines regulatory guidance on implementing the data protection law in Argentina.
chevron_forward
AAIP Data Security Principles
Defines the data security principles required under the law for organizations managing personal data.
chevron_forward
AAIP Rights of Data Subjects
Describes the rights provided to data subjects under the personal data protection law.
chevron_forward
SMARTSUITE

How SmartSuite Supports Americas Argentina

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Processing Inventory and Accountability

Document personal data categories, purposes, sharing, retention, and safeguards.

Notices and Governance

Manage privacy notices, policy reviews, and accountability evidence.

Rights Request Workflows

Track access, correction, and deletion requests with deadlines and audit trail.

Cross-Border Transfer Safeguards

Manage transfer safeguards, contracts, and ongoing review evidence.

Vendor and Processor Oversight

Track vendor contracts, safeguards, and periodic review cadence.

Compliance Posture Reporting

Report posture, open actions, and evidence coverage for ongoing compliance.

Related frameworks

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
LFPDPPP

LFPDPPP is Mexico's law requiring private organizations to protect personal data and uphold individuals' privacy rights.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Argentina Personal Data Protection Law (Law No. 25,326)

What is the Argentina Personal Data Protection Law (Law No. 25,326) used for?

The law establishes legal requirements for processing personal data, aiming to safeguard individuals’ privacy rights and prevent the misuse or unauthorized access to personal information. It outlines specific obligations for both public and private organizations managing personal data in Argentina.

Is compliance with Argentina Personal Data Protection Law mandatory?

Yes, compliance with Law No. 25,326 is mandatory for any organization that processes personal data within Argentina, including public agencies, private entities, and service providers. Noncompliance may result in administrative sanctions and corrective actions enforced by the Agency for Access to Public Information (AAIP).

Who does Argentina Personal Data Protection Law apply to?

The law applies to any data controller or processor that collects, stores, or uses personal data within Argentine territory. This includes both domestic organizations and foreign entities processing Argentine citizens’ data, especially when using local resources or services.

What are the key concepts required by Argentina Personal Data Protection Law?

Key concepts include obtaining lawful consent, maintaining transparency with data subjects, ensuring data quality and purpose limitation, and upholding data subject rights such as access, rectification, and deletion. The law also requires technical and organizational security measures to protect personal data.

How should organizations implement Argentina Personal Data Protection Law requirements?

Organizations should map their personal data processing activities, perform risk assessments, establish security controls, and formalize policies for consent management and breach notification. Designating a data protection officer and maintaining detailed processing records are also recommended best practices.

Does Argentina Personal Data Protection Law align with other global privacy frameworks?

Yes, Law No. 25,326 shares core principles with frameworks like the EU GDPR, such as data minimization, accountability, and individual rights. However, organizations may need to address local nuances and supplementary obligations specific to Argentine regulations.

What are organizations’ ongoing compliance obligations under Law No. 25,326?

Continuous compliance involves monitoring processing activities, updating security measures, maintaining policies and training, and managing incident response and breach notification procedures. Regular reviews and internal audits help verify continued alignment with regulatory requirements.

How would SmartSuite support Argentina Personal Data Protection Law (Law No. 25,326)?

SmartSuite assists organizations in managing Law No. 25,326 by enabling risk tracking, mapping obligations to a control library, and organizing compliance evidence and documentation. It supports control management, audit readiness, regulatory reporting, and workflow automation for ongoing regulatory oversight.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward