🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
AR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-04

Argentina

AR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 33 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Argentina's data-protection reform landscape sharpened this cycle with the introduction of a third competing comprehensive reform bill. On 16 July 2026, Deputy Agustin Rossi introduced expediente 3397-D-2026 in the Chamber of Deputies, proposing a new comprehensive data-protection regime that would repeal both Ley 25.326 and Ley 26.343, and which substantially reproduces the AAIP-drafted bill originally circulated in June 2023. This joins the previously reported expediente 1751-D-2026, proposed by Deputy Martin Yeza, which sets out a fresh 72-article regime organised across 13 titles that would expressly repeal the current statute and its implementing regulations. Neither bill has been enacted, and Argentina's operative regime remains Ley 25.326 as it stands, but the country now has three distinct legislative reform vehicles in play, none clearly ahead of the others.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, EU-adequacy-holding statute with an active, resourced supervisory authority; amber-tending risk only from the unsettled multi-bill reform pipeline.

Primary frameworkLey 25.326 (Personal Data Protection Act) and Decreto 1558/2001
Traffic-light rationale — GreenComprehensive, EU-adequacy-holding statute with an active, resourced supervisory authority; amber-tending risk only from the unsettled multi-bill reform pipeline.

Sub-modules (5)

Regulator And AuthorityGreen

AAIP, an autarchic body with functional autonomy under the Jefatura de Gabinete de Ministros, is the applicable authority for Ley 25.326, the Access to Public Information Law 27.275, and the Do-Not-Call Registry Law 26.951.

Claims (1):

  • The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority for the Personal Data Protection Act No. 25.326 in Argentina.

Act And InstrumentsGreen

Primary instruments are Ley 25.326 and Decreto 1558/2001 (amended by Decreto 1160/10), supplemented by numerous AAIP resolutions.

Claims (1):

  • Ley 25.326 of 2000 together with Decreto 1558/2001 (amended by Decreto 1160/10) form the primary legal instruments governing data protection in Argentina.

Material ScopeGreen

The Act and Decrees apply to both public and private-sector processing of personal data.

Claims (1):

  • The Act and its implementing Decrees apply to both public and private organizations and to processing activities carried out in the territory of Argentina.

Territorial ScopeAmber

Current law applies to processing carried out within Argentine territory; pending reform bills would add express extraterritorial application to controllers/processors located abroad but targeting Argentine data subjects.

Claims (2):

  • The Act and its implementing Decrees apply to both public and private organizations and to processing activities carried out in the territory of Argentina.
  • A pending Congressional reform bill would expressly extend extraterritorial application of the data protection law to controllers/processors located outside Argentina where their processing targets Argentine data subjects.

Regulator Registration And FilingAmber

Under the current regime, controllers must register databases with AAIP (over 2,000 databases registered in 2022 alone); pending reform bills would eliminate this registration duty entirely.

Claims (2):

  • Under the current regime, data controllers are required to register their databases with AAIP; 2,035 databases were registered in 2022 alone.
  • Pending reform bills (Carro/Doñate, inspired by the AAIP anteproyecto) would eliminate the currently-in-force duty to register databases with the supervisory authority.
Category narrative111 words

Argentina's data-protection regime is anchored in Ley 25.326 (Personal Data Protection Act, 2000) and its implementing Decreto 1558/2001 (as amended by Decreto 1160/10). The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority, having absorbed the functions of the former Dirección Nacional de Protección de Datos Personales. The Act applies to public and private data processing carried out in Argentine territory and underpins the EU's 2003 adequacy finding. Two parallel legislative tracks (Carro/Doñate bills inspired by the AAIP's own anteproyecto, and the independently filed Yeza bill 1751-D-2026) are pending before Congress to replace the 25-year-old Act wholesale, including express extraterritorial scope and removal of the current database-registration duty.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedIAPP — The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority for the Personal Data Protection Act No. 25.326 in Argentina.observed
  2. ConfirmedDataGuidance — Ley 25.326 of 2000 together with Decreto 1558/2001 (amended by Decreto 1160/10) form the primary legal instruments governing data protection in Argentina.observed
  3. ConfirmedDataGuidance — The Act and its implementing Decrees apply to both public and private organizations and to processing activities carried out in the territory of Argentina.observed
  4. ProbableIAPP — A pending Congressional reform bill would expressly extend extraterritorial application of the data protection law to controllers/processors located outside Argentina where their processing targets Argentine data subjects.observed
  5. ConfirmedIAPP — Under the current regime, data controllers are required to register their databases with AAIP; 2,035 databases were registered in 2022 alone.observed
  6. ProbableIAPP — Pending reform bills (Carro/Doñate, inspired by the AAIP anteproyecto) would eliminate the currently-in-force duty to register databases with the supervisory authority.observed

#

Core lawful-basis and sensitive-data concepts exist but are narrower/less granular than GDPR-aligned peers, with material change only at proposal stage.

Primary frameworkLey 25.326, Arts. 5–7; Decreto 1558/2001
Traffic-light rationale — AmberCore lawful-basis and sensitive-data concepts exist but are narrower/less granular than GDPR-aligned peers, with material change only at proposal stage.

Sub-modules (4)

Lawful BasesAmber

Consent is the dominant lawful basis under current law; the Yeza bill would introduce six alternative bases including legitimate interest.

Claims (2):

  • Under the current legal framework, consent operates as the almost-exclusive lawful basis for processing personal data in Argentina.
  • The pending Yeza bill (1751-D-2026) proposes six alternative lawful bases for processing — consent, contractual performance, legal obligations, vital interests, public interest and legitimate interest — with legitimate interest expressly covering AI training subject to a rights-prevalence test.

Special CategoriesAmber

Sensitive data categories are defined in the current Act; AAIP guidance addresses genetic data, and reform bills propose an expanded definition covering gender identity, genetic and biometric data.

Claims (2):

  • Reform bills propose replacing the current definition of sensitive data with a broader one covering information on private life or capable of causing discrimination or high risk, expressly listing gender identity, genetic and biometric data as examples.
  • AAIP Resolución 255/2022 sets out guiding criteria and best-practice indicators for the application of the Personal Data Protection Act with respect to genetic data.

Pseudonymisation And AnonymisationRed

Neither the Act nor the Decree substantively defines pseudonymisation or anonymisation safe-harbours.

Absence provenance: unavailable. Searched: Argentina Ley 25.326 pseudonymisation anonymisation safe harbour.

Category narrative91 words

Consent is the near-exclusive lawful basis under the current Act, a point the pending Yeza reform bill explicitly seeks to broaden by introducing six alternative bases (consent, contract performance, legal obligation, vital interests, public interest, legitimate interest — the last expressly covering AI-model training subject to a balancing test). Special/sensitive data ('datos sensibles') are already regulated, with AAIP soft-law (Resolución 255/2022) addressing genetic data specifically; reform proposals would broaden the definition to expressly include gender identity, genetic and biometric data. Pseudonymisation/anonymisation are not substantively addressed in the current Act or Decree.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ProbableIAPP — Under the current legal framework, consent operates as the almost-exclusive lawful basis for processing personal data in Argentina.observed
  2. ProbableIAPP — The pending Yeza bill (1751-D-2026) proposes six alternative lawful bases for processing — consent, contractual performance, legal obligations, vital interests, public interest and legitimate interest — with legitimate interest expressly covering AI training subject to a rights-prevalence test.observed
  3. ProbableIAPP — Reform bills propose replacing the current definition of sensitive data with a broader one covering information on private life or capable of causing discrimination or high risk, expressly listing gender identity, genetic and biometric data as examples.observed
  4. ConfirmedIAPP — AAIP Resolución 255/2022 sets out guiding criteria and best-practice indicators for the application of the Personal Data Protection Act with respect to genetic data.observed

#

Core access/rectification/erasure rights are binding and judicially enforceable today; portability/ADM-objection rights remain at proposal stage only.

Primary frameworkLey 25.326, Arts. 14–16; Constitución Nacional Art. 43 (habeas data)
Traffic-light rationale — GreenCore access/rectification/erasure rights are binding and judicially enforceable today; portability/ADM-objection rights remain at proposal stage only.

Sub-modules (5)

Access RightGreen

Access is enforceable via habeas data, a constitutionally-entrenched simplified judicial procedure.

Claims (1):

  • The Argentine Constitution provides a special, simplified and rapid judicial remedy known as 'habeas data' to protect personal data, elevating data protection to the status of a fundamental right.

Rectification And ErasureGreen

Rectification/erasure rights are actively enforced; AAIP sanctioned Rappi for failing to act on an erasure request in time.

Claims (2):

  • AAIP sanctioned Rappi Arg S.A.S. for failing to respond in due time and form to a data subject's request for erasure of personal data.
  • A separate 2022 bill proposes a standalone 'right to be forgotten' requiring search-engine providers to implement an accessible electronic form for erasure requests, with a 10-business-day compliance window and judicial recourse for denial or inaccuracy.

Restriction And ObjectionAmber

Reform bills add an objection right against automated decisions producing legal or adverse effects; no current binding restriction/objection right beyond consent withdrawal identified.

Claims (1):

  • Pending reform bills introduce new data-subject rights not present in the current Act, including data portability and objection to automated decisions producing legal effects or materially adversely affecting the data subject.

Data PortabilityRed

Portability is not part of the current Act; it is proposed in pending reform bills.

Claims (1):

  • Pending reform bills introduce new data-subject rights not present in the current Act, including data portability and objection to automated decisions producing legal effects or materially adversely affecting the data subject.

Deadlines And Response WindowsAmber

Reform bills propose a non-extendable 10-business-day deadline to satisfy data-subject requests, criticized by commentators as impractical.

Claims (1):

  • Pending reform bills propose a non-extendable 10-business-day deadline for controllers to satisfy data-subject rights requests, a timeframe criticized by commentators as difficult for the private sector to meet.
Category narrative82 words

Data subjects currently hold rights of information, access, rectification, updating, erasure and consent-withdrawal, enforceable through the constitutionally-entrenched 'habeas data' judicial remedy. Enforcement practice confirms erasure rights are actively policed (AAIP sanctioned Rappi for failing to honor a deletion request). Pending reform bills would add portability and a right to object to automated decisions with legal or materially adverse effect, alongside a proposed (contested) 10-business-day non-extendable response deadline; a separate 2022 bill would create a standalone 'right to be forgotten' against search engines.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedEUR-Lex — The Argentine Constitution provides a special, simplified and rapid judicial remedy known as 'habeas data' to protect personal data, elevating data protection to the status of a fundamental right.observed
  2. ConfirmedIAPP — AAIP sanctioned Rappi Arg S.A.S. for failing to respond in due time and form to a data subject's request for erasure of personal data.observed
  3. ProbableIAPP — Pending reform bills introduce new data-subject rights not present in the current Act, including data portability and objection to automated decisions producing legal effects or materially adversely affecting the data subject.observed
  4. ProbableIAPP — Pending reform bills propose a non-extendable 10-business-day deadline for controllers to satisfy data-subject rights requests, a timeframe criticized by commentators as difficult for the private sector to meet.observed
  5. ProbableIAPP — A separate 2022 bill proposes a standalone 'right to be forgotten' requiring search-engine providers to implement an accessible electronic form for erasure requests, with a 10-business-day compliance window and judicial recourse for denial or inaccuracy.observed

#

Foundational accountability tools exist mostly as non-binding guidance rather than statutory duties; binding DPIA/DPO/breach-notification obligations are pending, not yet in force.

Primary frameworkLey 25.326; AAIP Resolución 47/2018 (recommended security measures); AAIP DPIA Guide
Traffic-light rationale — AmberFoundational accountability tools exist mostly as non-binding guidance rather than statutory duties; binding DPIA/DPO/breach-notification obligations are pending, not yet in force.

Sub-modules (7)

Accountability And DpiaAmber

No statutory DPIA duty; AAIP has issued a non-binding DPIA Guide.

Claims (1):

  • The current Act does not provide for a requirement to conduct a Data Protection Impact Assessment, unlike the GDPR, although AAIP's non-binding Guide provides for such a practice.

Dpo RequirementsRed

No current DPO requirement; reform bills would introduce one.

Claims (2):

  • Unlike the GDPR, the current Act does not provide for a requirement to appoint a Data Protection Officer.
  • Pending reform bills introduce the figure of a data protection officer/delegate as a modern institute not present in the current Act.

Ropa RequirementsRed

No general ROPA duty under the Act itself; sector-specific instances (e.g., RENAPER internal policy) impose GDPR-style processing records, but this is not a generalized statutory duty.

Absence provenance: unavailable. Searched: Ley 25.326 registro de actividades de tratamiento ROPA Argentina.

Joint Controller ArrangementsRed

No specific joint-controller regime identified in current law.

Absence provenance: unavailable. Searched: Ley 25.326 corresponsables tratamiento conjunto.

Security MeasuresAmber

AAIP Resolución 47/2018 sets recommended (non-mandatory) technical and organizational security measures.

Claims (1):

  • AAIP's Resolución 47/2018 ('Recommended Security Measures') specifies suggested security procedures for controllers, including record-keeping recommendations.

Breach NotificationAmber

No general legal breach-notification obligation exists today; it is best practice only, though enforcement has penalized failure to act on breaches. Reform bills would impose a mandatory 72-hour notification duty.

Claims (3):

  • Reporting information security incidents is a best practice rather than a mandatory legal requirement under the Argentine Data Privacy Law; there is no general legal obligation to notify a data breach.
  • AAIP imposed an administrative fine on Cencosud SA after a security breach became public and the company failed to take recommended measures to prevent, notify and remedy the breach or notify affected users.
  • The AAIP-drafted data protection reform bill would impose an obligation to notify data breaches to the DPA without undue delay and within 72 hours of becoming aware, where the breach is likely to pose a risk to data subjects' rights, plus notification to affected data subjects for high-risk breaches.

Retention And DisposalRed

No dedicated statutory retention/disposal regime identified beyond general purpose-limitation principles.

Absence provenance: unavailable. Searched: Ley 25.326 plazos de conservación y baja de datos.

Category narrative83 words

The current Act imposes no DPIA or DPO obligation, though AAIP soft-law (a non-binding DPIA Guide and Resolución 47/2018 recommended security measures) fills part of the gap. There is no general legal duty to notify data breaches today — reporting is 'best practice' only — but AAIP has fined controllers (e.g., Cencosud) for failing to take recommended breach-prevention/notification steps. Pending reform bills would introduce a mandatory DPO figure and a 72-hour breach-notification duty to both AAIP and affected data subjects, mirroring GDPR-style timelines.

no periodic updates on record for this sub-brief

Sources and claims (7)
  1. ConfirmedDataGuidance — The current Act does not provide for a requirement to conduct a Data Protection Impact Assessment, unlike the GDPR, although AAIP's non-binding Guide provides for such a practice.observed
  2. ConfirmedDataGuidance — Unlike the GDPR, the current Act does not provide for a requirement to appoint a Data Protection Officer.observed
  3. ProbableIAPP — Pending reform bills introduce the figure of a data protection officer/delegate as a modern institute not present in the current Act.observed
  4. ConfirmedDataGuidance — AAIP's Resolución 47/2018 ('Recommended Security Measures') specifies suggested security procedures for controllers, including record-keeping recommendations.observed
  5. ConfirmedIAPP — Reporting information security incidents is a best practice rather than a mandatory legal requirement under the Argentine Data Privacy Law; there is no general legal obligation to notify a data breach.observed
  6. ConfirmedIAPP — AAIP imposed an administrative fine on Cencosud SA after a security breach became public and the company failed to take recommended measures to prevent, notify and remedy the breach or notify affected users.observed
  7. ProbableIAPP — The AAIP-drafted data protection reform bill would impose an obligation to notify data breaches to the DPA without undue delay and within 72 hours of becoming aware, where the breach is likely to pose a risk to data subjects' rights, plus notification to affected data subjects for high-risk breaches.observed

#

Adequacy-holding jurisdiction with an active, modernizing transfer-mechanism toolkit (BCRs, dual SCC regimes); no TIA or localisation mandate identified.

Primary frameworkLey 25.326, Art. 12; AAIP Resolución 198/2023 (SCC RIPD); Resolución 159/2018 (BCR guidelines)
Traffic-light rationale — GreenAdequacy-holding jurisdiction with an active, modernizing transfer-mechanism toolkit (BCRs, dual SCC regimes); no TIA or localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

Transfers are permitted via consent, contractual clauses, or self-regulatory systems providing adequate protection where the destination lacks an adequacy finding.

Claims (1):

  • The LPDP prohibits, in principle, international transfers of personal data to countries or international organizations lacking an adequate level of data protection, but permits such transfers where data subjects consent or where contractual clauses or self-regulatory systems guarantee adequate protection levels.

Adequacy ReceivedGreen

Not applicable in the classic sense — Argentina is a data exporter jurisdiction; see adequacy_granted for the relevant inbound EU recognition.

Absence provenance: unavailable. Searched: Argentina adequacy received from other regimes.

Adequacy GrantedGreen

The European Commission recognized Argentina as providing an adequate level of data protection on 30 June 2003, a decision that remains in force.

Claims (1):

  • On 30 June 2003, Argentina was recognized by the European Commission as providing an adequate level of protection for personal data.

Sccs And BcrsGreen

AAIP maintains both its own model clauses (2016) and the newer RIPD Standard Contractual Clauses (2023), alongside BCR guidelines (2018).

Claims (2):

  • Via Resolución 198/2023, AAIP approved the Red Iberoamericana de Protección de Datos (RIPD) Standard Contractual Clauses for international transfers of personal data, compatible with its own pre-existing model clauses.
  • AAIP's Resolución 159/2018 established guidelines and basic content requirements for Binding Corporate Rules as a self-regulatory transfer mechanism for corporate groups.

Transfer Impact AssessmentRed

No formal Transfer Impact Assessment requirement analogous to Schrems II-style TIAs was identified in Argentine law or AAIP guidance.

Absence provenance: unavailable. Searched: Argentina AAIP transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate was identified in the Argentine data protection framework.

Absence provenance: unavailable. Searched: Argentina data localisation requirement personal data Ley 25.326.

Category narrative79 words

Argentina received an EU Commission adequacy decision in 2003 — one of the earliest such findings — which remains in effect. The domestic Act prohibits transfers to jurisdictions lacking adequate protection unless the data subject consents or contractual/self-regulatory safeguards apply. AAIP has actively expanded transfer tooling: Binding Corporate Rules guidance (Resolución 159/2018) and, more recently, adoption of the Red Iberoamericana de Protección de Datos Standard Contractual Clauses (Resolución 198/2023), which coexist with Argentina's own earlier model clauses (Disposición 60-E/2016).

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedEUR-Lex — On 30 June 2003, Argentina was recognized by the European Commission as providing an adequate level of protection for personal data.observed
  2. ConfirmedIAPP — The LPDP prohibits, in principle, international transfers of personal data to countries or international organizations lacking an adequate level of data protection, but permits such transfers where data subjects consent or where contractual clauses or self-regulatory systems guarantee adequate protection levels.observed
  3. ConfirmedIAPP — Via Resolución 198/2023, AAIP approved the Red Iberoamericana de Protección de Datos (RIPD) Standard Contractual Clauses for international transfers of personal data, compatible with its own pre-existing model clauses.observed
  4. ConfirmedIAPP — AAIP's Resolución 159/2018 established guidelines and basic content requirements for Binding Corporate Rules as a self-regulatory transfer mechanism for corporate groups.observed

#

Health and financial overlays are well-documented and active; employment, credit-scoring, education and insurance sub-modules carry no substantiated findings.

Primary frameworkLey 25.326; Ley 26.529 (Patient Rights); Ley 27.553 (Telemedicine); Ley 26.951 (No Llame); BCRA cybersecurity regulations
Traffic-light rationale — AmberHealth and financial overlays are well-documented and active; employment, credit-scoring, education and insurance sub-modules carry no substantiated findings.

Sub-modules (7)

Financial Sector OverlayAmber

The Central Bank of Argentina (BCRA) maintains stringent cybersecurity regulations applicable to the financial sector, overlaying general LPDP obligations.

Claims (1):

  • The Central Bank of Argentina (BCRA) maintains stringent cybersecurity regulations that financial-sector entities must adhere to in order to ensure operational resilience and maintain customer trust.

Health Sector OverlayGreen

Telemedicine and digital-prescription platforms must comply with both the LPDP and the Patient Rights Law, given health data's sensitive-data status.

Claims (1):

  • Ley 27.553 on electronic/digital prescriptions requires that telehealth platforms used for medical and psychological consultations comply with Ley 25.326 and the Patient Rights Law 26.529, given that health data is classified as sensitive data subject to professional-secrecy principles.

Telecoms And EprivacyAmber

The Do-Not-Call Registry regime (Ley 26.951, updated by Resolución 126/2024) governs telemarketing communications, overlapping with general data-protection enforcement.

Claims (1):

  • AAIP's Resolución 126/2024 introduced a revised classification of infractions and sanctions regime for both the Personal Data Protection Law and the Do-Not-Call Registry Law, consolidating the prior regulatory framework.

Employment DataRed

No substantiated employment-specific data-protection overlay was located in the sources reviewed.

Absence provenance: unavailable. Searched: Argentina proteccion de datos personales derechos del trabajador empleo.

Credit And ScoringRed

No credit-scoring-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: unavailable. Searched: Argentina credit scoring buró de crédito proteccion de datos.

EducationRed

No education-sector-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: unavailable. Searched: Argentina proteccion de datos educacion sector.

InsuranceRed

No insurance-sector-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: unavailable. Searched: Argentina seguros proteccion de datos personales sector.

Category narrative70 words

Sectoral overlays are most developed in health (telemedicine/digital prescriptions must comply with both the LPDP and the Patient Rights Law 26.529, with sensitive-data confidentiality duties for health professionals) and in the Central Bank's (BCRA) cybersecurity regulations for financial-sector data. Telemarketing/direct-communications are separately regulated under the Do-Not-Call Registry Law 26.951, recently updated via Resolución 126/2024. No sector-specific findings were substantiated for employment data, credit/scoring, education, or insurance within the sources reviewed.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedIAPP — Ley 27.553 on electronic/digital prescriptions requires that telehealth platforms used for medical and psychological consultations comply with Ley 25.326 and the Patient Rights Law 26.529, given that health data is classified as sensitive data subject to professional-secrecy principles.observed
  2. ProbableDataGuidance — The Central Bank of Argentina (BCRA) maintains stringent cybersecurity regulations that financial-sector entities must adhere to in order to ensure operational resilience and maintain customer trust.observed
  3. ConfirmedIAPP — AAIP's Resolución 126/2024 introduced a revised classification of infractions and sanctions regime for both the Personal Data Protection Law and the Do-Not-Call Registry Law, consolidating the prior regulatory framework.observed

#

Only direct marketing (telemarketing) is substantiated; five of six sub-modules carry no evidenced Argentine-specific regime.

Primary frameworkLey 26.951 (Registro Nacional No Llame); Ley 25.326
Traffic-light rationale — RedOnly direct marketing (telemarketing) is substantiated; five of six sub-modules carry no evidenced Argentine-specific regime.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime for Argentina was located.

Absence provenance: unavailable. Searched: Argentina cookies consent law AAIP tracker regulation.

Dark PatternsRed

No Argentina-specific dark-pattern prohibition was located.

Absence provenance: unavailable. Searched: Argentina dark patterns prohibicion diseño engañoso AAIP.

Opt Out SignalsRed

No Global Privacy Control or DAA-equivalent opt-out signal recognition regime was located for Argentina.

Absence provenance: unavailable. Searched: Argentina Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room / data-collaboration-room specific rules were located for Argentina.

Absence provenance: unavailable. Searched: Argentina data clean room regulation AAIP.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising framework was located for Argentina.

Absence provenance: unavailable. Searched: Argentina cross-context advertising sale share personal data regulation.

Direct MarketingAmber

The Do-Not-Call Registry regime governs telemarketing consent/suppression, with active AAIP enforcement against unsolicited telemarketing practices.

Claims (1):

  • AAIP fined FCA Automobiles Argentina and Telefónica Móviles Argentina, each roughly ARS 10 million, for data protection violations involving unsolicited telemarketing practices.
Category narrative56 words

Direct marketing is the only well-substantiated sub-module: the Do-Not-Call Registry (Ley 26.951) plus AAIP enforcement (fines against FCA Automobiles Argentina and Telefónica Móviles Argentina for unsolicited telemarketing) evidence an active suppression/consent regime for telephone marketing. No dedicated cookie/tracker consent law, dark-pattern prohibition, GPC-style opt-out-signal recognition, clean-room rules, or CPRA-style cross-context 'sale/share' framework were identified for Argentina.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ConfirmedDataGuidance — AAIP fined FCA Automobiles Argentina and Telefónica Móviles Argentina, each roughly ARS 10 million, for data protection violations involving unsolicited telemarketing practices.observed

#

Existing binding guidance (Resolución 4/2019) covers automated processing/video surveillance; the more comprehensive ADM-objection right and facial-recognition-specific regime remain at bill stage.

Primary frameworkAAIP Resolución 4/2019; pending Facial Recognition Bill (Yeza); pending LPDP reform bills
Traffic-light rationale — AmberExisting binding guidance (Resolución 4/2019) covers automated processing/video surveillance; the more comprehensive ADM-objection right and facial-recognition-specific regime remain at bill stage.

Sub-modules (6)

Profiling RestrictionsAmber

No dedicated profiling-restriction regime beyond the pending ADM-objection right proposal.

Claims (1):

  • Pending reform bills add a data-subject right to object to automated decisions that produce legal effects or negatively affect the data subject, a right not present in the current Act.

Automated Decision Making TransparencyAmber

Resolución 4/2019 addresses automated data processing; reform bills add an explicit objection right for ADM with legal/adverse effect.

Claims (2):

  • AAIP's Resolución 4/2019 specifies mandatory guidelines for the application of the Act, addressing topics including video surveillance and automated data processing.
  • Pending reform bills add a data-subject right to object to automated decisions that produce legal effects or negatively affect the data subject, a right not present in the current Act.

Ai Risk AssessmentsAmber

The pending facial-recognition bill requires a prior impact assessment before security-purpose deployment; AAIP separately runs an AI transparency program.

Claims (2):

  • A pending bill (deputy Yeza) establishes that facial recognition systems to be used for public-security purposes must undergo a prior impact assessment and an AAIP authorization process before implementation.
  • AAIP has created a Transparency and Protection of Personal Data Program specifically addressing the use of Artificial Intelligence.

Biometric RegimeAmber

No general biometric-data statute exists; the pending facial-recognition bill is the most developed sector-specific proposal, covering authorization, prohibited uses and human-oversight requirements.

Claims (3):

  • A pending bill (deputy Yeza) establishes that facial recognition systems to be used for public-security purposes must undergo a prior impact assessment and an AAIP authorization process before implementation.
  • The pending facial-recognition bill expressly prohibits certain uses such as mass surveillance or routine tracking of persons not suspected of having committed crimes, in line with EU AI Act standards.
  • The pending facial-recognition bill requires human oversight of automated identifications performed by facial recognition systems.

Genetic DataAmber

Genetic data is addressed via AAIP Resolución 255/2022 best-practice guidance (see lawful_processing_and_special_data module for the underlying claim).

Claims (1):

  • AAIP Resolución 255/2022 sets out guiding criteria and best-practice indicators for the application of the Personal Data Protection Act with respect to genetic data.

State Surveillance CarveoutsAmber

The pending facial-recognition bill expressly prohibits mass surveillance and routine tracking of non-suspects, functioning as a proposed limitation on state-surveillance carveouts.

Claims (1):

  • The pending facial-recognition bill expressly prohibits certain uses such as mass surveillance or routine tracking of persons not suspected of having committed crimes, in line with EU AI Act standards.
Category narrative99 words

AAIP's Resolución 4/2019 already provides mandatory guidelines covering video surveillance and automated data processing, and AAIP has stood up a dedicated Transparency and Protection of Personal Data Program addressing AI. The most granular near-term development is deputy Yeza's dedicated facial-recognition bill, which would require a prior impact assessment and AAIP authorization before deployment for public-security purposes, expressly ban mass surveillance/routine tracking of non-suspects, and mandate human oversight of automated identifications — explicitly modeled on EU AI Act standards. Separately, the broader LPDP reform bills would add a right to object to automated decisions with legal or materially adverse effect.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ProbableIAPP — A pending bill (deputy Yeza) establishes that facial recognition systems to be used for public-security purposes must undergo a prior impact assessment and an AAIP authorization process before implementation.observed
  2. ProbableIAPP — The pending facial-recognition bill expressly prohibits certain uses such as mass surveillance or routine tracking of persons not suspected of having committed crimes, in line with EU AI Act standards.observed
  3. ProbableIAPP — The pending facial-recognition bill requires human oversight of automated identifications performed by facial recognition systems.observed
  4. ConfirmedIAPP — AAIP has created a Transparency and Protection of Personal Data Program specifically addressing the use of Artificial Intelligence.observed
  5. ConfirmedDataGuidance — AAIP's Resolución 4/2019 specifies mandatory guidelines for the application of the Act, addressing topics including video surveillance and automated data processing.observed
  6. ProbableIAPP — Pending reform bills add a data-subject right to object to automated decisions that produce legal effects or negatively affect the data subject, a right not present in the current Act.observed

#

Binding coverage of children's data exists only via soft-law guidance (Resolución 4/2019); dedicated statutory minor-protection provisions remain at proposal stage, and three of five sub-modules are unsubstantiated.

Primary frameworkAAIP Resolución 4/2019; pending LPDP reform bills
Traffic-light rationale — AmberBinding coverage of children's data exists only via soft-law guidance (Resolución 4/2019); dedicated statutory minor-protection provisions remain at proposal stage, and three of five sub-modules are unsubstantiated.

Sub-modules (5)

Age VerificationRed

No dedicated statutory age-verification mechanism was located.

Absence provenance: unavailable. Searched: Argentina age verification children data processing AAIP.

Minor Profiling BansRed

No dedicated minor-profiling ban was located.

Absence provenance: unavailable. Searched: Argentina prohibicion perfilado de menores proteccion de datos.

Education SettingsRed

No education-settings-specific children's-data rule was located.

Absence provenance: unavailable. Searched: Argentina proteccion de datos personales establecimientos educativos menores.

Dependent AdultsRed

No dependent-adult-specific data protection provision was located.

Absence provenance: unavailable. Searched: Argentina proteccion de datos personales adultos dependientes incapacidad.

Category narrative59 words

The current Act does not refer to children at all; AAIP's Resolución 4/2019 fills part of the gap by requiring consent for processing children's data. Pending reform bills would specifically regulate minors' personal data, generally treating consent given by persons aged 16 or older as valid. No substantiated findings were located for minor-profiling bans, education-settings-specific rules, or dependent-adult protections.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ConfirmedDataGuidance — Although the current Act does not refer to children, AAIP's Resolución 4/2019 provides for a requirement to obtain consent when processing children's personal data.observed
  2. ProbableIAPP — A pending reform bill specifically regulates the processing of minors' personal data, generally treating consent given by persons sixteen years of age or older for the processing of their personal data as valid.observed

#

Regulator is demonstrably active with a documented inspection/sanction track record and a judicially-enforceable private remedy; amber-tending on funding/capacity and collective-redress sub-modules, which are unsubstantiated.

Primary frameworkLey 25.326, Art. 31; AAIP Resolución 332/2020 (Guía de Fiscalización); Constitución Nacional Art. 43 (habeas data)
Traffic-light rationale — GreenRegulator is demonstrably active with a documented inspection/sanction track record and a judicially-enforceable private remedy; amber-tending on funding/capacity and collective-redress sub-modules, which are unsubstantiated.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AAIP holds investigative/inspection powers (Resolución 332/2020) and applies penalties under Art. 31 LPDP; a reform would raise ceilings materially, including a global-turnover-based option.

Claims (2):

  • AAIP's Guía de Fiscalización (Resolución 332/2020) empowers it to conduct planned or spontaneous inspections, request judicial authorization where a subject fails to cooperate, and use verbal, visual, documentary and technical investigation techniques.
  • A pending reform proposes fines set between five and one million movable accounting units (based on an initial unit value of ARS 10,000), with the AAIP's own bill version adding an alternative graduation of 2% to 4% of the infringer's total global annual turnover.

Enforcement Activity IndexGreen

AAIP issued 63 resolutions in 2022 alone, 52 of them sanctionatory, evidencing sustained enforcement activity; more recent fines (FCA Automobiles, Telefónica) confirm continuity.

Claims (1):

  • In 2022, AAIP opened 491 complaint files under the Personal Data Protection Law (27% more than 2021) and issued 63 resolutions, 52 of which were sanctionatory, imposing fines totaling approximately ARS 7,383,061.

Regulator Funding And CapacityAmber

No specific budget or headcount data for AAIP was substantiated in the sources reviewed.

Absence provenance: unavailable. Searched: AAIP Argentina presupuesto dotacion de personal capacidad institucional.

Collective Redress And Class ActionsAmber

No data-protection-specific collective-redress or class-action mechanism was substantiated in the sources reviewed.

Absence provenance: unavailable. Searched: Argentina accion de clase proteccion de datos personales.

Private Right Of ActionGreen

The constitutionally-entrenched habeas data remedy provides data subjects a direct judicial avenue independent of AAIP's administrative process.

Claims (1):

  • Argentine legislation provides effective and dissuasive sanctions, both administrative and criminal, and enforcement of data protection rules is guaranteed through the special, simplified and rapid habeas data judicial remedy alongside general judicial remedies.

Recent Developments 180DAmber

Within the last 180 days, two Congressional reform bills (Carro, Doñate) were introduced (reported February 2026) alongside an independently-filed comprehensive replacement bill by deputy Yeza (1751-D-2026, reported June 2026); none has been enacted as of the run date.

Claims (2):

  • Two bills recently introduced in Congress — one by deputy Pablo Carro and another by senator Martín Doñate — propose a comprehensive reform of Ley 25.326, inspired by the AAIP's own draft that lost parliamentary status at the end of 2024.
  • A new bill (project 1751-D-2026) filed by deputy Martín Yeza proposes to entirely replace the current Personal Data Protection Law with a 72-article, 13-title framework expressly repealing the current law and its regulations, drawing on South Korean, UK and Singaporean models plus GDPR influence.
Category narrative149 words

AAIP exercises active investigative and sanctioning powers under its Guía de Fiscalización (Resolución 332/2020), including planned and spontaneous inspections and the ability to seek judicial authorization when a subject fails to cooperate. Current sanctions are set under Article 31 of the LPDP; a pending reform (mirrored in both the AAIP-drafted bill and other Congressional projects) would substantially raise the ceiling — fines expressed in movable accounting units up to one million units, and in the AAIP version alternatively graduated at 2–4% of the infringer's global annual turnover. 2022 enforcement data show 491 complaint files opened (up 27% year-on-year) and 63 resolutions issued, 52 of them sanctionatory. The constitutionally-entrenched habeas data remedy affords a private right of action independent of AAIP's administrative process. Recent 180-day developments include the Carro and Doñate reform bills (Feb 2026) and the independently-filed Yeza bill 1751-D-2026 (June 2026), none of which have yet been enacted.

Periodic update · new data 2026-09-28

Enforcement & Redress

Argentina's legislative reform picture escalated this cycle with the introduction of a third distinct comprehensive data-protection reform bill. On 16 July 2026, Deputy Agustin Rossi introduced expediente 3397-D-2026 in the Chamber of Deputies. The bill proposes a new comprehensive data-protection regime and would repeal both Ley 25.326, the operative statute, and Ley 26.343. Notably, the bill substantially reproduces the text of a bill originally drafted by the AAIP itself and circulated in June 2023, suggesting continuity of substantive policy content across what is otherwise a change in legislative sponsor and vehicle.

This joins expediente 1751-D-2026, proposed by Deputy Martin Yeza and reported previously, which sets out an entirely fresh 72-article regime organised across 13 titles and would expressly repeal both the current statute and its implementing regulations. Between these two bills and the underlying June 2023 AAIP proposal that expediente 3397-D-2026 substantially reproduces, Argentina's Congress now has multiple, only partially overlapping, comprehensive reform vehicles under simultaneous consideration. Neither bill has advanced to enactment, and neither has been reported as having secured committee approval or a floor vote timeline.

Separately, on the existing enforcement infrastructure, the Agencia de Acceso a la Informacion Publica maintains a public Registro de Infractores de las leyes 25.326 y 26.951, together with a formal electronic voluntary-payment mechanism, described variously as VEP, QR, or Boleta de Pago, for the payment of assessed fines. This is a standing enforcement-transparency mechanism under the current regime and represents no change this cycle, but it underscores that the current AAIP enforcement apparatus, however dated the substantive statute it enforces may be considered by reform proponents, continues to operate with a functioning public transparency and payment-collection infrastructure.

The overall picture for enforcement and redress in Argentina this cycle is therefore one of legislative escalation layered on top of a stable, functioning, if dated, enforcement infrastructure: the AAIP continues to operate its existing enforcement tools under Ley 25.326 without interruption, while the legislative branch pursues, in parallel, at least two and arguably three distinct paths toward eventually replacing that statute altogether.

Outlook

With three broadly comprehensive reform proposals now in play, expediente 3397-D-2026, expediente 1751-D-2026, and the AAIP's own June 2023 text that the former substantially reproduces, the near-term question is not whether reform will eventually occur but which vehicle, if any, gains legislative traction first. Watch for committee assignment or hearing scheduling on either numbered expediente, or for any move to consolidate the competing texts into a single bill, as the clearest indicators of which reform path is gaining momentum.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedIAPP — AAIP's Guía de Fiscalización (Resolución 332/2020) empowers it to conduct planned or spontaneous inspections, request judicial authorization where a subject fails to cooperate, and use verbal, visual, documentary and technical investigation techniques.observed
  2. ProbableIAPP — A pending reform proposes fines set between five and one million movable accounting units (based on an initial unit value of ARS 10,000), with the AAIP's own bill version adding an alternative graduation of 2% to 4% of the infringer's total global annual turnover.observed
  3. ConfirmedIAPP — In 2022, AAIP opened 491 complaint files under the Personal Data Protection Law (27% more than 2021) and issued 63 resolutions, 52 of which were sanctionatory, imposing fines totaling approximately ARS 7,383,061.observed
  4. ConfirmedEUR-Lex — Argentine legislation provides effective and dissuasive sanctions, both administrative and criminal, and enforcement of data protection rules is guaranteed through the special, simplified and rapid habeas data judicial remedy alongside general judicial remedies.observed
  5. ConfirmedIAPP — Two bills recently introduced in Congress — one by deputy Pablo Carro and another by senator Martín Doñate — propose a comprehensive reform of Ley 25.326, inspired by the AAIP's own draft that lost parliamentary status at the end of 2024.observed
  6. ConfirmedIAPP — A new bill (project 1751-D-2026) filed by deputy Martín Yeza proposes to entirely replace the current Personal Data Protection Law with a 72-article, 13-title framework expressly repealing the current law and its regulations, drawing on South Korean, UK and Singaporean models plus GDPR influence.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct24.14
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Argentina
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 33 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: upheld (2 confirmed against the cited source; 16 could not be checked). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, cross_border_and_adequacy and enforcement_and_redress modules are grounded in T1 (Ley 25.326, Decreto 1558/2001, EU Adequacy Decision 2003/490/EC) plus multiple corroborating T2 (IAPP) sources. lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely primarily on T2 (IAPP news analysis) and T3 (DataGuidance comparative summary) for the binding baseline, with a heavy admixture of not-yet-binding proposed-bill content (Carro/Doñate bills, Yeza bill 1751-D-2026, 2022 draft bill, 2022 derecho-al-olvido bill) clearly flagged is_binding=false. sectoral_watch is well-populated for health and telecoms/No-Llame (T2) and moderately for financial (T3) but carries explicit absent_field_provenance for employment, credit-scoring, education and insurance. adtech_and_commercial_privacy is populated only for direct_marketing (T2/T3); the remaining five sub-modules carry explicit absent_field_provenance after targeted searches yielded no Argentina-specific regime.

Unresolved questions (5):

  • Which of the four pending 2026 reform vehicles (Carro bill, Doñate bill, Yeza bill 1751-D-2026, and the AAIP's own anteproyecto) will actually advance to enactment, and on what timeline — none has passed committee as of the run date.
  • Does the current Ley 25.326 regime impose any sector-specific data-localisation mandate (e.g., for financial or health data) that was not surfaced in the sources reviewed?
  • Is there a data-protection-specific collective redress or class-action mechanism in Argentina beyond the general habeas data individual remedy and Argentina's general consumer-law class-action doctrine?
  • What is AAIP's current budget and headcount, to assess regulator capacity relative to its documented caseload growth (491 files in 2022, +27% YoY)?
  • Has any Argentine sectoral regulator (BCRA, health authority, ENACOM) issued binding — as opposed to AAIP soft-law — cybersecurity or breach-notification rules specific to their sector that interact with the LPDP?

Escalate to primary-source review: yes