🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LATAM v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing12 sources retrieved model claude-sonnet-5 · 2026-08-06

Latin America bloc

LATAM schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: AIC

Last updated · 10 categories · 41 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The Red Iberoamericana de Proteccion de Datos (RIPD) approved a new version of its Estandares de Proteccion de Datos para los Estados Iberoamericanos on 26 May 2026 in Cartagena de Indias, Colombia, replacing the 2017 version and pending submission to the November 2026 Ibero-American Summit for possible adoption. This is confirmed on the strength of two independent Tier-1 sources, and it is the most significant regional soft-law development for data protection in Latin America in some years. The RIPD itself, whose permanent secretariat is held by Spain's AEPD, is an Ibero-American practitioner-DPA network rather than a supervisory authority and is broader in scope than Latin America alone, a distinction worth holding clearly given how easily the two labels are conflated. The new Estandares are notable chiefly for what they add: for the first time, the regional benchmark includes language stating that automated-decision and AI-based processing that infers, classifies, profiles or significantly influences individuals could be subject to prohibitions under member states' own legislation, alongside new provisions promoting algorithmic-governance mechanisms such as traceability, effective human oversight, continuous risk evaluation, and periodic audit of automated and AI systems.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No enforceable bloc-wide instrument or single supervisory authority exists; only soft-law principles and a practitioner network operate at the regional layer.

Primary frameworkOAS Updated Principles on Privacy and Personal Data Protection (2021) — non-binding soft law
Traffic-light rationale — RedNo enforceable bloc-wide instrument or single supervisory authority exists; only soft-law principles and a practitioner network operate at the regional layer.

Sub-modules (5)

Regulator And AuthorityRed

OAS DIL is a technical secretariat, not an enforcement regulator; RIPD is an Ibero-American (not purely Latin American) convening network of national DPAs, secretariat held by Spain's AEPD.

Claims (2):

  • The OAS Inter-American Juridical Committee approved the Updated Principles on Privacy and Personal Data Protection on 9 April 2021, and the OAS General Assembly formally adopted them via resolution AG/RES.2974 (LI-O/21) in November 2021, with the OAS itself describing the instrument as inter-American soft law rather than binding treaty text.
  • RIPD is an Ibero-American practitioner network of data-protection authorities whose permanent secretariat is held by Spain's AEPD, and whose membership of roughly 18 states includes Spain and Portugal, making it distinct from a purely Latin American mechanism.

Act And InstrumentsAmber

Primary bloc-level instruments are the OAS Updated Principles (2021) and the RIPD Ibero-American Standards, updated 26 May 2026.

Claims (2):

  • The RIPD approved an updated version of the 'Estándares de Protección de Datos para los Estados Iberoamericanos' on 26 May 2026 at its XV Ibero-American Data Protection Meeting held in Cartagena de Indias, Colombia.
  • The updated RIPD Standards were, as of dispatch, still pending referral to SEGIB for possible formal adoption at the Ibero-American Summit of Heads of State and Government scheduled for 4-5 November 2026 in Madrid, and had not yet received summit-level political endorsement.

Material ScopeAmber

OAS Principles apply broadly to public- and private-sector personal-data processing across OAS membership, not to a LATAM-only footprint.

Claims (1):

  • The OAS Updated Principles are framed to apply to both public- and private-sector processing of personal data across OAS member states, a footprint that spans the Americas (including the US and Canada) rather than Latin America alone.

Territorial ScopeAmber

RIPD's Standards apply to 'Estados Iberoamericanos', a grouping including Spain and Portugal — must not be described as purely Latin American.

Claims (1):

  • The RIPD Standards are addressed to 'Estados Iberoamericanos', a membership grouping that includes Spain and Portugal alongside Latin American states, and should not be characterised as bloc-wide Latin American law.

Regulator Registration And FilingRed

No bloc-wide controller registration/filing obligation exists under either instrument; registration regimes (where they exist) are set at national level only.

Absence provenance: unavailable. Searched: OAS Principles registration obligation, RIPD Standards controller registration filing.

Claims (1):

  • No bloc-wide controller registration or filing regime was identified under either the OAS Principles or the RIPD Standards; any such obligations exist only under individual national statutes, which are outside the scope of this bloc-level row.
Category narrative111 words

There is no bloc-wide, binding LATAM regulator or omnibus statute. The operative Americas-wide layer is the OAS 'Updated Principles on Privacy and Personal Data Protection' (2021) — expressly characterised by the OAS as soft law, adopted by General Assembly resolution rather than treaty — and the separate Ibero-American practitioner network (RIPD), whose 2026 Standards are likewise non-binding guidance. RIPD is explicitly not a Latin-American-exclusive body: its permanent secretariat sits with Spain's AEPD and its ~18-member composition includes Spain and Portugal. Individual LATAM states (Argentina, Brazil, Mexico, Colombia, Chile, etc.) each run distinct, independently-enforced national statutes and DPAs, but those are out of scope for this bloc-level row per the seed disambiguation.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedOrganization of American States — The OAS Inter-American Juridical Committee approved the Updated Principles on Privacy and Personal Data Protection on 9 April 2021, and the OAS General Assembly formally adopted them via resolution AG/RES.2974 (LI-O/21) in November 2021, with the OAS itself describing the instrument as inter-American soft law rather than binding treaty text.observed
  2. ConfirmedAEPD — RIPD is an Ibero-American practitioner network of data-protection authorities whose permanent secretariat is held by Spain's AEPD, and whose membership of roughly 18 states includes Spain and Portugal, making it distinct from a purely Latin American mechanism.observed
  3. ConfirmedRIPD — The RIPD approved an updated version of the 'Estándares de Protección de Datos para los Estados Iberoamericanos' on 26 May 2026 at its XV Ibero-American Data Protection Meeting held in Cartagena de Indias, Colombia.observed
  4. ConfirmedAEPD — The updated RIPD Standards were, as of dispatch, still pending referral to SEGIB for possible formal adoption at the Ibero-American Summit of Heads of State and Government scheduled for 4-5 November 2026 in Madrid, and had not yet received summit-level political endorsement.observed
  5. ConfirmedOAS Secretariat for Legal Affairs, Department of International Law — The OAS Updated Principles are framed to apply to both public- and private-sector processing of personal data across OAS member states, a footprint that spans the Americas (including the US and Canada) rather than Latin America alone.observed
  6. ConfirmedRIPD — The RIPD Standards are addressed to 'Estados Iberoamericanos', a membership grouping that includes Spain and Portugal alongside Latin American states, and should not be characterised as bloc-wide Latin American law.observed
  7. UncertainOAS Secretariat for Legal Affairs, Department of International Law — No bloc-wide controller registration or filing regime was identified under either the OAS Principles or the RIPD Standards; any such obligations exist only under individual national statutes, which are outside the scope of this bloc-level row.observed

#

Special-category and consent-exception content is well evidenced for 2026; enumerated lawful-basis and pseudonymisation/anonymisation safe-harbour text was not confirmed in retrieved sources.

Primary frameworkRIPD Estándares de Protección de Datos para los Estados Iberoamericanos (2026)
Traffic-light rationale — AmberSpecial-category and consent-exception content is well evidenced for 2026; enumerated lawful-basis and pseudonymisation/anonymisation safe-harbour text was not confirmed in retrieved sources.

Sub-modules (4)

Lawful BasesAmber

OAS/RIPD instruments do not present an enumerated lawful-basis list akin to GDPR Art 6; they instead rest on general fairness, purpose-specification and accountability principles.

Absence provenance: unavailable. Searched: OAS Principles enumerated lawful basis text, RIPD Standards Article 6 equivalent lawful basis.

Claims (1):

  • The OAS Updated Principles and RIPD Standards are structured around general accountability, purpose-limitation and data-quality norms rather than an enumerated list of discrete lawful processing bases comparable to GDPR Article 6.

Special CategoriesGreen

2026 RIPD Standards add neurodata to the sensitive/special category taxonomy for the first time and flag that certain neurodata processing could be subject to outright national prohibitions.

Claims (2):

  • For the first time, the 2026 RIPD Standards expressly incorporate neurodata within the special/sensitive category taxonomy, defined by reference to brain function, activity or structure that can identify a person or infer information about their physiology or health.
  • The RIPD Standards note that certain neurodata-processing operations could be made subject to outright prohibitions under individual Ibero-American states' domestic legislation.

Pseudonymisation And AnonymisationRed

No specific pseudonymisation/anonymisation definition or safe-harbour clause was located in the retrieved text of either instrument.

Absence provenance: unavailable. Searched: OAS Principles anonymisation pseudonymisation definition, RIPD Standards 2026 anonymisation safe harbour.

Category narrative39 words

Neither bloc instrument enumerates discrete lawful bases analogous to GDPR Art 6; both rely on general fairness/purpose-limitation framing. The 2026 RIPD Standards materially advance consent-exception rules (archival/scientific/statistical processing) and, for the first time, add neurodata to the special-category taxonomy.

Sources and claims (5)
  1. UncertainOAS Secretariat for Legal Affairs, Department of International Law — The OAS Updated Principles and RIPD Standards are structured around general accountability, purpose-limitation and data-quality norms rather than an enumerated list of discrete lawful processing bases comparable to GDPR Article 6.observed
  2. ConfirmedRIPD — The 2026 RIPD Standards provide that further processing of personal data for archival, scientific/historical-research or statistical purposes in the public interest will not be treated as incompatible with the original purpose, distinct from consent-based processing.observed
  3. ConfirmedRIPD — Under the 2026 RIPD Standards, where a minor's personal data is processed for a new purpose, protection of the child's rights must be weighted with the same importance as other applicable interests.observed
  4. ConfirmedAEPD — For the first time, the 2026 RIPD Standards expressly incorporate neurodata within the special/sensitive category taxonomy, defined by reference to brain function, activity or structure that can identify a person or infer information about their physiology or health.observed
  5. ConfirmedAEPD — The RIPD Standards note that certain neurodata-processing operations could be made subject to outright prohibitions under individual Ibero-American states' domestic legislation.observed

#

Core access/rectification/objection concepts are present as soft-law principles; portability and statutory deadlines are absent at the bloc level.

Primary frameworkOAS Updated Principles on Privacy and Personal Data Protection (2021)
Traffic-light rationale — AmberCore access/rectification/objection concepts are present as soft-law principles; portability and statutory deadlines are absent at the bloc level.

Sub-modules (5)

Access RightGreen

OAS Principles recognise a right of access to personal data, including confirmation of holding and correction of inaccurate data.

Claims (1):

  • The OAS Updated Principles recognise a right of access allowing individuals to confirm and obtain the personal data held about them, and to have inaccurate or damaging data corrected.

Rectification And ErasureGreen

OAS Principles recognise rights to erasure and to object to processing.

Claims (1):

  • The OAS Updated Principles recognise an individual right to obtain erasure of personal data and to object to its processing.

Restriction And ObjectionGreen

2026 RIPD Standards reinforce a right against decisions based exclusively/essentially on automated processing with legal or significant effect, including a right to human intervention.

Claims (1):

  • The 2026 RIPD Standards reinforce a right for individuals not to be subject to decisions based exclusively or essentially on automated processing that produce legal effects or significant impacts, and to obtain human intervention in such cases.

Data PortabilityRed

No bloc-level data-portability right was evidenced in either instrument's retrieved text.

Absence provenance: unavailable. Searched: OAS Principles data portability right, RIPD Standards 2026 portability.

Deadlines And Response WindowsRed

Neither instrument specifies a concrete statutory response-window deadline; such deadlines exist only under individual national statutes, out of scope here.

Absence provenance: unavailable. Searched: OAS Principles response deadline, RIPD Standards subject access deadline days.

Category narrative35 words

OAS Principles articulate access, rectification and erasure/objection rights in general terms. RIPD's 2026 update strengthens the objection right in the ADM context (human intervention). Portability and concrete response-window deadlines are not evidenced at bloc level.

Sources and claims (3)
  1. ConfirmedOAS Secretariat for Legal Affairs, Department of International Law — The OAS Updated Principles recognise a right of access allowing individuals to confirm and obtain the personal data held about them, and to have inaccurate or damaging data corrected.observed
  2. ConfirmedOAS Secretariat for Legal Affairs, Department of International Law — The OAS Updated Principles recognise an individual right to obtain erasure of personal data and to object to its processing.observed
  3. ConfirmedAEPD — The 2026 RIPD Standards reinforce a right for individuals not to be subject to decisions based exclusively or essentially on automated processing that produce legal effects or significant impacts, and to obtain human intervention in such cases.observed

#

Accountability, processor-contract and security content is confirmed; DPO/ROPA/breach-notification content is absent at bloc level.

Primary frameworkRIPD Estándares de Protección de Datos para los Estados Iberoamericanos (2026)
Traffic-light rationale — AmberAccountability, processor-contract and security content is confirmed; DPO/ROPA/breach-notification content is absent at bloc level.

Sub-modules (7)

Accountability And DpiaGreen

RIPD Standards impose a demonstrable accountability duty toward data subjects and supervisory authorities, permitting reliance on standards, best practice, self-regulation or certification.

Claims (1):

  • The RIPD Standards impose an accountability duty requiring controllers to be able to demonstrate their processing of personal data to both the data subject and the supervisory authority, using standards, national or international best practices, self-regulation schemes, or certification mechanisms.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement was evidenced in retrieved text.

Absence provenance: unavailable. Searched: RIPD Standards DPO appointment requirement, OAS Principles data protection officer.

Ropa RequirementsRed

No records-of-processing obligation was evidenced in retrieved text.

Absence provenance: unavailable. Searched: RIPD Standards records of processing obligation.

Joint Controller ArrangementsGreen

RIPD Standards Article 34 sets minimum content for controller-processor legal instruments/contracts.

Claims (1):

  • RIPD Standards Article 34 requires that the contract or legal instrument governing a controller-processor relationship specify, at minimum, the object, scope, content, duration, nature and purpose of processing, the types of personal data involved, categories of data subjects, and the parties' obligations and responsibilities.

Security MeasuresGreen

RIPD Standards require administrative, physical and technical measures sufficient to guarantee confidentiality, integrity and availability, calibrated in part to prior breach history.

Claims (1):

  • RIPD Standards require controllers to implement administrative, physical and technical measures sufficient to guarantee the confidentiality, integrity and availability of personal data, with the appropriate measures determined partly by reference to prior breaches suffered in the processing.

Breach NotificationRed

No specific breach-notification threshold, timeline, or dual regulator/subject-notification structure was evidenced in retrieved text.

Absence provenance: unavailable. Searched: RIPD Standards breach notification timeline, OAS Principles data breach notification.

Retention And DisposalAmber

RIPD Standards permit individual Ibero-American states to legislate exceptions to retention periods, subject to full respect for data-subject rights and guarantees.

Claims (1):

  • RIPD Standards permit applicable Ibero-American state legislation to establish exceptions to personal-data retention periods, subject to full respect for the rights and guarantees of the data subject.
Category narrative36 words

The 2026 RIPD Standards contain the bloc's most concrete controller/processor content: an accountability duty, minimum contractual clauses for controller-processor relationships, security-measure obligations, and permitted retention exceptions. DPO thresholds, ROPA requirements and breach-notification timelines were not evidenced.

Sources and claims (4)
  1. ConfirmedRIPD — The RIPD Standards impose an accountability duty requiring controllers to be able to demonstrate their processing of personal data to both the data subject and the supervisory authority, using standards, national or international best practices, self-regulation schemes, or certification mechanisms.observed
  2. ConfirmedRIPD — RIPD Standards Article 34 requires that the contract or legal instrument governing a controller-processor relationship specify, at minimum, the object, scope, content, duration, nature and purpose of processing, the types of personal data involved, categories of data subjects, and the parties' obligations and responsibilities.observed
  3. ConfirmedRIPD — RIPD Standards require controllers to implement administrative, physical and technical measures sufficient to guarantee the confidentiality, integrity and availability of personal data, with the appropriate measures determined partly by reference to prior breaches suffered in the processing.observed
  4. ConfirmedRIPD — RIPD Standards permit applicable Ibero-American state legislation to establish exceptions to personal-data retention periods, subject to full respect for the rights and guarantees of the data subject.observed

#

Some concrete state-level transfer-safeguard evidence exists (RIPD model clauses, Convention 108+ accessions); no bloc-wide adequacy/localisation instrument exists.

Primary frameworkCouncil of Europe Convention 108+ (individual-state accession only); RIPD model contractual clauses (individual-state adoption only)
Traffic-light rationale — AmberSome concrete state-level transfer-safeguard evidence exists (RIPD model clauses, Convention 108+ accessions); no bloc-wide adequacy/localisation instrument exists.

Sub-modules (6)

Transfer MechanismsAmber

RIPD developed model contractual clauses for international transfers; Argentina's AAIP adopted them nationally via Resolución 198 (2023) as part of a modernisation process, but no bloc-wide binding transfer mechanism exists.

Claims (1):

  • RIPD developed its own model contractual clauses for international personal-data transfers, and Argentina's data protection authority (AAIP) adopted these clauses nationally via Resolución 198 in 2023 as part of a broader modernisation of cross-border transfer safeguards; this is state-level adoption of an RIPD-origin instrument, not a bloc-wide binding SCC regime.

Adequacy ReceivedRed

Adequacy decisions received by individual LATAM states (e.g., from the EU) are country-specific and fall outside this bloc-level row per the seed disambiguation.

Absence provenance: unavailable. Searched: LATAM bloc adequacy decision received EU.

Adequacy GrantedRed

No bloc-wide adequacy determination granted by a LATAM-wide body was identified; any such determinations are national and out of scope here.

Absence provenance: unavailable. Searched: LATAM bloc adequacy decision granted to third country.

Sccs And BcrsAmber

RIPD's own model contractual clauses have seen at least one confirmed national adoption (Argentina, 2023); no bloc-wide BCR-equivalent instrument was evidenced.

Claims (1):

  • RIPD developed its own model contractual clauses for international personal-data transfers, and Argentina's data protection authority (AAIP) adopted these clauses nationally via Resolución 198 in 2023 as part of a broader modernisation of cross-border transfer safeguards; this is state-level adoption of an RIPD-origin instrument, not a bloc-wide binding SCC regime.

Transfer Impact AssessmentRed

No TIA-equivalent obligation was evidenced in bloc-level instruments.

Absence provenance: unavailable. Searched: RIPD Standards transfer impact assessment, OAS Principles transfer risk assessment.

Data LocalisationRed

No bloc-wide data-localisation mandate was evidenced; localisation rules, where they exist, are set nationally and are out of scope for this row.

Absence provenance: unavailable. Searched: RIPD Standards data localisation requirement, OAS Principles data localisation.

Category narrative94 words

There is no bloc-wide adequacy, SCC, or localisation instrument. What exists is (a) RIPD-origin model contractual clauses adopted nationally (Argentina's AAIP, 2023), and (b) individual-state accessions to Council of Europe Convention 108+ (Uruguay 2021, Argentina 2023; Mexico as an original non-European Convention 108 party). Per the seed's caution flag, these are evidence of individual-state alignment with a global standard, not bloc-wide LATAM harmonisation, and must not be extrapolated to non-acceding states. EU-style adequacy decisions received/granted, TIAs, and localisation mandates are matters for individual national law and are out of scope for this bloc-level row.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableRIPD — RIPD developed its own model contractual clauses for international personal-data transfers, and Argentina's data protection authority (AAIP) adopted these clauses nationally via Resolución 198 in 2023 as part of a broader modernisation of cross-border transfer safeguards; this is state-level adoption of an RIPD-origin instrument, not a bloc-wide binding SCC regime.observed
  2. ConfirmedCouncil of Europe — Uruguay ratified the modernised Council of Europe Convention 108+ on 9 August 2021, becoming the first American-continent state to do so, having been a Party to the original Convention 108 since 1 August 2013.observed
  3. ConfirmedCouncil of Europe — Argentina ratified Convention 108+ on 17 April 2023, becoming the 23rd state party overall and the second American-continent state to join the modernised convention, having been a Party to the original Convention 108 since 2019.observed
  4. UncertainCouncil of Europe — Mexico is listed among the non-European states party to the original Council of Europe Convention 108 (alongside Cape Verde, Mauritius, Senegal and Tunisia); the seed anchor identifies Mexico's Convention 108+ accession as dating from 2018, though the Council of Europe parties page did not render an independently verifiable date table in retrieved content.observed
  5. ProbableIAPP — The modernised Convention 108+ removed the possibility for signatory states to declare exemptions from the Convention for national-security and defence-related data processing, a stricter standard than the original Convention 108 — a fact relevant only to LATAM states that have acceded (Uruguay, Argentina), not to non-acceding states.observed

#

No bloc-wide sectoral overlay content was found in either anchor instrument for any of the seven declared sub-modules.

Traffic-light rationale — RedNo bloc-wide sectoral overlay content was found in either anchor instrument for any of the seven declared sub-modules.

Sub-modules (7)

Financial Sector OverlayRed

No bloc-wide financial-sector DP overlay evidenced.

Absence provenance: unavailable. Searched: OAS Principles banking data, RIPD Standards financial sector.

Health Sector OverlayRed

No bloc-wide health-sector DP overlay evidenced beyond general special-category rules.

Absence provenance: unavailable. Searched: RIPD Standards health data sector rules.

Telecoms And EprivacyRed

No bloc-wide telecoms/ePrivacy overlay evidenced.

Absence provenance: unavailable. Searched: OAS Principles telecommunications ePrivacy.

Employment DataRed

No bloc-wide employment-data overlay evidenced.

Absence provenance: unavailable. Searched: RIPD Standards employment worker data.

Credit And ScoringRed

No bloc-wide credit-scoring overlay evidenced.

Absence provenance: unavailable. Searched: OAS Principles credit reporting scoring.

EducationRed

No bloc-wide education-sector overlay evidenced.

Absence provenance: unavailable. Searched: RIPD Standards education sector data.

InsuranceRed

No bloc-wide insurance-sector overlay evidenced.

Absence provenance: unavailable. Searched: RIPD Standards insurance sector data.

Category narrative54 words

Neither the OAS Principles nor the RIPD Standards establish sector-specific overlays (finance, health, telecoms, employment, credit-scoring, education, insurance) comparable to GDPR-adjacent sectoral instruments in the EU or HIPAA/GLBA in the US. Such overlays exist only within individual national statutes (e.g., Brazil's LGPD sectoral regulations), which are explicitly out of scope for this bloc-level row.

Sources and claims (1)
  1. ConfirmedOAS Secretariat for Legal Affairs, Department of International Law — Neither the OAS Updated Principles nor the RIPD Ibero-American Standards establish sector-specific data-protection overlays for banking, health, telecoms, employment, credit-scoring, education or insurance; such overlays exist only within individual national statutes, which fall outside this bloc-level row.observed

#

No general-population adtech/commercial-privacy content found; only a minors-specific cross-reference exists.

Traffic-light rationale — RedNo general-population adtech/commercial-privacy content found; only a minors-specific cross-reference exists.

Sub-modules (6)

Cookies And TrackersRed

No bloc-wide cookie/tracker consent regime evidenced.

Absence provenance: unavailable. Searched: RIPD Standards cookies trackers consent.

Dark PatternsRed

No bloc-wide dark-pattern prohibition evidenced.

Absence provenance: unavailable. Searched: RIPD Standards dark patterns interfaz engañosa.

Opt Out SignalsRed

No bloc-wide opt-out signal (e.g. GPC-equivalent) evidenced.

Absence provenance: unavailable. Searched: RIPD Standards opt-out signal global privacy control.

Clean Rooms And DcrRed

No bloc-wide data clean room/DCR rule evidenced.

Absence provenance: unavailable. Searched: RIPD Standards data clean room collaboration.

Cross Context AdvertisingRed

No bloc-wide cross-context/behavioural advertising rule evidenced for the general population (only minors-specific, cross-referenced).

Absence provenance: unavailable. Searched: RIPD Standards behavioural advertising general population.

Claims (1):

  • The only bloc-level adtech-adjacent finding is minors-specific: the 2026 RIPD Standards reference limiting profiling and behavioural-advertising practices directed at minors, with no equivalent general-population cross-context advertising rule evidenced.

Direct MarketingRed

No bloc-wide direct-marketing consent/suppression rule evidenced.

Absence provenance: unavailable. Searched: RIPD Standards direct marketing suppression list.

Category narrative50 words

General cookie/tracker consent regimes, dark-pattern prohibitions, opt-out signals, clean-room rules, cross-context advertising and direct-marketing suppression were not evidenced at bloc level. The only adtech-adjacent finding is minors-specific and is cross-referenced under children_and_vulnerable_groups: the 2026 RIPD Standards flag restrictions on profiling and behavioural advertising aimed at minors as a default-protection measure.

Sources and claims (1)
  1. ConfirmedAEPD — The only bloc-level adtech-adjacent finding is minors-specific: the 2026 RIPD Standards reference limiting profiling and behavioural-advertising practices directed at minors, with no equivalent general-population cross-context advertising rule evidenced.observed

#

Strong, recent (2026) soft-law content on profiling, ADM transparency, AI risk assessment and biometrics; genetic data and surveillance carveouts remain gaps.

Primary frameworkRIPD Estándares de Protección de Datos para los Estados Iberoamericanos (2026)
Traffic-light rationale — GreenStrong, recent (2026) soft-law content on profiling, ADM transparency, AI risk assessment and biometrics; genetic data and surveillance carveouts remain gaps.

Sub-modules (6)

Profiling RestrictionsGreen

RIPD Standards promote algorithmic-governance mechanisms including traceability, effective human oversight, continuous risk evaluation and periodic audit of automated/AI systems.

Claims (1):

  • The 2026 RIPD Standards promote algorithmic-governance mechanisms including traceability, effective human oversight, continuous risk evaluation and periodic audit of automated and AI systems.

Automated Decision Making TransparencyGreen

Individuals subject to automated decisions are entitled to information about the logic applied and the main criteria used, plus human intervention.

Claims (1):

  • Under the 2026 RIPD Standards, individuals subject to automated decisions producing legal effects or significant impacts are entitled to clear information about the logic applied and the main criteria used, in addition to human intervention.

Ai Risk AssessmentsGreen

RIPD Standards introduce impact-assessment references tied to disruptive technologies, AI systems, biometrics, predictive systems and neurotechnologies, and extend the data-quality principle across the AI system lifecycle.

Claims (2):

  • The 2026 RIPD Standards introduce specific references to impact assessments tied to disruptive technologies, AI systems, biometrics, predictive systems and neurotechnologies, particularly where these may pose high risk to rights and freedoms.
  • The 2026 RIPD Standards extend the data-quality principle for automated/AI systems beyond accuracy and currency to require assessment of representativeness, relevance, completeness and reliability of data across the system lifecycle, including training, validation, testing, adjustment and operational data.

Biometric RegimeAmber

RIPD's Strategic Plan 2026-2030 flags biometric-data treatments as a new priority work area alongside AI intersections and data spaces.

Claims (1):

  • RIPD's Strategic Plan 2026-2030, approved 2 June 2025, identifies biometric-data treatments as one of the network's new priority work areas, alongside the intersection of AI and data protection and the protection of vulnerable groups.

Genetic DataRed

No distinct genetic-data regime was evidenced separately from general special-category treatment or the newly-added neurodata category.

Absence provenance: unavailable. Searched: RIPD Standards genetic data specific regime, OAS Principles genetic data.

State Surveillance CarveoutsRed

No bloc-wide national-security/state-surveillance carveout provision was evidenced in the OAS Principles or RIPD Standards; the only related finding is Convention 108+'s removal of national-security exemption declarations, which binds only acceding states (Uruguay, Argentina), not the bloc as a whole.

Absence provenance: unavailable. Searched: RIPD Standards state surveillance national security carveout, OAS Principles national security exemption.

Claims (1):

  • The modernised Convention 108+ removed the possibility for signatory states to declare exemptions from the Convention for national-security and defence-related data processing, a stricter standard than the original Convention 108 — a fact relevant only to LATAM states that have acceded (Uruguay, Argentina), not to non-acceding states.
Category narrative44 words

This is the most developed bloc-level module. The 2026 RIPD Standards materially expand ADM/profiling rights, mandate AI/biometric/neurotech impact assessments, extend the data-quality principle to AI system lifecycles, and flag biometric treatments as a strategic priority. Genetic-data-specific rules and state-surveillance carveouts were not separately evidenced.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedAEPD — The 2026 RIPD Standards promote algorithmic-governance mechanisms including traceability, effective human oversight, continuous risk evaluation and periodic audit of automated and AI systems.observed
  2. ConfirmedAEPD — Under the 2026 RIPD Standards, individuals subject to automated decisions producing legal effects or significant impacts are entitled to clear information about the logic applied and the main criteria used, in addition to human intervention.observed
  3. ConfirmedAEPD — The 2026 RIPD Standards introduce specific references to impact assessments tied to disruptive technologies, AI systems, biometrics, predictive systems and neurotechnologies, particularly where these may pose high risk to rights and freedoms.observed
  4. ConfirmedAEPD — The 2026 RIPD Standards extend the data-quality principle for automated/AI systems beyond accuracy and currency to require assessment of representativeness, relevance, completeness and reliability of data across the system lifecycle, including training, validation, testing, adjustment and operational data.observed
  5. ConfirmedAEPD — RIPD's Strategic Plan 2026-2030, approved 2 June 2025, identifies biometric-data treatments as one of the network's new priority work areas, alongside the intersection of AI and data protection and the protection of vulnerable groups.observed

#

Strong minors-specific content in 2026 Standards; parental-consent mechanics, education-settings rules and dependent-adult protections remain gaps at bloc level.

Primary frameworkRIPD Estándares de Protección de Datos para los Estados Iberoamericanos (2026)
Traffic-light rationale — AmberStrong minors-specific content in 2026 Standards; parental-consent mechanics, education-settings rules and dependent-adult protections remain gaps at bloc level.

Sub-modules (5)

Age VerificationGreen

2026 RIPD Standards call for effective age-verification mechanisms as part of reinforced accountability for children's data.

Claims (1):

  • The 2026 RIPD Standards call for effective age-verification mechanisms as one of several reinforced accountability measures applicable to the processing of children's personal data.

Minor Profiling BansGreen

2026 RIPD Standards expressly reference restrictions on profiling and behavioural advertising directed at minors.

Claims (1):

  • The 2026 RIPD Standards expressly reference restrictions on profiling and behavioural-advertising practices directed at minors, among default privacy-protective measures that also include privacy-by-default settings, access limitations, and tools to block, mute and control groups.

Education SettingsRed

No education-settings-specific data-protection rule was evidenced.

Absence provenance: unavailable. Searched: RIPD Standards education settings schools data minors.

Dependent AdultsRed

RIPD's Strategic Plan references 'vulnerable groups' generally as a cross-cutting priority, but no dependent-adult-specific (elderly/incapacitated) rule distinct from children's protections was evidenced.

Absence provenance: unavailable. Searched: RIPD Standards dependent adults elderly incapacitated protection.

Claims (1):

  • RIPD's Strategic Plan 2026-2030 lists 'protección de colectivos vulnerables' as a cross-cutting priority, without isolating dependent-adult-specific (elderly or mentally-incapacitated) protections distinct from children's rights content.
Category narrative37 words

The 2026 RIPD Standards contain the bloc's strongest children-specific content: reinforced accountability, default protective settings, effective age verification, limits on profiling/behavioural advertising, and group-control tools. Parental-consent age thresholds, education-settings rules and dependent-adult-specific protections were not separately evidenced.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

Protection of children and adolescents in digital environments has been named among the principal innovations of the RIPD's 2026 Estandares update, sitting alongside the algorithmic-governance and neurodata additions discussed elsewhere in this cycle's coverage as one of the headline axes of the revised regional standard. This finding is reported at a probable, rather than confirmed, confidence tier, since it traces to a characterisation of the update's principal innovations rather than to a direct citation of the specific children's-protection provisions themselves; the underlying source establishes that this is a named priority of the update without necessarily detailing every specific mechanism the update introduces for this population.

The inclusion of children and adolescents' digital-environment protection as a principal innovation is notable given the RIPD's function as a regional soft-law benchmark spanning Ibero-American, not purely Latin American, member states: a standard-setting body of this kind naming a vulnerable-groups protection as one of its headline updates signals that the issue has achieved sufficient regional consensus to warrant explicit treatment in the benchmark document, even though, as with the algorithmic-governance provisions, any binding effect depends on subsequent domestic legislative or regulatory action by individual member states.

No LATAM-specific national-level development on children's or vulnerable-groups data protection, distinct from this regional benchmark update, was located this cycle; the finding here is confined to the regional-standard level.

Outlook

Given this is reported at a probable rather than confirmed confidence tier and traces only to a characterisation of the update's principal innovations, a dedicated review of the Estandares' specific children's-protection text would materially improve confidence in exactly what mechanisms this innovation comprises. Whether individual LATAM member states subsequently draw on this regional benchmark to strengthen their own domestic children's-data-protection provisions is the item to watch in coming cycles.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedAEPD — The 2026 RIPD Standards call for effective age-verification mechanisms as one of several reinforced accountability measures applicable to the processing of children's personal data.observed
  2. UncertainAEPD — The 2026 RIPD Standards emphasise reinforced accountability and default protective settings for minors' data but do not specify a discrete parental-consent age threshold comparable to GDPR Article 8's 13-16 model in the retrieved text.observed
  3. ConfirmedAEPD — The 2026 RIPD Standards expressly reference restrictions on profiling and behavioural-advertising practices directed at minors, among default privacy-protective measures that also include privacy-by-default settings, access limitations, and tools to block, mute and control groups.observed
  4. UncertainAEPD — RIPD's Strategic Plan 2026-2030 lists 'protección de colectivos vulnerables' as a cross-cutting priority, without isolating dependent-adult-specific (elderly or mentally-incapacitated) protections distinct from children's rights content.observed

#

No bloc-wide penalty/enforcement-activity content exists; DPA-capacity and judicial-recourse principles are evidenced, and recent (≤180d) developments are well documented.

Primary frameworkRIPD Estándares de Protección de Datos para los Estados Iberoamericanos (2026)
Traffic-light rationale — AmberNo bloc-wide penalty/enforcement-activity content exists; DPA-capacity and judicial-recourse principles are evidenced, and recent (≤180d) developments are well documented.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No bloc-wide penalty schedule or investigative-powers regime exists; these are set only at national level, out of scope for this row.

Absence provenance: unavailable. Searched: OAS Principles penalties enforcement powers, RIPD Standards sanction regime.

Claims (1):

  • Neither the OAS Updated Principles nor the RIPD Standards impose a bloc-wide penalty schedule or investigative-powers regime; these matters are governed exclusively by individual national data-protection statutes, which are out of scope for this bloc-level row.

Enforcement Activity IndexRed

No bloc-wide enforcement-activity index exists; enforcement actions occur at the national DPA level and are out of scope here.

Absence provenance: unavailable. Searched: LATAM bloc-wide enforcement decisions fines 2025 2026.

Regulator Funding And CapacityAmber

RIPD Standards emphasise that supervisory authorities must act with autonomy and independence and have sufficient resources for effective exercise of their functions.

Claims (1):

  • The 2026 RIPD Standards address the role of supervisory authorities, underscoring the need for them to act with autonomy and independence and to have sufficient resources to effectively exercise their functions.

Collective Redress And Class ActionsRed

No bloc-wide collective-redress or class-action mechanism was evidenced.

Absence provenance: unavailable. Searched: RIPD Standards collective redress class action data protection.

Private Right Of ActionAmber

RIPD Standards contemplate recourse before the supervisory authority and, absent resolution, before domestic judicial bodies under each state's internal law.

Claims (1):

  • The RIPD Standards contemplate that data subjects may seek recourse before the supervisory authority and, failing resolution, before domestic judicial bodies in accordance with each Ibero-American state's internal law.

Recent Developments 180DGreen

Multiple RIPD/AEPD developments occurred within 180 days of the 6 August 2026 dispatch date: the 26 May 2026 Standards update, its 15 June 2026 public announcement, and a 22 June 2026 neurodata reference document; summit-level adoption remains pending for November 2026.

Claims (3):

  • The RIPD approved its updated Ibero-American Data Protection Standards on 26 May 2026 at its XV Ibero-American Data Protection Meeting held in Cartagena de Indias, Colombia, with the update publicly announced by the AEPD, RIPD's permanent secretariat, on 15 June 2026.
  • On 22 June 2026, the RIPD separately adopted a reference document addressing regulatory challenges for protecting neurodata and personal-data processing using neurotechnologies outside the healthcare sector.
  • As of the 6 August 2026 dispatch date, the updated RIPD Standards remained pending referral to SEGIB for possible formal adoption at the Ibero-American Summit of Heads of State and Government scheduled for 4-5 November 2026 in Madrid, meaning summit-level political endorsement had not yet occurred.
Category narrative42 words

No bloc-wide investigative powers, penalty schedule, or collective-redress/private-right-of-action mechanism exists; these remain matters for individual national DPA statutes. RIPD Standards do address DPA independence/resourcing in general terms and judicial-recourse principles, and 2026 saw several concrete RIPD/AEPD developments within the 180-day recency window.

Periodic update · new data 2026-09-28

Enforcement & Redress

Brazil's ANPD underwent a significant capacity and institutional-standing shift this cycle. Lei No. 15.352/2026 converted the ANPD into an autonomous regulatory agency with its own legal personality and financial autonomy, a material change from its prior institutional status. Concretely reflecting that new capacity, the ANPD's first public hiring competition, for 50 positions, was authorised on 24 June 2026, suggesting the agency is moving to build out staffing commensurate with its expanded autonomous mandate.

That expanded capacity appears to be translating into enforcement activity: in June 2026 the ANPD opened 19 new administrative sanctioning proceedings, described as the largest such batch in the authority's history. This is a material escalation-of-activity signal, though it should be read against the authority's enforcement record to date, which remains thin in absolute terms: Brazil has, as of this cycle's sourcing, a single public LGPD fine applied to a private company, R$14,400 against Telekall Infoservice for processing without legal basis. That fine sits far below the maximum sanctioning power available to the ANPD under LGPD Article 52, which authorises fines of up to R$50 million or 2% of the company's Brazilian revenue per infraction, whichever is lower, alongside non-monetary sanctions including warnings, publicisation, data blocking or deletion, and processing suspension.

All of the Brazilian enforcement findings in this module are reported at a probable, rather than confirmed, confidence tier, since they trace to Brazilian legal-blog and compliance-industry sourcing rather than to a directly retrieved ANPD primary-source page; this is a material sourcing gap given that ANPD enforcement is the strongest enforcement-activity signal in this cycle's LATAM data-protection coverage, and a primary-source retrieval in a future cycle would be the single most valuable improvement to confidence here.

The combination of newly gained institutional autonomy, an enlarged hiring plan, and the largest-ever sanctioning batch together describe a regulator moving from a comparatively quiet enforcement posture toward a more active one, even though the absolute enforcement record, one public fine to date, has not yet caught up with that shift in institutional capacity and activity volume.

Outlook

Whether the 19 sanctioning proceedings opened in June 2026 result in published fines, and at what scale relative to the LGPD Article 52 ceiling, is the central item to track for Brazil's enforcement trajectory in coming cycles; a wave of published outcomes from this batch would be the clearest signal yet of whether the ANPD's new autonomy is translating into materially increased sanctioning activity. Separately, retrieving ANPD's own primary-source enforcement records directly, rather than relying on Brazilian legal-blog secondary sourcing, would meaningfully strengthen the evidentiary basis for tracking this module going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedOAS Secretariat for Legal Affairs, Department of International Law — Neither the OAS Updated Principles nor the RIPD Standards impose a bloc-wide penalty schedule or investigative-powers regime; these matters are governed exclusively by individual national data-protection statutes, which are out of scope for this bloc-level row.observed
  2. ConfirmedAEPD — The 2026 RIPD Standards address the role of supervisory authorities, underscoring the need for them to act with autonomy and independence and to have sufficient resources to effectively exercise their functions.observed
  3. ConfirmedRIPD — The RIPD Standards contemplate that data subjects may seek recourse before the supervisory authority and, failing resolution, before domestic judicial bodies in accordance with each Ibero-American state's internal law.observed
  4. ConfirmedRIPD — The RIPD approved its updated Ibero-American Data Protection Standards on 26 May 2026 at its XV Ibero-American Data Protection Meeting held in Cartagena de Indias, Colombia, with the update publicly announced by the AEPD, RIPD's permanent secretariat, on 15 June 2026.observed
  5. ConfirmedAEPD — On 22 June 2026, the RIPD separately adopted a reference document addressing regulatory challenges for protecting neurodata and personal-data processing using neurotechnologies outside the healthcare sector.observed
  6. ConfirmedAEPD — As of the 6 August 2026 dispatch date, the updated RIPD Standards remained pending referral to SEGIB for possible formal adoption at the Ibero-American Summit of Heads of State and Government scheduled for 4-5 November 2026 in Madrid, meaning summit-level political endorsement had not yet occurred.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct66.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Latin America bloc
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacydata localisation
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data (special categories/consent), data_subject_rights (core rights), controller_processor_duties (accountability/contracts/security/retention), algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups are grounded in T1/T2 primary-instrument text (OAS Principles PDF, RIPD 2026 Standards PDF, AEPD secretariat press releases). cross_border_and_adequacy relies on a mix of T1 (RIPD Standards), T2 (CoE parties page), and T3/T4 (CoE news releases, IAPP analysis) for individual-state Convention 108+ accession facts — these are explicitly scoped as state-level, not bloc-wide, per the seed caution flags. sectoral_watch and adtech_and_commercial_privacy modules returned almost entirely absent findings at the bloc level (T1 instruments confirmed to not contain sectoral/adtech content) and are carried with explicit absent_field_provenance rather than fabricated content. enforcement_and_redress mixes T1/T2 principle-level content (DPA independence, judicial recourse) with well-evidenced T1/T2 recent-developments content (≤180 days).

Unresolved questions (4):

  • Whether Mexico's Convention 108+ (as opposed to base Convention 108) ratification date is precisely 2018 as per the seed anchor — the CoE parties page did not render a verifiable date table in retrieved content.
  • Whether the RIPD 2026 Standards will in fact be adopted at the November 2026 Ibero-American Summit in Madrid, or whether SEGIB/summit-level endorsement will be deferred or modified.
  • Whether any LATAM-bloc-level (as opposed to national) sectoral overlays, DPO thresholds, ROPA obligations, or breach-notification timelines exist in RIPD/OAS guidance documents not surfaced by this search pass.
  • Whether RIPD's model contractual clauses (adopted nationally by Argentina's AAIP via Resolución 198, 2023) have been adopted by additional Ibero-American states beyond Argentina.

Escalate to primary-source review: yes