#
Mature omnibus statute with an operational, resourced supervisory authority and a freshly modernised implementing regulation in force since March 2025.
Sub-modules (5)
Regulator And AuthorityGreen
ANPD sits within MINJUSDH and exercises administrative, orienting, normative, resolutive, oversight and sanctioning functions via its Dirección de Protección de Datos Personales and Dirección de Fiscalización e Instrucción.
Claims (1):
- The Autoridad Nacional de Protección de Datos Personales (ANPD) operates two directorates, the Dirección de Protección de Datos Personales and the Dirección de Fiscalización e Instrucción, to enforce Ley N° 29733 and its Reglamento.
Act And InstrumentsGreen
Core instrument is Ley 29733 as amended by DL 1353 (2017); operative secondary instrument is the new Reglamento (DS 016-2024-JUS), replacing DS 003-2013-JUS.
Claims (2):
- Decreto Legislativo N° 1353 (published 7 January 2017) created the current Autoridad Nacional de Transparencia y Acceso a la Información Pública framework and strengthened/reformed the personal-data-protection regime, establishing the ANPD as it exists today.
- The new Reglamento of Ley 29733, approved by Decreto Supremo N° 016-2024-JUS and published 30 November 2024, entered into force on 31 March 2025, repealing the prior 2013 regulation (DS 003-2013-JUS) and introducing new concepts, obligations and rights.
Material ScopeGreen
The regime applies to all personal-data processing, automated or not, by natural persons, public entities or private-sector institutions, regardless of medium.
Claims (1):
- The Reglamento applies to every modality of personal-data processing carried out by natural persons, public entities, or private-sector institutions, irrespective of the medium in which the data are held.
Territorial ScopeGreen
The 2024 Reglamento clarifies extraterritorial reach: it applies to processing carried out in Peru, by an encargado acting for a responsable in Peru regardless of the encargado's location, or by a responsable outside Peru that uses means located in Peru, offers goods/services to persons in Peru, or monitors their behaviour.
Claims (1):
- The Reglamento's Article IV extends application to processing performed in Peruvian territory, by an encargado wherever located acting on behalf of a responsable established in Peru, or by a responsable outside Peru that uses means in Peru, offers goods/services to persons in Peru, or analyses their behaviour.
Regulator Registration And FilingAmber
Controllers (titulares) and processing entities must register the creation, modification or cancellation of 'bancos de datos personales' with the Registro Nacional de Protección de Datos Personales administered by ANPD.
Claims (1):
- Natural or legal persons in the private sector and public entities that create, modify or cancel bancos de datos personales are obligated to process the corresponding inscription before the Registro Nacional de Protección de Datos Personales.
Regulator & Framework
Peru's data-protection framework continues to rest on Ley No. 29733 (as amended by Legislative Decree No. 1353), with its implementing regulation replaced by Supreme Decree No. 016-2024-JUS, effective 30 March 2025. That replacement of the 2013 regulation is understood to have expanded the law's territorial scope so that it now applies to foreign companies offering services to Peruvian customers or analysing the behaviour of individuals located in Peru, a change reported to require such companies to appoint a local representative in Peru. This extraterritorial expansion, if applied as described, materially widens the population of controllers who must attend to Peruvian compliance obligations regardless of physical presence in the country.
A separate development, Legislative Decree No. 1700 of 24 January 2026, reportedly amends Peru's Cybercrime Law, Law No. 30096. Its substantive content and any interaction with the data-protection framework under Ley No. 29733 and DS 016-2024-JUS were not independently confirmed this cycle; reports suggest the amendment exists, but its relevance to controllers and processors under the data-protection regime specifically remains unverified.
Outlook
Confirming the substantive content of Legislative Decree No. 1700 and its precise interaction, if any, with the data-protection framework is the primary open item for this module. Should DS 016-2024-JUS's expanded territorial-scope provisions see active enforcement against foreign controllers without a Peru presence, that would be a significant next development to track.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (6)
- ConfirmedPlataforma del Estado Peruano (gob.pe) — The Autoridad Nacional de Protección de Datos Personales (ANPD) operates two directorates, the Dirección de Protección de Datos Personales and the Dirección de Fiscalización e Instrucción, to enforce Ley N° 29733 and its Reglamento.observed
- ConfirmedMINJUSDH — Decreto Legislativo N° 1353 (published 7 January 2017) created the current Autoridad Nacional de Transparencia y Acceso a la Información Pública framework and strengthened/reformed the personal-data-protection regime, establishing the ANPD as it exists today.observed
- ConfirmedMINJUSDH / El Peruano — The new Reglamento of Ley 29733, approved by Decreto Supremo N° 016-2024-JUS and published 30 November 2024, entered into force on 31 March 2025, repealing the prior 2013 regulation (DS 003-2013-JUS) and introducing new concepts, obligations and rights.observed
- ConfirmedSMV (mirror of MINJUSDH instrument) — The Reglamento applies to every modality of personal-data processing carried out by natural persons, public entities, or private-sector institutions, irrespective of the medium in which the data are held.observed
- ConfirmedIAPP — The Reglamento's Article IV extends application to processing performed in Peruvian territory, by an encargado wherever located acting on behalf of a responsable established in Peru, or by a responsable outside Peru that uses means in Peru, offers goods/services to persons in Peru, or analyses their behaviour.observed
- ConfirmedSMV (mirror of MINJUSDH instrument) — Natural or legal persons in the private sector and public entities that create, modify or cancel bancos de datos personales are obligated to process the corresponding inscription before the Registro Nacional de Protección de Datos Personales.observed