🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
PE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-07

Peru

PE schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 52 claims · 36 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
52Claimsbaseline..claims[]
20Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 19 sub-modules are flagged red.

Jurisdiction lead brief

Latest update · 28 September 2026

Lead Signal

Peru's data-protection framework continued to tighten this cycle on the controller-duty and enforcement fronts rather than on the core statutory text. Directorial Resolution No. 100-2025-JUS-DGTAIPD, effective 31 December 2025, establishes detailed requirements for the designation, performance and functions of Data Protection Officers, including accredited data-protection knowledge criteria that controllers must verify before appointment. This sits alongside continued active use of ANPD's sanctioning powers, which remain governed by a three-tiered infraction structure denominated in Unidades Impositivas Tributarias, with the 2026 UIT value set at S/5,500 under Decreto Supremo No. 301-2025-EF and total sanctioning capped at 10% of an offending entity's prior-year net revenue.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature omnibus statute with an operational, resourced supervisory authority and a freshly modernised implementing regulation in force since March 2025.

Primary frameworkLey N° 29733, Ley de Protección de Datos Personales (2011, as amended by Decreto Legislativo N° 1353 of 2017), and its Reglamento approved by Decreto Supremo N° 016-2024-JUS (in force since 31 March 2025)
Traffic-light rationale — GreenMature omnibus statute with an operational, resourced supervisory authority and a freshly modernised implementing regulation in force since March 2025.

Sub-modules (5)

Regulator And AuthorityGreen

ANPD sits within MINJUSDH and exercises administrative, orienting, normative, resolutive, oversight and sanctioning functions via its Dirección de Protección de Datos Personales and Dirección de Fiscalización e Instrucción.

Claims (1):

  • The Autoridad Nacional de Protección de Datos Personales (ANPD) operates two directorates, the Dirección de Protección de Datos Personales and the Dirección de Fiscalización e Instrucción, to enforce Ley N° 29733 and its Reglamento.

Act And InstrumentsGreen

Core instrument is Ley 29733 as amended by DL 1353 (2017); operative secondary instrument is the new Reglamento (DS 016-2024-JUS), replacing DS 003-2013-JUS.

Claims (2):

  • Decreto Legislativo N° 1353 (published 7 January 2017) created the current Autoridad Nacional de Transparencia y Acceso a la Información Pública framework and strengthened/reformed the personal-data-protection regime, establishing the ANPD as it exists today.
  • The new Reglamento of Ley 29733, approved by Decreto Supremo N° 016-2024-JUS and published 30 November 2024, entered into force on 31 March 2025, repealing the prior 2013 regulation (DS 003-2013-JUS) and introducing new concepts, obligations and rights.

Material ScopeGreen

The regime applies to all personal-data processing, automated or not, by natural persons, public entities or private-sector institutions, regardless of medium.

Claims (1):

  • The Reglamento applies to every modality of personal-data processing carried out by natural persons, public entities, or private-sector institutions, irrespective of the medium in which the data are held.

Territorial ScopeGreen

The 2024 Reglamento clarifies extraterritorial reach: it applies to processing carried out in Peru, by an encargado acting for a responsable in Peru regardless of the encargado's location, or by a responsable outside Peru that uses means located in Peru, offers goods/services to persons in Peru, or monitors their behaviour.

Claims (1):

  • The Reglamento's Article IV extends application to processing performed in Peruvian territory, by an encargado wherever located acting on behalf of a responsable established in Peru, or by a responsable outside Peru that uses means in Peru, offers goods/services to persons in Peru, or analyses their behaviour.

Regulator Registration And FilingAmber

Controllers (titulares) and processing entities must register the creation, modification or cancellation of 'bancos de datos personales' with the Registro Nacional de Protección de Datos Personales administered by ANPD.

Claims (1):

  • Natural or legal persons in the private sector and public entities that create, modify or cancel bancos de datos personales are obligated to process the corresponding inscription before the Registro Nacional de Protección de Datos Personales.
Category narrative90 words

Peru operates a comprehensive omnibus data-protection regime anchored on Ley N° 29733 (2011), Ley de Protección de Datos Personales, as substantially reformed by Decreto Legislativo N° 1353 (2017), which created the current Autoridad Nacional de Protección de Datos Personales (ANPD) within the Ministerio de Justicia y Derechos Humanos (MINJUSDH). A wholly new implementing regulation, Decreto Supremo N° 016-2024-JUS, was published 30 November 2024 and entered into force 31 March 2025, repealing the 2013 regulation (DS N° 003-2013-JUS) and modernising definitions (location/online identifiers, neural data), extraterritorial scope, portability, and breach-notification duties.

Periodic update · new data 2026-09-28

Regulator & Framework

Peru's data-protection framework continues to rest on Ley No. 29733 (as amended by Legislative Decree No. 1353), with its implementing regulation replaced by Supreme Decree No. 016-2024-JUS, effective 30 March 2025. That replacement of the 2013 regulation is understood to have expanded the law's territorial scope so that it now applies to foreign companies offering services to Peruvian customers or analysing the behaviour of individuals located in Peru, a change reported to require such companies to appoint a local representative in Peru. This extraterritorial expansion, if applied as described, materially widens the population of controllers who must attend to Peruvian compliance obligations regardless of physical presence in the country.

A separate development, Legislative Decree No. 1700 of 24 January 2026, reportedly amends Peru's Cybercrime Law, Law No. 30096. Its substantive content and any interaction with the data-protection framework under Ley No. 29733 and DS 016-2024-JUS were not independently confirmed this cycle; reports suggest the amendment exists, but its relevance to controllers and processors under the data-protection regime specifically remains unverified.

Outlook

Confirming the substantive content of Legislative Decree No. 1700 and its precise interaction, if any, with the data-protection framework is the primary open item for this module. Should DS 016-2024-JUS's expanded territorial-scope provisions see active enforcement against foreign controllers without a Peru presence, that would be a significant next development to track.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedPlataforma del Estado Peruano (gob.pe) — The Autoridad Nacional de Protección de Datos Personales (ANPD) operates two directorates, the Dirección de Protección de Datos Personales and the Dirección de Fiscalización e Instrucción, to enforce Ley N° 29733 and its Reglamento.observed
  2. ConfirmedMINJUSDH — Decreto Legislativo N° 1353 (published 7 January 2017) created the current Autoridad Nacional de Transparencia y Acceso a la Información Pública framework and strengthened/reformed the personal-data-protection regime, establishing the ANPD as it exists today.observed
  3. ConfirmedMINJUSDH / El Peruano — The new Reglamento of Ley 29733, approved by Decreto Supremo N° 016-2024-JUS and published 30 November 2024, entered into force on 31 March 2025, repealing the prior 2013 regulation (DS 003-2013-JUS) and introducing new concepts, obligations and rights.observed
  4. ConfirmedSMV (mirror of MINJUSDH instrument) — The Reglamento applies to every modality of personal-data processing carried out by natural persons, public entities, or private-sector institutions, irrespective of the medium in which the data are held.observed
  5. ConfirmedIAPP — The Reglamento's Article IV extends application to processing performed in Peruvian territory, by an encargado wherever located acting on behalf of a responsable established in Peru, or by a responsable outside Peru that uses means in Peru, offers goods/services to persons in Peru, or analyses their behaviour.observed
  6. ConfirmedSMV (mirror of MINJUSDH instrument) — Natural or legal persons in the private sector and public entities that create, modify or cancel bancos de datos personales are obligated to process the corresponding inscription before the Registro Nacional de Protección de Datos Personales.observed

#

Lawful-basis and special-category rules are well documented and current; pseudonymisation/anonymisation safe-harbour detail is thin (absent_field_provenance applies to that sub-module).

Primary frameworkLey N° 29733 Arts. 13-14, 2(5); Reglamento (DS 016-2024-JUS) Título Preliminar Art. III
Traffic-light rationale — AmberLawful-basis and special-category rules are well documented and current; pseudonymisation/anonymisation safe-harbour detail is thin (absent_field_provenance applies to that sub-module).

Sub-modules (4)

Lawful BasesGreen

Consent is the general lawful basis, subject to enumerated statutory exceptions such as contractual necessity, public-source data, health emergencies and international law-enforcement/intelligence cooperation.

Claims (2):

  • Peruvian data-protection law generally requires the free, express, unequivocal, prior and informed consent of the data subject before processing personal data.
  • Consent is not required where processing is necessary for performance of a contract to which the data subject is party (including authentication, service support, billing) or for health-emergency prevention, diagnosis or treatment by health professionals bound by professional secrecy.

Special CategoriesGreen

Sensitive data categories include biometric identifiers, racial/ethnic origin, income, political/religious/philosophical/moral opinions, union affiliation, health and sex-life data; the 2024 Reglamento expands this list to include neural data.

Claims (2):

  • Sensitive personal data ('datos sensibles') under Peruvian law comprises biometric data capable of identifying the data subject, racial and ethnic origin, income, political, religious, philosophical or moral convictions, union affiliation, and information concerning health or sexual life.
  • The 2024 Reglamento expands the definition of sensitive data to explicitly include neural data.

Pseudonymisation And AnonymisationRed

No dedicated statutory pseudonymisation/anonymisation safe-harbour provision was identified in the statute or the 2024 Reglamento within the sources reviewed.

Category narrative62 words

Consent is the default lawful basis, defined as free, express, unequivocal, prior and informed, with statutory exceptions (contract performance, public-source data, health emergencies, international treaty/intelligence cooperation against organised crime). Special/sensitive categories include biometric identifiers, racial/ethnic origin, income, political/religious/philosophical/moral opinions, union affiliation, and health/sex-life data; the 2024 Reglamento adds neural data to the sensitive list. No standalone statutory pseudonymisation/anonymisation safe-harbour framework was located.

Sources and claims (5)
  1. ConfirmedPlataforma del Estado Peruano (gob.pe) — Peruvian data-protection law generally requires the free, express, unequivocal, prior and informed consent of the data subject before processing personal data.observed
  2. ConfirmedOsinergmin (mirror) — Consent is not required where processing is necessary for performance of a contract to which the data subject is party (including authentication, service support, billing) or for health-emergency prevention, diagnosis or treatment by health professionals bound by professional secrecy.observed
  3. ConfirmedMINSA (mirror) — Processing of data relating to health or sexual life requires the express, written consent of the data subject, reflecting the heightened threshold applied to sensitive categories.observed
  4. ConfirmedSMV (mirror of MINJUSDH instrument) — Sensitive personal data ('datos sensibles') under Peruvian law comprises biometric data capable of identifying the data subject, racial and ethnic origin, income, political, religious, philosophical or moral convictions, union affiliation, and information concerning health or sexual life.observed
  5. ConfirmedIAPP — The 2024 Reglamento expands the definition of sensitive data to explicitly include neural data.observed

#

Rights framework, deadlines and escalation path to ANPD are clearly documented and current post-2025 Reglamento.

Primary frameworkLey N° 29733 Título III (Arts. 18-24, as renumbered/expanded); Reglamento (DS 016-2024-JUS) Arts. 55, 76
Traffic-light rationale — GreenRights framework, deadlines and escalation path to ANPD are clearly documented and current post-2025 Reglamento.

Sub-modules (5)

Access RightGreen

Data subjects may request confirmation and details of processing of their data; controllers must respond within 20 business days.

Claims (1):

  • Controllers must respond to a data subject's exercise of the right of access within a maximum of 20 business days.

Rectification And ErasureGreen

Rectification and cancellation (erasure) requests must be answered within 10 business days; cancellation is unavailable where data are retained for historical, statistical, scientific, contractual or legal reasons.

Claims (2):

  • Requests for rectification, cancellation or opposition must be answered by the controller within 10 business days.
  • The cancellation right does not proceed where data are retained for historical, statistical or scientific reasons, where necessary for a contractual relationship, or where required to be processed by law.

Restriction And ObjectionGreen

Data subjects may oppose processing on justified, legitimate grounds relating to their particular situation where consent was not required; the controller must then cease the challenged processing if the opposition is well-founded.

Claims (1):

  • A data subject may oppose processing of their data, absent prior consent, where founded and legitimate reasons relating to their concrete personal situation exist; if the opposition is justified, the controller or processor must act on it.

Data PortabilityGreen

The 2024 Reglamento introduces a portability right allowing data subjects to receive their data in a structured, commonly used, machine-readable format, or to have it transmitted to another controller, when processing is based on consent, contract, or automated means.

Claims (1):

  • Article 76 of the 2024 Reglamento creates a portability right permitting data subjects to receive their personal data in a structured, commonly used, machine-readable format, or to have it transmitted to another controller, where processing is consent-based, contractual, or automated, provided this is not excessively onerous and is technically feasible.

Deadlines And Response WindowsGreen

Response deadlines (20 business days for access; 10 business days for rectification/cancellation/opposition) run from the day after submission and may be extended once for an equal period if circumstances justify it.

Claims (1):

  • ARCO response deadlines may be extended once, for an equal period, when circumstances justify the extension, with the decision and justification communicated to the data subject within the original deadline.
Category narrative65 words

Peru grants the classic ARCO rights (Acceso, Rectificación, Cancelación, Oposición) with statutory response deadlines of 20 business days for access and 10 business days for rectification, cancellation and opposition, extendable once for an equal period. The 2024 Reglamento adds a standalone portability right (Art. 76) as a manifestation of the access right. Unresolved ARCO disputes may be escalated to ANPD via a trilateral administrative procedure.

Sources and claims (6)
  1. ConfirmedPlataforma del Estado Peruano (gob.pe) — Controllers must respond to a data subject's exercise of the right of access within a maximum of 20 business days.observed
  2. ConfirmedPlataforma del Estado Peruano (gob.pe) — Requests for rectification, cancellation or opposition must be answered by the controller within 10 business days.observed
  3. ConfirmedPlataforma del Estado Peruano (gob.pe) — The cancellation right does not proceed where data are retained for historical, statistical or scientific reasons, where necessary for a contractual relationship, or where required to be processed by law.observed
  4. ConfirmedOsinergmin (mirror) — A data subject may oppose processing of their data, absent prior consent, where founded and legitimate reasons relating to their concrete personal situation exist; if the opposition is justified, the controller or processor must act on it.observed
  5. ConfirmedIAPP — Article 76 of the 2024 Reglamento creates a portability right permitting data subjects to receive their personal data in a structured, commonly used, machine-readable format, or to have it transmitted to another controller, where processing is consent-based, contractual, or automated, provided this is not excessively onerous and is technically feasible.observed
  6. ConfirmedSMV (mirror of MINJUSDH instrument) — ARCO response deadlines may be extended once, for an equal period, when circumstances justify the extension, with the decision and justification communicated to the data subject within the original deadline.observed

#

Security, DPO and breach-notification duties are well documented and current; DPIA-trigger methodology and general retention/disposal rules are thin or absent in the sources reviewed.

Primary frameworkLey N° 29733 Art. 16; Reglamento (DS 016-2024-JUS) Arts. 34, 37, 47, 49-50
Traffic-light rationale — AmberSecurity, DPO and breach-notification duties are well documented and current; DPIA-trigger methodology and general retention/disposal rules are thin or absent in the sources reviewed.

Sub-modules (7)

Accountability And DpiaRed

No explicit DPIA-trigger regime was identified in the sources reviewed; accountability is expressed generally through the security and documentation duties in the 2024 Reglamento.

Dpo RequirementsGreen

A designated 'Oficial de Datos Personales' is mandatory for public entities and for private entities that process large volumes of data, sensitive data, data affecting a large number of people, or whose principal activities involve sensitive data.

Claims (1):

  • The 2024 Reglamento (Art. 37) requires designation of an Oficial de Datos Personales where processing is carried out by a public entity, involves large volumes of data or sensitive data or data affecting a large number of persons, or where the responsible party's principal activities involve sensitive data.

Ropa RequirementsAmber

Peru does not operate a GDPR-style internal ROPA obligation as such; instead, controllers must register/inscribe each banco de datos personales in the Registro Nacional, which performs an analogous transparency function.

Claims (1):

  • Controllers must register the creation, modification and cancellation of each banco de datos personales with the Registro Nacional de Protección de Datos Personales, providing its denomination, location, purposes and uses, functioning as the principal processing-inventory mechanism in lieu of a discrete ROPA obligation.

Joint Controller ArrangementsRed

No detailed joint-controller regime distinct from the general titular/encargado (controller/processor) framework was identified in the sources reviewed.

Security MeasuresGreen

Controllers must adopt technical, organisational and legal measures to secure personal data and prevent unauthorised alteration, loss, processing or access; the 2024 Reglamento adds documented, dated security-policy and access-control requirements.

Claims (2):

  • Controllers must adopt technical, organisational and legal measures guaranteeing the security of personal data and preventing its alteration, loss, unauthorised processing or access; processing in databases lacking such conditions is prohibited.
  • The 2024 Reglamento adds obligations to maintain a documented, dated security policy (Art. 47) and to implement access controls to secure areas (Art. 49) and equipment (Art. 50) inside and outside the controller's premises.

Breach NotificationGreen

Controllers must notify ANPD, and generally the affected data subject, within 48 hours of becoming aware of a security incident, even if already remediated, unless the incident caused no impact and was fully resolved.

Claims (1):

  • Article 34 of the 2024 Reglamento requires the controller to notify ANPD, at most within 48 hours of becoming aware of a security incident, and to notify the affected data subject within the same period in clear language, unless the incident caused no harm and was fully resolved internally.

Retention And DisposalRed

No general statutory retention-period ceiling or disposal-schedule requirement was located in the sources reviewed; retention limits appear tied case-by-case to purpose limitation and consent duration.

Category narrative95 words

Controllers must adopt technical, organisational and legal security measures; the 2024 Reglamento adds documented, dated security-policy and access-control obligations. A mandatory 'Oficial de Datos Personales' (DPO-equivalent) must be designated by public entities and by private entities processing large volumes of data, sensitive data, or whose core activity involves sensitive data. Security-incident notification to ANPD and to affected data subjects is required within 48 hours of becoming aware of the incident. The Registro Nacional functions as a de facto processing-inventory filing. No explicit statutory DPIA-trigger framework or general retention-period ceiling was located in the reviewed sources.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Controller and processor obligations in Peru tightened materially this cycle with the entry into force, on 31 December 2025, of Directorial Resolution No. 100-2025-JUS-DGTAIPD. The resolution sets out detailed requirements for the designation, performance and functions of Data Protection Officers, including criteria for accredited data-protection knowledge that a controller must verify before appointing a DPO. This is a concrete strengthening of what had previously been a more general DPO obligation, and it raises the bar for controllers who had treated DPO designation as a formality rather than a substantively assessed role.

Alongside this, Supreme Decree No. 016-2024-JUS obligates controllers to notify data breaches to the National Authority for the Protection of Personal Data, ANPD, and ANPD has launched a unified breach-reporting form to standardise how those notifications are made. Together, the DPO Directive and the unified breach-reporting mechanism indicate a regulator building out the procedural infrastructure behind its statutory powers rather than resting on the bare text of the law.

Outlook

The practical operation of the DPO accredited-knowledge criterion, now in force, is the item most likely to generate compliance friction and further guidance in the near term. Continued uptake of the unified breach-reporting form, and any published statistics on its usage, would be the next indicator of how actively ANPD is operationalising these controller-duty developments.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedIAPP — The 2024 Reglamento (Art. 37) requires designation of an Oficial de Datos Personales where processing is carried out by a public entity, involves large volumes of data or sensitive data or data affecting a large number of persons, or where the responsible party's principal activities involve sensitive data.observed
  2. ConfirmedSMV (mirror of MINJUSDH instrument) — Controllers must register the creation, modification and cancellation of each banco de datos personales with the Registro Nacional de Protección de Datos Personales, providing its denomination, location, purposes and uses, functioning as the principal processing-inventory mechanism in lieu of a discrete ROPA obligation.observed
  3. ConfirmedMINSA (mirror) — Controllers must adopt technical, organisational and legal measures guaranteeing the security of personal data and preventing its alteration, loss, unauthorised processing or access; processing in databases lacking such conditions is prohibited.observed
  4. ConfirmedIAPP — The 2024 Reglamento adds obligations to maintain a documented, dated security policy (Art. 47) and to implement access controls to secure areas (Art. 49) and equipment (Art. 50) inside and outside the controller's premises.observed
  5. ConfirmedIAPP — Article 34 of the 2024 Reglamento requires the controller to notify ANPD, at most within 48 hours of becoming aware of a security incident, and to notify the affected data subject within the same period in clear language, unless the incident caused no harm and was fully resolved internally.observed

#

Transfer mechanism (adequacy-or-SCC) is clear and current; adequacy status (received/granted) and localisation posture rely on absence-of-evidence inference rather than a directly confirmed negative source.

Primary frameworkLey N° 29733 Art. 15; Reglamento (DS 016-2024-JUS) Arts. 18-20
Traffic-light rationale — AmberTransfer mechanism (adequacy-or-SCC) is clear and current; adequacy status (received/granted) and localisation posture rely on absence-of-evidence inference rather than a directly confirmed negative source.

Sub-modules (6)

Transfer MechanismsGreen

Transfers are acceptable where the receiving country has an adequate protection level as evaluated by ANPD, or under agreements with common and general protection standards; otherwise the exporter must use model contractual clauses or equivalent instruments.

Claims (1):

  • Cross-border transfer of personal data from Peru is acceptable if the receiving country has an adequate protection level as evaluated by the competent authority, or if agreements exist establishing common and general protection standards; failing that, the exporter must guarantee adequate treatment via model contractual clauses or other legal instruments reflecting equivalent obligations, such as a code of conduct.

Adequacy ReceivedRed

No evidence was found in the sources reviewed that Peru has been granted an adequacy decision by the European Commission or another comparable third-country regime.

Claims (1):

  • No source reviewed indicates that Peru has been the subject of a European Commission adequacy decision under Article 45 GDPR; recent EU adequacy activity identified in the review period concerned Brazil, not Peru.

Adequacy GrantedRed

No published ANPD list of countries formally recognised as offering an adequate level of protection was located; ANPD appears to assess adequacy case-by-case rather than via a standing list.

Sccs And BcrsGreen

ANPD approved an Implementation Guide for Model Contractual Clauses for international data transfer in 2023, based on the Red Iberoamericana de Protección de Datos (RIPD) model clauses.

Claims (1):

  • ANPD approved a 'Guía de Implementación de Cláusulas Contractuales Modelo para la Transferencia Internacional de Datos Personales', based on the model published by the Red Iberoamericana de Protección de Datos (RIPD), to support compliant cross-border transfers.

Transfer Impact AssessmentAmber

No standalone, GDPR-style transfer-impact-assessment obligation distinct from the general 'burden of proof rests with the exporter' rule was identified in the sources reviewed.

Claims (1):

  • Under the Reglamento, the burden of proving that a cross-border transfer complied with the Law and Reglamento rests, in every case, on the exporter of the data (emisor), functioning as a de facto documentation obligation rather than a formal transfer-impact-assessment procedure.

Data LocalisationRed

No general data-localisation mandate (partial or absolute) was identified in the statute or the 2024 Reglamento within the sources reviewed.

Category narrative111 words

Cross-border transfer of personal data ('flujo transfronterizo') is permitted where the recipient country offers an adequate protection level as assessed by ANPD, or where agreements establishing common protection standards exist; absent either, the exporter must rely on model contractual clauses or equivalent legal instruments (including codes of conduct). ANPD approved an implementation guide for model contractual clauses in 2023, aligned with the Red Iberoamericana de Protección de Datos (RIPD) model. No evidence was found that Peru has received a European Commission adequacy decision, nor that Peru has issued a published list of countries it recognises as adequate; ANPD instead appears to make case-by-case adequacy assessments. No general data-localisation mandate was identified.

Sources and claims (4)
  1. ConfirmedIAPP — Cross-border transfer of personal data from Peru is acceptable if the receiving country has an adequate protection level as evaluated by the competent authority, or if agreements exist establishing common and general protection standards; failing that, the exporter must guarantee adequate treatment via model contractual clauses or other legal instruments reflecting equivalent obligations, such as a code of conduct.observed
  2. UncertainEUR-Lex — No source reviewed indicates that Peru has been the subject of a European Commission adequacy decision under Article 45 GDPR; recent EU adequacy activity identified in the review period concerned Brazil, not Peru.observed
  3. ConfirmedMINJUSDH — ANPD approved a 'Guía de Implementación de Cláusulas Contractuales Modelo para la Transferencia Internacional de Datos Personales', based on the model published by the Red Iberoamericana de Protección de Datos (RIPD), to support compliant cross-border transfers.observed
  4. ProbableSMV (mirror of MINJUSDH instrument) — Under the Reglamento, the burden of proving that a cross-border transfer complied with the Law and Reglamento rests, in every case, on the exporter of the data (emisor), functioning as a de facto documentation obligation rather than a formal transfer-impact-assessment procedure.observed

#

Financial and health overlays are well evidenced with recent enforcement; employment, education and insurance sub-modules rely on absent_field_provenance.

Primary frameworkLey N° 27489 (CEPIRS); Ley N° 26842 (Ley General de Salud); Ley N° 30024 (Historias Clínicas Electrónicas); Ley N° 29733 Reglamento Art. 26 (telemarketing)
Traffic-light rationale — AmberFinancial and health overlays are well evidenced with recent enforcement; employment, education and insurance sub-modules rely on absent_field_provenance.

Sub-modules (7)

Financial Sector OverlayAmber

Ley 27489 regulates CEPIRS credit-bureau data sharing; SBS holds prudential competence and INDECOPI exercises complementary consumer-protection jurisdiction over credit reporting, while ANPD separately sanctions financial entities for unlawful personal-data collection/use, including biometric data misuse.

Claims (2):

  • Ley N° 27489 regulates the supply of credit-risk information in the market by Centrales Privadas de Información de Riesgos (CEPIRS), promoting veracity, confidentiality and appropriate use of such information while protecting the rights of data subjects.
  • ANPD sanctioned Alfin Banco S.A. with fines of 139.32 UIT (approximately S/669,000) for unlawfully using personal data obtained from a private risk-information central without demonstrating the lawful origin of the collection.

Health Sector OverlayGreen

Ley 26842 and Ley 30024 protect the confidentiality of clinical/health records, guarantee patient access to their historia clínica, and designate MINSA as titular of the national electronic clinical-history database, operating alongside Ley 29733's sensitive-data rules for health information.

Claims (2):

  • Ley N° 26842 (Ley General de Salud) guarantees the patient's right to reserve/confidentiality of their historia clínica, subject only to statutory exceptions, and obliges health establishments to provide the patient or their legal representative a copy of the clinical history on request.
  • Ley N° 30024 creates the Registro Nacional de Historias Clínicas Electrónicas, granting patients or their legal representatives unrestricted access to their clinical information and designating the Ministerio de Salud as titular of the national database.

Telecoms And EprivacyAmber

The 2024 Reglamento permits a single call to solicit consent for commercial prospecting; INDECOPI provides consumer guidance distinguishing lawful consented contact from unlawful 'spam' calls.

Claims (1):

  • Under Article 26 of the 2024 Reglamento, companies may make a single call to request the citizen's consent for advertising/commercial-prospecting purposes, provided the contact data were obtained from a lawful source.

Employment DataRed

No dedicated employment-sector data-protection overlay distinct from the general LPDP regime was identified in the sources reviewed.

Credit And ScoringAmber

Credit-scoring data flows through CEPIRS are governed by Ley 27489, with the Tribunal Constitucional confirming that credit-history dissemination for risk purposes does not require the data subject's consent given its constitutionally legitimate market function, and 2025-2026 legislative activity requiring financial entities and risk centrals to update credit information promptly.

Claims (1):

  • The Tribunal Constitucional has held that CEPIRS dissemination of credit-history data serves a constitutionally legitimate market function and therefore does not require the data subject's consent, while remaining limited to credit-related data.

EducationAmber

No dedicated education-sector data-protection overlay was identified in the sources reviewed beyond a documented ANPD sanction against an educational entity for using illicitly sourced criminal-background data.

Claims (1):

  • ANPD sanctioned a consultancy firm and a higher-education entity for a very serious infraction consisting of collecting personal data (criminal/police background) through fraudulent, disloyal or unlawful means, carrying fines from 50 to 100 UIT.

InsuranceRed

No dedicated insurance-sector data-protection overlay distinct from the general LPDP regime was identified in the sources reviewed.

Category narrative117 words

Financial-sector personal data used for credit-risk purposes is separately regulated by Ley N° 27489 governing Centrales Privadas de Información de Riesgos (CEPIRS/credit bureaus), with SBS retaining prudential competence and INDECOPI exercising complementary/subsidiary consumer-protection oversight, while ANPD retains jurisdiction over unlawful personal-data use by financial entities (demonstrated by enforcement against Alfin Banco and BCP/BanBif). Health data is governed by Ley N° 26842 (Ley General de Salud) and Ley N° 30024 (Registro Nacional de Historias Clínicas Electrónicas), guaranteeing confidentiality of clinical records subject to patient access rights. Telecom-sector direct-marketing calls are addressed via the 2024 Reglamento's consent-for-first-contact rule and INDECOPI consumer guidance on 'spam' calls. No dedicated employment-data, education-sector, or insurance-sector data-protection overlay was identified in the sources reviewed.

Sources and claims (7)
  1. ConfirmedCongreso de la República — Ley N° 27489 regulates the supply of credit-risk information in the market by Centrales Privadas de Información de Riesgos (CEPIRS), promoting veracity, confidentiality and appropriate use of such information while protecting the rights of data subjects.observed
  2. ConfirmedMINJUSDH — ANPD sanctioned Alfin Banco S.A. with fines of 139.32 UIT (approximately S/669,000) for unlawfully using personal data obtained from a private risk-information central without demonstrating the lawful origin of the collection.observed
  3. ConfirmedEsSalud (mirror) — Ley N° 26842 (Ley General de Salud) guarantees the patient's right to reserve/confidentiality of their historia clínica, subject only to statutory exceptions, and obliges health establishments to provide the patient or their legal representative a copy of the clinical history on request.observed
  4. ConfirmedCongreso de la República — Ley N° 30024 creates the Registro Nacional de Historias Clínicas Electrónicas, granting patients or their legal representatives unrestricted access to their clinical information and designating the Ministerio de Salud as titular of the national database.observed
  5. ConfirmedMINJUSDH — Under Article 26 of the 2024 Reglamento, companies may make a single call to request the citizen's consent for advertising/commercial-prospecting purposes, provided the contact data were obtained from a lawful source.observed
  6. ProbableSBS — The Tribunal Constitucional has held that CEPIRS dissemination of credit-history data serves a constitutionally legitimate market function and therefore does not require the data subject's consent, while remaining limited to credit-related data.observed
  7. ConfirmedMINJUSDH — ANPD sanctioned a consultancy firm and a higher-education entity for a very serious infraction consisting of collecting personal data (criminal/police background) through fraudulent, disloyal or unlawful means, carrying fines from 50 to 100 UIT.observed

#

Direct-marketing consent rules are current and well evidenced; cookie/dark-pattern/opt-out-signal/clean-room sub-modules carry absent_field_provenance.

Primary frameworkReglamento (DS 016-2024-JUS) Art. 26; Ley N° 29733 Art. 39 (infractions)
Traffic-light rationale — AmberDirect-marketing consent rules are current and well evidenced; cookie/dark-pattern/opt-out-signal/clean-room sub-modules carry absent_field_provenance.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker-consent regime distinct from the general LPDP consent framework was identified in the sources reviewed.

Dark PatternsRed

No explicit statutory dark-pattern prohibition was identified in the sources reviewed.

Opt Out SignalsRed

No recognition of technical opt-out signals (e.g. Global Privacy Control, DAA AdChoices) was identified in the sources reviewed.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rules were identified in the sources reviewed.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept was identified; Peru's regime instead relies on the general consent/lawful-basis framework for any onward disclosure.

Direct MarketingGreen

Commercial prospecting/marketing processing requires direct consent obtained at first contact; using illicitly sourced data for such contact, or contacting without consent, are separately graded infractions.

Claims (2):

  • Processing personal data for commercial prospecting/advertising purposes is only permitted if the data subject has given direct consent at first contact, and the controller must be able to inform the data subject, on request, of the source from which the data were collected.
  • Under the 2024 Reglamento, using data of illicit origin for marketing purposes is sanctioned with fines ranging from 50 to 100 UIT, while processing data for commercial prospecting without requesting prior consent is sanctioned with a fine ranging from 5 to 50 UIT.
Category narrative69 words

Direct-marketing/commercial-prospecting processing requires the data subject's direct, first-contact consent under the 2024 Reglamento, with fines from 5-50 UIT for marketing without consent and 50-100 UIT where the underlying data derive from an unlawful source. No cookie-specific consent regime, dark-pattern prohibition, recognised opt-out signal (e.g. Global Privacy Control), or clean-room/data-collaboration framework was identified in the sources reviewed; these sub-modules are treated as evidentiary gaps rather than confirmed absences of law.

Sources and claims (2)
  1. ConfirmedIAPP — Processing personal data for commercial prospecting/advertising purposes is only permitted if the data subject has given direct consent at first contact, and the controller must be able to inform the data subject, on request, of the source from which the data were collected.observed
  2. ConfirmedMINJUSDH — Under the 2024 Reglamento, using data of illicit origin for marketing purposes is sanctioned with fines ranging from 50 to 100 UIT, while processing data for commercial prospecting without requesting prior consent is sanctioned with a fine ranging from 5 to 50 UIT.observed

#

Biometric-data enforcement is strongly evidenced and current; ADM-transparency, AI-risk-assessment and genetic-data sub-modules rely on absent_field_provenance.

Primary frameworkLey N° 29733 Art. 2(5)(sensitive data definitions); Reglamento (DS 016-2024-JUS)
Traffic-light rationale — AmberBiometric-data enforcement is strongly evidenced and current; ADM-transparency, AI-risk-assessment and genetic-data sub-modules rely on absent_field_provenance.

Sub-modules (6)

Profiling RestrictionsAmber

No Article-22-style dedicated profiling restriction distinct from the general opposition right and sensitive-data consent rules was identified in the sources reviewed.

Automated Decision Making TransparencyRed

No dedicated automated-decision-making transparency/explanation right distinct from the general access right was identified in the sources reviewed.

Ai Risk AssessmentsRed

Peru has no standalone AI-risk-assessment statute; the 2024 Reglamento's explanatory materials reference AI and profiling as drivers for regulatory modernisation, but no discrete AI-risk-assessment obligation was located.

Claims (1):

  • MINJUSDH's stated rationale for the new draft Reglamento explicitly cited the need to address challenges posed by digital technologies, e-commerce, artificial intelligence and personal-data profiling, though the resulting text does not create a discrete AI-specific risk-assessment procedure.

Biometric RegimeGreen

Biometric data capable of identifying the data subject is classified as sensitive data requiring express consent and enhanced security measures; ANPD has actively enforced against unauthorised fingerprint collection/storage by financial institutions.

Claims (2):

  • Biometric data that by itself can identify the data subject is classified as sensitive personal data under Peruvian law, requiring express consent and enhanced security safeguards.
  • In January 2026, ANPD fined Banco de Crédito del Perú (24.75 UIT plus 4.89 UIT), ALFIN Banco (66 UIT plus 13.50 UIT) and BanBif (7.5 UIT), totalling up to S/577,368, for collecting, storing and using fingerprint biometric data without adequate consent, disclosure or security measures.

Genetic DataAmber

No genetic-data-specific regime distinct from the general sensitive-data category was identified in the sources reviewed.

State Surveillance CarveoutsAmber

Cross-border data flows for international intelligence cooperation against terrorism, drug trafficking, money laundering, corruption, human trafficking and other organised crime are exempted from the standard adequacy/consent transfer conditions.

Claims (1):

  • Cross-border data flows undertaken for international intelligence-agency cooperation to combat terrorism, illicit drug trafficking, money laundering, corruption, human trafficking and other forms of organised crime are exempted from the ordinary cross-border transfer conditions.
Category narrative103 words

Biometric identifiers are treated as sensitive data requiring express consent and heightened security measures; ANPD's most significant recent enforcement action (January 2026) fined three major banks (BCP, ALFIN, BanBif) for collecting and storing fingerprint/biometric minutiae beyond disclosed purposes and without adequate security or privacy-notice practices. Peru has no standalone AI-specific statute; the 2024 Reglamento's drafting process was explicitly framed as responding to challenges from AI and profiling, but no dedicated AI-risk-assessment obligation, Article-22-style automated-decision-making transparency right, or genetic-data-specific regime distinct from the general sensitive-data rules was identified. National-security/intelligence carve-outs exist for cross-border data cooperation against terrorism, drug trafficking, money laundering and organised crime.

Sources and claims (4)
  1. ConfirmedSMV (mirror of MINJUSDH instrument) — Biometric data that by itself can identify the data subject is classified as sensitive personal data under Peruvian law, requiring express consent and enhanced security safeguards.observed
  2. ConfirmedMINJUSDH — In January 2026, ANPD fined Banco de Crédito del Perú (24.75 UIT plus 4.89 UIT), ALFIN Banco (66 UIT plus 13.50 UIT) and BanBif (7.5 UIT), totalling up to S/577,368, for collecting, storing and using fingerprint biometric data without adequate consent, disclosure or security measures.observed
  3. ConfirmedOsinergmin (mirror) — Cross-border data flows undertaken for international intelligence-agency cooperation to combat terrorism, illicit drug trafficking, money laundering, corruption, human trafficking and other forms of organised crime are exempted from the ordinary cross-border transfer conditions.observed
  4. UncertainPlataforma del Estado Peruano (gob.pe) — MINJUSDH's stated rationale for the new draft Reglamento explicitly cited the need to address challenges posed by digital technologies, e-commerce, artificial intelligence and personal-data profiling, though the resulting text does not create a discrete AI-specific risk-assessment procedure.observed

#

Age-of-consent and parental-consent rules are clearly defined and current in the 2024 Reglamento; education-setting and dependent-adult sub-modules are thin/absent.

Primary frameworkReglamento (DS 016-2024-JUS) Arts. 22, 23, 25, 27, 28
Traffic-light rationale — GreenAge-of-consent and parental-consent rules are clearly defined and current in the 2024 Reglamento; education-setting and dependent-adult sub-modules are thin/absent.

Sub-modules (5)

Age VerificationAmber

For online consent-taking, controllers must make reasonable efforts, given available technology, to verify the identity of the person granting consent.

Claims (1):

  • For internet-based processing of minors' data, controllers must make reasonable efforts, taking into account available technology, to verify the identity of the person granting consent.

Minor Profiling BansGreen

Minor self-consent is never valid for goods or services subject to age restrictions, and collecting data revealing a minor's family-group circumstances without parental consent is prohibited.

Claims (2):

  • In no case is a minor's own consent valid for the processing of data relating to goods or services that are age-restricted.
  • It is prohibited to collect personal data of minors that reveals information about their family group without the consent of the holders of patria potestad or tutela.

Education SettingsRed

No education-setting-specific data-protection sub-regime distinct from the general LPDP framework and the isolated ANPD enforcement action against an educational entity (noted under sectoral_watch) was identified in the sources reviewed.

Dependent AdultsRed

No dependent-adult-specific (elderly, mentally incapacitated) data-protection sub-regime was identified in the sources reviewed.

Category narrative96 words

Processing of minors' data generally requires parental/guardian (patria potestad/tutela) consent; minors between 14 and 18 years may consent directly provided information is given in comprehensible language, except for goods/services subject to age restrictions, where minor consent is never valid. Collecting data revealing a minor's family-group information without parental consent is prohibited, and reasonable identity-verification efforts are required for online consent. A pending legislative bill (approved at committee stage, November 2025) would create a broader online child-protection framework addressing cyberbullying, sextortion and digital wellbeing; it is not yet enacted. No education-setting-specific or dependent-adult-specific data-protection sub-regime was identified.

Sources and claims (5)
  1. ConfirmedIAPP — For internet-based processing of minors' data, controllers must make reasonable efforts, taking into account available technology, to verify the identity of the person granting consent.observed
  2. ConfirmedSMV (mirror of MINJUSDH instrument) — Processing of a minor's personal data generally requires the consent of the holders of patria potestad or tutela, as applicable.observed
  3. ConfirmedSMV (mirror of MINJUSDH instrument) — Minors older than 14 and younger than 18 may consent directly to processing of their personal data provided the information was expressed in language comprehensible to them, subject to statutory exceptions.observed
  4. ConfirmedIAPP — In no case is a minor's own consent valid for the processing of data relating to goods or services that are age-restricted.observed
  5. ConfirmedIAPP — It is prohibited to collect personal data of minors that reveals information about their family group without the consent of the holders of patria potestad or tutela.observed

#

Sanctioning framework and recent enforcement activity are strongly evidenced and current; collective-redress/class-action mechanisms specific to data protection are thin/absent.

Primary frameworkLey N° 29733 Arts. 38-40; Reglamento (DS 016-2024-JUS) Arts. 125, 132-134
Traffic-light rationale — GreenSanctioning framework and recent enforcement activity are strongly evidenced and current; collective-redress/class-action mechanisms specific to data protection are thin/absent.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

ANPD exercises administrative, oversight and sanctioning functions and can classify infractions as leve, grave or muy grave, with fines from 0.5 UIT up to 100 UIT depending on gravity, plus coercive fines up to 10 UIT.

Claims (3):

  • Infractions under Ley 29733 and its Reglamento are classified as leve, grave or muy grave, each carrying escalating fines.
  • Leve infractions carry a minimum fine of 0.5 UIT up to 5 UIT.
  • ANPD may impose coercive fines of up to 10 UIT for non-compliance with accessory obligations imposed in a sanctioning procedure, in addition to the principal fine.

Enforcement Activity IndexGreen

Enforcement activity has been visible and escalating, including the 2025 Alfin Banco sanction and the January 2026 multi-bank biometric-data sanctions.

Claims (2):

  • ANPD imposed fines totalling 139.32 UIT (approximately S/669,000) on Alfin Banco S.A. for unlawfully using personal data obtained from a private risk-information central, confirmed on appeal in one instance.
  • In January 2026, ANPD imposed combined fines of up to S/577,368 on Banco de Crédito del Perú, ALFIN Banco and BanBif for unlawful collection, storage and use of biometric fingerprint data.

Regulator Funding And CapacityAmber

Historical ANPD activity data (e.g. 128 sanctioning procedures initiated and 2,808 data banks registered in a prior reporting period) indicate an operationally active but resource-constrained regulator; no current staffing/budget figures were located.

Claims (1):

  • In a prior annual reporting period, ANPD initiated 128 sanctioning procedures, delivered informational talks to more than 10,000 people, and registered 2,808 personal-data banks.

Collective Redress And Class ActionsRed

No dedicated class-action or collective-redress mechanism specific to data-protection claims was identified in the sources reviewed; the trilateral ARCO procedure before ANPD functions as an individual, not collective, remedy.

Private Right Of ActionGreen

Data subjects harmed by non-compliance with the Law have a statutory right to obtain indemnification, in accordance with general civil-liability law, independent of any administrative sanction.

Claims (1):

  • A data subject affected by a controller's, processor's or third party's non-compliance with Ley 29733 has the right to obtain corresponding indemnification in accordance with law.

Recent Developments 180DAmber

Within the review window, ANPD published its 2018-2025 management-balance bulletin (late January 2026) and posted further institutional news (23 February 2026); the January 2026 biometric-data sanctions against major banks, while falling just outside a strict 180-day look-back from the 7 August 2026 run date, represent the most recent substantive enforcement action identified and are included here as the closest available recent-developments signal.

Claims (1):

  • ANPD published a '2018-2025 Management Balance' institutional bulletin in late January 2026 and posted additional institutional news on 23 February 2026, reflecting continued regulatory activity within the recent-developments window.
Category narrative113 words

ANPD's sanctioning powers are graded into leve (0.5-5 UIT), grave and muy grave (up to 50-100 UIT for the most serious infractions, e.g. unlawful-source data collection or mishandling sensitive data) infractions, plus coercive fines up to 10 UIT for non-compliance with accessory obligations. Enforcement has intensified through 2025-2026, exemplified by the Alfin Banco sanction (139.32 UIT) and the January 2026 biometric-data sanctions against BCP, ALFIN and BanBif (up to S/577,368 combined). Data subjects have a statutory right to indemnification for harm caused by non-compliance, and can escalate unresolved ARCO disputes to ANPD via a trilateral administrative procedure with published first- and second-instance resolutions; no dedicated class-action mechanism specific to data protection was identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

ANPD's sanctioning regime rests on a three-tiered infraction and fine structure denominated in Unidades Impositivas Tributarias, with total fines capped at 10% of the offending entity's prior-year net revenue. The UIT value for 2026 is set at S/5,500 under Decreto Supremo No. 301-2025-EF, providing the monetary basis against which the tiered fine bands are calculated for infractions occurring this year.

Reporting attributes continued active enforcement to ANPD, including a fine against Magic Dynasty International Club S.A.C. of PEN 194,350 for improper data processing and lack of transparency, and a fine against Alfin Banco of PEN 669,000 for unlawful marketing and data acquisition without consent. The same reporting states that in 2023 alone ANPD issued more than S/2.7 million in fines and resolved 272 complaints. These figures are drawn from aggregator reporting rather than confirmed directly against ANPD's own resolution numbers or exact dates this cycle, and should be read with that caveat, though the overall pattern is consistent with an actively enforcing regulator rather than a dormant one.

Outlook

Independent confirmation of the exact dates and resolution numbers behind the Magic Dynasty and Alfin Banco fines, along with any more recent 2026 enforcement actions, would sharpen the picture of ANPD's current enforcement tempo. The outcome of ANPD's public consultation on its draft fine-calculation methodology, which closed for comment on 21 October 2025, was not located this cycle and remains an open item.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ConfirmedOsinergmin (mirror) — Infractions under Ley 29733 and its Reglamento are classified as leve, grave or muy grave, each carrying escalating fines.observed
  2. ConfirmedMINSA (mirror) — Leve infractions carry a minimum fine of 0.5 UIT up to 5 UIT.observed
  3. ConfirmedMINSA (mirror) — ANPD may impose coercive fines of up to 10 UIT for non-compliance with accessory obligations imposed in a sanctioning procedure, in addition to the principal fine.observed
  4. ConfirmedMINJUSDH — ANPD imposed fines totalling 139.32 UIT (approximately S/669,000) on Alfin Banco S.A. for unlawfully using personal data obtained from a private risk-information central, confirmed on appeal in one instance.observed
  5. ConfirmedMINJUSDH — In January 2026, ANPD imposed combined fines of up to S/577,368 on Banco de Crédito del Perú, ALFIN Banco and BanBif for unlawful collection, storage and use of biometric fingerprint data.observed
  6. ProbablePlataforma del Estado Peruano (gob.pe) — In a prior annual reporting period, ANPD initiated 128 sanctioning procedures, delivered informational talks to more than 10,000 people, and registered 2,808 personal-data banks.observed
  7. ConfirmedOsinergmin (mirror) — A data subject affected by a controller's, processor's or third party's non-compliance with Ley 29733 has the right to obtain corresponding indemnification in accordance with law.observed
  8. UncertainPlataforma del Estado Peruano (gob.pe) — ANPD published a '2018-2025 Management Balance' institutional bulletin in late January 2026 and posted additional institutional news on 23 February 2026, reflecting continued regulatory activity within the recent-developments window.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct95.65
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Peru
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 52 claim(s) (52 category placement(s)), 36 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1-anchored coverage (statute Ley 29733, DL 1353, and the new Reglamento DS 016-2024-JUS in force since 2025-03-31) for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties (security/DPO/breach), cross_border_and_adequacy (transfer mechanism), children_and_vulnerable_groups, and enforcement_and_redress (penalty scale, recent biometric enforcement). Moderate T1/T2 coverage for sectoral_watch (financial via Ley 27489 and enforcement cases; health via Ley 26842/30024) and adtech direct-marketing rules. Thin/absent coverage (T3/T4 or no source) for: pseudonymisation/anonymisation safe-harbours, DPIA-trigger methodology, joint-controller specifics, general retention/disposal ceilings, cookie/tracker consent, dark patterns, opt-out signals (GPC/DAA), clean-room/DCR rules, cross-context-advertising 'sale/share' concepts, AI-risk-assessment procedures, ADM-transparency rights, genetic-data-specific rules, employment/education/insurance sector overlays, EU/other adequacy status (received/granted), data localisation, and collective-redress/class-action mechanisms specific to data protection. These gaps are recorded via absent_field_provenance and red/amber traffic lights rather than silent omission.

Unresolved questions (6):

  • Has ANPD published, or does it maintain, a formal list of countries recognised as offering an adequate level of protection for cross-border transfer purposes, distinct from case-by-case assessments?
  • Does Peru's DPIA-equivalent obligation exist in a more granular administrative directive not captured in the statute/Reglamento text reviewed?
  • What is the current confirmed staffing/budget level of ANPD (regulator_funding_and_capacity) beyond historical 2022-era activity statistics?
  • Has the pending congressional bill on children's online protection (approved at committee stage, November 2025) advanced to enactment as of the run date?
  • Are there ANPD resolutions or directives specifically addressing automated decision-making transparency or profiling beyond the general opposition right?
  • Does Peru's regime include any sector-specific employment-data, education-sector, or insurance-sector data-protection overlay not captured in the sources reviewed?

Escalate to primary-source review: yes