WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Argentina Privacy & Data Protection Laws

Every regime below can apply to a business handling Argentina residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Verify details

One of the oldest comprehensive regimes in Latin America and one of the few holding a European Commission adequacy decision (granted 2003, maintained under GDPR review). It is a registration-centric, pre-GDPR law: it applies to personal data recorded in databases located in Argentina or otherwise subject to Argentine jurisdiction, and databases must be registered with the Agencia de Acceso a la Informacion Publica (AAIP). There is no GDPR-style targeting test for a foreign controller with no Argentine database or establishment, so the trigger below is modeled on established presence only. A modernization bill closely tracking the GDPR (introducing extraterritorial scope, breach notification, DPOs, and turnover-linked fines) has been before Congress since 2023 without passage — confirm its status before treating the current law as the settled long-term position.

Ley No. 25.326 (sanctioned October 4, 2000), with Regulatory Decree 1558/2001Read regulation →

Cross-Border Data Transfer · 1

November 2, 2000 (Ley 25.326); Disposicion 60-E/2016 from November 2016
Ley 25.326 de Proteccion de los Datos Personales — international transfer of personal data
Argentina Ley 25.326 Art. 12
Verify details

Art. 12 prohibits transferring personal data to countries or international organisations that do not provide an adequate level of protection, subject to listed exceptions. The AAIP, empowered by Decree 1558/2001 to assess adequacy, published its list in Disposicion 60-E/2016 — EU and EEA member states, Switzerland, Guernsey, Jersey, the Isle of Man, the Faroe Islands, Canada (private sector only), New Zealand, Andorra, Israel and Uruguay — and approved model contractual clauses for transfers to controllers and to processors in non-adequate countries. The AAIP has since endorsed the Ibero-American Data Protection Network's standard contractual clauses and issued binding-corporate-rules guidelines, widening the toolkit. Argentina itself holds EU adequacy, which is why its own outbound regime matters to European groups routing data through Buenos Aires. Marked 'check': the operative texts are Spanish-language and the adequacy list is a regulator instrument that changes — confirm the current version rather than relying on the 2016 enumeration.

Ley N. 25.326, Art. 12; Decreto Reglamentario N. 1558/2001; AAIP Disposicion 60-E/2016Read regulation →

Other Americas jurisdictions