Jurisdiction Guides / Americas
Peru Privacy & Data Protection Laws
Every regime below can apply to a business handling Peru residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Peru substantially modernized its regime not by amending the 2011 Law but by replacing its implementing regulation: Supreme Decree 016-2024-JUS took effect March 30, 2025, adding data-protection officer requirements, breach-notification duties to the Autoridad Nacional de Proteccion de Datos Personales, privacy-by-design expectations, and — most relevant to foreign businesses — an expanded territorial reach extending to controllers outside Peru that use means located in Peru or direct processing activities at people in Peru. Because that extraterritorial expansion sits in a regulation interpreting a statute that itself lacks an explicit targeting clause, the triggers below are modeled generously but flagged: confirm the specific basis with Peruvian counsel before relying on either coverage or non-coverage. Database registration with the national authority remains a standing obligation.
Cross-Border Data Transfer · 1
Art. 15 permits cross-border flows only where the destination country maintains levels of protection equivalent to those the Law requires, or where a Peruvian treaty provides otherwise, with Art. 11's adequate-protection principle underpinning it. The 2024 Reglamento, which replaced the 2013 one and commenced in late March 2025, is the document that made this workable: it sets out the criteria the Autoridad Nacional de Proteccion de Datos Personales applies in assessing whether a destination offers an adequate level, and clarifies the routes available where it does not. Marked 'check': the operative texts are Spanish-language, the Reglamento is recent, and the specific safeguard instruments it recognises were not confirmed against the primary text — read the Reglamento directly before selecting a transfer mechanism.
Data Security & Breach Notification · 1
Peru had no meaningful breach-notification machinery until the 2024 Reglamento replaced the 2013 one. Since it commenced in late March 2025, a controller that detects — or has indications of — a security incident affecting personal data must notify the Autoridad Nacional de Proteccion de Datos Personales within 48 hours, and must notify affected data subjects within 48 hours of becoming aware where the incident affects their rights. Forty-eight hours is tighter than the GDPR's 72, and the trigger is deliberately early: 'indications of' an incident starts the clock, not confirmation of one. The Reglamento also extended the law's territorial reach and brought biometric data expressly within the sensitive-data category. Marked 'check': the operative texts are Spanish-language and the regime is recent enough that enforcement practice around what counts as an 'indication' is not yet settled.
Other Americas jurisdictions