WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Ley 29733, Ley de Proteccion de Datos Personales — notification of security breaches

Peru breach notification

Peru · March 30, 2025 (the 2024 Reglamento; sources differ by one day on the exact commencement)

Verify details

Peru had no meaningful breach-notification machinery until the 2024 Reglamento replaced the 2013 one. Since it commenced in late March 2025, a controller that detects — or has indications of — a security incident affecting personal data must notify the Autoridad Nacional de Proteccion de Datos Personales within 48 hours, and must notify affected data subjects within 48 hours of becoming aware where the incident affects their rights. Forty-eight hours is tighter than the GDPR's 72, and the trigger is deliberately early: 'indications of' an incident starts the clock, not confirmation of one. The Reglamento also extended the law's territorial reach and brought biometric data expressly within the sensitive-data category. Marked 'check': the operative texts are Spanish-language and the regime is recent enough that enforcement practice around what counts as an 'indication' is not yet settled.

Ley N. 29733; Reglamento approved by Decreto Supremo N. 016-2024-JUS (published November 30, 2024)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.