Argentina Personal Data Protection Law
Argentina
In force
Latin America & Caribbean
Argentina's Law 25.326 applies to individuals and organisations that operate databases, files or data banks containing personal data, including public and private databases intended to provide information. Organisations that collect or process personal information in Argentina should assess their obligations under Law 25.326, its implementing regulations and applicable guidance from the data protection authority.
The Argentine privacy framework provides for administrative sanctions for violations of Law 25.326 and its implementing rules. The applicable sanction depends on the nature and circumstances of the violation. Organisations should maintain appropriate privacy, security and data-management controls to reduce regulatory and legal risk.
These requirements derive from Law 25.326 and its implementing framework.
Consent is a central principle under Law 25.326.
The law generally requires consent to be free, express and informed, documented in writing or through another legally equivalent means appropriate to the circumstances. When consent is combined with other declarations, the consent must be expressly and prominently presented after the required information has been provided.
The law also establishes exceptions where consent is not required, including certain data obtained from unrestricted public sources, processing required by law or governmental functions, certain limited identification lists and data necessary for an existing contractual, scientific or professional relationship.
Consent may also be revoked, although revocation does not have retroactive effect.
Before collecting personal data, organisations should provide individuals with clear information about the processing activity.
The required information includes matters such as:
Argentine guidance also emphasises that information provided to individuals should be clear, simple and understandable.
Argentina's privacy framework provides individuals with important rights over their personal data.
These include:
The Argentine framework also provides for a habeas data action through which individuals can seek access to their data and, in applicable cases, rectification, suppression, confidentiality or updating.
Argentina's privacy framework can apply to cookies and online identifiers where they constitute personal data.
The Argentine government currently identifies information such as IP addresses and cookie identifiers among examples of personal data. Whether a particular cookie or tracking technology falls within the applicable requirements depends on the information collected, whether an individual can be identified and the purpose of processing.
Organisations using cookies and tracking technologies should therefore assess the data collected and provide appropriate notice and consent mechanisms where required.
Organisations responsible for databases must implement appropriate measures to protect personal data.
Law 25.326 requires databases to meet technical and organisational conditions that protect data integrity and security. It also imposes confidentiality obligations on individuals involved in the processing of personal data, with the duty continuing after their relationship with the data controller ends.
Manage consent, privacy preferences, data requests and compliance evidence across Argentina and other jurisdictions from one platform.
This page provides general information about Argentina's data protection framework and is not legal advice. Organisations should confirm their specific obligations with qualified Argentine privacy counsel.
Run a free scan to identify cookies, trackers, scripts and other technologies operating on your website. Understand what information may be collected and which third parties may receive it.
Use ConsentX to configure a privacy banner and preference centre appropriate for visitors in Argentina and the applicable processing activities.
Present relevant purposes, processing information and privacy disclosures clearly before or at the appropriate point of data collection.
Configure ConsentX to capture the appropriate consent where processing requires free, express and informed consent.
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.
Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.
Use ConsentX workflows to organise access, rectification, update and suppression requests and maintain a central record of request handling.