Personal Data Protection Law (Law 29733)
Peru
In force since 2011
The current implementing regulation, Decreto Supremo N.º 016-2024-JUS, has been in force since 31 March 2025.
Americas
Law 29733 applies to organisations and other entities that process personal data within the scope of Peru's data protection framework. This can include businesses, public-sector organisations, website operators, digital services, employers, financial institutions, healthcare organisations, and other entities that collect, use, store, disclose, or otherwise process personal data. Organisations operating outside Peru should also assess whether their processing activities fall within the territorial scope of the Peruvian framework.
Violations of Law 29733 and its implementing regulation can result in administrative sanctions. Fines are classified according to the seriousness of the infringement and can reach 100 UIT (Unidad Impositiva Tributaria) for the most serious violations. The applicable sanction depends on the specific infringement and circumstances of the case.
The current Regulation also strengthens organisations' accountability and introduces additional compliance mechanisms.
Consent is a central element of Peru's data protection framework.
Where consent is required, organisations must generally obtain it before processing begins, and the consent must be:
Consent should be distinguishable from other terms or conditions and should provide individuals with sufficient information to understand what they are agreeing to.
However, organisations should not assume that consent is required for every processing activity. Law 29733 contains circumstances in which personal data may be processed without consent.
Sensitive personal data receives enhanced protection under Peru's data protection framework.
Organisations handling sensitive information should apply the additional requirements and safeguards established by Law 29733 and its Regulation.
Privacy notices and consent mechanisms should clearly explain the relevant categories of data and the purposes for which sensitive information will be processed.
Law 29733 gives individuals rights over their personal data.
These include the ARCO rights:
Organisations should establish clear processes for receiving, authenticating, tracking, and responding to these requests.
Organisations should provide individuals with clear information about the processing of their personal data.
A privacy notice should address relevant information such as:
The current Regulation reinforces transparency and information requirements for personal data processing.
Organisations must implement appropriate security measures to protect personal data against risks such as unauthorised access, loss, alteration, disclosure, or destruction.
The 2024 Regulation strengthens the compliance and accountability framework and introduces additional mechanisms for organisations to demonstrate that appropriate data protection measures are in place.
Organisations should therefore maintain appropriate documentation, policies, procedures, technical controls, and evidence of compliance.
The current Regulation introduces requirements concerning notification of certain personal data security incidents.
The ANPD states that incidents involving personal data must be notified to the authority within 48 hours of becoming aware of the incident, where the applicable notification requirement is triggered.
Organisations should therefore maintain an incident response process capable of identifying, assessing, documenting, and escalating personal data breaches within the required timeframe.
Organisations transferring personal data outside Peru should assess the applicable requirements under Law 29733 and its Regulation.
Before transferring personal data internationally, organisations should consider:
International transfers should form part of the organisation's broader data mapping and privacy compliance programme.
Peru's data protection framework includes requirements concerning the registration of personal data databases.
Organisations should determine which databases are subject to registration and ensure that required registrations and updates are maintained.
Database registration should be considered alongside privacy notices, processing purposes, security controls, and data subject rights procedures.
Cookies, pixels, analytics tools, advertising technologies, and other online tracking technologies may involve the processing of personal data.
Organisations operating websites in Peru should therefore assess:
A consent management platform can help organisations identify trackers, communicate processing purposes, obtain consent where required, and prevent applicable technologies from running before consent.
Capture consent before applicable cookies, trackers, or processing activities are activated.
Present clear information about the purposes for which personal data and tracking technologies are used.
Scan websites to identify cookies and trackers and control the activation of applicable non-essential technologies.
Create auditable consent records containing information about users' choices and the consent event.
Support workflows for receiving and managing privacy requests, including access, rectification, cancellation, and opposition requests.
Apply jurisdiction-specific consent rules through ConsentX's region rule engine.
Scan your website → Identify trackers → Configure consent → Block applicable trackers → Record consent → Manage privacy requests. Build a more transparent and auditable privacy experience for users in Peru.
This page provides a plain-English summary of Peru's personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Peruvian legal counsel where necessary.
Scan your website to identify cookies, trackers, scripts, pixels, and other technologies that may process personal data.
Classify each technology according to its purpose, such as analytics, advertising, personalisation, functionality, or other processing.
Deploy a consent banner that provides clear information and captures the appropriate consent for processing activities where consent is required.
Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.
Store users' consent choices together with relevant contextual information to help demonstrate compliance.
Use a centralised workflow to receive and manage applicable requests relating to access, rectification, cancellation, and opposition.
Regularly rescan your website and review cookies, trackers, consent settings, privacy notices, and third-party technologies.