DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Argentina

Argentina PDPL Compliance with ConsentX

Argentina Personal Data Protection Law

Argentina's Personal Data Protection Law (PDPL), formally known as Law No. 25.326 on the Protection of Personal Data, establishes the country's framework for the collection, processing, storage, use and disclosure of personal data. The law applies to personal data contained in public or private databases and establishes principles around data quality, purpose limitation, transparency, consent, confidentiality, security and individual rights. Argentina's privacy framework requires consent to generally be free, express and informed, subject to specific legal exceptions. Individuals also have rights to access, rectify, update, suppress and seek confidentiality of their personal data.
Region

Argentina

Status

In force

Group

Latin America & Caribbean

Who must comply

Argentina's Law 25.326 applies to individuals and organisations that operate databases, files or data banks containing personal data, including public and private databases intended to provide information. Organisations that collect or process personal information in Argentina should assess their obligations under Law 25.326, its implementing regulations and applicable guidance from the data protection authority.

Penalties

The Argentine privacy framework provides for administrative sanctions for violations of Law 25.326 and its implementing rules. The applicable sanction depends on the nature and circumstances of the violation. Organisations should maintain appropriate privacy, security and data-management controls to reduce regulatory and legal risk.

Key obligations

  • Obtain free, express and informed consent where consent is required
  • Provide individuals with clear information about the collection and use of their personal data
  • Identify the purpose of the database or processing activity
  • Inform individuals about relevant recipients of their data
  • Collect data that is adequate, relevant and not excessive for the stated purpose
  • Keep personal data accurate and up to date
  • Use data only for purposes compatible with those for which it was collected
  • Delete or destroy data when it is no longer necessary or relevant
  • Maintain appropriate technical and organisational security measures
  • Maintain confidentiality of personal data
  • Respect individual rights to access, rectification, update and suppression
  • Provide appropriate mechanisms for exercising privacy rights
  • Obtain consent before transferring personal data where required
  • Allow consent to be revoked where applicable

These requirements derive from Law 25.326 and its implementing framework.

Consent requirements under Argentina PDPL

Consent is a central principle under Law 25.326.

The law generally requires consent to be free, express and informed, documented in writing or through another legally equivalent means appropriate to the circumstances. When consent is combined with other declarations, the consent must be expressly and prominently presented after the required information has been provided.

The law also establishes exceptions where consent is not required, including certain data obtained from unrestricted public sources, processing required by law or governmental functions, certain limited identification lists and data necessary for an existing contractual, scientific or professional relationship.

Consent may also be revoked, although revocation does not have retroactive effect.

Privacy notice and transparency

Before collecting personal data, organisations should provide individuals with clear information about the processing activity.

The required information includes matters such as:

  • The existence of the database or file
  • The identity and contact details of the responsible party
  • The purpose of the collection
  • The intended recipients or categories of recipients
  • Whether providing the requested information is mandatory or optional where applicable
  • The individual's rights under the applicable privacy framework

Argentine guidance also emphasises that information provided to individuals should be clear, simple and understandable.

Data subject rights

Argentina's privacy framework provides individuals with important rights over their personal data.

These include:

  • Access - obtain information about personal data held and processed
  • Rectification - correct inaccurate or incomplete information
  • Update - ensure personal data remains accurate and current
  • Suppression - request deletion where the applicable requirements are met
  • Confidentiality - request appropriate protection of personal information in applicable circumstances

The Argentine framework also provides for a habeas data action through which individuals can seek access to their data and, in applicable cases, rectification, suppression, confidentiality or updating.

Cookies and online tracking

Argentina's privacy framework can apply to cookies and online identifiers where they constitute personal data.

The Argentine government currently identifies information such as IP addresses and cookie identifiers among examples of personal data. Whether a particular cookie or tracking technology falls within the applicable requirements depends on the information collected, whether an individual can be identified and the purpose of processing.

Organisations using cookies and tracking technologies should therefore assess the data collected and provide appropriate notice and consent mechanisms where required.

Security and confidentiality

Organisations responsible for databases must implement appropriate measures to protect personal data.

Law 25.326 requires databases to meet technical and organisational conditions that protect data integrity and security. It also imposes confidentiality obligations on individuals involved in the processing of personal data, with the duty continuing after their relationship with the data controller ends.

How ConsentX helps

Express consent capture for processing activities where consent is required

Clear purpose and recipient disclosures within the consent experience

Customisable privacy banners for Argentina

Consent and preference receipts to maintain evidence of user choices

Prior-script blocking to help control selected non-essential tracking technologies

Region Rule Engine to configure Argentina-specific privacy experiences

DSAR workflows to help manage access, rectification and suppression requests

Consent withdrawal mechanisms to help manage changing user preferences

Audit-ready records for consent and privacy interactions

Multi-jurisdictional controls for organisations operating across Argentina and other markets

Get Argentina PDPL ready with ConsentX

Manage consent, privacy preferences, data requests and compliance evidence across Argentina and other jurisdictions from one platform.

This page provides general information about Argentina's data protection framework and is not legal advice. Organisations should confirm their specific obligations with qualified Argentine privacy counsel.

How to comply with Argentina PDPL using ConsentX

  1. 1

    Scan your website

    Run a free scan to identify cookies, trackers, scripts and other technologies operating on your website. Understand what information may be collected and which third parties may receive it.

  2. 2

    Configure an Argentina-specific privacy experience

    Use ConsentX to configure a privacy banner and preference centre appropriate for visitors in Argentina and the applicable processing activities.

  3. 3

    Provide clear privacy information

    Present relevant purposes, processing information and privacy disclosures clearly before or at the appropriate point of data collection.

  4. 4

    Capture consent

    Configure ConsentX to capture the appropriate consent where processing requires free, express and informed consent.

  5. 5

    Block selected trackers

    Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.

  6. 6

    Record consent and preferences

    Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.

  7. 7

    Manage privacy requests

    Use ConsentX workflows to organise access, rectification, update and suppression requests and maintain a central record of request handling.

Domande frequenti