DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Peru

Peru Law 29733 Compliance with ConsentX

Personal Data Protection Law (Law 29733)

Peru's Personal Data Protection Law, Law No. 29733, establishes the legal framework for protecting and processing personal data in Peru. The law is supported by its current implementing regulation, Decreto Supremo N.º 016-2024-JUS, which replaced the previous 2013 regulation and entered into force on 31 March 2025. Peru's data protection framework requires organisations to process personal data in accordance with principles including legality, consent, purpose limitation, proportionality, security, and transparency. Where consent is the applicable legal basis, it must generally be free, prior, express, unequivocal, and informed. The law also establishes rights for individuals, security obligations, database registration requirements, rules for international data transfers, and enforcement powers for the Peruvian data protection authority.
Region

Peru

Status

In force since 2011

The current implementing regulation, Decreto Supremo N.º 016-2024-JUS, has been in force since 31 March 2025.

Group

Americas

Who must comply with Law 29733?

Law 29733 applies to organisations and other entities that process personal data within the scope of Peru's data protection framework. This can include businesses, public-sector organisations, website operators, digital services, employers, financial institutions, healthcare organisations, and other entities that collect, use, store, disclose, or otherwise process personal data. Organisations operating outside Peru should also assess whether their processing activities fall within the territorial scope of the Peruvian framework.

Penalties under Law 29733

Violations of Law 29733 and its implementing regulation can result in administrative sanctions. Fines are classified according to the seriousness of the infringement and can reach 100 UIT (Unidad Impositiva Tributaria) for the most serious violations. The applicable sanction depends on the specific infringement and circumstances of the case.

Key obligations under Law 29733

  • Obtain valid consent where consent is the applicable legal basis.
  • Ensure consent is free, prior, express, unequivocal, and informed.
  • Clearly communicate the purpose of data processing.
  • Provide appropriate privacy information to individuals.
  • Respect data subject rights.
  • Implement appropriate technical and organisational security measures.
  • Register personal data databases where registration is required.
  • Establish procedures for handling data subject requests.
  • Assess requirements for international transfers and disclosures.
  • Maintain appropriate evidence demonstrating compliance.

The current Regulation also strengthens organisations' accountability and introduces additional compliance mechanisms.

Consent requirements

Consent is a central element of Peru's data protection framework.

Where consent is required, organisations must generally obtain it before processing begins, and the consent must be:

  • Free
  • Prior
  • Express
  • Unequivocal
  • Informed

Consent should be distinguishable from other terms or conditions and should provide individuals with sufficient information to understand what they are agreeing to.

However, organisations should not assume that consent is required for every processing activity. Law 29733 contains circumstances in which personal data may be processed without consent.

Sensitive personal data

Sensitive personal data receives enhanced protection under Peru's data protection framework.

Organisations handling sensitive information should apply the additional requirements and safeguards established by Law 29733 and its Regulation.

Privacy notices and consent mechanisms should clearly explain the relevant categories of data and the purposes for which sensitive information will be processed.

Data subject rights

Law 29733 gives individuals rights over their personal data.

These include the ARCO rights:

  • Access - individuals can request information about their personal data and relevant processing activities.
  • Rectification - individuals can request correction of inaccurate, incomplete, or outdated personal data.
  • Cancellation - individuals can request the deletion or cancellation of their personal data where the applicable legal requirements are satisfied.
  • Opposition - individuals can object to certain processing of their personal data when the applicable requirements for opposition are met.

Organisations should establish clear processes for receiving, authenticating, tracking, and responding to these requests.

Privacy notices and transparency

Organisations should provide individuals with clear information about the processing of their personal data.

A privacy notice should address relevant information such as:

  • Categories of personal data collected
  • Purposes of processing
  • How personal data is used
  • Relevant recipients
  • International transfers, where applicable
  • Data subject rights
  • How individuals can exercise their rights
  • Other information required under the applicable framework

The current Regulation reinforces transparency and information requirements for personal data processing.

Security and accountability

Organisations must implement appropriate security measures to protect personal data against risks such as unauthorised access, loss, alteration, disclosure, or destruction.

The 2024 Regulation strengthens the compliance and accountability framework and introduces additional mechanisms for organisations to demonstrate that appropriate data protection measures are in place.

Organisations should therefore maintain appropriate documentation, policies, procedures, technical controls, and evidence of compliance.

Data security incidents

The current Regulation introduces requirements concerning notification of certain personal data security incidents.

The ANPD states that incidents involving personal data must be notified to the authority within 48 hours of becoming aware of the incident, where the applicable notification requirement is triggered.

Organisations should therefore maintain an incident response process capable of identifying, assessing, documenting, and escalating personal data breaches within the required timeframe.

International data transfers

Organisations transferring personal data outside Peru should assess the applicable requirements under Law 29733 and its Regulation.

Before transferring personal data internationally, organisations should consider:

  • The destination country
  • The recipient
  • The purpose of the transfer
  • Applicable safeguards
  • The legal basis for the transfer
  • Contractual requirements
  • Any applicable notification or authorisation requirements

International transfers should form part of the organisation's broader data mapping and privacy compliance programme.

Personal data database registration

Peru's data protection framework includes requirements concerning the registration of personal data databases.

Organisations should determine which databases are subject to registration and ensure that required registrations and updates are maintained.

Database registration should be considered alongside privacy notices, processing purposes, security controls, and data subject rights procedures.

Cookies and online tracking

Cookies, pixels, analytics tools, advertising technologies, and other online tracking technologies may involve the processing of personal data.

Organisations operating websites in Peru should therefore assess:

  • What cookies and trackers are deployed
  • What information they collect
  • Whether they process personal data
  • The purpose of each technology
  • Whether consent is required
  • Whether data is transferred to third parties
  • Whether information is transferred internationally

A consent management platform can help organisations identify trackers, communicate processing purposes, obtain consent where required, and prevent applicable technologies from running before consent.

How ConsentX helps with Law 29733 compliance

Prior and express consent capture

Capture consent before applicable cookies, trackers, or processing activities are activated.

Purpose-based consent

Present clear information about the purposes for which personal data and tracking technologies are used.

Cookie and tracker management

Scan websites to identify cookies and trackers and control the activation of applicable non-essential technologies.

Consent records

Create auditable consent records containing information about users' choices and the consent event.

Data subject request management

Support workflows for receiving and managing privacy requests, including access, rectification, cancellation, and opposition requests.

Regional compliance

Apply jurisdiction-specific consent rules through ConsentX's region rule engine.

Get Law 29733 ready with ConsentX

Scan your website → Identify trackers → Configure consent → Block applicable trackers → Record consent → Manage privacy requests. Build a more transparent and auditable privacy experience for users in Peru.

This page provides a plain-English summary of Peru's personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Peruvian legal counsel where necessary.

How to comply with Law 29733 using ConsentX

  1. 1

    Scan your website

    Scan your website to identify cookies, trackers, scripts, pixels, and other technologies that may process personal data.

  2. 2

    Identify processing purposes

    Classify each technology according to its purpose, such as analytics, advertising, personalisation, functionality, or other processing.

  3. 3

    Configure a Peru-ready consent banner

    Deploy a consent banner that provides clear information and captures the appropriate consent for processing activities where consent is required.

  4. 4

    Block applicable trackers before consent

    Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.

  5. 5

    Record consent evidence

    Store users' consent choices together with relevant contextual information to help demonstrate compliance.

  6. 6

    Manage data subject requests

    Use a centralised workflow to receive and manage applicable requests relating to access, rectification, cancellation, and opposition.

  7. 7

    Monitor your compliance posture

    Regularly rescan your website and review cookies, trackers, consent settings, privacy notices, and third-party technologies.

Perguntas frequentes