EnglishEspañol
Argentina flag

Argentina

Argentina Data Privacy Laws: PDPL Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202626 min read
Argentina Data Privacy Laws: PDPL Compliance Guide (2026)

Frequently Asked Questions

Does Argentina's data protection law apply to foreign companies?

Yes. If a foreign company processes personal data of Argentine residents, it falls within the scope of Law 25.326. Since Resolution 132/2018, foreign data controllers must also register their databases with the AAIP's National Registry of Databases (RNBD), even without a physical presence in Argentina.

Is Argentina considered adequate for data transfers from the European Union?

Yes. The European Commission confirmed Argentina's adequacy status on January 15, 2024, after reviewing all 11 existing adequacy decisions under the GDPR. Personal data can flow from the EU to Argentina without requiring standard contractual clauses or other additional safeguards. Argentina has held this status since the early 2000s. The EU's review recommended that Argentina enshrine sub-legislative protections in statute, which the pending reform bills would accomplish.

What is habeas data and how does it work in Argentina?

Habeas data is a constitutional right established in Article 43 of Argentina's constitution. It allows any person to file a judicial action to access personal data held about them in public or private databases, and to demand correction, deletion, or confidentiality of false or discriminatory data. It functions as a court remedy when data controllers refuse to honor data subject requests. Courts have used it to halt a Buenos Aires biometric facial recognition system that was applied to more than 15,000 people who were not listed fugitives.

Are companies in Argentina required to report data breaches?

Under the current Law 25.326, there is no mandatory breach notification requirement. However, AAIP Resolution 47/2018 strongly recommends notifying the authority and affected individuals as a best practice. Reform bills introduced since 2025 would make breach notification mandatory. The rights-focused proposals (S-0644/2025 and 1948-D-2025) proposed a 72-hour notification deadline to the AAIP, while an innovation-oriented proposal used a 'reasonable time' standard instead; their current legislative status is unconfirmed. The most recent confirmed-pending bill, 1751-D-2026 (April 2026), is a broader repeal-and-replace proposal for Law 25.326.

What penalties can companies face for violating Argentina's data privacy law?

Current administrative penalties under AAIP Resolution 126/2024 (effective June 1, 2024) are structured in three tiers: minor infractions carry per-incident fines of ARS 1,000 to ARS 80,000 (accumulation cap ARS 40,000,000 under Anexo II point 7); serious infractions carry ARS 80,001 to ARS 90,000 per incident (cap ARS 45,000,000) plus database suspension for up to 30 days; very serious infractions carry ARS 90,001 to ARS 100,000 per incident (cap ARS 50,000,000) plus suspension for up to 365 days and possible database closure. Fines are reduced by 50% if paid within 20 business days. Resolution 179/2025 (Boletin Oficial, September 30, 2025) later amended the infractor-registry provision under Resolution 126/2024 but did not change these per-infraction ranges or the accumulation cap. Criminal penalties range from one month to three years of imprisonment for offenses like inserting false data or illegally accessing databases. Pending reform bills, including Bill 1751-D-2026, propose dramatically higher fines of up to 4% of global annual turnover.

What is Ley Olimpia and how does it affect data privacy in Argentina?

Ley Olimpia is Law 27.736, promulgated on October 23, 2023. It amended Law 26.485 to add digital or telematic violence as a form of gender-based violence. It covers non-consensual sharing of intimate images, unauthorized dissemination of personal data, digital espionage, and unauthorized access to devices or accounts. Judges can order platforms and websites to remove content constituting digital violence by URL. For organizations operating platforms in Argentina, Ley Olimpia creates a parallel content removal obligation that runs alongside PDPL deletion rights.

Does Argentina have rules on artificial intelligence and automated decision-making?

As of 2026, Argentina has no enacted AI-specific legislation. Law 25.326 contains no provisions on automated decision-making. The AAIP issued non-binding AI guidelines through Resolution 161/2023 and requires public agencies to document automated systems on a Transparency Portal. Bill 4243-D-2025, introduced in August 2025, would have created an AI-specific framework including a National AI Registry, mandatory risk assessments for medium- and high-risk systems, and audit powers; its current status could not be confirmed. Separately, Bill 1751-D-2026 (introduced April 22, 2026) is a confirmed-pending, broader repeal-and-replace proposal for Law 25.326, though its specific provisions on AI or automated decision-making have not been independently verified by recordinglaw.com.

Does Argentina require organizations to appoint a Data Protection Officer?

Under the current Law 25.326, there is no mandatory DPO requirement. The pending comprehensive reform bills would change this. The 2025 rights-focused bills (S-0644/2025 and 1948-D-2025) would have required DPO appointments for public agencies and private controllers engaged in large-scale, high-risk, or sensitive data processing, while an innovation-oriented 2025 proposal would have limited the DPO obligation to organizations classified as 'advanced' data processors; the current status of these 2025 bills is unconfirmed. The most recent confirmed-pending reform bill, 1751-D-2026 (April 2026), is a broader repeal-and-replace proposal for Law 25.326; whether it retains a DPO requirement has not been independently confirmed by recordinglaw.com. AAIP Resolution 145/2025 (August 2025) already requires federal agencies to appoint and train data protection officers as part of a three-year program.

Updates

Verified the AAIP Resolucion 126/2024 500x accumulation cap (Anexo II punto 7: 'se aplicara un tope al monto total de la multa ... equivalente al maximo de la escala ... multiplicado por QUINIENTOS (500)') against InfoLEG's official texto actualizado; the existing per-infraction ranges and category ceilings (minor ARS 1,000-80,000 / cap ARS 40,000,000; serious ARS 80,001-90,000 / cap ARS 45,000,000; very serious ARS 90,001-100,000 / cap ARS 50,000,000) are confirmed accurate and retained, with the 50% early-payment reduction (within 20 business days) also added where missing. Added AAIP Resolucion 179/2025 (Boletin Oficial, September 30, 2025), which amended the infractor-registry provision (art. 5 inciso b) of Resolucion 126/2024) without changing the fine ranges or cap. Added Bill 1751-D-2026 (introduced April 22, 2026 by Representative Yeza), a confirmed-currently-pending repeal-and-replace proposal for Law 25.326, in committee; described only by what the Diputados.gob.ar docket supports (title, author, introduction date, committee referral), without asserting unconfirmed GDPR-alignment or AI-provision descriptors. Hedged references to the older 2025 bill roster (S-0644/2025, 1948-D-2025, 0904-D-2025, 3540-D-2025, 2968-D-2025, S-0968/2025, 4243-D-2025) since their current legislative status could not be reconfirmed. No reform bill has been enacted; Law 25.326 remains in force. Added in-context links to EU adequacy decisions, standard contractual clauses, and the GDPR-vs-LGPD comparison. Sources: InfoLEG texto actualizado of Resolucion 126/2024 including Anexo II (servicios.infoleg.gob.ar), Boletin Oficial notice of Resolucion 179/2025, Diputados.gob.ar page for Bill 1751-D-2026.

Corrected material error in penalty tiers under Resolution 126/2024. Per-infraction ranges are: minor ARS 1,000-80,000, serious ARS 80,001-90,000, very serious ARS 90,001-100,000. The 500x accumulation cap yields category ceilings of ARS 40,000,000 / 45,000,000 / 50,000,000 (roughly USD 28,000-36,000 at May 2026 official exchange rates). Replaced incorrect pre-Resolution figures (minor ARS 3,000-25,000, serious ARS 25,000-80,000, very serious ARS 80,000-100,000) and removed the false claim that the maximum was worth under USD 100. Sources: Infoleg official text (argentina.gob.ar/normativa/nacional/resolucion-126-2024-399750), Digital Policy Alert analysis.

Expanded from 2,847 to approximately 5,700 words. Added H2 sections on Quick Answer, Ley Olimpia (Law 27.736), AI Governance and Automated Decision-Making, and Recent Developments (2024-2026). Updated Pending Reform section with all 2025 bills including S-0644/2025, 1948-D-2025, 0904-D-2025, S-0968/2025, and 4243-D-2025; clarified 72-hour vs. reasonable-time breach notification divergence; added DPO scope differences. Added EU adequacy January 15, 2024 exact date and review recommendation to enshrine sub-legislative protections. Added Resolution 145/2025 (August 2025 public-sector program) and Resolution 126/2024 (sanctions unification). Expanded habeas data section with full Buenos Aires facial recognition case details (Appeals Court, April 28, 2023). Added internal link to Argentina recording laws.

Initial publication. Covered Ley 25.326, AAIP, habeas data, consent requirements, data subject rights, penalties, breach notification, international transfers, Convention 108+ ratification, EU adequacy, and pending reform bills.

Sources and References

  1. Ley 25.326 de Proteccion de los Datos Personales -- Texto completo (Congreso de la Nacion Argentina)(argentina.gob.ar).gov
  2. Constitucion de la Nacion Argentina -- Articulo 43 (Habeas Data)(argentina.gob.ar).gov
  3. Decreto Reglamentario 1558/2001 -- Reglamentacion de la Ley 25.326(argentina.gob.ar).gov
  4. Agencia de Acceso a la Informacion Publica (AAIP) -- Proteccion de Datos Personales(argentina.gob.ar).gov
  5. AAIP Resolution 47/2018 -- Recommended Security Measures for Personal Data(argentina.gob.ar).gov
  6. AAIP Resolution 132/2018 -- Registration of Foreign Data Controllers in the RNBD(argentina.gob.ar).gov
  7. AAIP Resolution 161/2023 -- Program for Transparency and Personal Data Protection in the Use of AI(argentina.gob.ar).gov
  8. AAIP Resolution 145/2025 -- Program for Strengthening Personal Data Protection in the National Public Administration (Boletin Oficial, August 4, 2025)(boletinoficial.gob.ar).gov
  9. Ley 27.736 Ley Olimpia -- Promulgation via Decreto 542/2023 (Boletin Oficial, October 23, 2023)(boletinoficial.gob.ar).gov
  10. European Commission -- Adequacy Decisions under the GDPR (including January 2024 confirmation of Argentina)(commission.europa.eu).gov
  11. Council of Europe -- Argentina ratifies Convention 108+ (April 2023)(coe.int)
  12. CELS -- Court of Appeals of Buenos Aires confirms unconstitutionality of SRFP facial recognition system (April 28, 2023)(cels.org.ar)
  13. Digital Policy Alert -- Argentina Personal Data Protection Bill S-0644/2025 introduced to Senate(digitalpolicyalert.org)
  14. Digital Policy Alert -- Bill 4243-D-2025 on Personal Data Protection in AI Systems introduced in Chamber of Deputies (August 2025)(digitalpolicyalert.org)
  15. Baker McKenzie -- Argentina AAIP Resolution 145/2025: Program for Strengthening Personal Data Protection in the National Public Administration(connectontech.bakermckenzie.com)
  16. DataGuidance -- Argentina: Data Protection Overview(dataguidance.com)
  17. Cornell LII Gender Justice -- Ley 27736 Ley Olimpia (2023)(law.cornell.edu)
  18. AAIP Resolution 126/2024 -- Full text with Annex I (Infraction Classification) and Annex II (Sanction Graduation Regime): per-infraction tiers ARS 1,000-80,000 / 80,001-90,000 / 90,001-100,000 with 500x accumulation cap yielding ceilings of ARS 40M / 45M / 50M (Infoleg, argentina.gob.ar)(servicios.infoleg.gob.ar).gov
  19. AAIP Resolucion 126/2024 (InfoLEG texto actualizado, unified sanctions regime + Anexo II point 7 500x accumulation cap, eff. June 1, 2024)(servicios.infoleg.gob.ar).gov
  20. Boletin Oficial notice of AAIP Resolucion 179/2025 (published Sept. 30, 2025; amended art. 5 inciso b) infractor-registry provision of Resolucion 126/2024)(boletinoficial.gob.ar).gov
  21. Bill 1751-D-2026 (Diputados.gob.ar, Rep. Yeza, introduced April 22, 2026, referred to committee)(diputados.gob.ar).gov
Share: