EnglishEspañol
Panama flag

Panama

Panama Data Privacy Laws: Law 81 and Executive Decree 285 Compliance Guide

By Recording Law Editorial TeamReviewed May 19, 202624 min read
Panama Data Privacy Laws: Law 81 and Executive Decree 285 Compliance Guide

Frequently Asked Questions

What is Panama's Law 81 and when did it enter into force?

Law 81 of March 26, 2019, is Panama's primary personal data protection statute. It establishes the principles, legal bases, data subject rights, controller obligations, and enforcement framework for the processing of personal data. The law was published in the Official Gazette on March 29, 2019, and included an 18-month transition period. Both Law 81 and its implementing regulation, Executive Decree 285 of May 28, 2021, entered into force on March 29, 2021.

What is Executive Decree 285 of 2021 and what does it add?

Executive Decree 285 of May 28, 2021 is the implementing regulation for Law 81. It provides the operational rulebook that Law 81 delegates to the executive: registration procedures for databases, detailed breach notification requirements (including the 72-hour timeline for notifying ANTAI), data subject request workflows, cross-border transfer mechanisms and approved safeguards, sanction procedures, and guidance on the Data Protection Officer role. Decree 285 also expanded the territorial reach of the law to cover foreign controllers that process Panamanian data through online commercial activities targeting the Panamanian market.

What is ANTAI's role in data protection?

The Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) is Panama's sole supervisory authority for personal data protection. Through its Personal Data Directorate, ANTAI receives and investigates complaints from data subjects, initiates ex officio audits, issues regulatory guidance and binding resolutions, maintains the database registry, evaluates the adequacy of foreign data protection regimes for cross-border transfer purposes, and imposes administrative sanctions ranging from warnings to fines of up to B/.10,000 or suspension and closure of databases.

What is the habeas data action under Panama's Constitution?

Article 44 of Panama's Political Constitution creates the writ of habeas data, a constitutional guarantee that any person may invoke to enforce their right of access to personal data held in official or private registries. Through the writ, a data subject can demand correction, updating, rectification, deletion, or protection of confidentiality of their personal data. The habeas data action is a judicial remedy pursued before the courts, separate from and complementary to the administrative complaint procedure before ANTAI.

What type of consent does Law 81 require?

Law 81 requires consent that is prior (obtained before processing begins), informed (the data subject understands what they are consenting to, including the controller's identity, the purposes, the data categories, their ARCO rights, and any transfers), express (silence or inaction is not valid consent), and unequivocal (no ambiguity about intent). For sensitive data (health, biometric, genetic, racial or ethnic origin, sexual orientation, and related categories), the law requires explicit written consent as the default, with narrow statutory exceptions.

What are ARCO rights and what deadlines apply?

ARCO rights are the data subject rights recognized by Law 81: Access (Acceso), Rectification (Rectificación), Cancellation or Deletion (Cancelación), and Opposition (Oposición), plus a right of portability. Access requests must be answered within 15 business days. Rectification, cancellation, and opposition requests must be resolved within 10 business days. Requests are made directly to the controller; if the controller fails to respond or responds inadequately, the data subject may escalate to ANTAI or file a habeas data writ.

How does Panama regulate cross-border data transfers?

Law 81 permits cross-border transfers to countries that ANTAI has determined provide adequate data protection. For transfers to countries without an adequacy determination, Law 81 and Decree 285 permit transfers based on: express data-subject consent (with disclosure of the destination and absence of adequacy); contractual necessity; important public interest; legal claims; standard contractual clauses approved by ANTAI; binding corporate rules approved by ANTAI; or other safeguards approved by ANTAI. Organizations should not assume that EU-style SCCs are automatically valid under Panamanian law without ANTAI review.

What penalties does ANTAI impose for violations?

ANTAI classifies violations into three tiers. Minor violations (procedural non-compliance, failure to meet filing deadlines) result in a summons or formal warning with corrective action. Serious violations (processing without consent, breaching principles, restricting ARCO rights, inadequate security) result in fines of B/.1,000 to B/.10,000 (USD equivalent). Very serious violations (intentional unlawful collection, repeated serious violations, non-compliance with ANTAI orders, unauthorized international transfers) can result in temporary or permanent suspension of database operations or disqualification from processing activities.

What does the 72-hour breach notification rule require?

Under Executive Decree 285, when a controller becomes aware of a security breach likely to result in a high risk to the rights and freedoms of data subjects, it must notify ANTAI within 72 hours of becoming aware. The notification must state the nature of the breach, the data categories affected, the approximate number of affected data subjects, the likely consequences, and the measures taken or planned to mitigate the breach. Where the breach creates a high risk to data subjects, the controller must also notify affected individuals in clear language without undue delay.

Is a Data Protection Officer mandatory in Panama?

A DPO is not universally mandatory for the private sector under Law 81 as currently enacted. However, Decree 285 specifies that whether an organization has a DPO is a factor in grading penalties, creating a strong incentive to appoint one. For insurance-sector entities (insurance companies, reinsurers, brokers, and sales agents), DPO appointment became mandatory under Insurance Regulation 5-2025, enacted August 5, 2025. Organizations processing large volumes of sensitive data should treat DPO appointment as a practical necessity even outside the insurance sector.

How does Law 81 interact with Panama's banking secrecy law?

Panama's banking secrecy framework operates in parallel with Law 81. Both regimes apply to personal data processed by banks. Banking secrecy requires specific written authorization from the customer or a judicial order before a bank can disclose customer information to any third party, including for cross-border transfers. This standard is stricter than Law 81's general consent or contractual necessity bases, meaning financial institutions must satisfy both frameworks. In practice, the stricter banking secrecy standard applies when the two overlap.

What sectoral rules apply in addition to Law 81?

Three sectoral instruments currently add data protection obligations on top of Law 81: Superintendency of Banks Rule 1-2022 (February 2022) for banks; ANTAI Resolution AN 1267-ADM/2023 (June 2023) for public utilities and service providers; and Insurance Regulation 5-2025 (August 2025) for all insurance-sector entities, including mandatory DPO appointment. The credit data sector continues to be governed by Law 24 of 2002 alongside Law 81.

Does Law 81 require database registration?

Yes. Law 81 requires data controllers to register their databases with ANTAI before processing begins. The registration must include the controller's identity and contact details, the categories of personal data, the purposes of processing, any third-party recipients, and any planned cross-border transfers. Failure to register is a violation subject to sanction. ANTAI maintains the registry and publishes registration guidance at antai.gob.pa.

Updates

Full audit-and-evolve refresh. Added constitutional basis (Articles 29, 42-44), Decree 285/2021 detail, breach notification rules, DPO framework, DPIA requirements, violation classification table, sectoral rules (Rule 1-2022, Resolution 1267-ADM/2023, Insurance Regulation 5-2025), Budapest Convention alignment (October 2024), and compliance checklist.

Initial publication.

Sources and References

  1. ANTAI - Autoridad Nacional de Transparencia y Acceso a la Información (Official Website)(antai.gob.pa).gov
  2. Gaceta Oficial Digital de Panamá - Law 81 of March 26, 2019(gacetaoficial.gob.pa).gov
  3. Gaceta Oficial Digital de Panamá - Executive Decree 285 of May 28, 2021(gacetaoficial.gob.pa).gov
  4. Political Constitution of the Republic of Panama (Articles 29, 42, 43, 44)(constituteproject.org)
  5. Superintendencia de Bancos de Panamá - Rule 1-2022(superbancos.gob.pa).gov
  6. Asamblea Nacional de Panamá(asamblea.gob.pa).gov
  7. Council of Europe - Panama cybercrime legislation alignment (October 2024)(coe.int)
  8. Morgan & Morgan - Insurance Regulation 5-2025(morimor.com)
  9. Ibero-American Data Protection Network (RIPD)(redipd.org)
  10. DLA Piper - Data Protection Laws of the World: Panama(dlapiperdataprotection.com)
  11. UNCTAD - Data Protection and Privacy Legislation Worldwide(unctad.org)
Share: