Argentina Law 25.326 (Personal Data Protection Law)
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Confidentiality
The controller and all persons involved in any phase of personal data processing are bound by professional secrecy. This obligation persists even after the relationship with the data subject or controller ends.
- Confidentiality undertakings for those processing data
- Disclosure breaching confidentiality duty
Cross-border transfers
AAIP maintains a list of countries deemed to provide adequate protection. EU member states and EEA countries are recognized, along with others such as Switzerland, Andorra, Guernsey, Jersey, Isle of Man, Faroe Islands, Israel, New Zealand, Uruguay, and Canada (commercial sector).
- Reliance on the AAIP adequate-countries list
- Transfer to a non-listed country without safeguards
Transfer of personal data to countries or international entities that do not provide adequate levels of protection is prohibited, except with data subject consent, for international judicial cooperation, for medical treatment, for bank or stock exchange transfers, under international treaties, or for international cooperation against terrorism and organized crime.
- Restriction on transfers to countries without adequate protection
- Transfer to inadequate country
Argentina has held EU adequacy status since Commission Decision 2003/490/EC. Maintenance of adequacy depends on continued alignment with EU standards. Modernization Bill is partly motivated by adequacy review pressure.
- Maintenance of conditions supporting EU adequacy
- Not a control objective; contextual
Data subject rights
The data subject has the right to request and obtain information about their personal data included in public databases or private databases that provide reports. Information must be provided within 10 calendar days of the request.
- Access-request handling (free, periodic)
- No access mechanism
Information provided must be in clear language, exempt from codifications, and accompanied by an explanation of the technical terms used. Information must be broad and cover the entire registry pertaining to the data subject, including origin and recipients.
- Access response content & format
- Incomplete access responses
Every person has the right to rectification, updating, and when applicable suppression or confidentiality of their personal data. Controller must act within 5 business days of the request. Free of charge.
- Rectification/update/suppression within 5 business days
- Corrections not actioned in time
Controllers may refuse suppression in defined cases including legal duty to retain, contractual obligations, or where suppression would prejudice legitimate interests of third parties. Refusal must be reasoned.
- Documented basis for refusing access/rectification (exceptions)
- Improper refusal of rights
Judicial decisions or administrative acts that imply assessment of human behavior may not have as their sole basis the result of computerized treatment of personal data revealing personality aspects of the data subject.
- Right to contest decisions based solely on automated data processing
- No recourse against automated assessments
Articles 33 to 46 establish the habeas data action, a constitutional remedy by which data subjects may judicially demand access, rectification, suppression, or confidentiality of their personal data after the administrative route is exhausted or refused.
- Process to respond to habeas data judicial actions
- Unprepared for habeas data claims
Disclosure
Personal data may only be disclosed for purposes directly related to the legitimate interest of the controller and the recipient, and with prior consent of the data subject, who must be informed of the purpose and identify the recipient.
- Consent/legal basis for disclosure to third parties
- Disclosure without basis
Governance
AAIP Resolution 47/2018 recommends a Privacy Impact Assessment for high risk processing, including large scale sensitive data, profiling, monitoring of public areas, and biometric data.
- Privacy impact assessments (AAIP recommended)
- No PIA for high-risk processing
AAIP Resolution 47/2018 recommends appointment of a Data Protection Officer for organizations processing large volumes of data, sensitive data, or where principal activity requires regular and systematic monitoring of data subjects.
- DPO appointment (AAIP recommended; mandatory under the modernization bill)
- No DPO where recommended
Incident response
AAIP Resolution 47/2018 recommends notification of personal data breaches to AAIP and affected data subjects when the breach poses risks to rights. Modernization Bill would make notification mandatory with defined timelines.
- Breach detection & notification to the AAIP
- No breach notification process
Lawful basis
Processing requires the free, express, and informed consent of the data subject, given in writing or by equivalent means depending on the circumstances.
- Free, express, informed consent records
- Processing without consent
Consent is not required when data comes from public sources, is collected for state functions, consists of limited identifying data, derives from a contractual relationship, or is from financial institutions under Article 39.
- Documented basis for a consent exception
- Relying on an invalid exception
Marketing
Personal data with direct marketing purpose may be processed when it is from public sources or provided by the data subject with consent. The data subject may at any time request withdrawal or blocking of their name from databases used for advertising or direct marketing.
- Direct-marketing opt-out (derecho de retiro/bloqueo)
- No marketing opt-out
Oversight
AAIP is the supervisory authority responsible for ensuring compliance with the law, conducting investigations, imposing sanctions, issuing guidance, and approving codes of conduct. AAIP succeeded the prior Directorate (DNPDP) following Decree 746/2017.
- Cooperation with the AAIP supervisory authority
- Obstructing AAIP supervision
Penalties
AAIP may impose warnings, suspensions, fines from ARS 1,000 to ARS 100,000, and closure or cancellation of databases for violations. Sanction amounts have been updated by subsequent AAIP resolutions.
- Awareness of administrative sanction exposure
- Not applicable; enforcement
Article 32 amends the Penal Code to criminalize insertion of false data, unlawful access to databases, and disclosure of confidential data. Penalties include imprisonment from 1 month to 3 years.
- Awareness of criminal-liability exposure
- Not applicable; enforcement
Principles
Collection must be for determined, explicit, and lawful purposes. Data cannot be used for purposes incompatible with those for which it was collected.
- Specified, explicit, legitimate purpose
- Processing beyond stated purpose
Personal data must be true, adequate, pertinent, and not excessive relative to purposes. Data must be accurate and updated, and inaccurate or incomplete data must be suppressed or corrected.
- Accurate, adequate, relevant, non-excessive data
- Inaccurate/excessive data
Data must be destroyed when no longer necessary or pertinent for the purposes for which it was collected.
- Retention no longer than necessary; destruction
- Indefinite retention
Public sector
Public databases must be created by law or administrative act and must publish their existence, purpose, and access conditions. Public databases are subject to AAIP oversight.
- Public-database operation per the law
- Public DB non-compliant
Reform
Executive submitted a draft new Personal Data Protection Law to Congress in June 2023 to align with GDPR. The bill introduces legitimate interest, mandatory DPO for defined cases, mandatory breach notification (72 hours), revised cross-border rules, DPIAs, and increased fines. As of 2026 the bill remains under congressional consideration.
- Monitoring of the pending reform
- Not a control objective; contextual/forward-looking
Registration
All public databases and private databases destined to provide reports must be registered in the National Database Registry maintained by AAIP. Registration includes controller identity, purpose, data categories, retention, recipients, security measures, and cross-border transfers.
- Database registration with the AAIP/Registro Nacional
- Database not registered
Scope
Law applies to personal data recorded in public or private databases that provide reports. Defines personal data, sensitive data, database, data subject, data controller, and processing.
- Determination of personal-data/database scope
- Misclassified scope
Sectoral
Credit information may be processed with data from public sources or provided by the data subject or with consent. Adverse information must be deleted after 5 years from last default and 2 years if the debt was paid.
- Credit-data rules (5/2-year limits, sources)
- Stale/unlawful credit data
Security
The data controller must adopt technical and organizational measures necessary to guarantee the security and confidentiality of personal data, to prevent its alteration, loss, unauthorized consultation or treatment, and to detect deviations.
- Technical & organisational security measures (AAIP Res 47/2018 baseline)
- Inadequate security measures
Sensitive data
Data relating to criminal or contravention records may only be processed by competent public authorities within the framework of their legal authority.
- Criminal-record processing restricted to competent authorities
- Unlawful criminal-record processing
No person may be compelled to provide sensitive data. Sensitive data can only be collected and processed for reasons of general interest authorized by law or for statistical or scientific purposes when data subjects cannot be identified. Sensitive data includes data revealing racial or ethnic origin, political opinions, religious, philosophical or moral convictions, union membership, and health or sexual information.
- Justification/prohibition controls for sensitive data
- Sensitive data without legal basis
Public and private health establishments and health professionals may collect and process data relating to physical or mental health of patients subject to professional secrecy.
- Health-data processing limited to health professionals/institutions with confidentiality
- Health data processed without safeguards
Transparency
When data is collected, the data subject must be informed of the purpose, recipients, existence of the database, controller identity and address, mandatory or optional nature of responses, consequences of refusal, and rights of access, rectification, and suppression.
- Information provided at collection (purpose, recipients, rights)
- No information at collection
Vendors
When personal data is processed by a third party on behalf of the controller, the relationship must be governed by a contract that ensures the processor uses the data only as instructed, applies adequate security, and returns or destroys data at the end of the relationship.
- Processor (prestador de servicios) agreement restricting use to the controller's instruction (Art. 25)
- Processor uses data beyond the instruction
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.