Skip to content

Evidence request lists

Argentina Law 25.326 (Personal Data Protection Law)

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Confidentiality

AR-25326-ART9-CONFIDENTIALITY
Confidentiality Duty

The controller and all persons involved in any phase of personal data processing are bound by professional secrecy. This obligation persists even after the relationship with the data subject or controller ends.

Artefacts an auditor will ask for
  • Confidentiality undertakings for those processing data
Where this commonly fails
  • Disclosure breaching confidentiality duty

Cross-border transfers

AR-25326-ART12-ADEQUACY
AAIP Adequacy List Reliance

AAIP maintains a list of countries deemed to provide adequate protection. EU member states and EEA countries are recognized, along with others such as Switzerland, Andorra, Guernsey, Jersey, Isle of Man, Faroe Islands, Israel, New Zealand, Uruguay, and Canada (commercial sector).

Artefacts an auditor will ask for
  • Reliance on the AAIP adequate-countries list
Where this commonly fails
  • Transfer to a non-listed country without safeguards
AR-25326-ART12-XBORDER
Cross-Border Transfer Restrictions

Transfer of personal data to countries or international entities that do not provide adequate levels of protection is prohibited, except with data subject consent, for international judicial cooperation, for medical treatment, for bank or stock exchange transfers, under international treaties, or for international cooperation against terrorism and organized crime.

Artefacts an auditor will ask for
  • Restriction on transfers to countries without adequate protection
Where this commonly fails
  • Transfer to inadequate country
AR-25326-EU-ADEQUACY
EU Adequacy Status Maintenance

Argentina has held EU adequacy status since Commission Decision 2003/490/EC. Maintenance of adequacy depends on continued alignment with EU standards. Modernization Bill is partly motivated by adequacy review pressure.

Artefacts an auditor will ask for
  • Maintenance of conditions supporting EU adequacy
Where this commonly fails
  • Not a control objective; contextual

Data subject rights

AR-25326-ART14-ACCESS
Right of Access

The data subject has the right to request and obtain information about their personal data included in public databases or private databases that provide reports. Information must be provided within 10 calendar days of the request.

Artefacts an auditor will ask for
  • Access-request handling (free, periodic)
Where this commonly fails
  • No access mechanism
AR-25326-ART15-CONTENT
Content of Access Response

Information provided must be in clear language, exempt from codifications, and accompanied by an explanation of the technical terms used. Information must be broad and cover the entire registry pertaining to the data subject, including origin and recipients.

Artefacts an auditor will ask for
  • Access response content & format
Where this commonly fails
  • Incomplete access responses
AR-25326-ART16-RECTIFICATION
Right of Rectification, Update, Suppression and Confidentiality

Every person has the right to rectification, updating, and when applicable suppression or confidentiality of their personal data. Controller must act within 5 business days of the request. Free of charge.

Artefacts an auditor will ask for
  • Rectification/update/suppression within 5 business days
Where this commonly fails
  • Corrections not actioned in time
AR-25326-ART17-OPPOSITION
Right of Opposition and Refusal Exceptions

Controllers may refuse suppression in defined cases including legal duty to retain, contractual obligations, or where suppression would prejudice legitimate interests of third parties. Refusal must be reasoned.

Artefacts an auditor will ask for
  • Documented basis for refusing access/rectification (exceptions)
Where this commonly fails
  • Improper refusal of rights
AR-25326-ART20-ADM
Automated Decisions

Judicial decisions or administrative acts that imply assessment of human behavior may not have as their sole basis the result of computerized treatment of personal data revealing personality aspects of the data subject.

Artefacts an auditor will ask for
  • Right to contest decisions based solely on automated data processing
Where this commonly fails
  • No recourse against automated assessments
AR-25326-HABEAS-DATA
Habeas Data Judicial Remedy

Articles 33 to 46 establish the habeas data action, a constitutional remedy by which data subjects may judicially demand access, rectification, suppression, or confidentiality of their personal data after the administrative route is exhausted or refused.

Artefacts an auditor will ask for
  • Process to respond to habeas data judicial actions
Where this commonly fails
  • Unprepared for habeas data claims

Disclosure

AR-25326-ART11-DISCLOSURE
Disclosure to Third Parties

Personal data may only be disclosed for purposes directly related to the legitimate interest of the controller and the recipient, and with prior consent of the data subject, who must be informed of the purpose and identify the recipient.

Artefacts an auditor will ask for
  • Consent/legal basis for disclosure to third parties
Where this commonly fails
  • Disclosure without basis

Governance

AR-25326-AAIP-DPIA
Data Protection Impact Assessment Recommendation

AAIP Resolution 47/2018 recommends a Privacy Impact Assessment for high risk processing, including large scale sensitive data, profiling, monitoring of public areas, and biometric data.

Artefacts an auditor will ask for
  • Privacy impact assessments (AAIP recommended)
Where this commonly fails
  • No PIA for high-risk processing
AR-25326-AAIP-DPO
Data Protection Officer (DPO) Recommendation

AAIP Resolution 47/2018 recommends appointment of a Data Protection Officer for organizations processing large volumes of data, sensitive data, or where principal activity requires regular and systematic monitoring of data subjects.

Artefacts an auditor will ask for
  • DPO appointment (AAIP recommended; mandatory under the modernization bill)
Where this commonly fails
  • No DPO where recommended

Incident response

AR-25326-AAIP-BREACH
Personal Data Breach Notification

AAIP Resolution 47/2018 recommends notification of personal data breaches to AAIP and affected data subjects when the breach poses risks to rights. Modernization Bill would make notification mandatory with defined timelines.

Artefacts an auditor will ask for
  • Breach detection & notification to the AAIP
Where this commonly fails
  • No breach notification process

Lawful basis

AR-25326-ART5-CONSENT
Consent as Default Lawful Basis

Processing requires the free, express, and informed consent of the data subject, given in writing or by equivalent means depending on the circumstances.

Artefacts an auditor will ask for
  • Free, express, informed consent records
Where this commonly fails
  • Processing without consent
AR-25326-ART5-EXCEPTIONS
Consent Exceptions

Consent is not required when data comes from public sources, is collected for state functions, consists of limited identifying data, derives from a contractual relationship, or is from financial institutions under Article 39.

Artefacts an auditor will ask for
  • Documented basis for a consent exception
Where this commonly fails
  • Relying on an invalid exception

Marketing

AR-25326-ART27-MARKETING
Direct Marketing and Opt-Out

Personal data with direct marketing purpose may be processed when it is from public sources or provided by the data subject with consent. The data subject may at any time request withdrawal or blocking of their name from databases used for advertising or direct marketing.

Artefacts an auditor will ask for
  • Direct-marketing opt-out (derecho de retiro/bloqueo)
Where this commonly fails
  • No marketing opt-out

Oversight

AR-25326-ART29-AAIP
AAIP Authority and Powers

AAIP is the supervisory authority responsible for ensuring compliance with the law, conducting investigations, imposing sanctions, issuing guidance, and approving codes of conduct. AAIP succeeded the prior Directorate (DNPDP) following Decree 746/2017.

Artefacts an auditor will ask for
  • Cooperation with the AAIP supervisory authority
Where this commonly fails
  • Obstructing AAIP supervision

Penalties

AR-25326-ART31-ADM-SANCTIONS
Administrative Sanctions

AAIP may impose warnings, suspensions, fines from ARS 1,000 to ARS 100,000, and closure or cancellation of databases for violations. Sanction amounts have been updated by subsequent AAIP resolutions.

Artefacts an auditor will ask for
  • Awareness of administrative sanction exposure
Where this commonly fails
  • Not applicable; enforcement
AR-25326-ART32-CRIMINAL
Criminal Penalties

Article 32 amends the Penal Code to criminalize insertion of false data, unlawful access to databases, and disclosure of confidential data. Penalties include imprisonment from 1 month to 3 years.

Artefacts an auditor will ask for
  • Awareness of criminal-liability exposure
Where this commonly fails
  • Not applicable; enforcement

Principles

AR-25326-ART4-PURPOSE
Lawful Purpose and Purpose Limitation

Collection must be for determined, explicit, and lawful purposes. Data cannot be used for purposes incompatible with those for which it was collected.

Artefacts an auditor will ask for
  • Specified, explicit, legitimate purpose
Where this commonly fails
  • Processing beyond stated purpose
AR-25326-ART4-QUALITY
Data Quality Principle

Personal data must be true, adequate, pertinent, and not excessive relative to purposes. Data must be accurate and updated, and inaccurate or incomplete data must be suppressed or corrected.

Artefacts an auditor will ask for
  • Accurate, adequate, relevant, non-excessive data
Where this commonly fails
  • Inaccurate/excessive data
AR-25326-ART4-RETENTION
Retention Limitation

Data must be destroyed when no longer necessary or pertinent for the purposes for which it was collected.

Artefacts an auditor will ask for
  • Retention no longer than necessary; destruction
Where this commonly fails
  • Indefinite retention

Public sector

AR-25326-ART22-PUBLIC-DB
Public Database Operation

Public databases must be created by law or administrative act and must publish their existence, purpose, and access conditions. Public databases are subject to AAIP oversight.

Artefacts an auditor will ask for
  • Public-database operation per the law
Where this commonly fails
  • Public DB non-compliant

Reform

AR-25326-MODERNIZATION
Pending Modernization Bill 2023

Executive submitted a draft new Personal Data Protection Law to Congress in June 2023 to align with GDPR. The bill introduces legitimate interest, mandatory DPO for defined cases, mandatory breach notification (72 hours), revised cross-border rules, DPIAs, and increased fines. As of 2026 the bill remains under congressional consideration.

Artefacts an auditor will ask for
  • Monitoring of the pending reform
Where this commonly fails
  • Not a control objective; contextual/forward-looking

Registration

AR-25326-ART21-REGISTRATION
Database Registration with AAIP

All public databases and private databases destined to provide reports must be registered in the National Database Registry maintained by AAIP. Registration includes controller identity, purpose, data categories, retention, recipients, security measures, and cross-border transfers.

Artefacts an auditor will ask for
  • Database registration with the AAIP/Registro Nacional
Where this commonly fails
  • Database not registered

Scope

AR-25326-ART2
Scope and Definitions

Law applies to personal data recorded in public or private databases that provide reports. Defines personal data, sensitive data, database, data subject, data controller, and processing.

Artefacts an auditor will ask for
  • Determination of personal-data/database scope
Where this commonly fails
  • Misclassified scope

Sectoral

AR-25326-ART26-CREDIT
Credit Information Database Rules

Credit information may be processed with data from public sources or provided by the data subject or with consent. Adverse information must be deleted after 5 years from last default and 2 years if the debt was paid.

Artefacts an auditor will ask for
  • Credit-data rules (5/2-year limits, sources)
Where this commonly fails
  • Stale/unlawful credit data

Security

AR-25326-ART9-SECURITY
Security Measures Obligation

The data controller must adopt technical and organizational measures necessary to guarantee the security and confidentiality of personal data, to prevent its alteration, loss, unauthorized consultation or treatment, and to detect deviations.

Artefacts an auditor will ask for
  • Technical & organisational security measures (AAIP Res 47/2018 baseline)
Where this commonly fails
  • Inadequate security measures

Sensitive data

AR-25326-ART7-CRIMINAL
Criminal Records Restrictions

Data relating to criminal or contravention records may only be processed by competent public authorities within the framework of their legal authority.

Artefacts an auditor will ask for
  • Criminal-record processing restricted to competent authorities
Where this commonly fails
  • Unlawful criminal-record processing
AR-25326-ART7-SENSITIVE
Sensitive Data Restrictions

No person may be compelled to provide sensitive data. Sensitive data can only be collected and processed for reasons of general interest authorized by law or for statistical or scientific purposes when data subjects cannot be identified. Sensitive data includes data revealing racial or ethnic origin, political opinions, religious, philosophical or moral convictions, union membership, and health or sexual information.

Artefacts an auditor will ask for
  • Justification/prohibition controls for sensitive data
Where this commonly fails
  • Sensitive data without legal basis
AR-25326-ART8-HEALTH
Health Data Special Rules

Public and private health establishments and health professionals may collect and process data relating to physical or mental health of patients subject to professional secrecy.

Artefacts an auditor will ask for
  • Health-data processing limited to health professionals/institutions with confidentiality
Where this commonly fails
  • Health data processed without safeguards

Transparency

AR-25326-ART6-NOTICE
Information Duty at Collection

When data is collected, the data subject must be informed of the purpose, recipients, existence of the database, controller identity and address, mandatory or optional nature of responses, consequences of refusal, and rights of access, rectification, and suppression.

Artefacts an auditor will ask for
  • Information provided at collection (purpose, recipients, rights)
Where this commonly fails
  • No information at collection

Vendors

AR-25326-PROCESSOR
Processor Agreements (Art 25)

When personal data is processed by a third party on behalf of the controller, the relationship must be governed by a contract that ensures the processor uses the data only as instructed, applies adequate security, and returns or destroys data at the end of the relationship.

Artefacts an auditor will ask for
  • Processor (prestador de servicios) agreement restricting use to the controller's instruction (Art. 25)
Where this commonly fails
  • Processor uses data beyond the instruction
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.