Skip to content

Evidence request lists

Peru DPL

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach and Enforcement

PERU-8
Breach Notification, ANPD Cooperation, Sanctions, Compliance

Per Peru Law 29733 + Supreme Decree + Law 32200 (2024 amendments): breach notification + enforcement. Requirements include (a) implement Personal Data Breach Notification to ANPD per statutory timeline + notify affected data subjects where high risk + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain ANPD Inspection Cooperation including responding to inquiries + facilitating audits + (d) implement Compliance Monitoring including periodic review + internal audit + reporting to leadership + (e) maintain sanctions awareness including administrative penalties + civil liability + (f) maintain breach log + incident response + tabletop exercises.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-8
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Consent and Notice

PERU-2
Consent, Privacy Notice, Sensitive Data

Per Peru Law 29733 + Supreme Decree: consent + notice + sensitive data. Requirements include (a) obtain Informed Consent that is free + prior + express + informed + unambiguous with mechanism for withdrawal + (b) provide Privacy Notice and Transparency including identity of controller + purposes + categories + recipients + retention + rights + transfer + (c) implement Sensitive Data Processing Restrictions including stricter consent + safeguards for health + biometric + ideological + political + sexual orientation + (d) implement special consent mechanisms for sensitive data + (e) maintain records of consent + privacy notices + (f) maintain change management for consent + notice updates.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-2
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Governance and Lifecycle

PERU-7
DPO, Records, Retention, Marketing, Training

Per Peru Law 29733 + Supreme Decree: governance + lifecycle. Requirements include (a) appoint Personal Data Protection Officer or Equivalent Function where required + (b) maintain Records of Processing Activities + (c) implement Retention and Disposal including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing Restrictions including consent + opt-out + suppression lists + (e) deliver Training and Awareness on Personal Data Protection across personnel + (f) maintain documented governance + accountability framework + (g) integrate with broader privacy + risk programme.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-7
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

High-Risk Processing

PERU-4
Children's Data, Privacy Impact, Sensitive Categories

Per Peru Law 29733: heightened safeguards for high-risk processing. Requirements include (a) implement Children and Minors Data Processing protections requiring parental consent per Peruvian civil age + (b) implement sensitive categories handling per the Law + (c) maintain Privacy Impact Assessment for high-risk processing aligned to ANPD guidance + (d) integrate privacy considerations into design + procurement + change management + (e) maintain documented safeguards + risk assessments + (f) review high-risk processing periodically.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-4
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Individual Rights

PERU-3
Data Subject Rights (ARCO), Habeas Data, Automated Decisions

Per Peru Law 29733 + Supreme Decree: data subject rights. Requirements include (a) implement Data Subject Rights Fulfilment including ARCO (Access + Rectification + Cancellation + Opposition) + (b) implement Habeas Data action enabling judicial remedy + (c) implement Automated Decision Making Disclosure including human review + explanation + objection rights where applicable + (d) maintain mechanism for receiving + verifying + responding within statutory timelines + (e) maintain records of requests + responses + decisions + (f) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-3
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Scope and Principles

PERU-1
Scope, Lawful Basis, Purpose Limitation, Quality

Per Peru Law 29733 (Ley de Proteccion de Datos Personales) + Supreme Decree 003-2013-JUS: scope + lawful basis + principles. Requirements include (a) determine Scope and Application of the Data Protection Law including extraterritorial reach where applicable + (b) establish Lawful Basis for Personal Data Processing including consent + contract + legal obligation + vital interests + legitimate interests per Peruvian law + (c) apply Purpose Limitation - personal data must be processed only for purposes informed at collection + (d) maintain Quality and Accuracy of Personal Data including timeliness + completeness + (e) document applicability + lawful basis + (f) align with ANPD (Autoridad Nacional de Proteccion de Datos Personales) guidance.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-1
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Security and Processor

PERU-5
Security of Personal Data and Processor Agreements

Per Peru Law 29733: security + processor management. Requirements include (a) implement Security of Personal Data including organisational + technical + physical measures appropriate to risk per ANPD guidance + (b) maintain Data Processor Agreements ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme + (f) maintain documented security baseline aligned to ANPD minimum standards.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-5
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial

Transfer and Registration

PERU-6
Cross-Border Transfer and Personal Data Bank Registration

Per Peru Law 29733: cross-border + registration. Requirements include (a) implement Cross-Border Data Transfer Controls including transfer only to countries providing adequate level of protection or with appropriate safeguards (consent + binding corporate rules + standard contractual clauses) + (b) maintain Registration of Personal Data Banks with ANPD per the Law - personal data banks must be registered with ANPD + (c) maintain inventory of cross-border data flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) maintain records for regulator inspection + (f) cooperate with ANPD on transfer matters.

Artefacts an auditor will ask for
  • Peru Law 29733 evidence for PERU-6
Where this commonly fails
  • personal data bank registration + DPO + breach notification partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Peru DPL framework page.