🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
AR · run data-protection-2026-08-04 v13-gdpri-1.0.0
content: ai_generated 23 sources retrieved model claude-sonnet-5 ·

Argentina

AR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 44 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

Argentina's twenty-three-year-old adequacy relationship with the European Union has been reaffirmed rather than revisited this cycle. The European Commission recognized Argentina as providing an adequate level of data protection by decision of 30 June 2003, and that decision remains in force. The European Commission's periodic review of eleven Article 25(6) adequacy decisions, published 15 January 2024 alongside SWD(2024) 3 final, concluded that Argentina continues to provide adequate protection and that the 2003 decision did not need to be withdrawn or amended, while noting accompanying country-specific recommendations. That external validation sits alongside an unsettled domestic picture. Two parallel congressional reform tracks are pending to replace Ley 25.326. One track comprises bills associated with legislators Carro and Doñate, which propose a comprehensive reform inspired by a draft the AAIP had itself circulated before that draft lost parliamentary status at the end of 2024. The other, the Yeza bill (project 1751-D-2026), proposes replacing Ley 25.326 in its entirety with a 72-article, 13-title framework drawing on South Korean, UK, Singaporean and GDPR models. Neither track has cleared committee.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, EU-adequacy-holding statute with an active, resourced supervisory authority; amber-tending risk only from the unsettled multi-bill reform pipeline.

Primary frameworkLey 25.326 (Personal Data Protection Act) and Decreto 1558/2001
Traffic-light rationale — GreenComprehensive, EU-adequacy-holding statute with an active, resourced supervisory authority; amber-tending risk only from the unsettled multi-bill reform pipeline.

Sub-modules (5)

Regulator And AuthorityGreen

AAIP, an autarchic body with functional autonomy under the Jefatura de Gabinete de Ministros, is the applicable authority for Ley 25.326, the Access to Public Information Law 27.275, and the Do-Not-Call Registry Law 26.951.

Claims: CLM-AR-1a2b3c4d

Act And InstrumentsGreen

Primary instruments are Ley 25.326 and Decreto 1558/2001 (amended by Decreto 1160/10), supplemented by numerous AAIP resolutions.

Claims: CLM-AR-2b3c4d5e

Material ScopeGreen

The Act and Decrees apply to both public and private-sector processing of personal data.

Claims: CLM-AR-3c4d5e6f

Territorial ScopeAmber

Current law applies to processing carried out within Argentine territory; pending reform bills would add express extraterritorial application to controllers/processors located abroad but targeting Argentine data subjects.

Claims: CLM-AR-3c4d5e6f, CLM-AR-4d5e6f7a

Regulator Registration And FilingAmber

Under the current regime, controllers must register databases with AAIP (over 2,000 databases registered in 2022 alone); pending reform bills would eliminate this registration duty entirely.

Claims: CLM-AR-5e6f7a8b, CLM-AR-6f7a8b9c

Category narrative111 words

Argentina's data-protection regime is anchored in Ley 25.326 (Personal Data Protection Act, 2000) and its implementing Decreto 1558/2001 (as amended by Decreto 1160/10). The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority, having absorbed the functions of the former Dirección Nacional de Protección de Datos Personales. The Act applies to public and private data processing carried out in Argentine territory and underpins the EU's 2003 adequacy finding. Two parallel legislative tracks (Carro/Doñate bills inspired by the AAIP's own anteproyecto, and the independently filed Yeza bill 1751-D-2026) are pending before Congress to replace the 25-year-old Act wholesale, including express extraterritorial scope and removal of the current database-registration duty.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPThe Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority for the Personal Data Protection Act No. 25.326 in Argentina.
  2. ConfirmedDataGuidanceLey 25.326 of 2000 together with Decreto 1558/2001 (amended by Decreto 1160/10) form the primary legal instruments governing data protection in Argentina.
  3. ConfirmedDataGuidanceThe Act and its implementing Decrees apply to both public and private organizations and to processing activities carried out in the territory of Argentina.
  4. ProbableIAPPA pending Congressional reform bill would expressly extend extraterritorial application of the data protection law to controllers/processors located outside Argentina where their processing targets Argentine data subjects.
  5. ConfirmedIAPPUnder the current regime, data controllers are required to register their databases with AAIP; 2,035 databases were registered in 2022 alone.
  6. ProbableIAPPPending reform bills (Carro/Doñate, inspired by the AAIP anteproyecto) would eliminate the currently-in-force duty to register databases with the supervisory authority.

#

Core lawful-basis and sensitive-data concepts exist but are narrower/less granular than GDPR-aligned peers, with material change only at proposal stage.

Primary frameworkLey 25.326, Arts. 5–7; Decreto 1558/2001
Traffic-light rationale — AmberCore lawful-basis and sensitive-data concepts exist but are narrower/less granular than GDPR-aligned peers, with material change only at proposal stage.

Sub-modules (4)

Lawful BasesAmber

Consent is the dominant lawful basis under current law; the Yeza bill would introduce six alternative bases including legitimate interest.

Claims: CLM-AR-7a8b9c1d, CLM-AR-8b9c1d2e

Special CategoriesAmber

Sensitive data categories are defined in the current Act; AAIP guidance addresses genetic data, and reform bills propose an expanded definition covering gender identity, genetic and biometric data.

Claims: CLM-AR-9c1d2e3f, CLM-AR-1d2e3f4a

Pseudonymisation And AnonymisationRed

Neither the Act nor the Decree substantively defines pseudonymisation or anonymisation safe-harbours.

Absence provenance: not recorded. Searched: Argentina Ley 25.326 pseudonymisation anonymisation safe harbour.

Category narrative91 words

Consent is the near-exclusive lawful basis under the current Act, a point the pending Yeza reform bill explicitly seeks to broaden by introducing six alternative bases (consent, contract performance, legal obligation, vital interests, public interest, legitimate interest — the last expressly covering AI-model training subject to a balancing test). Special/sensitive data ('datos sensibles') are already regulated, with AAIP soft-law (Resolución 255/2022) addressing genetic data specifically; reform proposals would broaden the definition to expressly include gender identity, genetic and biometric data. Pseudonymisation/anonymisation are not substantively addressed in the current Act or Decree.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ProbableIAPPUnder the current legal framework, consent operates as the almost-exclusive lawful basis for processing personal data in Argentina.
  2. ProbableIAPPThe pending Yeza bill (1751-D-2026) proposes six alternative lawful bases for processing — consent, contractual performance, legal obligations, vital interests, public interest and legitimate interest — with legitimate interest expressly covering AI training subject to a rights-prevalence test.
  3. ProbableIAPPReform bills propose replacing the current definition of sensitive data with a broader one covering information on private life or capable of causing discrimination or high risk, expressly listing gender identity, genetic and biometric data as examples.
  4. ConfirmedIAPPAAIP Resolución 255/2022 sets out guiding criteria and best-practice indicators for the application of the Personal Data Protection Act with respect to genetic data.

#

Core access/rectification/erasure rights are binding and judicially enforceable today; portability/ADM-objection rights remain at proposal stage only.

Primary frameworkLey 25.326, Arts. 14–16; Constitución Nacional Art. 43 (habeas data)
Traffic-light rationale — GreenCore access/rectification/erasure rights are binding and judicially enforceable today; portability/ADM-objection rights remain at proposal stage only.

Sub-modules (5)

Access RightGreen

Access is enforceable via habeas data, a constitutionally-entrenched simplified judicial procedure.

Claims: CLM-AR-3f4a5b6c

Rectification And ErasureGreen

Rectification/erasure rights are actively enforced; AAIP sanctioned Rappi for failing to act on an erasure request in time.

Claims: CLM-AR-4a5b6c7d, CLM-AR-7d8e9f1a

Restriction And ObjectionAmber

Reform bills add an objection right against automated decisions producing legal or adverse effects; no current binding restriction/objection right beyond consent withdrawal identified.

Claims: CLM-AR-5b6c7d8e

Data PortabilityRed

Portability is not part of the current Act; it is proposed in pending reform bills.

Claims: CLM-AR-5b6c7d8e

Deadlines And Response WindowsAmber

Reform bills propose a non-extendable 10-business-day deadline to satisfy data-subject requests, criticized by commentators as impractical.

Claims: CLM-AR-6c7d8e9f

Category narrative82 words

Data subjects currently hold rights of information, access, rectification, updating, erasure and consent-withdrawal, enforceable through the constitutionally-entrenched 'habeas data' judicial remedy. Enforcement practice confirms erasure rights are actively policed (AAIP sanctioned Rappi for failing to honor a deletion request). Pending reform bills would add portability and a right to object to automated decisions with legal or materially adverse effect, alongside a proposed (contested) 10-business-day non-extendable response deadline; a separate 2022 bill would create a standalone 'right to be forgotten' against search engines.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEUR-LexThe Argentine Constitution provides a special, simplified and rapid judicial remedy known as 'habeas data' to protect personal data, elevating data protection to the status of a fundamental right.
  2. ConfirmedIAPPAAIP sanctioned Rappi Arg S.A.S. for failing to respond in due time and form to a data subject's request for erasure of personal data.
  3. ProbableIAPPPending reform bills introduce new data-subject rights not present in the current Act, including data portability and objection to automated decisions producing legal effects or materially adversely affecting the data subject.
  4. ProbableIAPPPending reform bills propose a non-extendable 10-business-day deadline for controllers to satisfy data-subject rights requests, a timeframe criticized by commentators as difficult for the private sector to meet.
  5. ProbableIAPPA separate 2022 bill proposes a standalone 'right to be forgotten' requiring search-engine providers to implement an accessible electronic form for erasure requests, with a 10-business-day compliance window and judicial recourse for denial or inaccuracy.

#

Foundational accountability tools exist mostly as non-binding guidance rather than statutory duties; binding DPIA/DPO/breach-notification obligations are pending, not yet in force.

Primary frameworkLey 25.326; AAIP Resolución 47/2018 (recommended security measures); AAIP DPIA Guide
Traffic-light rationale — AmberFoundational accountability tools exist mostly as non-binding guidance rather than statutory duties; binding DPIA/DPO/breach-notification obligations are pending, not yet in force.

Sub-modules (7)

Accountability And DpiaAmber

No statutory DPIA duty; AAIP has issued a non-binding DPIA Guide.

Claims: CLM-AR-8e9f1a2b

Dpo RequirementsRed

No current DPO requirement; reform bills would introduce one.

Claims: CLM-AR-9f1a2b3c, CLM-AR-1a2b3c5d

Ropa RequirementsRed

No general ROPA duty under the Act itself; sector-specific instances (e.g., RENAPER internal policy) impose GDPR-style processing records, but this is not a generalized statutory duty.

Absence provenance: not recorded. Searched: Ley 25.326 registro de actividades de tratamiento ROPA Argentina.

Joint Controller ArrangementsRed

No specific joint-controller regime identified in current law.

Absence provenance: not recorded. Searched: Ley 25.326 corresponsables tratamiento conjunto.

Security MeasuresAmber

AAIP Resolución 47/2018 sets recommended (non-mandatory) technical and organizational security measures.

Claims: CLM-AR-2b3c5d6e

Breach NotificationAmber

No general legal breach-notification obligation exists today; it is best practice only, though enforcement has penalized failure to act on breaches. Reform bills would impose a mandatory 72-hour notification duty.

Claims: CLM-AR-3c5d6e7f, CLM-AR-4d6e7f8a, CLM-AR-5e7f8a9b

Retention And DisposalRed

No dedicated statutory retention/disposal regime identified beyond general purpose-limitation principles.

Absence provenance: not recorded. Searched: Ley 25.326 plazos de conservación y baja de datos.

Category narrative83 words

The current Act imposes no DPIA or DPO obligation, though AAIP soft-law (a non-binding DPIA Guide and Resolución 47/2018 recommended security measures) fills part of the gap. There is no general legal duty to notify data breaches today — reporting is 'best practice' only — but AAIP has fined controllers (e.g., Cencosud) for failing to take recommended breach-prevention/notification steps. Pending reform bills would introduce a mandatory DPO figure and a 72-hour breach-notification duty to both AAIP and affected data subjects, mirroring GDPR-style timelines.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedDataGuidanceThe current Act does not provide for a requirement to conduct a Data Protection Impact Assessment, unlike the GDPR, although AAIP's non-binding Guide provides for such a practice.
  2. ConfirmedDataGuidanceUnlike the GDPR, the current Act does not provide for a requirement to appoint a Data Protection Officer.
  3. ProbableIAPPPending reform bills introduce the figure of a data protection officer/delegate as a modern institute not present in the current Act.
  4. ConfirmedDataGuidanceAAIP's Resolución 47/2018 ('Recommended Security Measures') specifies suggested security procedures for controllers, including record-keeping recommendations.
  5. ConfirmedIAPPReporting information security incidents is a best practice rather than a mandatory legal requirement under the Argentine Data Privacy Law; there is no general legal obligation to notify a data breach.
  6. ConfirmedIAPPAAIP imposed an administrative fine on Cencosud SA after a security breach became public and the company failed to take recommended measures to prevent, notify and remedy the breach or notify affected users.
  7. ProbableIAPPThe AAIP-drafted data protection reform bill would impose an obligation to notify data breaches to the DPA without undue delay and within 72 hours of becoming aware, where the breach is likely to pose a risk to data subjects' rights, plus notification to affected data subjects for high-risk breaches.

#

Adequacy-holding jurisdiction with an active, modernizing transfer-mechanism toolkit (BCRs, dual SCC regimes); no TIA or localisation mandate identified.

Primary frameworkLey 25.326, Art. 12; AAIP Resolución 198/2023 (SCC RIPD); Resolución 159/2018 (BCR guidelines)
Traffic-light rationale — GreenAdequacy-holding jurisdiction with an active, modernizing transfer-mechanism toolkit (BCRs, dual SCC regimes); no TIA or localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

Transfers are permitted via consent, contractual clauses, or self-regulatory systems providing adequate protection where the destination lacks an adequacy finding.

Claims: CLM-AR-7a9b1c2d

Adequacy ReceivedGreen

Not applicable in the classic sense — Argentina is a data exporter jurisdiction; see adequacy_granted for the relevant inbound EU recognition.

Absence provenance: not recorded. Searched: Argentina adequacy received from other regimes.

Adequacy GrantedGreen

The European Commission recognized Argentina as providing an adequate level of data protection on 30 June 2003, a decision that remains in force.

Claims: CLM-AR-6f8a9b1c

Sccs And BcrsGreen

AAIP maintains both its own model clauses (2016) and the newer RIPD Standard Contractual Clauses (2023), alongside BCR guidelines (2018).

Claims: CLM-AR-8b1c2d3e, CLM-AR-9c2d3e4f

Transfer Impact AssessmentRed

No formal Transfer Impact Assessment requirement analogous to Schrems II-style TIAs was identified in Argentine law or AAIP guidance.

Absence provenance: not recorded. Searched: Argentina AAIP transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate was identified in the Argentine data protection framework.

Absence provenance: not recorded. Searched: Argentina data localisation requirement personal data Ley 25.326.

Category narrative79 words

Argentina received an EU Commission adequacy decision in 2003 — one of the earliest such findings — which remains in effect. The domestic Act prohibits transfers to jurisdictions lacking adequate protection unless the data subject consents or contractual/self-regulatory safeguards apply. AAIP has actively expanded transfer tooling: Binding Corporate Rules guidance (Resolución 159/2018) and, more recently, adoption of the Red Iberoamericana de Protección de Datos Standard Contractual Clauses (Resolución 198/2023), which coexist with Argentina's own earlier model clauses (Disposición 60-E/2016).

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEUR-LexOn 30 June 2003, Argentina was recognized by the European Commission as providing an adequate level of protection for personal data.
  2. ConfirmedIAPPThe LPDP prohibits, in principle, international transfers of personal data to countries or international organizations lacking an adequate level of data protection, but permits such transfers where data subjects consent or where contractual clauses or self-regulatory systems guarantee adequate protection levels.
  3. ConfirmedIAPPVia Resolución 198/2023, AAIP approved the Red Iberoamericana de Protección de Datos (RIPD) Standard Contractual Clauses for international transfers of personal data, compatible with its own pre-existing model clauses.
  4. ConfirmedIAPPAAIP's Resolución 159/2018 established guidelines and basic content requirements for Binding Corporate Rules as a self-regulatory transfer mechanism for corporate groups.

#

Health and financial overlays are well-documented and active; employment, credit-scoring, education and insurance sub-modules carry no substantiated findings.

Primary frameworkLey 25.326; Ley 26.529 (Patient Rights); Ley 27.553 (Telemedicine); Ley 26.951 (No Llame); BCRA cybersecurity regulations
Traffic-light rationale — AmberHealth and financial overlays are well-documented and active; employment, credit-scoring, education and insurance sub-modules carry no substantiated findings.

Sub-modules (7)

Financial Sector OverlayAmber

The Central Bank of Argentina (BCRA) maintains stringent cybersecurity regulations applicable to the financial sector, overlaying general LPDP obligations.

Claims: CLM-AR-2e4f5a6b

Health Sector OverlayGreen

Telemedicine and digital-prescription platforms must comply with both the LPDP and the Patient Rights Law, given health data's sensitive-data status.

Claims: CLM-AR-1d3e4f5a

Telecoms And EprivacyAmber

The Do-Not-Call Registry regime (Ley 26.951, updated by Resolución 126/2024) governs telemarketing communications, overlapping with general data-protection enforcement.

Claims: CLM-AR-3f5a6b7c

Employment DataRed

No substantiated employment-specific data-protection overlay was located in the sources reviewed.

Absence provenance: not recorded. Searched: Argentina proteccion de datos personales derechos del trabajador empleo.

Credit And ScoringRed

No credit-scoring-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: not recorded. Searched: Argentina credit scoring buró de crédito proteccion de datos.

EducationRed

No education-sector-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: not recorded. Searched: Argentina proteccion de datos educacion sector.

InsuranceRed

No insurance-sector-specific data-protection overlay was substantiated in the sources reviewed.

Absence provenance: not recorded. Searched: Argentina seguros proteccion de datos personales sector.

Category narrative70 words

Sectoral overlays are most developed in health (telemedicine/digital prescriptions must comply with both the LPDP and the Patient Rights Law 26.529, with sensitive-data confidentiality duties for health professionals) and in the Central Bank's (BCRA) cybersecurity regulations for financial-sector data. Telemarketing/direct-communications are separately regulated under the Do-Not-Call Registry Law 26.951, recently updated via Resolución 126/2024. No sector-specific findings were substantiated for employment data, credit/scoring, education, or insurance within the sources reviewed.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedIAPPLey 27.553 on electronic/digital prescriptions requires that telehealth platforms used for medical and psychological consultations comply with Ley 25.326 and the Patient Rights Law 26.529, given that health data is classified as sensitive data subject to professional-secrecy principles.
  2. ProbableDataGuidanceThe Central Bank of Argentina (BCRA) maintains stringent cybersecurity regulations that financial-sector entities must adhere to in order to ensure operational resilience and maintain customer trust.
  3. ConfirmedIAPPAAIP's Resolución 126/2024 introduced a revised classification of infractions and sanctions regime for both the Personal Data Protection Law and the Do-Not-Call Registry Law, consolidating the prior regulatory framework.

#

Only direct marketing (telemarketing) is substantiated; five of six sub-modules carry no evidenced Argentine-specific regime.

Primary frameworkLey 26.951 (Registro Nacional No Llame); Ley 25.326
Traffic-light rationale — RedOnly direct marketing (telemarketing) is substantiated; five of six sub-modules carry no evidenced Argentine-specific regime.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime for Argentina was located.

Absence provenance: not recorded. Searched: Argentina cookies consent law AAIP tracker regulation.

Dark PatternsRed

No Argentina-specific dark-pattern prohibition was located.

Absence provenance: not recorded. Searched: Argentina dark patterns prohibicion diseño engañoso AAIP.

Opt Out SignalsRed

No Global Privacy Control or DAA-equivalent opt-out signal recognition regime was located for Argentina.

Absence provenance: not recorded. Searched: Argentina Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room / data-collaboration-room specific rules were located for Argentina.

Absence provenance: not recorded. Searched: Argentina data clean room regulation AAIP.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising framework was located for Argentina.

Absence provenance: not recorded. Searched: Argentina cross-context advertising sale share personal data regulation.

Direct MarketingAmber

The Do-Not-Call Registry regime governs telemarketing consent/suppression, with active AAIP enforcement against unsolicited telemarketing practices.

Claims: CLM-AR-4a6b7c8d

Category narrative56 words

Direct marketing is the only well-substantiated sub-module: the Do-Not-Call Registry (Ley 26.951) plus AAIP enforcement (fines against FCA Automobiles Argentina and Telefónica Móviles Argentina for unsolicited telemarketing) evidence an active suppression/consent regime for telephone marketing. No dedicated cookie/tracker consent law, dark-pattern prohibition, GPC-style opt-out-signal recognition, clean-room rules, or CPRA-style cross-context 'sale/share' framework were identified for Argentina.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedDataGuidanceAAIP fined FCA Automobiles Argentina and Telefónica Móviles Argentina, each roughly ARS 10 million, for data protection violations involving unsolicited telemarketing practices.

#

Existing binding guidance (Resolución 4/2019) covers automated processing/video surveillance; the more comprehensive ADM-objection right and facial-recognition-specific regime remain at bill stage.

Primary frameworkAAIP Resolución 4/2019; pending Facial Recognition Bill (Yeza); pending LPDP reform bills
Traffic-light rationale — AmberExisting binding guidance (Resolución 4/2019) covers automated processing/video surveillance; the more comprehensive ADM-objection right and facial-recognition-specific regime remain at bill stage.

Sub-modules (6)

Profiling RestrictionsAmber

No dedicated profiling-restriction regime beyond the pending ADM-objection right proposal.

Claims: CLM-AR-1a3b4c6d

Automated Decision Making TransparencyAmber

Resolución 4/2019 addresses automated data processing; reform bills add an explicit objection right for ADM with legal/adverse effect.

Claims: CLM-AR-9f2a3b4c, CLM-AR-1a3b4c6d

Ai Risk AssessmentsAmber

The pending facial-recognition bill requires a prior impact assessment before security-purpose deployment; AAIP separately runs an AI transparency program.

Claims: CLM-AR-5b7c8d9e, CLM-AR-8e1f2a3b

Biometric RegimeAmber

No general biometric-data statute exists; the pending facial-recognition bill is the most developed sector-specific proposal, covering authorization, prohibited uses and human-oversight requirements.

Claims: CLM-AR-5b7c8d9e, CLM-AR-6c8d9e1f, CLM-AR-7d9e1f2a

Genetic DataAmber

Genetic data is addressed via AAIP Resolución 255/2022 best-practice guidance (see lawful_processing_and_special_data module for the underlying claim).

Claims: CLM-AR-1d2e3f4a

State Surveillance CarveoutsAmber

The pending facial-recognition bill expressly prohibits mass surveillance and routine tracking of non-suspects, functioning as a proposed limitation on state-surveillance carveouts.

Claims: CLM-AR-6c8d9e1f

Category narrative99 words

AAIP's Resolución 4/2019 already provides mandatory guidelines covering video surveillance and automated data processing, and AAIP has stood up a dedicated Transparency and Protection of Personal Data Program addressing AI. The most granular near-term development is deputy Yeza's dedicated facial-recognition bill, which would require a prior impact assessment and AAIP authorization before deployment for public-security purposes, expressly ban mass surveillance/routine tracking of non-suspects, and mandate human oversight of automated identifications — explicitly modeled on EU AI Act standards. Separately, the broader LPDP reform bills would add a right to object to automated decisions with legal or materially adverse effect.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ProbableIAPPA pending bill (deputy Yeza) establishes that facial recognition systems to be used for public-security purposes must undergo a prior impact assessment and an AAIP authorization process before implementation.
  2. ProbableIAPPThe pending facial-recognition bill expressly prohibits certain uses such as mass surveillance or routine tracking of persons not suspected of having committed crimes, in line with EU AI Act standards.
  3. ProbableIAPPThe pending facial-recognition bill requires human oversight of automated identifications performed by facial recognition systems.
  4. ConfirmedIAPPAAIP has created a Transparency and Protection of Personal Data Program specifically addressing the use of Artificial Intelligence.
  5. ConfirmedDataGuidanceAAIP's Resolución 4/2019 specifies mandatory guidelines for the application of the Act, addressing topics including video surveillance and automated data processing.
  6. ProbableIAPPPending reform bills add a data-subject right to object to automated decisions that produce legal effects or negatively affect the data subject, a right not present in the current Act.

#

Binding coverage of children's data exists only via soft-law guidance (Resolución 4/2019); dedicated statutory minor-protection provisions remain at proposal stage, and three of five sub-modules are unsubstantiated.

Primary frameworkAAIP Resolución 4/2019; pending LPDP reform bills
Traffic-light rationale — AmberBinding coverage of children's data exists only via soft-law guidance (Resolución 4/2019); dedicated statutory minor-protection provisions remain at proposal stage, and three of five sub-modules are unsubstantiated.

Sub-modules (5)

Age VerificationRed

No dedicated statutory age-verification mechanism was located.

Absence provenance: not recorded. Searched: Argentina age verification children data processing AAIP.

Minor Profiling BansRed

No dedicated minor-profiling ban was located.

Absence provenance: not recorded. Searched: Argentina prohibicion perfilado de menores proteccion de datos.

Education SettingsRed

No education-settings-specific children's-data rule was located.

Absence provenance: not recorded. Searched: Argentina proteccion de datos personales establecimientos educativos menores.

Dependent AdultsRed

No dependent-adult-specific data protection provision was located.

Absence provenance: not recorded. Searched: Argentina proteccion de datos personales adultos dependientes incapacidad.

Category narrative59 words

The current Act does not refer to children at all; AAIP's Resolución 4/2019 fills part of the gap by requiring consent for processing children's data. Pending reform bills would specifically regulate minors' personal data, generally treating consent given by persons aged 16 or older as valid. No substantiated findings were located for minor-profiling bans, education-settings-specific rules, or dependent-adult protections.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedDataGuidanceAlthough the current Act does not refer to children, AAIP's Resolución 4/2019 provides for a requirement to obtain consent when processing children's personal data.
  2. ProbableIAPPA pending reform bill specifically regulates the processing of minors' personal data, generally treating consent given by persons sixteen years of age or older for the processing of their personal data as valid.

#

Regulator is demonstrably active with a documented inspection/sanction track record and a judicially-enforceable private remedy; amber-tending on funding/capacity and collective-redress sub-modules, which are unsubstantiated.

Primary frameworkLey 25.326, Art. 31; AAIP Resolución 332/2020 (Guía de Fiscalización); Constitución Nacional Art. 43 (habeas data)
Traffic-light rationale — GreenRegulator is demonstrably active with a documented inspection/sanction track record and a judicially-enforceable private remedy; amber-tending on funding/capacity and collective-redress sub-modules, which are unsubstantiated.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AAIP holds investigative/inspection powers (Resolución 332/2020) and applies penalties under Art. 31 LPDP; a reform would raise ceilings materially, including a global-turnover-based option.

Claims: CLM-AR-4d7e8f9a, CLM-AR-5e8f9a1b

Enforcement Activity IndexGreen

AAIP issued 63 resolutions in 2022 alone, 52 of them sanctionatory, evidencing sustained enforcement activity; more recent fines (FCA Automobiles, Telefónica) confirm continuity.

Claims: CLM-AR-6f9a1b2c

Regulator Funding And CapacityAmber

No specific budget or headcount data for AAIP was substantiated in the sources reviewed.

Absence provenance: not recorded. Searched: AAIP Argentina presupuesto dotacion de personal capacidad institucional.

Collective Redress And Class ActionsAmber

No data-protection-specific collective-redress or class-action mechanism was substantiated in the sources reviewed.

Absence provenance: not recorded. Searched: Argentina accion de clase proteccion de datos personales.

Private Right Of ActionGreen

The constitutionally-entrenched habeas data remedy provides data subjects a direct judicial avenue independent of AAIP's administrative process.

Claims: CLM-AR-7a1b2c3d

Recent Developments 180DAmber

Within the last 180 days, two Congressional reform bills (Carro, Doñate) were introduced (reported February 2026) alongside an independently-filed comprehensive replacement bill by deputy Yeza (1751-D-2026, reported June 2026); none has been enacted as of the run date.

Claims: CLM-AR-8b2c3d4e, CLM-AR-9c3d4e5f

Category narrative149 words

AAIP exercises active investigative and sanctioning powers under its Guía de Fiscalización (Resolución 332/2020), including planned and spontaneous inspections and the ability to seek judicial authorization when a subject fails to cooperate. Current sanctions are set under Article 31 of the LPDP; a pending reform (mirrored in both the AAIP-drafted bill and other Congressional projects) would substantially raise the ceiling — fines expressed in movable accounting units up to one million units, and in the AAIP version alternatively graduated at 2–4% of the infringer's global annual turnover. 2022 enforcement data show 491 complaint files opened (up 27% year-on-year) and 63 resolutions issued, 52 of them sanctionatory. The constitutionally-entrenched habeas data remedy affords a private right of action independent of AAIP's administrative process. Recent 180-day developments include the Carro and Doñate reform bills (Feb 2026) and the independently-filed Yeza bill 1751-D-2026 (June 2026), none of which have yet been enacted.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPAAIP's Guía de Fiscalización (Resolución 332/2020) empowers it to conduct planned or spontaneous inspections, request judicial authorization where a subject fails to cooperate, and use verbal, visual, documentary and technical investigation techniques.
  2. ProbableIAPPA pending reform proposes fines set between five and one million movable accounting units (based on an initial unit value of ARS 10,000), with the AAIP's own bill version adding an alternative graduation of 2% to 4% of the infringer's total global annual turnover.
  3. ConfirmedIAPPIn 2022, AAIP opened 491 complaint files under the Personal Data Protection Law (27% more than 2021) and issued 63 resolutions, 52 of which were sanctionatory, imposing fines totaling approximately ARS 7,383,061.
  4. ConfirmedEUR-LexArgentine legislation provides effective and dissuasive sanctions, both administrative and criminal, and enforcement of data protection rules is guaranteed through the special, simplified and rapid habeas data judicial remedy alongside general judicial remedies.
  5. ConfirmedIAPPTwo bills recently introduced in Congress — one by deputy Pablo Carro and another by senator Martín Doñate — propose a comprehensive reform of Ley 25.326, inspired by the AAIP's own draft that lost parliamentary status at the end of 2024.
  6. ConfirmedIAPPA new bill (project 1751-D-2026) filed by deputy Martín Yeza proposes to entirely replace the current Personal Data Protection Law with a 72-article, 13-title framework expressly repealing the current law and its regulations, drawing on South Korean, UK and Singaporean models plus GDPR influence.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Argentina
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 23 source(s) in the cumulative register.