Country:阿根廷 · Data Privacy
Argentina · Data Privacy
Personal data protection in Argentina is governed by Law No. 25.326 (PDPL), supervised by the AAIP (Agencia de Acceso a la Información Pública), which was among the first to receive an EU adequacy determination, facilitating data transfers to the EU. Core obligations include: personal databases must be registered with the AAIP; cross-border transfers to non-adequacy countries require authorization or the data subject's explicit consent; a lawful consent mechanism must be established. Since 2025, AAIP enforcement has noticeably strengthened.
Key points
- Core law: Personal Data Protection Law No. 25.326 (PDPL) and Decree 1558/2001.
- Regulator: AAIP (Agencia de Acceso a la Información Pública).
- Personal databases must be registered with the AAIP (mandatory, not optional).
- Cross-border transfers: transfers to non-adequacy countries require authorization or the data subject's explicit consent.
- Consent must be free, specific, and recorded in writing; pre-checked or bundled consent is non-compliant.
- Extraterritorial effect: overseas companies processing Argentine residents' data are also subject to jurisdiction.
- Enforcement strengthened since 2025 (finance, e-commerce, healthcare, technology, and other industries).
- China data export obligations (pkulaw verified 2026-07): transfers/return of data to China must use one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC·SAMR Order No. 20, effective 2025-10-14); the 2024–2025 regulatory stance has relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Regulations on Network Data Security Administration (State Council Order No. 790) exempt some situations.
Procedure
- Data mapping and classification.
- Register databases with the AAIP.
- Design privacy notices and consent mechanisms.
- Cross-border transfer authorization or standard contracts (SCC).
- Sign data processing agreements with processors.
Hard requirements
- Local representative (when no Argentine entity); database registration; Data Protection Officer (DPO, where applicable).
Costs
Registration and compliance costs; fines, and processing can be suspended in serious cases.⏱ ⏱ Timeline:Continuous compliance.⚠ Common risks
- Failing to register a database is itself a violation (independently penalizable).
- Cross-border transfers without a lawful mechanism face rectification orders or suspension.
- 2025 enforcement is stricter; consent mechanisms and processor management are inspection priorities.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing Argentine residents' personal data in Argentina, or transferring it back to China (governed by the Personal Data Protection Law No. 25.326 and Decree 1558/2001, supervised by the AAIP).
Prerequisites
- Processing activities identified and database registration prepared.
- Assessment of whether a local representative is needed (when no Argentine entity).
- Budget reserved for database registration and compliance costs.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data mapping and classification. Map personal data categories, processing purposes, recipients, and distinguish sensitive data. | Legal/IT. | 2 weeks | Internal cost. | Data inventory. | Processing Argentine residents' data abroad is also subject to jurisdiction. Penalty:Fines; processing may be suspended in serious cases. |
| 2 | Register databases with the AAIP. Personal databases must be mandatorily registered with the AAIP (Public Information Access Agency) — not optional. | Legal | Registration cycle. | Registration cost. | AAIP database registration. | Non-registration is itself an independently penalizable matter. Penalty:Operating without registration is a violation, separately punishable. |
| 3 | Design privacy notices and consent mechanisms. Publish privacy notices and obtain free, specific consent recorded in writing (pre-checked or bundled consent is non-compliant). | Legal | 1–2 weeks | Internal cost | Privacy notice, consent records | Must be revocable. Penalty:Penalized for defective consent. |
| 4 | Cross-border transfer authorization / standard contractual clauses (SCC). Transfers to countries without an adequacy determination (including China) require AAIP authorization or the data subject's explicit consent, plus standard contractual clauses. | Legal | 3–6 weeks | Internal/lawyer fees | Cross-border authorization, SCC, PIPL export documents | Reverse transfers require authorization. Penalty:Without a lawful mechanism, rectification orders or transfer suspension. |
| 5 | Sign data processing agreements with processors. Sign data processing agreements (DPA) with third-party processors, defining responsibilities and security obligations. | Legal | 1–2 weeks | Internal cost | DPA contract | Processor management is a 2025 enforcement focus. Penalty:Penalized for missing DPAs. |
| 6 | Data subject rights response. Establish response processes for access, rectification, erasure, and information requests. | DPO/customer service | Ongoing | Internal cost | Data subject access request (DSAR) process | Must be recorded. Penalty:Refusing to respond faces penalties. |
| 7 | Continuous compliance and annual review. In response to strengthened AAIP enforcement since 2025, conduct regular reviews and training. | Compliance | Annual | Internal cost | Annual review | Stronger enforcement across industries. Penalty:Continuous violations accumulate. |
✅ Self-check list
⚠ Common pitfalls
Processing without registering databases影响:Independently penalizable规避:Register with the AAIP first
Pre-checked/bundled consent影响:Penalized for invalid consent规避:Free, specific, written consent
Cross-border transfers without AAIP authorization影响:Rectification orders or suspension规避:Apply for authorization or obtain explicit consent
Ignoring PIPL export when returning data to China影响:Double violation规避:Handle China-side mechanisms in parallel
No DPA with processors影响:Key 2025 enforcement target规避:Sign data processing agreements
Assuming extraterritorial processing is unregulated影响:Compliance gaps规避:Argentine residents' data is subject to jurisdiction
📅 Ongoing post-incorporation obligations
- AAIP database registration and maintenance
- Continuous DSAR response
- Processor DPA management
- PIPL export mechanisms for data return to China remain effective
- Annual review and training
🔗 Official portals
📎 Source:Argentina Public Information Access Agency (AAIP); Personal Data Protection Law No. 25.326 (PDPL); Decree 1558/2001; EU adequacy determination; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.