{
  "node_id": "ar-pdp-25326-2000",
  "title": "Argentina Personal Data Protection Act - Ley 25.326 de Protección de los Datos Personales",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Argentina's Personal Data Protection Act (Ley 25.326 de Protección de los Datos Personales), enacted 4 October 2000 (promulgated 30 October 2000, published in the Official Gazette 2 November 2000), is Latin America's first comprehensive data protection law and remains the foundational data protection framework in Argentina as of April 2026. Argentina has been granted an EU adequacy finding (European Commission Decision 2003/490/EC of 30 June 2003), recognising Argentina as providing adequate protection for personal data transferred from EU member states - one of only two Latin American countries to hold EU adequacy (alongside Uruguay). Enforcement authority: the Agencia de Acceso a la Información Pública (AAIP), established by Decree 746/2017 as successor to the Dirección Nacional de Protección de Datos Personales (DNPDP), is the primary data protection enforcement authority. The habeas data action: Art. 43 of the Argentine Constitution provides a constitutional guarantee known as 'habeas data' - any person may bring a habeas data action before the courts to access, correct, or delete personal data held about them in public registries or in private databases of public utility. This constitutional protection reinforces the statutory framework of Ley 25.326. Key provisions: (1) Data quality principles: personal data must be accurate, adequate, relevant, not excessive for the purpose, and not kept longer than necessary; (2) Sensitive data: data revealing racial origin, political opinions, religious or moral beliefs, health or sexual life, and criminal records - may only be processed with express written consent or in defined exceptional circumstances; (3) Consent: prior, informed, express, and written consent is required for data processing, except where processing is necessary for a pre-contractual or contractual relationship, or required by law; (4) Database registration: all databases (public or private) containing personal data must be registered with the AAIP; unregistered databases may not be used; (5) Data subject rights: right of access (must be provided free of charge, within 30 calendar days), right to rectify or update, right to delete (within 5 business days), right to block, right to oppose; (6) Cross-border transfers: prohibited to countries that do not provide adequate protection, unless exempted by the AAIP or data subject consent; (7) Habeas data action: constitutional right enforceable by summary judicial procedure. Sanctions: the AAIP may impose fines of up to ARS 100 million (subject to periodic adjustment), order database closure, and initiate criminal proceedings. Reform: Argentina has been actively developing a new comprehensive data protection law (Proyecto de Nueva LPDP) to align with GDPR and modernise the 2000 framework - the reform was in advanced stages as of April 2026 but had not yet been enacted.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "gdpr-adequacy-decisions-article-45",
    "coe-convention-108-plus",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}