Ley 25.326, enforcement, sanctions, and the habeas data action
Ley 25.326, arts. 29-43 (supervisory authority, sanctions, and habeas data)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 30 October 2000.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Give the control body the antecedents, documents, programs, or other elements about your personal-data processing that it requests, and let it verify your compliance with the Act, including through a judicially authorized inspection.
- Expect the control body to impose a warning, suspension, a fine of one thousand to one hundred thousand pesos, or closure of the file for a violation, graded to the violation's gravity and harm under due process, without prejudice to civil or criminal liability.
- Do not access a personal database without authorization, disclose personal data you are bound to keep secret, or insert data into a personal-data file illegitimately; a heavier penalty applies when the conduct reaches a genetic-data databank or DNA registry.
- Register a private-sector code of conduct for personal-data processing practices with the control body before relying on it as your compliance standard.
- Expect an affected person, their guardian, or their universal successor to bring a habeas data judicial action against you to learn, correct, delete, or restrict their personal data, and expect the court's judgment to be reported to the control body's own registry.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Código Penal art. 157 bis, as substituted by Ley 27.759 (2024), punishes unauthorized access to a personal database, disclosure of data one is bound to keep secret, or illegitimate insertion of data, with one month to two years' imprisonment, rising to six months to four years plus two to five years' special disqualification when the conduct reaches a genetic-data databank, DNA registry, examination, or sample; a public officer offender additionally faces one to four years' special disqualification.
Penalty structure
Article 31 sets this statutory range for administrative fines; the enforcement authority's implementing regulation (Resolución AAIP 126/2024, replacing Disposición DNPDP 7/2005 as amended by Resoluciones AAIP 240/2022 and 244/2022) grades it into three severity tiers and caps the aggregate fine for multiple sanctions of identical conduct in one proceeding at five hundred times the applicable tier's maximum fine.
- Rule
- Fixed only
- As of
- 5 September 2026
- Minimum
- 1,000
- Currency
- ARS
- Fixed cap
- 100,000
Who enforces it
Enforcement body
Agencia de Acceso a la Información Pública (AAIP), acting through its Dirección Nacional de Protección de Datos Personales
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 29.1 charges the control body (the AAIP's Dirección Nacional de Protección de Datos Personales) with assisting and advising people about their rights, issuing the rules the Act requires, keeping a census and permanent registry of databases, controlling compliance with data-integrity and security rules, with judicial authorization to inspect premises, equipment, or processing programs, requesting information and records from public and private entities, imposing the administrative sanctions the Act allows, acting as a private prosecutor in a criminal case the Act's violation brings, and controlling a private reporting database's registration requirements.
Article 30 lets an association or entity representing private-sector database controllers or users draft a professional code of conduct for personal-data processing, and requires the control body to register it, which it may refuse where the code does not conform to the applicable rules.
Article 31 lets the control body impose a warning, suspension, a fine of one thousand to one hundred thousand pesos, or closure of the file, without prejudice to any public-sector administrative liability, civil damages, or criminal sanction, graded to the violation's gravity and harm under due process; the enforcement authority's implementing regulation, Resolución AAIP 126/2024, grades these into three severity tiers and caps the aggregate fine for identical multiple sanctions in one proceeding at five hundred times the applicable tier's maximum.
Article 32 inserted articles 117 bis and 157 bis into the Código Penal; article 157 bis, since substituted by Ley 27.759 in 2024, punishes unauthorized access to, disclosure from, or illegitimate insertion into a personal database with one month to two years' imprisonment. The penalty rises to six months to four years, with a further two to five years' special disqualification from practising the profession, for conduct reaching a genetic-data databank or a DNA record, examination or sample.
Articles 33 to 43 arm an affected person, their guardian, or their universal successor with a habeas data judicial action against a public or private reporting database's controller or user, heard by the judge of the plaintiff's or defendant's domicile or of the place the act had effect, with federal jurisdiction over a national public database or one interconnected across jurisdictions, following the ordinary amparo procedure and, where the record's falsity or inaccuracy is manifest, letting the judge provisionally block the file pending the court's judgment, which must be reported to the control body's own registry.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachprocesses_biometrics
Read the law
Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.