Law / Argentina

Ley 25.326, Ley de Protección de los Datos Personales

Ley 25.326, Ley de Protección de los Datos Personales (2000)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 30 October 2000.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain the data subject's free, express, and informed consent before processing their personal data, unless it comes from an unrestricted public-access source, is needed for a State function or legal obligation, or falls within a few other narrow exceptions.
  • Do not collect or process sensitive data (racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, or health or sexual-life information) except for a public-interest reason authorized by law, or for statistical or scientific purposes that cannot identify the data subject.
  • Before transferring personal data outside Argentina, confirm the recipient country or organization provides an adequate level of protection, unless a narrow exception applies.
  • Do not base a court decision or administrative act evaluating a person's conduct solely on the result of automated processing that profiles their character or personality.
  • Register any file, record, or database intended to provide reports with the National Registry, and limit an advertising or profiling database to data drawn from public sources or the data subject's consent.
  • Do not access a personal database without authorization, disclose personal data one is bound to keep secret, or insert data into a personal-data file illegitimately; a heavier penalty applies when the data reaches a genetic-data databank or DNA registry.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Código Penal art. 157 bis, as substituted by Ley 27.759 (2024), punishes unauthorized access to a personal database, disclosure of data one is bound to keep secret, or illegitimate insertion of data, with one month to two years' imprisonment, rising to six months to four years plus two to five years' special disqualification when the conduct reaches a genetic-data databank, DNA registry, examination, or sample; a public officer offender additionally faces one to four years' special disqualification.

Penalty structure

Article 31 sets this statutory range for administrative fines; the enforcement authority's implementing regulation (Resolución AAIP 126/2024, replacing Disposición DNPDP 7/2005 as amended by Resoluciones AAIP 240/2022 and 244/2022) grades it into three severity tiers and caps the aggregate fine for multiple sanctions of identical conduct in one proceeding at five hundred times the applicable tier's maximum fine.

Rule
Fixed only
As of
5 September 2026
Minimum
1,000
Currency
ARS
Fixed cap
100,000

Who enforces it

Enforcement body

Agencia de Acceso a la Información Pública (AAIP), acting through its Dirección Nacional de Protección de Datos Personales

What it reaches

Obligation class

Consent, Data subject rights, Transfer, Security, Biometric, Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Ley 25.326 requires free, express, and informed consent before processing personal data, with exceptions for data from unrestricted public-access sources, data gathered for a State function or legal obligation, and a few other narrow grounds.

Article 7 forbids collecting sensitive data (racial or ethnic origin, political opinions, religious, philosophical, or moral beliefs, union membership, or health or sexual-life information) except for reasons of general public interest authorized by law or for statistical or scientific purposes that cannot identify the data subject.

Article 12 prohibits transferring personal data to a country or international organization that does not provide an adequate level of protection, subject to enumerated exceptions such as international judicial cooperation and treaty-based transfers. Article 20 bars basing a court decision or administrative act that evaluates a person's conduct solely on the result of automated processing that profiles their character or personality.

Article 21 requires registering any file, record, or database intended to provide reports with the National Registry, and article 27 lets a business gather data for advertising or profiling purposes only from sources available to the public or furnished with the data subject's consent.

Article 31 backs the Act with administrative sanctions of warning, suspension, a fine of one thousand to one hundred thousand pesos, or closure of the file, and article 32 inserted articles 117 bis and 157 bis into the Código Penal. Article 157 bis, since substituted by Ley 27.759 in 2024, punishes unauthorized access to, disclosure from, or illegitimate insertion into a personal database with one month to two years' imprisonment.

That penalty rises to six months to four years for conduct reaching a genetic-data databank or DNA registry. Article 33 arms an affected person with a habeas data judicial action to learn what personal data is held and demand its correction, deletion, or confidentiality.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • processes_biometrics

Read the law

Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

Back to the example  ·  Lint your app