Ley 25.326, Ley de Protección de los Datos Personales
Ley 25.326, Ley de Protección de los Datos Personales (2000)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 October 2000.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's free, express, and informed consent before processing their personal data, unless it comes from an unrestricted public-access source, is needed for a State function or legal obligation, or falls within a few other narrow exceptions.
- Do not collect or process sensitive data (racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, or health or sexual-life information) except for a public-interest reason authorized by law, or for statistical or scientific purposes that cannot identify the data subject.
- Before transferring personal data outside Argentina, confirm the recipient country or organization provides an adequate level of protection, unless a narrow exception applies.
- Do not base a court decision or administrative act evaluating a person's conduct solely on the result of automated processing that profiles their character or personality.
- Register any file, record, or database intended to provide reports with the National Registry, and limit an advertising or profiling database to data drawn from public sources or the data subject's consent.
- Do not access a personal database without authorization, disclose personal data one is bound to keep secret, or insert data into a personal-data file illegitimately; a heavier penalty applies when the data reaches a genetic-data databank or DNA registry.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Código Penal art. 157 bis, as substituted by Ley 27.759 (2024), punishes unauthorized access to a personal database, disclosure of data one is bound to keep secret, or illegitimate insertion of data, with one month to two years' imprisonment, rising to six months to four years plus two to five years' special disqualification when the conduct reaches a genetic-data databank, DNA registry, examination, or sample; a public officer offender additionally faces one to four years' special disqualification.
Penalty structure
Article 31 sets this statutory range for administrative fines; the enforcement authority's implementing regulation (Resolución AAIP 126/2024, replacing Disposición DNPDP 7/2005 as amended by Resoluciones AAIP 240/2022 and 244/2022) grades it into three severity tiers and caps the aggregate fine for multiple sanctions of identical conduct in one proceeding at five hundred times the applicable tier's maximum fine.
- Rule
- Fixed only
- As of
- 5 September 2026
- Minimum
- 1,000
- Currency
- ARS
- Fixed cap
- 100,000
Who enforces it
Enforcement body
Agencia de Acceso a la Información Pública (AAIP), acting through its Dirección Nacional de Protección de Datos Personales
What it reaches
Obligation class
Consent, Data subject rights, Transfer, Security, Biometric, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Ley 25.326 requires free, express, and informed consent before processing personal data, with exceptions for data from unrestricted public-access sources, data gathered for a State function or legal obligation, and a few other narrow grounds.
Article 7 forbids collecting sensitive data (racial or ethnic origin, political opinions, religious, philosophical, or moral beliefs, union membership, or health or sexual-life information) except for reasons of general public interest authorized by law or for statistical or scientific purposes that cannot identify the data subject.
Article 12 prohibits transferring personal data to a country or international organization that does not provide an adequate level of protection, subject to enumerated exceptions such as international judicial cooperation and treaty-based transfers. Article 20 bars basing a court decision or administrative act that evaluates a person's conduct solely on the result of automated processing that profiles their character or personality.
Article 21 requires registering any file, record, or database intended to provide reports with the National Registry, and article 27 lets a business gather data for advertising or profiling purposes only from sources available to the public or furnished with the data subject's consent.
Article 31 backs the Act with administrative sanctions of warning, suspension, a fine of one thousand to one hundred thousand pesos, or closure of the file, and article 32 inserted articles 117 bis and 157 bis into the Código Penal. Article 157 bis, since substituted by Ley 27.759 in 2024, punishes unauthorized access to, disclosure from, or illegitimate insertion into a personal database with one month to two years' imprisonment.
That penalty rises to six months to four years for conduct reaching a genetic-data databank or DNA registry. Article 33 arms an affected person with a habeas data judicial action to learn what personal data is held and demand its correction, deletion, or confidentiality.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachprocesses_biometrics
Read the law
Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)