Law / Peru

Ley 29733, enforcement, supervisory authority and sanctions

Ley No. 29733, arts. 32-40 and Disposición complementaria final sexta (enforcement, supervisory authority and sanctions)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 3 July 2011.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Autoridad Nacional de Protección de Datos Personales, within the Ministry of Justice and Human Rights, to open an investigation on its own initiative or on complaint, resolve titleholders' claims, and order precautionary or corrective measures or an administrative sanction for a breach of the Law or its regulation.
  • Register your personal-data bank in the Registro Nacional de Protección de Datos Personales, and expect any cross-border data-flow communication, sanction, or precautionary or corrective measure to be recorded there too.
  • Expect a fine of 0.5 to 5 Tax Units (UIT) for a minor infraction, more than 5 up to 50 UIT for a serious infraction, or more than 50 up to 100 UIT for a very serious infraction, capped at ten percent of your gross annual income for the preceding fiscal year, without prejudice to separate civil or criminal liability.
  • Comply with an accessory obligation the sanctioning procedure imposes within its deadline, or expect a coercive fine of up to 10 UIT on top of the underlying sanction.
  • Expect the constitutional habeas data process to remain open to a titleholder independently of, and without first requiring, the Law's own administrative procedure before the Authority.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Law's own sanctioning scheme is administrative, through fines imposed by the Autoridad Nacional de Protección de Datos Personales; it states that this does not preclude civil damages or criminal sanctions that may separately apply under other law, but it does not itself create a criminal offense for violating its personal-data duties.

Who enforces it

Enforcement body

Autoridad Nacional de Protección de Datos Personales (ANPD), Ministry of Justice and Human Rights

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 32 makes the Ministry of Justice, through its Dirección Nacional de Justicia, the Autoridad Nacional de Protección de Datos Personales, empowers it to open offices nationwide, and gives it sanctioning power under the general administrative-procedure law and coercive power under the coercive-execution law.

Article 33 lists the Authority's functions, including representing Peru internationally on data protection, cooperating with foreign authorities, administering the Registro Nacional de Protección de Datos Personales, publishing the registry of public and private data banks, promoting protection of children's and adolescents' data, issuing technical opinions on draft rules touching personal data that are binding, resolving titleholders' claims and ordering precautionary or corrective measures, and opening investigations on its own initiative or on complaint and applying the corresponding administrative sanctions.

Article 34 creates the Registro Nacional de Protección de Datos Personales to record public and private data banks, cross-border data-flow communications, and the sanctions and precautionary or corrective measures the Authority imposes, open to public consultation as to a bank's existence, purpose, and ownership.

Article 35 binds Authority personnel to confidentiality that survives their tenure, and article 36 funds the Authority from administrative fees, fine proceeds, international technical cooperation, and legacies and donations.

Article 37 lets the sanctioning procedure open on the Authority's own initiative or on a complaint, with its resolutions exhausting the administrative channel and reviewable only through a contencioso-administrativo action; article 38 has the regulation classify infractions as minor, serious, or very serious and lets the Authority order corrective measures alongside a sanction, holding a respondent strictly liable for a breach of personal-data-protection duties.

Article 39 sets three fine tiers, a minor infraction from 0.5 to 5 Tax Units (UIT), a serious infraction from more than 5 to 50 UIT, and a very serious infraction from more than 50 to 100 UIT, with the fine never exceeding ten percent of the offender's gross annual income for the prior fiscal year, without prejudice to any disciplinary, civil, or criminal liability that separately applies; and article 40 lets the Authority impose coercive fines of up to 10 UIT for failing to comply with an accessory obligation the sanctioning procedure imposed.

Disposición complementaria final sexta keeps the constitutional habeas data process, under the Código Procesal Constitucional, independent of the Law's own administrative procedure, and states that the administrative procedure is not a precondition for pursuing the constitutional action, so the Law does not itself arm a titleholder with a private cause of action beyond its own administrative channel and that separate constitutional remedy.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • is_listed_company

Read the law

consolidated text of Ley 29733
Ley de Protección de Datos Personales, as republished by LP Derecho (Pasión por el Derecho), a Peruvian legal publisher

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app