Ley 29733, Ley de Protección de Datos Personales
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 3 July 2011.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain a person's prior, informed, express, and unequivocal consent before processing their personal data, and let them revoke that consent at any time.
- For sensitive data, obtain that consent in writing; absent a law authorizing processing without it on important public-interest grounds, do not process sensitive data without written consent.
- Before transferring personal data outside Peru, confirm the destination country maintains an adequate level of protection, or, if it does not, guarantee that the processing will comply with the Law.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Law's own sanctioning scheme is administrative, through fines imposed by the Autoridad Nacional de Protección de Datos Personales; it states that this does not preclude civil damages or criminal sanctions that may separately apply under other law, but it does not itself create a criminal offense for violating its personal-data duties.
Who enforces it
Enforcement body
Autoridad Nacional de Protección de Datos Personales (ANPD), Ministry of Justice and Human Rights
What it reaches
Obligation class
Consent, Biometric, Data subject rights, Transfer, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Law applies to personal data contained or destined to be contained in a personal-data bank of public or private administration whose processing takes place within Peru, and gives special protection to sensitive data; it excludes a bank a natural person creates for purposes exclusively related to their private or family life.
Processing personal data requires the titleholder's consent, which must be prior, informed, express, and unequivocal, and the titleholder may revoke it at any time under the same requirements as its grant. For sensitive data, consent must additionally be given in writing; processing without it is permitted only where a law authorizes it and the processing serves important public-interest grounds.
A cross-border transfer of personal data is permitted only where the receiving country maintains an adequate level of protection under the Law; where it does not, the sender of the transfer must instead guarantee that the processing will comply with the Law, subject to statutory exceptions including a transfer under an international treaty Peru is party to and a transfer the titleholder has consented to.
The Autoridad Nacional de Protección de Datos Personales (ANPD) enforces the Law and may impose administrative fines for its violation or that of its regulation: a minor infraction draws a fine of 0.5 to 5 Tax Units (UIT), a serious infraction more than 5 up to 50 UIT, and a very serious infraction more than 50 up to 100 UIT, in no case exceeding ten percent of the offender's gross annual income for the preceding fiscal year.
The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; its own operative text is not reproduced here.
When LexLint raises it
automated_outreachprocesses_biometrics
Read the law
consolidated text of Ley 29733
Ley de Protección de Datos Personales, as republished by LP Derecho (Pasión por el Derecho), a Peruvian legal publisher