Law / Peru

Ley 29733, Ley de Protección de Datos Personales

Ley No. 29733, Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 3 July 2011.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain a person's prior, informed, express, and unequivocal consent before processing their personal data, and let them revoke that consent at any time.
  • For sensitive data, obtain that consent in writing; absent a law authorizing processing without it on important public-interest grounds, do not process sensitive data without written consent.
  • Before transferring personal data outside Peru, confirm the destination country maintains an adequate level of protection, or, if it does not, guarantee that the processing will comply with the Law.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Law's own sanctioning scheme is administrative, through fines imposed by the Autoridad Nacional de Protección de Datos Personales; it states that this does not preclude civil damages or criminal sanctions that may separately apply under other law, but it does not itself create a criminal offense for violating its personal-data duties.

Who enforces it

Enforcement body

Autoridad Nacional de Protección de Datos Personales (ANPD), Ministry of Justice and Human Rights

What it reaches

Obligation class

Consent, Biometric, Data subject rights, Transfer, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Law applies to personal data contained or destined to be contained in a personal-data bank of public or private administration whose processing takes place within Peru, and gives special protection to sensitive data; it excludes a bank a natural person creates for purposes exclusively related to their private or family life.

Processing personal data requires the titleholder's consent, which must be prior, informed, express, and unequivocal, and the titleholder may revoke it at any time under the same requirements as its grant. For sensitive data, consent must additionally be given in writing; processing without it is permitted only where a law authorizes it and the processing serves important public-interest grounds.

A cross-border transfer of personal data is permitted only where the receiving country maintains an adequate level of protection under the Law; where it does not, the sender of the transfer must instead guarantee that the processing will comply with the Law, subject to statutory exceptions including a transfer under an international treaty Peru is party to and a transfer the titleholder has consented to.

The Autoridad Nacional de Protección de Datos Personales (ANPD) enforces the Law and may impose administrative fines for its violation or that of its regulation: a minor infraction draws a fine of 0.5 to 5 Tax Units (UIT), a serious infraction more than 5 up to 50 UIT, and a very serious infraction more than 50 up to 100 UIT, in no case exceeding ten percent of the offender's gross annual income for the preceding fiscal year.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; its own operative text is not reproduced here.

When LexLint raises it

  • automated_outreach
  • processes_biometrics

Read the law

consolidated text of Ley 29733
Ley de Protección de Datos Personales, as republished by LP Derecho (Pasión por el Derecho), a Peruvian legal publisher

Back to the example  ·  Lint your app