Ley N° 7593/2025, notificación de un incidente de seguridad
Ley 7593/2025, art. 17 (notificacion de un incidente de seguridad)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 434 days, effective 27 November 2027.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This law was enacted on 27 November 2025 but does not take effect until 27 November 2027; what follows applies from that date.
- Notify the National Data Protection Agency, and the affected person where relevant, of a security incident within 72 hours of becoming aware of it.
- Expect the conditions and requirements of that notification to be fixed in the regulation of the law, which article 17 leaves to be issued.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 17 requires the controller, on a personal-data security incident occurring, to notify the supervisory authority and, where applicable, the data subject, within a period that may not exceed seventy-two hours counted from becoming aware of the incident. The conditions and requirements are left to the regulation of the law, which has not been issued.
Article 57 enters the law into force twenty-four months after its official publication, so it is enacted and binds nobody until 27 November 2027.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsoperates_essential_service
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.