Law / Paraguay

Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay

Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 437 days, effective 27 November 2027.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • This law was enacted on 27 November 2025 but does not take effect until 27 November 2027; what follows applies from that date.
  • Establish a valid legal basis, such as the data subject's consent or a contract, before processing any personal data, and make sure any consent obtained is prior, free, informed and unambiguous.
  • Treat racial or ethnic origin, religious or political belief, health, sexual orientation, genetic data and biometric data used to uniquely identify a person as sensitive data, and process it only on one of the law's narrow grounds.
  • Honor a data subject's rights of access, rectification, deletion, objection and portability, free of charge, and let them contest an automated or semi-automated decision made about them.
  • Notify the National Data Protection Agency, and the affected person where relevant, of a security incident within 72 hours of becoming aware of it.
  • Before transferring personal data outside Paraguay, confirm the destination offers an adequate level of protection or put in place safeguards such as standard contractual clauses, binding corporate rules or a code of conduct.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Who enforces it

Enforcement body

Agencia Nacional de Protección de Datos Personales

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Breach notice, DPIA, Governance, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 states the object of the law as the integral protection of the personal data of natural persons, guaranteeing the full exercise of their rights and the free flow of information. Article 2 applies the law to any automated or non-automated processing of personal data forming part of a file, by natural or legal persons, and Chapter V of Title II extends its rules into the public sector as well as the private one.

Article 5 requires at least one lawful basis, such as the data subject's consent or a legal obligation, before personal data may be processed, and article 6 requires that consent be prior, free, informed and unambiguous.

Article 3 defines personal data sensibles to include racial or ethnic origin, religious or political belief, health, sexual orientation, genetic data and biometric data aimed at uniquely identifying a person, and article 20 prohibits processing sensitive data except on narrow grounds such as the data subject's own consent or a case where the person has manifestly made the data public.

Article 17 requires the controller to notify the Control Authority, and the data subject where applicable, of a security incident within 72 hours of becoming aware of it. Article 19 permits an international transfer of personal data only where the destination country, territory or organization offers an adequate level of protection as the Agency determines, or where the controller adopts appropriate safeguards such as standard contractual clauses, binding corporate rules or a code of conduct.

Articles 26 through 33 give a data subject rights of access, rectification, deletion, objection, portability and a right to contest an automated or semi-automated decision.

Article 34 creates the National Personal Data Protection Agency as an independent supervisory authority within the Ministry of Information and Communication Technologies, and article 41 lets a data subject seek judicial compensation for damages from a violation of their data-protection rights, alongside the constitutional habeas data action.

Article 46 sets administrative fines from 20 up to 2,500 minimum daily wages, rising to 5,000 for infractions involving sensitive data and to 10,000 for infractions involving the sensitive data of children or adolescents, none of which are stated as a fixed currency amount. Article 57 provides that the law enters into force twenty-four months after its official publication, and the law was promulgated and published on 27 November 2025.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_biometrics

Read the law

Official text of Ley N° 7593/2025, published by the Biblioteca y Archivo Central del Congreso Nacional (BACN)

Back to the example  ·  Lint your app