Law / El Salvador

Ley para la Protección de Datos Personales, personal data breach notification

Decreto Legislativo No. 144, art. 25 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 23 November 2024.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Agencia de Ciberseguridad del Estado, the Fiscalia General de la Republica, and every affected data subject of a personal data breach within seventy two hours of becoming aware of it.
  • Within that same seventy two hours, begin a thorough review of the breach's magnitude, adopt corrective and preventive measures, and update your security policies to prevent a recurrence.
  • Tell the Agencia de Ciberseguridad del Estado, in clear and simple language, the incident's nature, the personal data compromised, the immediate corrective actions taken, recommendations for the data subject, and where to learn more, and give the affected data subject the incident's nature, the data compromised, the recommendations, and where to learn more.
  • Document every breach that risks the security of personal data, noting its date, cause, related facts, effects and corrective measures, and keep that record available to the Agencia de Ciberseguridad del Estado.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 25 requires a responsible party, on learning of a personal data breach in any phase of processing, meaning any damage, loss, alteration, destruction, illegitimate access, or other unlawful or unauthorized use of personal data, including an accidental one, to notify the Agencia de Ciberseguridad del Estado, the Fiscalia General de la Republica, and the affected data subjects, within a maximum period of seventy two hours from becoming aware of the breach.

Within that same seventy two hours the responsible party must begin a thorough review to gauge the breach's magnitude, adopt corrective and preventive measures, and update its security policies.

The notification to the Entidad Rectora must be in clear, simple language and state the incident's nature, the personal data compromised, the immediate corrective actions taken, recommendations to the data subject, and where the data subject can learn more, while the notification to affected data subjects need only carry the incident's nature, the data compromised, the recommendations, and where to learn more.

The responsible party must also document every breach that risks the security of personal data, noting at least its date, cause, related facts, effects, and the corrective measures taken, and keep that record available to the supervisory authority.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Official decree text, Asamblea Legislativa de El Salvador, published Diario Oficial No. 219, Tomo 445, 15 de noviembre de 2024

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app