Law / El Salvador

Ley para la Protección de Datos Personales, enforcement and sanctions

Decreto Legislativo No. 144, arts. 35 and 50-59 (enforcement, infractions and sanctions)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 23 November 2024.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Agencia de Ciberseguridad del Estado (ACE) to supervise, inspect, and exercise sanctioning power over you under this Law, and to issue mandatory operating policies and security measures you must follow.
  • Expect a fine of one to ten monthly minimum wages of the commercial sector for a minor infraction, eleven to twenty five for a serious infraction, and twenty six to forty for a very serious infraction, without prejudice to any civil or criminal liability the same conduct also carries.
  • Expect ACE to order remedial measures beyond a fine, and to publish its sanctioning resolutions on its website with personal data dissociated or anonymized.
  • Carry the burden of proving that you obtained consent or delivered the privacy notice, and, for an international transfer, that the transfer was lawful.
  • Do not process personal data without prior consent, deny an ARCO-POL request, use a child's data without parental consent, reverse a pseudonymization, or use, transfer, share or commercialize personal data in violation of this Law.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 57 fines a minor infraction one to ten, a serious infraction eleven to twenty five, and a very serious infraction twenty six to forty monthly minimum wages of the commercial sector. That is a multiple of a wage rather than a currency amount, so penalty_structure carries no figure: coding it would state a cap in dollars the statute does not. Article 58 preserves civil or criminal liability arising elsewhere rather than creating it.

Who enforces it

Enforcement body

Agencia de Ciberseguridad del Estado (ACE)

What it reaches

Obligation class

Governance, Reporting, Prohibition

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 35 gives the Entidad Rectora, the Agencia de Ciberseguridad del Estado (ACE), power to dictate mandatory policies for managing personal data.

Article 50 lists ACE's attributes, among them supervising and inspecting obligated institutions, exercising sanctioning power, issuing provisional measures, promoting public awareness, resolving disputes over sensitive data classification, supporting responsible parties technically, cooperating with other supervisory authorities, issuing operating policies and security measures, certifying data protection compliance and auditing those certifications yearly, training public and private institutions, publishing implementation guides, and requesting information from public and private entities.

Article 51 gives the ACE Director General these powers except the power to sanction, which a separately appointed Director of Data Protection exercises through delegated administrative sanctioning proceedings, and article 52 sets that Director's qualifications. Article 53 applies the Ley de Ciberseguridad y Seguridad de la Informacion's sanctioning procedure and prescription rules to this Law's infractions.

Article 54 puts the burden of proving consent or delivery of the privacy notice on the responsible party, and the burden of proving a lawful international transfer on the party that transferred the data. Article 55 requires ACE to publish every sanctioning resolution on its website, in a version with personal data dissociated or anonymized.

Article 56 classifies infractions as minor, such as failing to inform a data subject of their rights, not publishing the processor's contact details, failing to notify a breach, unauthorized database access, inaccurate processing, altering an authorization document, charging for a free service, breaching the information or public sector notice duties, or ignoring an ACE request, serious, such as incomplete or inaccurate access responses, unanswered ARCO POL requests, repurposed processing, obstructing an ACE audit, ignoring ACE technical measures, breaching the article 59 prohibitions, or ignoring ACE security policies, and very serious, such as processing without prior consent, denying ARCO POL requests, using a child's data without parental consent, processing an incapacitated person's data without consent, an unlawful international transfer, an unconsented transfer, commercializing personal data, reversing pseudonymization, processing after a revoked consent, or ignoring a valid revocation.

Article 57 fines a minor infraction one to ten, a serious infraction eleven to twenty five, and a very serious infraction twenty six to forty monthly minimum wages of the commercial sector. Article 58 lets ACE order remedial measures on top of a fine and preserves the infractor's civil or criminal liability.

Article 59 bars a responsible party from creating a sensitive data database unlawfully, processing racial, ethnic, political, religious, health, or sexual orientation data outside this Law's sensitive data rules, disclosing personal data learned through one's position, or using, transferring, sharing or commercializing personal data in violation of this Law.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Official decree text, Asamblea Legislativa de El Salvador, published Diario Oficial No. 219, Tomo 445, 15 de noviembre de 2024

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app