Law / Panama

Panama

2 of 3 named instruments researched to a stage, across two of the six areas of law we track: 2 in force. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (174 words)

Panama's comprehensive data-protection statute is Ley No. 81 de 26 de marzo de 2019, Sobre Protección de Datos Personales, which entered into force on 29 March 2021, two years after its promulgation.

Decreto Ejecutivo No. 285 de 28 de mayo de 2021 develops the Law's implementation and confirms that entry-into-force date in its own recitals, but the only located copy of the Decreto is served over plain HTTP rather than HTTPS, so it is described here in general terms and not cited as a pinned source.

The Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) is the supervisory authority, and the Law binds any natural or legal person, public or private, that processes personal data.

The Law sets a defined sensitive-data category, conditions cross-border transfers on consent or an equivalent-protection test rather than a localization mandate, arms a data subject with a right against a decision based solely on automated processing that produces a negative legal effect, and sanctions infractions with administrative fines of B/.1,000 to B/.10,000 rather than a criminal penalty.

Comprehensive regime

Ley 81 de 2019, Sobre Protección de Datos Personales

Ley No. 81 de 26 de marzo de 2019, Sobre Protección de Datos Personales, Gaceta Oficial No. 28743-AOfficial Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 1 sets the Law's object as the principles, rights, obligations and procedures governing personal-data protection. Article 1's second paragraph lets any natural or legal person, public or private, for-profit or not, process personal data provided it does so under the Law and for permitted purposes. Article 2 lists nine governing principles, including loyalty (no deceptive or fraudulent collection), purpose limitation, proportionality, veracity, security, and portability.

Article 11 defines a sensitive datum as one touching a person's intimate sphere or whose misuse could cause discrimination or a serious risk, naming racial or ethnic origin and religious, philosophical and moral beliefs among the enumerated examples. Article 13 bars transferring sensitive data except with the data subject's explicit authorization or on narrow statutory grounds.

Article 19 gives a data subject the right not to be subject to a decision based solely on the automated processing of their personal data that produces a negative legal effect or a detriment to a right, where the decision evaluates aspects of personality, health, job performance, creditworthiness, reliability or conduct, unless the subject consented, the decision is necessary to perform a contract, or a special law authorizes it.

Article 33 makes an international transfer of personal data lawful if at least one of several conditions is met, including the data subject's consent or the receiving country or organization providing an equivalent or superior level of protection. ANTAI, with the support of the Autoridad Nacional para la Innovación Gubernamental on information-technology matters, supervises compliance.

Article 47 provides that the Law takes effect two years after its promulgation, and the Law's Gaceta Oficial publication date of 29 March 2019 places that entry into force on 29 March 2021. Decreto Ejecutivo No. 285 de 2021 develops the Law's implementation in coordination with ANTAI and states in its own recitals that this deferred entry into force took effect on 29 March 2021.

What it requires

Scraping law1 instrument, 1 in force

Research summary (223 words)

Panama has no scraping-specific statute, so general law governs each dimension separately.

The Código Penal's computer-crimes chapter criminalizes improperly entering or using a database, network or computer system, and improperly seizing, copying, using or modifying data in transit or held in a database or computer system, both without requiring proof that a technical access control was defeated, so a plain reading reaches unauthorized use of a public, unauthenticated page as well as a password-protected one.

No Panamanian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no statute or reported case establishing a scraping-specific unfair-competition, misappropriation or trespass doctrine, or assigning legal weight to a robots.txt directive or an AI-training-specific rule, was located.

Ley No. 64 de 2012, Panama's current copyright statute, appears to carry a chapter on Bases y Compilaciones de Datos (Bases and Compilations of Data, art. 33) and a text-and-data-mining posture, but no official copy of its full text at a stable, durable address was located, so neither is confirmed here.

Ley No. 81 de 2019, Panama's comprehensive data-protection statute, applies to personal data without a general carve-out for information a person made public themselves, so scraping personal data from a public Panamanian website remains subject to its consent, purpose-limitation and international-transfer duties, and its sensitive-data category reaches a narrower set of scraped identifiers.

Computer misuse

Código Penal, Delitos contra la Seguridad Informática

Código Penal de la República de Panamá (texto único 2010), Libro Segundo, Título VIII, Capítulo I, arts. 289-292Consolidated Código Penal text (texto único 2010) reproduced by the UNODC Sherloc/CLD legislation database

In force. Binds public and private bodies.

What this law does

Article 289 sanctions with two to four years' imprisonment anyone who improperly enters or uses a database, network or computer system.

Article 290 imposes the same two-to-four-year range on anyone who improperly seizes, copies, uses or modifies data in transit or held in a database or computer system, or who interferes with, intercepts, obstructs or prevents its transmission; neither article conditions the offence on defeating a technical security measure, so a plain reading reaches unauthorized use of a public, unauthenticated page as well as a password-protected one.

Article 291 aggravates the penalty by a third to a sixth when the conduct targets data held by a public office, a public, private or mixed institution providing a public service, or a bank, insurer or other financial or securities institution, and aggravates it further when committed for profit.

Article 292 aggravates the penalty by a sixth to a third when the offender is the person in charge of the database or system, a person authorized to access it, or someone who used privileged information to commit the offence. The consolidated text names an adoption date of 15 April 2010 for this compiled version of the Código Penal, but that date marks the compilation rather than a stated commencement day for these specific articles, so no commencement date is recorded here.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.