Law / Peru

Peru

8 of 9 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 5 September 2026.

When they take effect7 of 8 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 5 instruments (5 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 1
  3. Scraping law 4
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (152 words)

Peru's AI framework rests on Ley No. 31814 (5 July 2023), a short principles-and-authority statute that designates the Secretaría de Gobierno y Transformación Digital (SGTD), within the Presidencia del Consejo de Ministros, as the national technical-regulatory authority for artificial intelligence, but imposes no direct duty on a developer or deployer itself.

Its implementing regulation, Decreto Supremo No. 115-2025-PCM (published 9 September 2025, in force from 22 January 2026), supplies the operative duties: it classifies AI uses as prohibited (uso indebido), high-risk, or otherwise acceptable, applies to both public administration and private-sector organizations, and phases in its private-sector transparency duty by economic sector.

The regulation creates no sanctioning regime of its own; a breach of the data-protection duties it restates is enforced under Ley No. 29733's own regime, and other suspected violations are referred to the competent regulator or the Contraloría General de la República rather than fined directly under this Decreto Supremo.

AI prohibited practices

Reglamento de la Ley 31814, prohibited AI uses

Decreto Supremo 115-2025-PCM, arts. 22-23 (Reglamento de la Ley 31814, Clasificación de Riesgos: Uso Indebido)Reglamento de la Ley No. 31814, approved by Decreto Supremo No. 115-2025-PCM, El Peruano, reproduced by LP Derecho (Pasión por el Derecho)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 22 classifies AI risk into two named categories, uso indebido (misuse, deemed prohibited by definition) and high-risk use, and treats every other use as acceptable risk. Article 23 deems it misuse to influence a person's decision-making in a deceptive or manipulative way, including through subliminal techniques or by exploiting cognitive, emotional, or socioeconomic vulnerabilities to substantially alter behavior.

It is also misuse to generate an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting. Carrying out mass surveillance without a legal basis or where it generates or may generate a disproportionate impact on the exercise of fundamental rights is misuse as well.

So is analyzing, classifying, or inferring a person's sensitive data from their biometric data to deduce racial or ethnic origin, political opinions, union affiliation, religious or philosophical convictions, or sexual life or orientation, or evaluating or classifying natural persons or groups in a way that produces discriminatory or disproportionate results violating fundamental rights.

Carrying out real-time biometric identification to categorize natural persons in public spaces is misuse too, except for pure digital-identity authentication or the preliminary investigation of a defined list of serious crimes. Predicting that a natural person will commit a crime based on profiling or an assessment of personality traits is likewise misuse.

Article 23.4 excepts, specifically from the real-time biometric identification prohibition, a system that supports a human evaluator's assessment of a person's involvement in an existing criminal activity, provided the assessment rests on objective, verifiable facts and the system carries human-oversight, transparency, and auditability mechanisms guaranteeing non-discrimination.

The Regulation applies to public-administration entities and to private-sector organizations, civil society, citizens, and academia, and enters into force ninety business days after its publication. It creates no sanctioning regime of its own for a breach of these prohibitions distinct from referring suspected violations to the competent authority.

What it requires

AI risk obligations

Reglamento de la Ley 31814, high-risk AI system duties

Decreto Supremo 115-2025-PCM, arts. 24-25 (Reglamento de la Ley 31814, Riesgo Alto y Transparencia Algorítmica)Reglamento de la Ley No. 31814, approved by Decreto Supremo No. 115-2025-PCM, El Peruano, reproduced by LP Derecho (Pasión por el Derecho)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 24 classifies an AI-based system's use as high-risk where, among other criteria, it manages critical national assets supporting essential services (energy, telecommunications, health, transport, water, and banking, among others) or is used to evaluate a person in a selection process. A developer or implementer may ask the SGTD to determine whether a use falls within the high-risk category.

Article 25 requires the developer or implementer of a high-risk system to establish mechanisms guaranteeing algorithmic transparency, informing the user beforehand, clearly and simply, of the system's purpose or use, its main functions, and the kind of decisions it can make, and, where the system's decisions affect human rights, to explain its results to affected users in accessible language.

For a private-sector developer or implementer, article 25's transparency duty and a related Title VI chapter phase in gradually by sector, starting the day after the Decreto Supremo's publication: one year for AI uses in health, education, justice, security, and economy-finance; two years for transport, commerce, and labor; three years for production, agriculture, energy, and mining; and four years for every other use nationwide, with a further, longer schedule for small businesses and innovative start-ups.

Public-sector entities implement article 25 on their own graduated schedule, running from one to three years after the Decreto Supremo's publication depending on the type of entity; only for the smallest local governments (Tipo D, E, F, and G) is implementing article 25 described as facultative, according to their resources and capacities.

Article 26 requires compliance with the personal-data and privacy rules in force for any high-risk system's development, implementation, or use, and states that liability for a breach of those data-protection duties is determined under Ley No. 29733's own sanctioning regime rather than under this Decreto Supremo.

What it requires

Privacy law1 instrument, 1 in force

Research summary (200 words)

Peru's comprehensive data-protection regime is Ley No. 29733, Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017), enforced by the Autoridad Nacional de Protección de Datos Personales (ANPD) within the Ministry of Justice and Human Rights.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; the regulation's own text is not reproduced here, so no specific provision of it beyond its existence and publication date is described here.

The Law applies to personal data contained or destined to be contained in a public or private personal-data bank processed within Peru, gives special protection to sensitive data, and requires the titleholder's prior, informed, express, and unequivocal consent for processing, with written consent additionally required for sensitive data absent a law authorizing processing without it on important public-interest grounds.

A cross-border transfer of personal data is permitted only where the receiving country maintains an adequate level of protection under the Law, or, absent that, where the sender guarantees the processing will comply with the Law; several statutory exceptions to this second requirement apply, including a transfer under an international treaty to which Peru is party and a transfer the titleholder has consented to.

Comprehensive regime

Ley 29733, Ley de Protección de Datos Personales

Ley No. 29733, Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

The Law applies to personal data contained or destined to be contained in a personal-data bank of public or private administration whose processing takes place within Peru, and gives special protection to sensitive data; it excludes a bank a natural person creates for purposes exclusively related to their private or family life.

Processing personal data requires the titleholder's consent, which must be prior, informed, express, and unequivocal, and the titleholder may revoke it at any time under the same requirements as its grant. For sensitive data, consent must additionally be given in writing; processing without it is permitted only where a law authorizes it and the processing serves important public-interest grounds.

A cross-border transfer of personal data is permitted only where the receiving country maintains an adequate level of protection under the Law; where it does not, the sender of the transfer must instead guarantee that the processing will comply with the Law, subject to statutory exceptions including a transfer under an international treaty Peru is party to and a transfer the titleholder has consented to.

The Autoridad Nacional de Protección de Datos Personales (ANPD) enforces the Law and may impose administrative fines for its violation or that of its regulation: a minor infraction draws a fine of 0.5 to 5 Tax Units (UIT), a serious infraction more than 5 up to 50 UIT, and a very serious infraction more than 50 up to 100 UIT, in no case exceeding ten percent of the offender's gross annual income for the preceding fiscal year.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; its own operative text is not reproduced here.

What it requires

Scraping law4 instruments, 4 in force

Research summary (366 words)

Peru has no scraping-specific statute, so each dimension is answered from general law.

Unauthorized access to a computer system is criminalized by Ley No. 30096, Ley de Delitos Informáticos (2013), whose article 2 punishes deliberately and illegitimately accessing all or part of a computer system, or exceeding what was authorized, so a scraper reading a public, unauthenticated page without defeating an access control falls outside a plain reading of the offense; a higher penalty tier applies where the agent defeats a security measure to gain access.

Decreto Legislativo 1700 (24 January 2026), as amended by Decreto Legislativo 1741 (13 February 2026), added article 12-A to that same Law, a separate offense for acquiring, possessing, or trafficking computer data, access credentials, or personal databases known or presumed to have been obtained without the titleholder's consent or through a security breach. No Peruvian court decision has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Decreto Legislativo 822, Ley sobre el Derecho de Autor (1996), permits quoting a lawfully disclosed work without the author's consent, subject to proper practice and the extent its purpose justifies, but Peru has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on that general quotation ground where the reproduction can be characterized as a citation rather than a wholesale copy.

The same statute protects an anthology, compilation, or database only where the selection, coordination, or arrangement of its contents is original, and it expressly excludes a database or compilation of data from the personal-use copying privilege it grants for other recordings, so Peru confers no sui generis database right, only a compilation-style copyright conditioned on originality.

Personal-data law reaches scraped personal information from Peruvian websites through Ley No. 29733, Ley de Protección de Datos Personales, which requires a lawful basis and, for sensitive categories, written consent, with no carve-out found here for publicly accessible personal data; that Law is researched in full under the privacy topic rather than repeated here.

No Peruvian statute or reported decision establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine distinct from these enactments, and none assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096)

Decreto Legislativo 1700 (24 January 2026) incorporating art. 12-A into Ley 30096, as amended by Decreto Legislativo 1741 (13 February 2026)official text of Decreto Legislativo 1700

In force. Binds public and private bodies.

What this law does

Article 12-A, incorporated into Ley 30096 by Decreto Legislativo 1700, punishes possessing, buying, receiving, marketing, selling, facilitating, exchanging, or trafficking computer data, access credentials, or personal databases, knowing or having reason to presume they were obtained without the titleholder's consent or through a security breach or the commission of a computer offense, with five to eight years' imprisonment and 180 to 365 day-fines.

The penalty rises to eight to ten years' imprisonment, with disqualification, where the agent acts as a member of a criminal organization, causes serious patrimonial harm or affects a plurality of persons, or the database is processed or held by a public entity.

Decreto Legislativo 1741 widened the article's exemption clause: conduct is exempt from criminal liability where it is carried out with the titleholder's express authorization under Ley 29733, in compliance with a lawful judicial or administrative order, in the legitimate exercise of fundamental rights or legally recognized functions, or as an activity carried out in the securities, financial, pension, or insurance sectors, provided there is no purpose of unlawful gain or improper commercialization of the information. Neither decree states a commencement date for the offense distinct from its own publication.

What it requires

Ley 30096, unauthorized access and data/system integrity offenses

Ley 30096, Ley de Delitos Informáticos (2013), arts. 2-4, 7, 10-12, as amended by Ley 30171 (2014) and Decreto Legislativo 1614 (2023)consolidated text of Ley 30096

In force since 22 October 2013. Binds public and private bodies.

What this law does

Article 2 punishes deliberately and illegitimately accessing all or part of a computer system, or exceeding authorized access, with one to four years' imprisonment and thirty to ninety day-fines; the penalty rises to three to six years' imprisonment and eighty to one hundred twenty day-fines where the agent defeats a security measure to gain access.

Article 3 punishes deliberately and illegitimately damaging, introducing, deleting, deteriorating, altering, suppressing, or making inaccessible computer data, and article 4 punishes deliberately and illegitimately disabling a computer system in whole or in part, impeding access to it, or hindering its operation or the provision of its services, each with three to six years' imprisonment and eighty to one hundred twenty day-fines.

Article 7 punishes deliberately and illegitimately intercepting non-public computer data transmissions to, from, or within a computer system. Article 10 punishes fabricating, designing, developing, selling, facilitating, distributing, importing, or obtaining a mechanism, program, device, password, access code, or other computer data specifically designed to commit one of the Law's offenses.

Article 11 raises the sentence by up to one-third above the legal maximum for any of these offenses where an aggravating circumstance applies, including, since Ley 32314 (29 April 2025), where the agent commits the offense using artificial intelligence or a similar or analogous technology. Article 12 exempts from criminal liability conduct described in articles 2, 3, 4, or 10 undertaken to carry out an authorized test or other authorized procedure to protect computer systems.

What it requires

Copyright and text and data mining (TDM)

Decreto Legislativo 822, quotation exception

Decreto Legislativo 822, art. 44 (quotation exception), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 44 permits quoting from a lawfully disclosed work without the author's consent or payment, provided the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies. The provision is a general quotation exception rather than a text-and-data-mining exception, and Peru has not enacted a distinct exception for automated extraction or analysis of a work's text or data.

This consolidated WIPO Lex text is current to Decreto Legislativo 1391 (2018), whose amendments reach other articles of the statute and not article 44; WIPO Lex flags a further consolidated version as available that is not reproduced here.

What it requires

Database right

Decreto Legislativo 822, protection of compilations and databases

Decreto Legislativo 822 arts. 5(l) and 48 (protection of compilations and databases), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 5(l) protects an anthology or compilation of works or expressions of folklore, and a database, as a protected work only where the collection is original in the selection, coordination, or arrangement of its contents, so Peru confers no sui generis database right and protects a database only under ordinary copyright's originality standard.

Article 48 permits copying a published sound or audiovisual recording for exclusively personal use, but expressly excludes a database or compilation of data from that personal-use privilege.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (230 words)

Peru has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Decreto Legislativo 822, Ley sobre el Derecho de Autor (1996), is the only law reaching an aggregator's reproduction of news content.

Its quotation provision permits quoting a lawfully disclosed work without the author's consent or payment, subject to stating the author's name and source and to the quotation following proper practice and not exceeding what its purpose justifies, and a separate provision permits, without authorization, disseminating by the press or transmitting by any means, as news of current events, speeches, lectures, addresses, sermons, and similar works delivered in public, to the extent the informatory purpose justifies.

Neither provision carries a headline-length or short-extract cap distinct from this proper-practice test, and no reported Peruvian decision applies either provision to a systematic news aggregator as opposed to an individual quoting or reporting a published work.

Peru has enacted no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates, no compelled platform-to-publisher bargaining regime, and no hot-news or misappropriation doctrine distinct from ordinary copyright law.

No statute or case law addresses whether a hyperlink is itself a communication to the public or whether framing or inline display changes the answer, and the statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Decreto Legislativo 822, quotation and news-of-the-day exceptions

Decreto Legislativo 822 arts. 44-45 (quotation and news-of-the-day exceptions), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 44 permits quoting from a lawfully disclosed work without the author's consent or payment, provided the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies.

Article 45(a) permits, without authorization, disseminating images or sounds of a work seen or heard in the course of a current event, by sound or audiovisual means, to the extent an informatory purpose justifies, and article 45(b) permits the press or any transmission medium to disseminate, as news of current events, speeches, lectures, addresses, sermons, and similar works delivered in public, to the extent an informatory purpose justifies and without prejudice to the authors' own right to publish those works individually.

Neither provision carries a headline-length or short-extract cap distinct from this proper-practice and informatory-purpose test, and no reported Peruvian decision applies either provision to a systematic news aggregator rather than an individual quoting or reporting a published work. This consolidated WIPO Lex text is current to Decreto Legislativo 1391 (2018), whose amendments reach other articles of the statute and not articles 44 or 45.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.