Ley 25.326, Ley de Protección de los Datos Personales
Ley 25.326 Ley de Protección de los Datos Personales (2000), arts. 1-5, 9-11, 21-28, 47 (general regime, data quality, security, confidentiality, disclosure, registration, and sector rules)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 30 October 2000.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain the data subject's free, express, and informed consent before processing their personal data, unless it comes from an unrestricted public-access source, is needed for a State function or legal obligation, is limited to a short listing of name and identifying numbers, arises from a contractual, scientific, or professional relationship, or is financial-entity customer data covered by Ley 21.526.
- Collect only personal data that is true, adequate, relevant, and not excessive for the purpose you obtained it, use it only for that purpose, keep it accurate and updated, correct or delete it once you learn it is inaccurate or incomplete, store it so the data subject's access right can be exercised, and destroy it once it is no longer necessary.
- Adopt the technical and organizational measures needed to guarantee the security and confidentiality of personal data and to detect unauthorized or accidental deviations, and do not register personal data in a file that lacks adequate technical integrity and security conditions.
- Keep personal data confidential during and after your involvement in processing it, and disclose it to a third party only for a purpose tied to both parties' legitimate interest and with the data subject's prior, revocable, informed consent naming the purpose and the recipient, unless a listed exception applies.
- Register any database intended to provide reports, public or private, with the National Registry before operating it, stating your identity, the file's purpose, its data sources, recipients, security measures, retention period, and how a data subject can exercise their rights, and do not hold data of a kind you did not declare.
- As a public body, create, modify, or suppress a database only through a general disposition published in the Official Gazette that states the file's characteristics and purpose, how data is obtained and updated, and where a data subject can exercise their rights.
- As a military, security, police, or intelligence body, limit consent-free processing of personal data for defense or public-security purposes to what your legally assigned mission strictly requires, keep the resulting files specific and classified by reliability, and cancel police-purpose data once it is no longer needed for the inquiry that justified it.
- As a data-processing service provider acting for another party, use the personal data only for the purpose stated in the service contract, do not disclose it to others, and destroy it once the contracted service ends unless further engagements are reasonably expected, in which case you may keep it securely for up to two years.
- As a credit-information service, process only patrimonial solvency and credit data from public sources or the data subject's own information or consent and payment-default data the creditor furnishes, keep it no longer than five years significant to evaluating solvency (two years once the debt is cancelled or extinguished), and disclose to the data subject on request what was reported about them in the last six months.
- Build an advertising, direct-marketing, or profiling database only from sources accessible to the public or furnished by, or with the consent of, the data subject.
- Treat opinion-poll, market-research, or scientific-research data as outside this Act only while it cannot be attributed to an identifiable person, and apply a dissociation technique where anonymity cannot otherwise be kept during collection.
- If you operate a credit-reporting database, purge and stop recording any delinquency or Central Bank risk-category 2 to 5 entry tied to an obligation that fell due between January 1, 2000 and December 10, 2003 once the debt is cancelled or regularized, and tell any database you disclosed the original default to about the cancellation.
What it reaches
Obligation class
Consent, Security, Retention, Governance, Disclosure, Contract terms
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Ley 25.326 requires free, express, and informed consent before processing personal data, with exceptions for data from unrestricted public-access sources, data gathered for a State function or legal obligation, short listings limited to name and identifying numbers, data arising from a contractual, scientific, or professional relationship, and financial-entity customer data under Ley 21.526.
Article 4 requires personal data to be true, adequate, relevant, and not excessive for the purpose it was obtained, collected lawfully, used only for the purpose that motivated its collection, kept accurate and updated, corrected or deleted when found inaccurate or incomplete, stored so the data subject's access right can be exercised, and destroyed once no longer necessary.
Article 9 requires the controller or user of a database to adopt the technical and organizational measures needed to guarantee security and confidentiality and to detect deviations, and bars registering personal data in a file that lacks the technical conditions of integrity and security.
Article 10 binds the controller and everyone who takes part in processing to professional secrecy, surviving the end of their relationship with the database's owner, relievable only by judicial order or for public-security, national-defense, or public-health reasons.
Article 11 lets personal data be disclosed to a third party only for a purpose directly tied to the legitimate interest of both discloser and recipient and with the data subject's prior, revocable consent naming the purpose and the recipient, subject to listed exceptions including a legal mandate, an inter-agency transfer within the same competence, health data needed for public-health or epidemiological reasons under dissociation, or already-dissociated data; the recipient takes on the discloser's same legal obligations and the discloser answers jointly for their observance.
Article 21 requires registering any public or private database intended to provide reports with the National Registry, stating the controller's identity, the file's characteristics and purpose, how data is collected and updated, its recipients, its security measures, its retention period, and how a data subject can exercise their rights, and bars holding data of a different nature than what is declared; article 24 extends that registration duty to any private-sector file not for exclusively personal use.
Article 22 requires a public body to create, modify, or suppress a database only by a general disposition published in the Official Gazette stating the file's characteristics and purpose, the people it covers, how data is obtained and updated, its structure, its planned disclosures or interconnections, the responsible body, and where a data subject can exercise their rights.
Article 23 limits a military, security, police, or intelligence body's processing of personal data for national-defense or public-security purposes, taken without the data subject's consent, to what is strictly necessary for its legally assigned missions, requires the resulting files to be specific and classified by reliability, and requires police-purpose data to be cancelled once no longer needed for the inquiry that justified it.
Article 25 bars a data-processing service provider from using the personal data it processes for a purpose other than the one in the service contract or from disclosing it to others, and requires it to destroy the data once the contracted service ends unless further engagements are reasonably expected, in which case it may keep the data securely for up to two years.
Article 26 limits a credit-information service to patrimonial solvency and credit data obtained from public sources or the data subject's own information or consent, and to payment-default data furnished by the creditor, caps what may be filed or disclosed to the last five years significant to evaluating the person's solvency (two years once the debt is cancelled or otherwise extinguished), and requires disclosing to the data subject on request what was reported about them in the last six months.
Article 27 lets a business collect data for advertising, direct-marketing, or profiling purposes only from sources accessible to the public or furnished by, or with the consent of, the data subject. Article 28 exempts opinion-poll, market-research, and scientific or medical-research data from the Act only while it cannot be attributed to an identifiable person, and requires a dissociation technique where anonymity cannot otherwise be kept during collection.
Article 47, added in 2008, required a credit-reporting database to purge and stop recording delinquency or Central Bank risk-category 2 to 5 entries tied to obligations that fell due between 1 January 2000 and 10 December 2003, once the debt was cancelled or regularized, and required the original creditor to notify any database it had disclosed the default to of that cancellation.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachprocesses_biometrics
Read the law
Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.