Ley 81 de 2019, Sobre Protección de Datos Personales
Ley No. 81 de 26 de marzo de 2019 Sobre Protección de Datos Personales, Gaceta Oficial No. 28743-A, arts. 1-4, 6-12, 14, 24-32, 44 and 47 (general provisions, lawful basis and accountability)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 29 March 2021.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Have a lawful basis, such as consent, contractual necessity or a legal obligation, before processing a person's personal data, and use it only for the purpose for which it was collected.
- Keep confidential any personal data you access that did not come from a source open to the public, even after your relationship to the processing ends.
- Present a clear, distinguishable privacy notice before collecting personal data online, and keep any bundled consent request identifiable from the rest of the terms.
- Maintain a registry of every database you disclose to third parties, covering its legal basis, its contents, who receives it, retention periods and everyone who accessed it, and produce that registry to ANTAI on request.
- Before disclosing personal data to a requester, identify the requester and the purpose, notify the data subject, and record how long the requester will hold the data and how it will be destroyed, unless the data subject has consented.
- Do not disclose personal data identifying a person once seven years have passed since your legal duty to retain it ended, unless that data subject asks you to.
- Hand over stored personal data to a competent judicial authority only on a properly substantiated request, never in response to a bulk request, and, if you operate a public communications network, maintain the security measures this Law requires to protect it.
What it reaches
Obligation class
Consent, Governance, Security, Disclosure, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 sets the Law's object as the principles, rights, obligations and procedures that govern personal data protection, and lets any natural or legal person, public or private, for profit or not, process personal data provided it does so under the Law and for permitted purposes.
Article 6 conditions any processing of personal data on the data subject's consent, contractual necessity, a legal obligation, or authorization under a special law, requires the person consenting to be duly informed of the purpose, and lets consent be revoked without retroactive effect.
Article 11 confines personal data to the determined, explicit and lawful purposes disclosed when it was collected, and bars any other use absent the data subject's consent, a special law, contractual necessity, or a public entity's legal functions or a judicial order. Article 9 obliges everyone with access to personal data, in public or private organizations, to keep it confidential when it did not come from a source open to the public, an obligation that survives the end of their involvement.
Article 14 makes a database custodian answerable for damages its own lack of due diligence causes. Article 26 requires an operator of a public communications network to adopt technical and management measures that secure its network and services to the standard this Law sets. Article 27 requires an online collector to present an accessible privacy policy or terms of service, set apart from other terms in clear and simple language where consent is bundled with them.
Article 28 bars disclosing or communicating data identifying a person once seven years have passed since the legal duty to retain it ended, unless that data subject expressly asks otherwise.
Article 29 confines a public entity's processing of personal data to matters within its own competence, and article 30 bars a public entity from disclosing a data subject's criminal or disciplinary record once the underlying sanction has lapsed or been served, except to a competent court or another public body bound to the same confidentiality.
Article 24 requires a database custodian to hand stored or transferred personal data to a competent judicial authority on a properly substantiated request, and bars any mass request for personal data outright.
Articles 31 and 32 require a registry of every database disclosed to third parties, naming the database, its legal basis, how it is obtained and treated, its recipients, retention periods and everyone who accessed it, and require a disclosure request itself to identify the requester and purpose, notify the data subject, and state how long the data will be used and how it will be destroyed.
Article 44 extends the Law's rights to personal data already held in a database that existed before the Law took effect. Article 47 sets the Law's entry into force two years after its promulgation, and the Law's 29 March 2019 Gaceta Oficial publication places that entry into force on 29 March 2021.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.