Law / Peru

Ley 29733, Ley de Protección de Datos Personales

Ley No. 29733 Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017), arts. 1-10, 12-14, 16-17, 28-31 (object, definitions, scope, principles, lawful processing, security, confidentiality, and personal-data-bank obligations)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 3 July 2011.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain a person's prior, informed, express, and unequivocal consent before processing their personal data, unless a law authorizes the processing without it, and let them revoke that consent at any time under the same requirements that applied when they gave it.
  • Do not collect personal data by fraudulent, unfair, or unlawful means, and collect only data that is updated, necessary, relevant, and adequate to a determined, explicit, and lawful purpose stated at the time of collection.
  • Do not use personal data for a purpose other than the one that justified its collection, unless you first apply an anonymization or dissociation procedure.
  • Adopt technical, organizational, and legal measures that guarantee the security of personal data and prevent its alteration, loss, unauthorized processing, or access, and do not process personal data in a data bank that does not meet the Authority's security requirements.
  • Keep confidential any personal data you hold or process, and continue to do so even after your relationship with the data bank's owner ends.
  • Register your personal-data bank with the Registro Nacional de Protección de Datos Personales before creating it, or, for a bank that predates the Law, declare it to the Authority within the deadline the regulation sets.
  • As a processor handling personal data under contract for a third party, use it only for the purpose the contract states, do not transfer it to anyone else, and delete it once the contract is performed unless the data bank's owner authorized retaining it against a likely further engagement.

What it reaches

Obligation class

Consent, Security, Governance, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 states the Law's object as guaranteeing the constitutional right to personal-data protection, and article 3 applies it to personal data contained or destined to be contained in a personal-data bank of public or private administration whose processing takes place within Peru, excluding a bank a natural person creates for purposes exclusively related to their private or family life and, within the limits it states, a public-administration bank's processing that is strictly necessary for the competencies the law assigns the entity, national defense, public security, or criminal investigation and prosecution.

Articles 4 through 10 and 12 state the Law's guiding principles: legality (no collection by fraudulent, unfair, or unlawful means), consent, purpose limitation, proportionality, quality (data must be truthful, accurate, and kept only as long as the purpose requires), security, and a right of recourse, and article 12 makes the principles interpretive criteria for the whole Law and its regulation.

Article 13 requires the titleholder's prior, informed, express, and unequivocal consent for ordinary processing, revocable at any time under the same requirements as its grant, and article 14 lists the cases where consent is not required, including processing by a public entity within its own competencies, data from publicly accessible sources, and processing necessary to perform a contract the titleholder is party to.

Article 16 requires the data bank's owner to adopt technical, organizational, and legal measures that guarantee security and prevent unauthorized alteration, loss, processing, or access, and bars processing in a data bank that does not meet the Authority's security requirements, while article 17 binds the data bank's owner, its processor, and anyone else who takes part in the processing to confidentiality that survives the end of their relationship with the owner.

Article 28 lists the titleholder's and processor's general obligations, echoing the consent, purpose-limitation, and deletion duties, and requiring cooperation with the Authority's information requests in a pending administrative proceeding.

Article 29 conditions a personal-data bank's creation, modification, or cancellation on the regulation and guarantees public access to its existence, purpose, and ownership; article 30 requires a processor handling data under a service contract to use it only for the contracted purpose, not transfer it further, and delete it once the contract is performed, absent authorization to retain it against a likely further engagement; and article 31 lets private-sector representative bodies adopt conduct codes for their members.

The Law's fifth complementary final provision requires a personal-data bank created before the Law and its regulations to conform to this Law within the deadline the regulation sets, and requires the bank's owner to declare it to the Autoridad Nacional de Protección de Datos Personales, subject to article 29.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; its own operative text is not reproduced here, so no specific provision of it beyond its existence and publication date is described here.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

consolidated text of Ley 29733
Ley de Protección de Datos Personales, as republished by LP Derecho (Pasión por el Derecho), a Peruvian legal publisher

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app