Law / Argentina

Argentina

9 of 14 named instruments researched to a stage, across three of the six areas of law we track: 9 in force. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 9 instruments (9 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (257 words)

Argentina's comprehensive data-protection regime is Ley 25.326 de Protección de los Datos Personales (2000), one of the earliest such statutes in Latin America, enforced by the Agencia de Acceso a la Información Pública (AAIP) through its Dirección Nacional de Protección de Datos Personales.

The Act defines personal data broadly, without carving out publicly accessible information, but excuses the consent requirement specifically for data drawn from unrestricted public-access sources and a short list of other grounds.

Its closed list of sensitive categories covers racial or ethnic origin, political opinions, religious, philosophical, or moral convictions, union membership, and health or sexual-life data, but names no biometric identifier, so a faceprint or voiceprint stays inside the Act's general rules rather than its heightened sensitive-data rules.

Data subjects hold statutory rights to be informed at collection, to access, rectify, update, or erase their records, and to challenge a decision based solely on automated profiling, all enforceable through a judicial habeas data action.

It restricts cross-border transfer to countries or organizations that do not provide an adequate level of protection, and backs administrative sanctions with two Código Penal offenses, articles 117 bis and 157 bis, the second most recently amended in 2024 to add an aggravated penalty for genetic-data databanks; the Act states no breach-notification duty to the authority or to an affected person.

Multiple bills to replace the 25-year-old Act with a General Data Protection Regulation (GDPR)-aligned regime, including a 2023 executive-branch proposal that later lost parliamentary status and newer 2025-2026 legislator bills, remain before Congress; none has passed either chamber as of this writing.

Comprehensive regime

Ley 25.326, Ley de Protección de los Datos Personales

Ley 25.326 Ley de Protección de los Datos Personales (2000), arts. 1-5, 9-11, 21-28, 47 (general regime, data quality, security, confidentiality, disclosure, registration, and sector rules)Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Ley 25.326 requires free, express, and informed consent before processing personal data, with exceptions for data from unrestricted public-access sources, data gathered for a State function or legal obligation, short listings limited to name and identifying numbers, data arising from a contractual, scientific, or professional relationship, and financial-entity customer data under Ley 21.526.

Article 4 requires personal data to be true, adequate, relevant, and not excessive for the purpose it was obtained, collected lawfully, used only for the purpose that motivated its collection, kept accurate and updated, corrected or deleted when found inaccurate or incomplete, stored so the data subject's access right can be exercised, and destroyed once no longer necessary.

Article 9 requires the controller or user of a database to adopt the technical and organizational measures needed to guarantee security and confidentiality and to detect deviations, and bars registering personal data in a file that lacks the technical conditions of integrity and security.

Article 10 binds the controller and everyone who takes part in processing to professional secrecy, surviving the end of their relationship with the database's owner, relievable only by judicial order or for public-security, national-defense, or public-health reasons.

Article 11 lets personal data be disclosed to a third party only for a purpose directly tied to the legitimate interest of both discloser and recipient and with the data subject's prior, revocable consent naming the purpose and the recipient, subject to listed exceptions including a legal mandate, an inter-agency transfer within the same competence, health data needed for public-health or epidemiological reasons under dissociation, or already-dissociated data; the recipient takes on the discloser's same legal obligations and the discloser answers jointly for their observance.

Article 21 requires registering any public or private database intended to provide reports with the National Registry, stating the controller's identity, the file's characteristics and purpose, how data is collected and updated, its recipients, its security measures, its retention period, and how a data subject can exercise their rights, and bars holding data of a different nature than what is declared; article 24 extends that registration duty to any private-sector file not for exclusively personal use.

Article 22 requires a public body to create, modify, or suppress a database only by a general disposition published in the Official Gazette stating the file's characteristics and purpose, the people it covers, how data is obtained and updated, its structure, its planned disclosures or interconnections, the responsible body, and where a data subject can exercise their rights.

Article 23 limits a military, security, police, or intelligence body's processing of personal data for national-defense or public-security purposes, taken without the data subject's consent, to what is strictly necessary for its legally assigned missions, requires the resulting files to be specific and classified by reliability, and requires police-purpose data to be cancelled once no longer needed for the inquiry that justified it.

Article 25 bars a data-processing service provider from using the personal data it processes for a purpose other than the one in the service contract or from disclosing it to others, and requires it to destroy the data once the contracted service ends unless further engagements are reasonably expected, in which case it may keep the data securely for up to two years.

Article 26 limits a credit-information service to patrimonial solvency and credit data obtained from public sources or the data subject's own information or consent, and to payment-default data furnished by the creditor, caps what may be filed or disclosed to the last five years significant to evaluating the person's solvency (two years once the debt is cancelled or otherwise extinguished), and requires disclosing to the data subject on request what was reported about them in the last six months.

Article 27 lets a business collect data for advertising, direct-marketing, or profiling purposes only from sources accessible to the public or furnished by, or with the consent of, the data subject. Article 28 exempts opinion-poll, market-research, and scientific or medical-research data from the Act only while it cannot be attributed to an identifiable person, and requires a dissociation technique where anonymity cannot otherwise be kept during collection.

Article 47, added in 2008, required a credit-reporting database to purge and stop recording delinquency or Central Bank risk-category 2 to 5 entries tied to obligations that fell due between 1 January 2000 and 10 December 2003, once the debt was cancelled or regularized, and required the original creditor to notify any database it had disclosed the default to of that cancellation.

What it requires

Cross border transfer

Ley 25.326, cross-border transfer

Ley 25.326, art. 12 (cross-border transfer)Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Article 12.1 prohibits transferring personal data of any kind to a country or international or supranational organization that does not provide an adequate level of protection.

Article 12.2 narrows the prohibition to exempt international judicial cooperation, health-data exchange the affected person's treatment or an epidemiological investigation requires, carried out under the dissociation safeguard article 11.3.d states, banking or securities transfers governed by their own applicable law, a transfer agreed under a treaty to which Argentina is a party, and intelligence-agency cooperation against organized crime, terrorism, or drug trafficking.

What it requires

Data subject rights

Ley 25.326, rights of data subjects

Ley 25.326, arts. 6, 13-17, 19-20, 27.3 (data subject rights)Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Article 6 requires telling a data subject, before their personal data is collected, the purpose for which it will be processed and the recipients or classes of recipients, that a file, registry, or database exists together with its controller's identity and address, whether answering the questionnaire is mandatory or optional, the consequences of providing the data, refusing to, or giving inaccurate data, and that they may exercise access, rectification, and erasure rights.

Article 13 lets any person query the control body's public, free registry to learn what personal-data files exist, their purposes, and their controllers' identity.

Article 14 gives the data subject, once their identity is verified, the right to request and obtain their personal data from a public or private reporting database, to be answered within ten running days, exercisable free of charge at intervals no shorter than six months absent a legitimate interest, and exercisable by a deceased person's universal successors.

Article 15 requires the information to be given clearly, without codes, in plain language, covering the subject's whole record without revealing a third party's data, in the medium of the data subject's choice.

Article 16 gives a data subject the right to have their inaccurate, incomplete, or outdated personal data rectified, updated, or, where appropriate, deleted or made confidential, requires the controller to act within five business days of the claim or of learning of the error, requires notifying any recipient the data were disclosed to within five business days, bars erasure where it would harm a third party's legitimate rights or a legal duty requires retention, and requires marking a record under review while its accuracy is verified.

Article 17 lets a public database's controller deny access, rectification, or erasure by a reasoned decision grounded in national defense, public order and security, or a third party's rights, or where disclosure would obstruct an ongoing tax, welfare, health, environmental, or criminal-law inquiry, subject to notifying the affected person with reasons and still giving access when the person needs it to exercise a legal defense.

Article 19 makes rectification, updating, or erasure of inaccurate or incomplete personal data free of charge. Article 20 bars basing a court decision or administrative act that evaluates a person's conduct solely on the result of automated processing that profiles their character or personality, and voids an act that does so. Article 27.3 lets a data subject request the removal or blocking of their name from an advertising, direct-marketing, or profiling database at any time.

What it requires

Enforcement supervision

Ley 25.326, enforcement, sanctions, and the habeas data action

Ley 25.326, arts. 29-43 (supervisory authority, sanctions, and habeas data)Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Article 29.1 charges the control body (the AAIP's Dirección Nacional de Protección de Datos Personales) with assisting and advising people about their rights, issuing the rules the Act requires, keeping a census and permanent registry of databases, controlling compliance with data-integrity and security rules, with judicial authorization to inspect premises, equipment, or processing programs, requesting information and records from public and private entities, imposing the administrative sanctions the Act allows, acting as a private prosecutor in a criminal case the Act's violation brings, and controlling a private reporting database's registration requirements.

Article 30 lets an association or entity representing private-sector database controllers or users draft a professional code of conduct for personal-data processing, and requires the control body to register it, which it may refuse where the code does not conform to the applicable rules.

Article 31 lets the control body impose a warning, suspension, a fine of one thousand to one hundred thousand pesos, or closure of the file, without prejudice to any public-sector administrative liability, civil damages, or criminal sanction, graded to the violation's gravity and harm under due process; the enforcement authority's implementing regulation, Resolución AAIP 126/2024, grades these into three severity tiers and caps the aggregate fine for identical multiple sanctions in one proceeding at five hundred times the applicable tier's maximum.

Article 32 inserted articles 117 bis and 157 bis into the Código Penal; article 157 bis, since substituted by Ley 27.759 in 2024, punishes unauthorized access to, disclosure from, or illegitimate insertion into a personal database with one month to two years' imprisonment. The penalty rises to six months to four years, with a further two to five years' special disqualification from practising the profession, for conduct reaching a genetic-data databank or a DNA record, examination or sample.

Articles 33 to 43 arm an affected person, their guardian, or their universal successor with a habeas data judicial action against a public or private reporting database's controller or user, heard by the judge of the plaintiff's or defendant's domicile or of the place the act had effect, with federal jurisdiction over a national public database or one interconnected across jurisdictions, following the ordinary amparo procedure and, where the record's falsity or inaccuracy is manifest, letting the judge provisionally block the file pending the court's judgment, which must be reported to the control body's own registry.

What it requires

Sensitive categories

Ley 25.326, sensitive data categories and health data

Ley 25.326, arts. 7-8 (sensitive data categories and health data)Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Article 7.1 bars requiring any person to provide sensitive data, defined in article 2 as data revealing racial or ethnic origin, political opinions, religious, philosophical, or moral convictions, union membership, or health or sexual-life information; article 7.2 permits collecting and processing it only for reasons of general interest authorized by law, or for statistical or scientific purposes where the data subject cannot be identified.

Article 7.3 bars forming a file, bank, or registry whose purpose is to store information that directly or indirectly reveals sensitive data, but excepts a membership registry the Catholic Church, a religious association, or a political or union organization keeps of its own members. Article 7.4 confines processing of a person's criminal or administrative-offense record to the competent public authorities acting under the applicable laws and regulations.

Article 8 lets a public or private health establishment, or a health professional, collect and process a patient's physical or mental health data under the rules of professional secrecy. The Act's closed sensitive-data list names no biometric identifier, so a faceprint, fingerprint, or voiceprint falls within the Act's general rules rather than this heightened regime.

What it requires

Scraping law3 instruments, 3 in force

Research summary (220 words)

Argentina has no scraping-specific statute, so general law reaches each dimension separately. Código Penal article 153 bis criminalizes knowingly accessing, without due authorization or exceeding the authorization held, a computer system or data of restricted access, but the offense's own restricted-access qualifier means a plain reading does not reach a public, unauthenticated page carrying no access control; no case law testing that reading in a scraping context was located.

No Argentine court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

Ley 11.723 protects data compilations as literary works, subject to the ordinary originality threshold, so Argentina has no sui generis database right distinct from copyright; its quotation exception permits including up to one thousand words of a literary or scientific work, or eight musical measures, for didactic or scientific commentary, criticism, or notes, but Argentina has not enacted a text-and-data-mining exception for training a model on scraped copyrighted text.

Ley 25.326 applies to personal data without excluding information obtained from public sources from its definition of covered personal data, though it excuses the consent requirement specifically where the data comes from an unrestricted public-access source. No Argentine statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Código Penal, art. 153 bis, unauthorized access to a restricted computer system or data

Código Penal (Ley 11.179, texto ordenado), art. 153 bis, incorporated by Ley N° 26.388 (B.O. 25/6/2008)Official consolidated text of the Código Penal, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 25 June 2008. Binds public and private bodies.

What this law does

Article 153 bis punishes with fifteen days to six months' imprisonment, if the act is not a more severely punished offense, a person who knowingly accesses, by any means, without due authorization or exceeding the authorization held, a computer system or data of restricted access. The penalty rises to one month to one year's imprisonment when the access harms a system or data belonging to a state public body or a public-services or financial-services provider.

Because the offense's own text requires the system or data to be one 'de acceso restringido' (of restricted access), a plain reading does not reach reading a public, unauthenticated page that carries no access-control barrier such as a password, permission, or authentication requirement; no reported Argentine decision testing that reading against a web-scraping fact pattern was located.

What it requires

Copyright and text and data mining (TDM)

Ley 11.723, art. 10, quotation exception

Ley 11.723, Régimen Legal de la Propiedad Intelectual, art. 10Official consolidated text of Ley 11.723, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 September 1933. Binds public and private bodies.

What this law does

Article 10 lets anyone publish, for didactic or scientific purposes, commentary, criticism, or notes on intellectual works, including up to one thousand words of a literary or scientific work, or eight musical measures, and only the indispensable portions of the text for that purpose; the same provision reaches teaching works, collections, anthologies, and similar compilations.

Article 1 protects, among literary and scientific works, source and object computer programs and data compilations, so Argentina protects a compilation as a copyright work rather than through a separate sui generis database right, subject to the same originality standard as any other work. Article 1 also states that copyright protection reaches the expression of ideas, procedures, operating methods, and mathematical concepts but not those ideas, procedures, methods, and concepts themselves.

Argentina has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general quotation exception if it can be characterized as didactic or scientific commentary within the one-thousand-word or eight-measure limits.

What it requires

Personal data

Ley 25.326, personal data reached by scraping

Ley 25.326, Ley de Protección de los Datos Personales, arts. 2 and 5Official consolidated text of Ley 25.326, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 October 2000. Binds public and private bodies.

What this law does

Ley 25.326 defines personal data as information of any kind referring to identified or identifiable individuals or corporations, without excluding information that is publicly accessible, so scraping personal data from a public Argentine website does not by itself remove the data from the Act's coverage.

Article 5.2.a excuses the consent requirement specifically where the data is obtained from an unrestricted public-access source, but that exception is textually confined to consent, leaving the Act's other duties, registration of the resulting file or database, data quality, security, and the cross-border transfer restriction in article 12, applicable to a scraper that becomes the person in charge of, or user of, a database intended to provide reports.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (202 words)

Argentina has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, and no located statute or case law addressing hyperlinking or framing liability specifically.

The relevant instrument is Ley 11.723, Régimen Legal de la Propiedad Intelectual, whose article 28 makes unsigned articles, anonymous contributions, and other original material acquired by a newspaper, magazine, or news agency with exclusivity the property of that outlet, while letting news of general interest be used, transmitted, or retransmitted freely, provided the source is stated when the item is reproduced in its original form; that provision functions as a hot-news-like exclusivity confined to exclusively acquired content rather than a general facts exclusion, and no reported Argentine decision applying it to a systematic news aggregator, as opposed to a competing outlet, was located.

Article 10 separately lets anyone quote up to one thousand words of a literary or scientific work, or eight musical measures, for didactic or scientific commentary, criticism, or notes, and article 27 bars publishing a political or literary speech, or a lecture on an intellectual subject, without the author's express authorization, except for press reporting on it. The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Ley 11.723, news exclusivity, speeches, and quotation exception

Ley 11.723, Régimen Legal de la Propiedad Intelectual, arts. 10, 27, and 28Official consolidated text of Ley 11.723, InfoLEG (Ministerio de Justicia y Derechos Humanos)

In force since 30 September 1933. Binds public and private bodies.

What this law does

Article 28 makes unsigned articles, anonymous contributions, reports, drawings, engravings, or other original material acquired by a newspaper, magazine, or other periodical, or by a news agency, with exclusivity, the property of that outlet or agency; general-interest news, by contrast, may be used, transmitted, or retransmitted, though its source must be stated whenever it is published in its original form.

Article 27 bars publishing a political or literary speech, or a lecture on an intellectual subject, without the author's express authorization, and separately bars publishing a parliamentary speech for profit without the author's authorization, except for press reporting on it.

Article 10 lets anyone publish, for didactic or scientific purposes, commentary, criticism, or notes on intellectual works, including up to one thousand words of a literary or scientific work or eight musical measures, limited to the portions indispensable for that purpose; it carries no headline-length cap distinct from that word count and is not confined to the press industry.

No reported Argentine decision applies article 28's exclusivity rule, or article 10's quotation exception, to a systematic news aggregator as opposed to a competing news outlet or an individual quoting a published work. Argentina has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.