What this law does
Article 1 states the Act's object as protecting a natural or legal person against automated or non-automated processing of their personal data held in public or private data files, to guarantee the right to personal and family privacy and the right to informational self determination, and article 2 applies it to the processing of personal data found in public and private data files alike.
Article 4 makes creating a data file lawful only when it is duly authorized and registered with the data subject's consent, unless the law excepts it, and bars a data file from serving a purpose other than one this Act permits. Article 5 requires that personal data be obtained only when adequate, proportional and necessary to the purpose for which it is collected and only by lawful means that guarantee the right to informational self determination.
Article 6 makes the data subject's consent, given by the data subject or their legal representative in writing or another suitable physical or electronic means and revocable without retroactive effect, the general basis for delivering personal data, except where a competent judicial authority so orders, the data first undergo a dissociation procedure, the purpose is to perform obligations arising from a legal relationship between the data subject and the controller, or the data are drawn from an unrestricted public access source and limited to name, national identity document number, and date of birth.
Article 9 requires that all processing be adequate, proportional, and necessary to the purpose for which the data were requested, and requires the data controller and, where applicable, the data processor, to adopt the technical and organizational measures necessary to guarantee the security of personal data and prevent unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination.
Article 11 requires the data controller to adopt the technical and organizational measures necessary to guarantee the integrity, confidentiality, and security of personal data, to prevent its corruption, loss, unauthorized consultation, processing, disclosure, transfer, or dissemination, and to detect intentional or unintentional deviations of private information, whether the risk comes from human action or the technical medium used.
Article 12 binds the data controller and anyone who takes part in any phase of processing personal data to professional secrecy, an obligation that survives the end of their relationship with the data controller, releasable only by judicial order and only for reasons of national security, national defense, public security, or public health.
Article 13 lets personal data be assigned or transferred domestically only for purposes directly related to the legitimate interest of the assignor and the assignee and with the data subject's prior consent, informed of the purpose of the assignment and the assignee's identity, revocable by written notice, except where a law so provides, the assignment is between state institutions in the exercise of their powers, it concerns public health, social interest, or national security, or a dissociation procedure has been applied.
Article 19, item f, limits the retention of personal data to five years, or to the term the parties' contract sets, or until the data are no longer adequate, proportional, and necessary for the purpose for which they were requested.
Article 22 requires every data controller to register with the data file register the Direccion de Proteccion de Datos Personales keeps, to wait thirty days for its registration decision, and to record the controller's name and domicile, the nature of the data held, how and when data are collected and updated, the data's destination and recipients, how the records interrelate, the security measures used, the retention period, and how a person can exercise their rights over the file.
Article 23 lets a public or private data file be created, modified, or extinguished only under this Act's provisions, which must state the file's characteristics and purpose, whose data it seeks, whether supplying it is mandatory or optional, and, on suppression, the file's destination or the measures taken to destroy it.
Article 54 excludes from this Act's application the information handled and regulated by the Comision Nacional de Microfinanzas, the Superintendencia de Bancos y de Otras Instituciones Financieras, the entities those regulators supervise, information exchanged under reciprocal supervisory agreements, and private credit bureaus handling credit information, without prejudice to this Act's general principles, the data subject's rights, and its other limitations.
What it requires