Law / Panama

Panama

7 of 8 named instruments researched to a stage, across two of the six areas of law we track: 7 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (222 words)

Panama's comprehensive data-protection statute is Ley No. 81 de 26 de marzo de 2019, Sobre Protección de Datos Personales, which entered into force on 29 March 2021, two years after its promulgation.

Decreto Ejecutivo No. 285 de 28 de mayo de 2021 develops the Law's implementation and confirms that entry into force date in its own recitals, but the only located copy of the Decreto is served over plain HTTP rather than HTTPS, so it is described here in general terms and not cited as a pinned source.

The Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) is the supervisory authority, and the Law binds any natural or legal person, public or private, that processes personal data.

Reading the Law provision by provision surfaces a sensitive personal data regime, a data subject rights chapter, a cross border transfer regime conditioning transfer on consent or an equivalent protection test rather than a localization mandate, and a breach notification duty running to the data subject alone, with no fixed clock and no parallel duty to notify ANTAI, alongside the general regime and its enforcement chapter.

The Law sanctions infractions with administrative fines of B/.1,000 to B/.10,000 graduated by severity rather than a criminal penalty, and lets a data subject sue for damages in the ordinary courts on top of that administrative sanction.

Breach notification

Ley 81 de 2019, personal data breach notification

Ley 81 de 2019, arts. 2(5) and 26 (duty to notify security breaches)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 2(5), among the Law's general principles, requires a responsible party to inform the data subject as soon as possible when their personal data has been stolen without authorization or there is sufficient indication that its security has been compromised, alongside the technical and organizational measures the same principle requires to protect data under the responsible party's custody.

The Law fixes no number of hours or days for that notice, and states no parallel duty to notify the Autoridad Nacional de Transparencia y Acceso a la Información of a breach. Article 26 carries a sector specific duty for an operator of a public communications network, requiring it to tell affected data subjects about a particular breach of its network's security and the measures it is taking, again with no fixed period and no notice to a supervisory authority stated.

What it requires

Comprehensive regime

Ley 81 de 2019, Sobre Protección de Datos Personales

Ley No. 81 de 26 de marzo de 2019 Sobre Protección de Datos Personales, Gaceta Oficial No. 28743-A, arts. 1-4, 6-12, 14, 24-32, 44 and 47 (general provisions, lawful basis and accountability)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 1 sets the Law's object as the principles, rights, obligations and procedures that govern personal data protection, and lets any natural or legal person, public or private, for profit or not, process personal data provided it does so under the Law and for permitted purposes.

Article 6 conditions any processing of personal data on the data subject's consent, contractual necessity, a legal obligation, or authorization under a special law, requires the person consenting to be duly informed of the purpose, and lets consent be revoked without retroactive effect.

Article 11 confines personal data to the determined, explicit and lawful purposes disclosed when it was collected, and bars any other use absent the data subject's consent, a special law, contractual necessity, or a public entity's legal functions or a judicial order. Article 9 obliges everyone with access to personal data, in public or private organizations, to keep it confidential when it did not come from a source open to the public, an obligation that survives the end of their involvement.

Article 14 makes a database custodian answerable for damages its own lack of due diligence causes. Article 26 requires an operator of a public communications network to adopt technical and management measures that secure its network and services to the standard this Law sets. Article 27 requires an online collector to present an accessible privacy policy or terms of service, set apart from other terms in clear and simple language where consent is bundled with them.

Article 28 bars disclosing or communicating data identifying a person once seven years have passed since the legal duty to retain it ended, unless that data subject expressly asks otherwise.

Article 29 confines a public entity's processing of personal data to matters within its own competence, and article 30 bars a public entity from disclosing a data subject's criminal or disciplinary record once the underlying sanction has lapsed or been served, except to a competent court or another public body bound to the same confidentiality.

Article 24 requires a database custodian to hand stored or transferred personal data to a competent judicial authority on a properly substantiated request, and bars any mass request for personal data outright.

Articles 31 and 32 require a registry of every database disclosed to third parties, naming the database, its legal basis, how it is obtained and treated, its recipients, retention periods and everyone who accessed it, and require a disclosure request itself to identify the requester and purpose, notify the data subject, and state how long the data will be used and how it will be destroyed.

Article 44 extends the Law's rights to personal data already held in a database that existed before the Law took effect. Article 47 sets the Law's entry into force two years after its promulgation, and the Law's 29 March 2019 Gaceta Oficial publication places that entry into force on 29 March 2021.

What it requires

Cross border transfer

Ley 81 de 2019, cross border transfer of personal data

Ley 81 de 2019, arts. 5 and 33 (cross border transfer of personal data)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 5 subjects a database located in Panama, or whose responsible party is domiciled there, to this Law, and permits storing or transferring confidential, sensitive or restricted data with cross border treatment only where the responsible party meets this Law's data protection standards or standards equal to or higher than it, unless the data subject consented, a contract requires the transfer, it is a banking, monetary or securities transfer, or an international treaty Panama has ratified compels it.

Article 33 makes an international transfer of personal data lawful if at least one of thirteen listed conditions is met, among them the data subject's consent, the receiving country or organization providing an equivalent or superior level of protection, a treaty or law to which Panama is party, medical necessity, transfer within the same corporate group, a contract in the data subject's unequivocal interest, a public interest or legal defense need, judicial cooperation, a banking or securities transaction, international intelligence cooperation against organized crime, a binding self-regulation mechanism, or contractual clauses that meet this Law's protections, and holds both the transferring party and the recipient responsible for the lawfulness of the processing transferred.

What it requires

Data subject rights

Ley 81 de 2019, rights of data subjects

Ley 81 de 2019, arts. 15-19 and 21-23 (rights of data subjects)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 15 gives every data subject the irrenounceable rights of access, rectification, cancellation, opposition and portability, including a structured, commonly used, machine readable copy of their personal data that can be moved to another responsible party, at least where the data subject supplied the data directly, a relevant volume of automated processing is involved, or the data subject consented or a contract requires it.

Article 16 requires a response to an access request within ten business days, free of charge, and article 17 requires an inaccurate, erroneous or incomplete datum to be corrected within five business days of the request, letting the Autoridad Nacional de Transparencia y Acceso a la Información decide when a datum is inaccurate or unfounded.

Article 18 lets a data subject take an unanswered request to that Authority, which may then demand information and carry out verifications limited to the complaint presented.

Article 19 gives a data subject the right not to be subject to a decision based solely on the automated processing of their personal data that produces a negative legal effect or a detriment to a right, evaluating aspects such as personality, health, job performance, creditworthiness, reliability or conduct, unless the subject consented, the decision is necessary to perform a contract, or a special law authorizes it.

Article 21 bars limiting a data subject's access, revocation, cancellation, opposition or blocking rights by any act or agreement between parties, voiding any clause that tries. Article 22 lets a data subject reach any one of several responsible parties feeding a shared database.

Article 23 withholds an information, rectification, cancellation or blocking request where it would impede a pending administrative or judicial process or state security, and withholds rectification, cancellation or blocking of data a legal mandate requires to be kept, outside the cases special laws allow. Article 44 extends these rights to personal data already held in a database that existed before the Law took effect.

What it requires

Enforcement supervision

Ley 81 de 2019, enforcement and sanctions

Ley 81 de 2019, arts. 34-37 and 38-46 (enforcement, sanctions and offences)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 34 creates the Consejo de Protección de Datos Personales as a consultative body drawing members from government ministries, regulators, the private sector, the bar and the banking industry, and article 35 gives it the power to advise the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI), recommend public policy, and evaluate submitted cases.

Article 36 empowers ANTAI to sanction a responsible party or database custodian found, on investigation of a complaint, to have infringed a data subject's rights, sets fines from B/.1,000 to B/.10,000 graduated by the infraction's gravity, and allows reconsideration before ANTAI's own Dirección and appeal to its director general.

Article 37 lets a data subject sue a responsible party in the ordinary courts for patrimonial or moral damage its unlawful processing caused, independent of ANTAI's administrative sanction.

Articles 38 to 41 classify infractions as minor, serious or very serious, minor being a late report to ANTAI, serious spanning consent failures, principle violations, breach of confidentiality, obstructing a data subject's rights, or failing to secure stored data, and very serious spanning bad faith collection, violating the sensitive data rules, ignoring an ANTAI suspension order, an unlawful international transfer, or repeating a serious infraction.

Article 43 sanctions a minor infraction with a citation, a serious infraction with a proportionate fine, and a very serious infraction with closure of the database's registries or suspension of the processing activity in addition to a fine, treats repetition of the same infraction within three years as recidivism, and requires every sanctioned fact to be documented so ANTAI can weigh gravity, repetition or recidivism.

Articles 45 and 46 give ANTAI its own budget line to carry out the Law and task the Órgano Ejecutivo with regulating the Law in coordination with ANTAI.

What it requires

Sensitive categories

Ley 81 de 2019, sensitive personal data

Ley 81 de 2019, arts. 4(11), 8, 13 and 20 (sensitive personal data)Official Legispan text of Ley 81 de 2019, Asamblea Nacional de Panamá

In force since 29 March 2021. Binds public and private bodies.

What this law does

Article 4(11) defines a sensitive datum as one touching a person's intimate sphere, or whose misuse could cause discrimination or a serious risk, naming racial or ethnic origin, religious, philosophical or moral belief, union affiliation, political opinion, health, sexual orientation, and genetic or biometric data among the enumerated examples.

Article 13 bars transferring sensitive data at all, except with the data subject's explicit authorization, to safeguard the life of a data subject who cannot consent, for the recognition or defense of a right in a judicial proceeding, or for a historical, statistical or scientific purpose that first dissociates the data subject's identity.

Article 8 requires consent to processing sensitive health data to be prior, irrefutable and express, a heightened standard above the ordinary consent article 6 sets. Article 20 lets a public or private health establishment or medical professional collect and process the health data of its own patients, subject to professional secrecy and this Law.

What it requires

Scraping law1 instrument, 1 in force

Research summary (223 words)

Panama has no scraping-specific statute, so general law governs each dimension separately.

The Código Penal's computer-crimes chapter criminalizes improperly entering or using a database, network or computer system, and improperly seizing, copying, using or modifying data in transit or held in a database or computer system, both without requiring proof that a technical access control was defeated, so a plain reading reaches unauthorized use of a public, unauthenticated page as well as a password-protected one.

No Panamanian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no statute or reported case establishing a scraping-specific unfair-competition, misappropriation or trespass doctrine, or assigning legal weight to a robots.txt directive or an AI-training-specific rule, was located.

Ley No. 64 de 2012, Panama's current copyright statute, appears to carry a chapter on Bases y Compilaciones de Datos (Bases and Compilations of Data, art. 33) and a text-and-data-mining posture, but no official copy of its full text at a stable, durable address was located, so neither is confirmed here.

Ley No. 81 de 2019, Panama's comprehensive data-protection statute, applies to personal data without a general carve-out for information a person made public themselves, so scraping personal data from a public Panamanian website remains subject to its consent, purpose-limitation and international-transfer duties, and its sensitive-data category reaches a narrower set of scraped identifiers.

Computer misuse

Código Penal, Delitos contra la Seguridad Informática

Código Penal de la República de Panamá (texto único 2010), Libro Segundo, Título VIII, Capítulo I, arts. 289-292Consolidated Código Penal text (texto único 2010) reproduced by the UNODC Sherloc/CLD legislation database

In force. Binds public and private bodies.

What this law does

Article 289 sanctions with two to four years' imprisonment anyone who improperly enters or uses a database, network or computer system.

Article 290 imposes the same two-to-four-year range on anyone who improperly seizes, copies, uses or modifies data in transit or held in a database or computer system, or who interferes with, intercepts, obstructs or prevents its transmission; neither article conditions the offence on defeating a technical security measure, so a plain reading reaches unauthorized use of a public, unauthenticated page as well as a password-protected one.

Article 291 aggravates the penalty by a third to a sixth when the conduct targets data held by a public office, a public, private or mixed institution providing a public service, or a bank, insurer or other financial or securities institution, and aggravates it further when committed for profit.

Article 292 aggravates the penalty by a sixth to a third when the offender is the person in charge of the database or system, a person authorized to access it, or someone who used privileged information to commit the offence. The consolidated text names an adoption date of 15 April 2010 for this compiled version of the Código Penal, but that date marks the compilation rather than a stated commencement day for these specific articles, so no commencement date is recorded here.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.