Law / Peru

Peru

13 of 14 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 1 proposed. As of 19 September 2026.

When they take effect11 of 13 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 9 instruments (9 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 5
  3. Scraping law 4
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (152 words)

Peru's AI framework rests on Ley No. 31814 (5 July 2023), a short principles-and-authority statute that designates the Secretaría de Gobierno y Transformación Digital (SGTD), within the Presidencia del Consejo de Ministros, as the national technical-regulatory authority for artificial intelligence, but imposes no direct duty on a developer or deployer itself.

Its implementing regulation, Decreto Supremo No. 115-2025-PCM (published 9 September 2025, in force from 22 January 2026), supplies the operative duties: it classifies AI uses as prohibited (uso indebido), high-risk, or otherwise acceptable, applies to both public administration and private-sector organizations, and phases in its private-sector transparency duty by economic sector.

The regulation creates no sanctioning regime of its own; a breach of the data-protection duties it restates is enforced under Ley No. 29733's own regime, and other suspected violations are referred to the competent regulator or the Contraloría General de la República rather than fined directly under this Decreto Supremo.

AI prohibited practices

Reglamento de la Ley 31814, prohibited AI uses

Decreto Supremo 115-2025-PCM, arts. 22-23 (Reglamento de la Ley 31814, Clasificación de Riesgos: Uso Indebido)Reglamento de la Ley No. 31814, approved by Decreto Supremo No. 115-2025-PCM, El Peruano, reproduced by LP Derecho (Pasión por el Derecho)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 22 classifies AI risk into two named categories, uso indebido (misuse, deemed prohibited by definition) and high-risk use, and treats every other use as acceptable risk. Article 23 deems it misuse to influence a person's decision-making in a deceptive or manipulative way, including through subliminal techniques or by exploiting cognitive, emotional, or socioeconomic vulnerabilities to substantially alter behavior.

It is also misuse to generate an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting. Carrying out mass surveillance without a legal basis or where it generates or may generate a disproportionate impact on the exercise of fundamental rights is misuse as well.

So is analyzing, classifying, or inferring a person's sensitive data from their biometric data to deduce racial or ethnic origin, political opinions, union affiliation, religious or philosophical convictions, or sexual life or orientation, or evaluating or classifying natural persons or groups in a way that produces discriminatory or disproportionate results violating fundamental rights.

Carrying out real-time biometric identification to categorize natural persons in public spaces is misuse too, except for pure digital-identity authentication or the preliminary investigation of a defined list of serious crimes. Predicting that a natural person will commit a crime based on profiling or an assessment of personality traits is likewise misuse.

Article 23.4 excepts, specifically from the real-time biometric identification prohibition, a system that supports a human evaluator's assessment of a person's involvement in an existing criminal activity, provided the assessment rests on objective, verifiable facts and the system carries human-oversight, transparency, and auditability mechanisms guaranteeing non-discrimination.

The Regulation applies to public-administration entities and to private-sector organizations, civil society, citizens, and academia, and enters into force ninety business days after its publication. It creates no sanctioning regime of its own for a breach of these prohibitions distinct from referring suspected violations to the competent authority.

What it requires

AI risk obligations

Reglamento de la Ley 31814, high-risk AI system duties

Decreto Supremo 115-2025-PCM, arts. 24-25 (Reglamento de la Ley 31814, Riesgo Alto y Transparencia Algorítmica)Reglamento de la Ley No. 31814, approved by Decreto Supremo No. 115-2025-PCM, El Peruano, reproduced by LP Derecho (Pasión por el Derecho)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 24 classifies an AI-based system's use as high-risk where, among other criteria, it manages critical national assets supporting essential services (energy, telecommunications, health, transport, water, and banking, among others) or is used to evaluate a person in a selection process. A developer or implementer may ask the SGTD to determine whether a use falls within the high-risk category.

Article 25 requires the developer or implementer of a high-risk system to establish mechanisms guaranteeing algorithmic transparency, informing the user beforehand, clearly and simply, of the system's purpose or use, its main functions, and the kind of decisions it can make, and, where the system's decisions affect human rights, to explain its results to affected users in accessible language.

For a private-sector developer or implementer, article 25's transparency duty and a related Title VI chapter phase in gradually by sector, starting the day after the Decreto Supremo's publication: one year for AI uses in health, education, justice, security, and economy-finance; two years for transport, commerce, and labor; three years for production, agriculture, energy, and mining; and four years for every other use nationwide, with a further, longer schedule for small businesses and innovative start-ups.

Public-sector entities implement article 25 on their own graduated schedule, running from one to three years after the Decreto Supremo's publication depending on the type of entity; only for the smallest local governments (Tipo D, E, F, and G) is implementing article 25 described as facultative, according to their resources and capacities.

Article 26 requires compliance with the personal-data and privacy rules in force for any high-risk system's development, implementation, or use, and states that liability for a breach of those data-protection duties is determined under Ley No. 29733's own sanctioning regime rather than under this Decreto Supremo.

What it requires

Privacy law5 instruments, 5 in force

Research summary (317 words)

Peru's comprehensive data-protection regime is Ley No. 29733, Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017), enforced by the Autoridad Nacional de Protección de Datos Personales (ANPD) within the Ministry of Justice and Human Rights.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; the regulation's own text is not reproduced here, so no specific provision of it beyond its existence and publication date is described here.

The Law applies to personal data contained or destined to be contained in a public or private personal-data bank processed within Peru, gives special protection to sensitive data including biometric identifiers, health, and origin information, requires written consent for processing it, and defers special measures for a child's or adolescent's data to the regulation while requiring them to exercise their rights through a legal representative in the meantime.

It grants the titleholder rights of information, access, rectification, deletion, opposition to supply, objection, protection from a decision based solely on automated evaluation of personality or conduct, and a claim to the Authority or a constitutional habeas data action where those rights are denied.

A cross-border transfer of personal data is permitted only where the receiving country maintains an adequate level of protection under the Law, or, absent that, where the sender guarantees the processing will comply with the Law; several statutory exceptions to this second requirement apply, including a transfer under an international treaty to which Peru is party and a transfer the titleholder has consented to.

The Authority enforces the Law through investigations, precautionary and corrective measures, and administrative fines reaching ten percent of an offender's gross annual income, but the reviewed text of the Law itself states no duty to notify the Authority or an affected person of a personal-data breach; that duty, if any, would have to come from the regulation, whose own text is not reproduced here.

Comprehensive regime

Ley 29733, Ley de Protección de Datos Personales

Ley No. 29733 Ley de Protección de Datos Personales (2011), as amended by Decreto Legislativo 1353 (2017), arts. 1-10, 12-14, 16-17, 28-31 (object, definitions, scope, principles, lawful processing, security, confidentiality, and personal-data-bank obligations)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

Article 1 states the Law's object as guaranteeing the constitutional right to personal-data protection, and article 3 applies it to personal data contained or destined to be contained in a personal-data bank of public or private administration whose processing takes place within Peru, excluding a bank a natural person creates for purposes exclusively related to their private or family life and, within the limits it states, a public-administration bank's processing that is strictly necessary for the competencies the law assigns the entity, national defense, public security, or criminal investigation and prosecution.

Articles 4 through 10 and 12 state the Law's guiding principles: legality (no collection by fraudulent, unfair, or unlawful means), consent, purpose limitation, proportionality, quality (data must be truthful, accurate, and kept only as long as the purpose requires), security, and a right of recourse, and article 12 makes the principles interpretive criteria for the whole Law and its regulation.

Article 13 requires the titleholder's prior, informed, express, and unequivocal consent for ordinary processing, revocable at any time under the same requirements as its grant, and article 14 lists the cases where consent is not required, including processing by a public entity within its own competencies, data from publicly accessible sources, and processing necessary to perform a contract the titleholder is party to.

Article 16 requires the data bank's owner to adopt technical, organizational, and legal measures that guarantee security and prevent unauthorized alteration, loss, processing, or access, and bars processing in a data bank that does not meet the Authority's security requirements, while article 17 binds the data bank's owner, its processor, and anyone else who takes part in the processing to confidentiality that survives the end of their relationship with the owner.

Article 28 lists the titleholder's and processor's general obligations, echoing the consent, purpose-limitation, and deletion duties, and requiring cooperation with the Authority's information requests in a pending administrative proceeding.

Article 29 conditions a personal-data bank's creation, modification, or cancellation on the regulation and guarantees public access to its existence, purpose, and ownership; article 30 requires a processor handling data under a service contract to use it only for the contracted purpose, not transfer it further, and delete it once the contract is performed, absent authorization to retain it against a likely further engagement; and article 31 lets private-sector representative bodies adopt conduct codes for their members.

The Law's fifth complementary final provision requires a personal-data bank created before the Law and its regulations to conform to this Law within the deadline the regulation sets, and requires the bank's owner to declare it to the Autoridad Nacional de Protección de Datos Personales, subject to article 29.

The current implementing regulation is Decreto Supremo No. 016-2024-JUS, published 30 November 2024; its own operative text is not reproduced here, so no specific provision of it beyond its existence and publication date is described here.

What it requires

Cross border transfer

Ley 29733, cross-border transfer of personal data

Ley No. 29733, arts. 11, 15 (cross-border transfer)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

Article 11 states the guiding principle that a cross-border transfer of personal data must guarantee a sufficient level of protection for the data to be processed, or, at minimum, a level comparable to what this Law or applicable international standards provide.

Article 15 operationalizes that principle: the titleholder and the processor of a cross-border data flow may carry it out only where the destination country maintains an adequate level of protection under the Law; where it does not, the sender of the transfer must instead guarantee the processing will comply with the Law.

That second requirement does not apply to eight listed cases: a transfer under an international treaty Peru is party to; international judicial cooperation; international cooperation between intelligence agencies against terrorism, drug trafficking, money laundering, corruption, human trafficking, or other organized crime; a transfer necessary to perform a contract the titleholder is party to, including user authentication, service improvement and support, quality monitoring, and account maintenance and billing support; a banking or securities transfer, for the respective transactions and under applicable law; a transfer for the titleholder's medical or surgical prevention, diagnosis, or treatment, or for an epidemiological or similar study using an adequate dissociation procedure; the titleholder's prior, informed, express, and unequivocal consent; and any other case the Law's regulation establishes, subject to article 12.

What it requires

Data subject rights

Ley 29733, rights of the data subject

Ley No. 29733, arts. 18-27 (rights of the data subject)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

Article 18 gives the titleholder a right to be informed, in detailed, simple, express, and unequivocal terms before their data is collected, of the processing's purpose, its recipients, the data bank's existence and its owner's identity and address, whether answering is mandatory or optional, any transfer, the retention period, and how to exercise their rights, and lets a controller collecting data online satisfy this through an easily accessible and identifiable privacy policy; it also requires notice to the titleholder of a new processor engaged after consent was given, or of a new data-bank owner following a merger, portfolio acquisition, or similar transfer.

Article 19 gives a right of access to the information processed about oneself, how it was collected, why, at whose request, and what transfers were made or are planned.

Article 20 gives a right to update, include, rectify, or delete personal data that is inaccurate, incomplete, or obsolete, requires the processor to pass the correction on to anyone the data were previously transferred to, and requires the processor to block the data during the update, inclusion, rectification, or deletion process so no third party can access it, with an exception for a public entity that needs the data for its own competencies.

Article 21 gives a right to prevent the data from being supplied to others, especially where that would affect a fundamental right, though it does not reach the internal relationship between a data bank's owner and its processor. Article 22 gives a right to object to processing, absent the titleholder's consent, on well-founded and legitimate grounds tied to a specific personal situation, requiring deletion where the objection is justified.

Article 23 gives a right not to be subject to a decision with legal effects, or that significantly affects the titleholder, based solely on processing meant to evaluate aspects of their personality or conduct, except within a contractual relationship or an evaluation for entry into a public entity, and preserves the right to state one's own view to safeguard a legitimate interest.

Article 24 lets a titleholder whose rights are denied bring a claim to the Autoridad Nacional de Protección de Datos Personales, whose resolution exhausts the administrative channel and opens the door to a contencioso-administrativo action, or pursue a constitutional habeas data action before the Judiciary instead. Article 25 gives a right to compensation for harm the Law's breach causes.

Article 26 sets the fee for exercising these rights before a public-administration data bank by the general administrative-procedure law and leaves a private data bank's fee to special rules.

Article 27 lets a public-administration titleholder or processor deny access, deletion, or objection on grounds tied to protecting a third party's rights, or to avoid obstructing a pending judicial or administrative proceeding on tax, welfare, criminal, health, environmental, or administrative-infraction matters, or where the law otherwise so provides.

What it requires

Enforcement supervision

Ley 29733, enforcement, supervisory authority and sanctions

Ley No. 29733, arts. 32-40 and Disposición complementaria final sexta (enforcement, supervisory authority and sanctions)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

Article 32 makes the Ministry of Justice, through its Dirección Nacional de Justicia, the Autoridad Nacional de Protección de Datos Personales, empowers it to open offices nationwide, and gives it sanctioning power under the general administrative-procedure law and coercive power under the coercive-execution law.

Article 33 lists the Authority's functions, including representing Peru internationally on data protection, cooperating with foreign authorities, administering the Registro Nacional de Protección de Datos Personales, publishing the registry of public and private data banks, promoting protection of children's and adolescents' data, issuing technical opinions on draft rules touching personal data that are binding, resolving titleholders' claims and ordering precautionary or corrective measures, and opening investigations on its own initiative or on complaint and applying the corresponding administrative sanctions.

Article 34 creates the Registro Nacional de Protección de Datos Personales to record public and private data banks, cross-border data-flow communications, and the sanctions and precautionary or corrective measures the Authority imposes, open to public consultation as to a bank's existence, purpose, and ownership.

Article 35 binds Authority personnel to confidentiality that survives their tenure, and article 36 funds the Authority from administrative fees, fine proceeds, international technical cooperation, and legacies and donations.

Article 37 lets the sanctioning procedure open on the Authority's own initiative or on a complaint, with its resolutions exhausting the administrative channel and reviewable only through a contencioso-administrativo action; article 38 has the regulation classify infractions as minor, serious, or very serious and lets the Authority order corrective measures alongside a sanction, holding a respondent strictly liable for a breach of personal-data-protection duties.

Article 39 sets three fine tiers, a minor infraction from 0.5 to 5 Tax Units (UIT), a serious infraction from more than 5 to 50 UIT, and a very serious infraction from more than 50 to 100 UIT, with the fine never exceeding ten percent of the offender's gross annual income for the prior fiscal year, without prejudice to any disciplinary, civil, or criminal liability that separately applies; and article 40 lets the Authority impose coercive fines of up to 10 UIT for failing to comply with an accessory obligation the sanctioning procedure imposed.

Disposición complementaria final sexta keeps the constitutional habeas data process, under the Código Procesal Constitucional, independent of the Law's own administrative procedure, and states that the administrative procedure is not a precondition for pursuing the constitutional action, so the Law does not itself arm a titleholder with a private cause of action beyond its own administrative channel and that separate constitutional remedy.

What it requires

Sensitive categories

Ley 29733, sensitive personal data and minors

Ley No. 29733, arts. 2.5, 13.3, 13.6, 14.6 (sensitive data and children)consolidated text of Ley 29733

In force since 3 July 2011. Binds public and private bodies.

What this law does

Article 2.5 defines sensitive data as personal data made up of biometric data that by itself can identify the titleholder, data on racial and ethnic origin, income, political, religious, philosophical, or moral opinions or convictions, union affiliation, and information related to health or sex life.

Article 13.6 requires written consent for processing sensitive data, in addition to the general consent requirements article 13.5 states, and permits processing without it only where a law authorizes it and the processing serves important public-interest grounds.

Article 14.6 lets health data be processed without consent where necessary, in a risk situation, for the titleholder's medical or surgical prevention, diagnosis, or treatment, carried out at a health establishment or by a health-sciences professional observing professional secrecy, or where a public-interest or public-health reason the Ministry of Health has qualified as such applies, or for an epidemiological or similar study using an adequate dissociation procedure.

Article 13.3 defers special measures for processing children's and adolescents' personal data to the regulation, and in the meantime requires children and adolescents to exercise the rights the Law grants through their legal representatives, subject to exceptions the regulation may set having regard to the child's or adolescent's best interest.

What it requires

Scraping law4 instruments, 4 in force

Research summary (366 words)

Peru has no scraping-specific statute, so each dimension is answered from general law.

Unauthorized access to a computer system is criminalized by Ley No. 30096, Ley de Delitos Informáticos (2013), whose article 2 punishes deliberately and illegitimately accessing all or part of a computer system, or exceeding what was authorized, so a scraper reading a public, unauthenticated page without defeating an access control falls outside a plain reading of the offense; a higher penalty tier applies where the agent defeats a security measure to gain access.

Decreto Legislativo 1700 (24 January 2026), as amended by Decreto Legislativo 1741 (13 February 2026), added article 12-A to that same Law, a separate offense for acquiring, possessing, or trafficking computer data, access credentials, or personal databases known or presumed to have been obtained without the titleholder's consent or through a security breach. No Peruvian court decision has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Decreto Legislativo 822, Ley sobre el Derecho de Autor (1996), permits quoting a lawfully disclosed work without the author's consent, subject to proper practice and the extent its purpose justifies, but Peru has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on that general quotation ground where the reproduction can be characterized as a citation rather than a wholesale copy.

The same statute protects an anthology, compilation, or database only where the selection, coordination, or arrangement of its contents is original, and it expressly excludes a database or compilation of data from the personal-use copying privilege it grants for other recordings, so Peru confers no sui generis database right, only a compilation-style copyright conditioned on originality.

Personal-data law reaches scraped personal information from Peruvian websites through Ley No. 29733, Ley de Protección de Datos Personales, which requires a lawful basis and, for sensitive categories, written consent, with no carve-out found here for publicly accessible personal data; that Law is researched in full under the privacy topic rather than repeated here.

No Peruvian statute or reported decision establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine distinct from these enactments, and none assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096)

Decreto Legislativo 1700 (24 January 2026) incorporating art. 12-A into Ley 30096, as amended by Decreto Legislativo 1741 (13 February 2026)official text of Decreto Legislativo 1700

In force. Binds public and private bodies.

What this law does

Article 12-A, incorporated into Ley 30096 by Decreto Legislativo 1700, punishes possessing, buying, receiving, marketing, selling, facilitating, exchanging, or trafficking computer data, access credentials, or personal databases, knowing or having reason to presume they were obtained without the titleholder's consent or through a security breach or the commission of a computer offense, with five to eight years' imprisonment and 180 to 365 day-fines.

The penalty rises to eight to ten years' imprisonment, with disqualification, where the agent acts as a member of a criminal organization, causes serious patrimonial harm or affects a plurality of persons, or the database is processed or held by a public entity.

Decreto Legislativo 1741 widened the article's exemption clause: conduct is exempt from criminal liability where it is carried out with the titleholder's express authorization under Ley 29733, in compliance with a lawful judicial or administrative order, in the legitimate exercise of fundamental rights or legally recognized functions, or as an activity carried out in the securities, financial, pension, or insurance sectors, provided there is no purpose of unlawful gain or improper commercialization of the information. Neither decree states a commencement date for the offense distinct from its own publication.

What it requires

Ley 30096, unauthorized access and data/system integrity offenses

Ley 30096, Ley de Delitos Informáticos (2013), arts. 2-4, 7, 10-12, as amended by Ley 30171 (2014) and Decreto Legislativo 1614 (2023)consolidated text of Ley 30096

In force since 22 October 2013. Binds public and private bodies.

What this law does

Article 2 punishes deliberately and illegitimately accessing all or part of a computer system, or exceeding authorized access, with one to four years' imprisonment and thirty to ninety day-fines; the penalty rises to three to six years' imprisonment and eighty to one hundred twenty day-fines where the agent defeats a security measure to gain access.

Article 3 punishes deliberately and illegitimately damaging, introducing, deleting, deteriorating, altering, suppressing, or making inaccessible computer data, and article 4 punishes deliberately and illegitimately disabling a computer system in whole or in part, impeding access to it, or hindering its operation or the provision of its services, each with three to six years' imprisonment and eighty to one hundred twenty day-fines.

Article 7 punishes deliberately and illegitimately intercepting non-public computer data transmissions to, from, or within a computer system. Article 10 punishes fabricating, designing, developing, selling, facilitating, distributing, importing, or obtaining a mechanism, program, device, password, access code, or other computer data specifically designed to commit one of the Law's offenses.

Article 11 raises the sentence by up to one-third above the legal maximum for any of these offenses where an aggravating circumstance applies, including, since Ley 32314 (29 April 2025), where the agent commits the offense using artificial intelligence or a similar or analogous technology. Article 12 exempts from criminal liability conduct described in articles 2, 3, 4, or 10 undertaken to carry out an authorized test or other authorized procedure to protect computer systems.

What it requires

Copyright and text and data mining (TDM)

Decreto Legislativo 822, quotation exception

Decreto Legislativo 822, art. 44 (quotation exception), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 44 permits quoting from a lawfully disclosed work without the author's consent or payment, provided the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies. The provision is a general quotation exception rather than a text-and-data-mining exception, and Peru has not enacted a distinct exception for automated extraction or analysis of a work's text or data.

This consolidated WIPO Lex text is current to Decreto Legislativo 1391 (2018), whose amendments reach other articles of the statute and not article 44; WIPO Lex flags a further consolidated version as available that is not reproduced here.

What it requires

Database right

Decreto Legislativo 822, protection of compilations and databases

Decreto Legislativo 822 arts. 5(l) and 48 (protection of compilations and databases), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 5(l) protects an anthology or compilation of works or expressions of folklore, and a database, as a protected work only where the collection is original in the selection, coordination, or arrangement of its contents, so Peru confers no sui generis database right and protects a database only under ordinary copyright's originality standard.

Article 48 permits copying a published sound or audiovisual recording for exclusively personal use, but expressly excludes a database or compilation of data from that personal-use privilege.

What it requires

Cybersecurity law1 instrument, 1 proposed

Research summary (563 words)

Peru's product-security and cyber-resilience posture rests on a framework decree whose sector-specific private duties are now in force, a security-of-processing clause inside the comprehensive privacy statute that is not restated here, a separate binding regulation for the financial sector, and one pending bill.

Decreto de Urgencia N.° 007-2020 (Marco de Confianza Digital) and its implementing Decreto Supremo N.° 126-2025-PCM, signed 4 November 2025 and entering into force ninety calendar days after its publication in the Diario Oficial El Peruano's edicion extraordinaria (dated 3 November 2025 on the hosting page), require a private organization that provides a digital service in the financial, basic-utility (electricity, water, gas), health, passenger-transport, internet-service, critical-activity, or education sector to manage digital-security risk so as to protect the confidentiality, integrity, and availability of its information, and to notify Peru's Centro Nacional de Seguridad Digital (CNSD) of a digital-security incident, with a critical-level incident notified within a mandatory forty-eight-hour clock; a private organization outside those sectors treats the same rules as merely referential.

None of those bound sectors is an activity this vocabulary can express (no declared LexLint activity means a financial service, a health provider, a transport provider, an internet service provider, a basic-utility provider, or an education provider), so this regime is deferred rather than flagged on a guess, the same treatment DORA and NY DFS Part 500 receive elsewhere in this topic; no instrument is filed for it here.

The Superintendencia de Banca, Seguros y AFP (SBS) separately maintains its own binding cybersecurity regulation for the banks, insurers, and pension-fund administrators it licenses, the Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad (Resolucion SBS N.° 504-2021), which several 2024 and 2026 SBS resolutions describe as still in force and amended; a licensed financial entity is likewise a role this vocabulary cannot express, so this regulation is deferred too.

Ley 30096 (the computer-crimes law, Ley de Delitos Informaticos) creates no operator- or manufacturer-facing security duty: its own security-adjacent disposition (Disposicion Complementaria Final SEXTA) directs the Oficina Nacional de Gobierno Electronico e Informatica to permanently promote, in coordination with public-sector institutions, the strengthening of those institutions' own security measures for sensitive computerized data and the integrity of their information systems, and its substantive offenses (unauthorized access, data-integrity attacks) are computer-misuse crimes committed against a system, filed under this jurisdiction's scraping topic rather than here.

Ley 29733 (Ley de Proteccion de Datos Personales) carries its own security-of-processing clause, articles 9 (Principio de seguridad) and 16 (Seguridad del tratamiento de datos personales), requiring a personal-data controller and processor to adopt technical, organizational, and legal safeguards; because that duty is a section inside a comprehensive data-protection act rather than a standalone security statute, it stays with this jurisdiction's privacy row and is not restated here.

Ley 30999 (Ley de Ciberdefensa) and its regulation (Decreto Supremo N.° 017-2024-PCM) regulate military operations in and through cyberspace under the Ministerio de Defensa, a government-accountability matter rather than a private-sector duty, and are not researched further here.

Proyecto de Ley 9906/2024-CR, introduced before the Congreso de la Republica on 10 January 2025, would add a standalone cybersecurity law that reaches a private institution through guidelines rather than an enforceable duty; unlike the sector regimes above, its reach is not sector-gated, so it is filed below as a proposed instrument that would flag inclusively, the way a baseline security statute does, once enacted.

Security baseline statutes

Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad

Proyecto de Ley 9906/2024-CR, introduced before the Congreso de la Republica on 10 January 2025LP Derecho, comparative-law commentary on the bill text and its exposicion de motivos

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Proyecto de Ley 9906/2024-CR, introduced before the Congreso de la Republica on 10 January 2025, would enact a standalone digital-security law. Its stated purpose, per the bill's own exposicion de motivos, is to strengthen information security in Peru against unlawful conduct that seeks to access, damage, or remove digital information belonging to a natural or legal person under public or private law alike.

Article 5 creates a Comite de Ciberseguridad that plans cyberattack-mitigation action lines for public institutions. Article 7 separately empowers that Comite to adopt guidelines addressed to a private institution to counter security breaches. Article 8 separately requires a public and a private entity to cooperate with each other to maintain national cybersecurity.

As introduced, the bill sets no incident-reporting clock and creates no agency with inspection or sanctioning power over a private institution's compliance, a gap a comparative commentary measures against Chile's Ley 21663 (Ley Marco de Ciberseguridad), which the same commentary names as the region's first cybersecurity framework law.

This bill does not currently bind: as of the source's own date (2 October 2025), no committee report or floor vote is described in the located commentary, and no later legislative stage is confirmed here.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (230 words)

Peru has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Decreto Legislativo 822, Ley sobre el Derecho de Autor (1996), is the only law reaching an aggregator's reproduction of news content.

Its quotation provision permits quoting a lawfully disclosed work without the author's consent or payment, subject to stating the author's name and source and to the quotation following proper practice and not exceeding what its purpose justifies, and a separate provision permits, without authorization, disseminating by the press or transmitting by any means, as news of current events, speeches, lectures, addresses, sermons, and similar works delivered in public, to the extent the informatory purpose justifies.

Neither provision carries a headline-length or short-extract cap distinct from this proper-practice test, and no reported Peruvian decision applies either provision to a systematic news aggregator as opposed to an individual quoting or reporting a published work.

Peru has enacted no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates, no compelled platform-to-publisher bargaining regime, and no hot-news or misappropriation doctrine distinct from ordinary copyright law.

No statute or case law addresses whether a hyperlink is itself a communication to the public or whether framing or inline display changes the answer, and the statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Decreto Legislativo 822, quotation and news-of-the-day exceptions

Decreto Legislativo 822 arts. 44-45 (quotation and news-of-the-day exceptions), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018)Copyright Law of Peru (Legislative Decree No. 822, amended up to Legislative Decree No. 1391), WIPO Lex

In force since 24 May 1996. Binds public and private bodies.

What this law does

Article 44 permits quoting from a lawfully disclosed work without the author's consent or payment, provided the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies.

Article 45(a) permits, without authorization, disseminating images or sounds of a work seen or heard in the course of a current event, by sound or audiovisual means, to the extent an informatory purpose justifies, and article 45(b) permits the press or any transmission medium to disseminate, as news of current events, speeches, lectures, addresses, sermons, and similar works delivered in public, to the extent an informatory purpose justifies and without prejudice to the authors' own right to publish those works individually.

Neither provision carries a headline-length or short-extract cap distinct from this proper-practice and informatory-purpose test, and no reported Peruvian decision applies either provision to a systematic news aggregator rather than an individual quoting or reporting a published work. This consolidated WIPO Lex text is current to Decreto Legislativo 1391 (2018), whose amendments reach other articles of the statute and not articles 44 or 45.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.