Data Protection Atlas

Argentina

Tier 3 Comprehensive law Americas

Principal framework: Law 25.326 (reform pending) (2000). Regulator: AAIP. One of the region’s oldest regimes (2000) and an adequacy holder since 2003; a GDPR-style replacement bill remains pending in Congress.

At a glance

Principal law
Law 25.326 (reform pending)
Regulator
AAIP
Breach notification
No hard statutory deadline under Law 25.326; AAIP guidance encourages prompt notice
Maximum penalty
Administrative fines are low and outdated
DPO required
Not mandatory under the current law
Digital consent age
No statutory age — civil capacity rules
Extraterritorial reach
Limited

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
AR

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
Yes
Granted
30 June 2003
Review
Confirmed Jan 2024 review

Argentina; 1995 Directive (Dec. 2003/490/EC).

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.