Skip to the content
Global Data RulesData governance rules, country by country

Argentina

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Argentina lets personal data leave the country, but only on paper terms it sets. You either send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars, but the regulator can order a database shut down, and some misuse is a crime.

Eight questions about Argentina

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Argentina's rules apply to my company?

The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size threshold, no revenue threshold, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina, and in practice the regulator has acted against local subsidiaries of global firms rather than against foreign entities directly.

High confidenceControllerProcessorPersonal data

Can I store my users' data outside Argentina?

Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts, and for everywhere else you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina - banking, payments, insurance, securities, health, telecoms, government cloud and mapping - and found none as of 18 August 2026.

High confidenceYes, with paperworkAllowlistOfficial 'this country is safe' decisionStandard contract clauses

What do I need in place before data leaves Argentina?

The model is an approved-destinations list, and it is populated today with about a dozen places, including the whole European Union. If your destination is not on it, use the regulator's published model contract - two versions, one for handing data to another company that decides how to use it and one for a supplier processing it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentImportant public interestSomeone's life is at risk

Who enforces the rules in Argentina, and what can they do?

The Agency for Access to Public Information, known by its Spanish initials AAIP, enforces both privacy and freedom of information. It is real and working: it has a named head, it publishes a register of final penalties that was updated on 3 July 2026, it opened a public investigation into debt-collection calls in April 2026, and it chaired an international data-protection committee in July 2026. Its 244 final penalties are mostly small, and more than half are for calling people on the do-not-call list.

High confidenceActiveRegulator

How long do I have to keep the data?

Argentina has strong floors and one hard ceiling. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years and produce it immediately on demand. The ceiling: credit-reporting data may only show the last five years, dropping to two years once the debt is paid.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

There is no general duty to report a data breach in Argentina, checked on 18 August 2026 - the privacy law has no deadline and the regulator's security rules are recommendations, not commands. Finance is the exception and the clock is brutal: banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted, keep sending updates, and file a closing report within five days.

High confidenceReport cyber incidentsSecure the data

What trips people up in Argentina?

Five things bite people. Answer times are very short: ten days for an access request and five working days to correct or delete. The maximum fine is one hundred thousand pesos, about seventy US dollars, so the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.

High confidenceFixed maximum fineCriminal liabilityOrder to stopRegister or notifyLet people see their data

What is changing soon in Argentina?

Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law; the regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity: public bodies have about 180 days from 13 May 2026 to have contingency plans and a working alternative data centre, which lands around November 2026, and a new national cybersecurity centre started issuing rules in 2026.

Medium confidenceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Ley 25.326 de Protección de los Datos Personales (Ley de Hábeas Data), reglamentada por el Decreto 1558/2001

Act of parliament · Ley 25.326, B.O. 2 November 2000; Decreto 1558/2001

In forceYes, with paperwork

Argentina's general privacy law. Personal data may not be sent to a country that does not protect it adequately, but there is no duty to keep anything inside Argentina. Rights must be answered in days, not weeks, and databases must be registered.

In force since 2 November 2000

Enforced by Agency for Access to Public Information

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest, Someone's life is at risk, Legal claims

High confidence

Disposición DNPDP 60-E/2016 (modelos de contrato y países con protección adecuada), Resolución AAIP 159/2018, Resolución AAIP 34/2019 y Resolución AAIP 198/2023

Government rules · Disposición 60-E/2016; Res. AAIP 159/2018; Res. AAIP 34/2019; Res. AAIP 198/2023

In forceYes, with paperwork

The approved-destination list is populated: the European Union and European Economic Area, the United Kingdom, Switzerland, Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand, Uruguay, Israel for automated processing and Canada for the private sector. Everywhere else needs the regulator's model contract.

In force since 18 November 2016

Enforced by Agency for Access to Public Information

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Resolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de los datos personales

Regulator guideline · RESOL-2018-47-APN-AAIP, Boletin Oficial 25 July 2018

In forceYes — store it anywhere

Argentina's security rules for personal data are recommendations, not commands, and they set no breach-reporting deadline. That is why a company can suffer a data breach in Argentina and owe the privacy regulator nothing at all, while a bank in the same position owes the central bank a report within an hour.

In force since 25 July 2018

Enforced by Agency for Access to Public Information

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI)

Regulator directive · Comunicación A 7266 (17 April 2021), consolidated text to 17 July 2025, last communication A 8280 (18 July 2025) · Banking

In forceYes — store it anywhere

Banks, registered payment service providers and systemically important payment infrastructures must report a cyber incident to the banking supervisor within one hour, including loss or unauthorised disclosure of customer data. This is the shortest reporting clock in Argentina and it applies whether or not the incident is a privacy breach.

In force since 17 April 2021

Enforced by Central Bank of Argentina

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información

Regulator directive · Comunicación A 7724, Circular RUNOR 1-1785, 10 March 2023 · Finance

In forceYes — store it anywhere

Banks may use foreign cloud and foreign suppliers, but the people managing technology and security must sit in Argentina, the supervisor must be told before any outsourcing begins, and the supervisor's access rights must follow the data into every subcontractor wherever it sits.

In force since 10 March 2023

Enforced by Central Bank of Argentina

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Ley 19.798 de Telecomunicaciones, artículos 45 bis, 45 ter y 45 quáter (incorporados por la Ley 25.873)

Act of parliament · Ley 25.873, B.O. 9 February 2004, adding articles 45 bis to 45 quáter to Ley 19.798; implementing Decreto 1563/2004 suspended by Decreto 357/2005; articles struck down by the Supreme Court in Halabi (24 February 2009, Fallos 332:111) · Telecoms

UnenforceableYes — store it anywhere

The official consolidated telecommunications law still prints a duty to keep subscriber and call-traffic records for ten years for judicial and prosecutorial access. It is not enforceable: the implementing decree was suspended in 2005 and the Supreme Court struck the provisions down in 2009, yet Congress never removed them from the text. A plain reading of the statute would wrongly report a ten-year telecom retention mandate.

In force since 9 February 2004

Enforced by National Communications Entity

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • Agencia de Acceso a la Información Pública (AAIP)

    Personal data protection, freedom of information, and the national do-not-call register

    Fully operational. Head: Beatriz de Anchorena, appointed by Decreto 110/2022 and still listed on the agency's own authorities page on 18 August 2026. Register of final sanctions updated 3 July 2026 and listing 244 penalties (111 under the data protection law, 133 under the do-not-call law); a public investigation into debt-collection calling was opened in April 2026; the agency chaired the Council of Europe Convention 108 committee plenary in July 2026.

  • Banco Central de la República Argentina (BCRA)

    Banks, payment service providers and payment infrastructures; technology risk, outsourcing and cyber incident reporting through the Superintendencia de Entidades Financieras y Cambiarias

    Actively issuing rules: the cyber incident text was last updated by Comunicación A 8280 in July 2025.

  • Centro Nacional de Ciberseguridad (CNC)

    Public sector cybersecurity, critical information infrastructure and the national incident response team CERT.ar

    Created by Decreto 941/2025 (published 2 January 2026), publicly launched 21 May 2026 under executive director Ariel Waissbein, and already issuing binding technical rules (Disposición 1/2026). Its published content is being revised under Decreto 269/2026, so its remit is still moving.

  • Unidad de Información Financiera (UIF)

    Anti-money-laundering record keeping and reporting by regulated entities

  • Comisión Nacional de Valores (CNV)

    Capital markets participants and, since Ley 27.739, virtual asset service providers

    Operational and publishing disciplinary decisions. No securities-sector data localisation rule was found.

  • Superintendencia de Seguros de la Nación (SSN)

    Insurers and reinsurers; record keeping at the registered office in Argentina

    Its consolidated rulebook was reissued on 7 August 2026 and contains no cloud, cybersecurity or data localisation chapter.

  • Ente Nacional de Comunicaciónes (ENACOM)

    Telecommunications and audiovisual services

  • Instituto Geográfico Nacional (IGN)

    Approval of maps and any publication depicting Argentine territory

    Runs a live map-approval service. How consistently the approval duty is enforced against digital and in-app maps was not established.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Supreme Court's 2009 Halabi ruling struck down the telecom retention articles, cited to the court's own site

    The Supreme Court's own domains (csjn.gov.ar, sjconsulta.csjn.gov.ar, cij.gov.ar) returned 403 or blocked automated fetching on 18 August 2026. The claim rests on the official consolidated statute text plus the well-documented ruling; the rule is therefore marked medium confidence.

  • The current parliamentary status of the 2023 data protection reform bill (Mensaje 87/2023)

    The regulator's page on the bill was last updated in May 2025 and says nothing about committee stages. Argentine bills lapse if not passed within a set period, but this was not verified on Congress's own site, so the record only asserts that the bill never became law.

  • Whether the 100,000 peso maximum fine has been raised by a later resolution or index mechanism

    Only the statutory figure in Ley 25.326 article 31 was found. No updating instrument was located, but the absence of one was not proven.

  • Whether Resolución AAIP 47/2018 recommends notifying the regulator of security incidents

    The annexes to the resolution were not retrieved in full. The operative text of the resolution contains no notification duty or deadline, so the record states there is no binding deadline rather than that no recommendation exists.

  • Whether any national public procurement or public cloud rule requires hosting inside Argentina

    Decision Administrativa 641/2021 sets minimum information security requirements for national public bodies, but its full annex was not read. The 2026 resilience rule expressly does not fix a location for the alternative data centre.

  • Whether any province imposes its own data storage or residency rules

    Argentina is a federal country and provinces regulate their own public sector files. Provincial instruments were not searched in this pass.

  • The exact date the 2026 public sector resilience deadline falls

    The rule gives 180 days from entry into force and was published on 13 May 2026. The record uses 9 November 2026 as a working date; a one or two day difference is possible depending on how commencement is counted.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.