Argentina
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Argentina lets personal data leave the country, but only on paper terms it sets. You either send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars, but the regulator can order a database shut down, and some misuse is a crime.
Eight questions about Argentina
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Argentina's rules apply to my company?
The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size threshold, no revenue threshold, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina, and in practice the regulator has acted against local subsidiaries of global firms rather than against foreign entities directly.
Ley 25.326 article 1 frames the law around data 'asentados en archivos, registros, bancos de datos, u otros medios tecnicos de tratamiento de datos', public or private, and grounds it in article 43 of the Constitution (the habeas data right). Unlike Brazil's LGPD or the EU's GDPR, there is no express extraterritoriality clause and no representative obligation; the 2023 reform bill would have added both. Journalistic sources are expressly carved out. The law is also applied, 'in so far as relevant', to legal persons - unusual internationally, and it means company data can be in scope. The regulator's own final-sanctions register shows action against, for example, Google Argentina SRL (2020), which is a locally incorporated entity.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceInfoLEG, Ministerio de Justicia de la NaciónLey 25.326 - official InfoLEG text
servicios.infoleg.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
Can I store my users' data outside Argentina?
Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts, and for everywhere else you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina - banking, payments, insurance, securities, health, telecoms, government cloud and mapping - and found none as of 18 August 2026.
Ley 25.326 article 12 prohibits transfers to countries or international bodies that do not provide adequate levels of protection, with narrow exceptions for judicial cooperation, medical and epidemiological exchange for treatment, banking and stock-exchange transfers, treaty obligations, and intelligence cooperation against organised crime and terrorism. The AAIP's approved destinations are the European Union and European Economic Area states, the United Kingdom, Switzerland, Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand, Uruguay, Israel (automated processing only) and Canada (private sector only). The sector search produced storage-adjacent duties rather than residency walls: the central bank requires that technology and information-security management functions be performed in Argentina and that the supervisor be told before any process is outsourced, with unrestricted supervisory access written into the contract and into every subcontract 'con independencia de la ubicacion geografica'; the insurance rulebook requires records to be held at the entity's registered office in Argentina and available to the supervisor, but contains no cloud, cybersecurity or localisation chapter at all; and the public sector's new resilience rule requires an alternative data processing centre without saying where it must be. No health, telecom or securities localisation rule was found.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Seguros de la NaciónReglamento General de la Actividad Aseguradora, consolidated text of 7 August 2026
argentina.gob.ar
Link checked 18 August 2026
What do I need in place before data leaves Argentina?
The model is an approved-destinations list, and it is populated today with about a dozen places, including the whole European Union. If your destination is not on it, use the regulator's published model contract - two versions, one for handing data to another company that decides how to use it and one for a supplier processing it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.
The instruments are Disposición DNPDP 60-E/2016 (model clauses and the adequacy list), Resolución AAIP 34/2019 (updating the list, notably for the United Kingdom), Resolución AAIP 159/2018 (criteria for binding corporate rules, which need no formal approval if they follow the published guidance) and Resolución AAIP 198/2023 (October 2023), which adopted the Ibero-American Data Protection Network model clauses for controller-to-controller and controller-to-processor transfers as an additional option. Non-standard contracts go to datospersonales@aaip.gob.ar within 30 days of signature. Traffic in the other direction also matters commercially: the European Commission treats Argentina as an adequate destination, so EU data can flow in without extra paperwork.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Secondary sourceEuropean CommissionEuropean Commission adequacy decisions - Argentina listed as adequate
commission.europa.eu
Link checked 18 August 2026
Who enforces the rules in Argentina, and what can they do?
The Agency for Access to Public Information, known by its Spanish initials AAIP, enforces both privacy and freedom of information. It is real and working: it has a named head, it publishes a register of final penalties that was updated on 3 July 2026, it opened a public investigation into debt-collection calls in April 2026, and it chaired an international data-protection committee in July 2026. Its 244 final penalties are mostly small, and more than half are for calling people on the do-not-call list.
Beatriz de Anchorena has been the head of the AAIP since Decreto 110/2022, following a public hearing process; the agency's own authorities page still showed her in post on 18 August 2026, and its structure includes a dedicated Dirección Nacional de Protección de Datos Personales. The final-sanctions register lists 244 penalties: 111 under the data protection law (Ley 25.326) and 133 under the do-not-call law (Ley 26.951), running from 2016 to a most recent final decision in September 2025. Named targets include banks, telecoms operators, Google Argentina, Andreani Logística and Swiss Medical. Enforcement is therefore steady and unglamorous rather than headline-grabbing. Sector regulators matter more in practice for large firms: the central bank (BCRA) through its Superintendencia de Entidades Financieras y Cambiarias, the securities regulator (CNV), the insurance regulator (SSN), the telecoms regulator (ENACOM), the financial intelligence unit (UIF), and since Decreto 941/2025 a new Centro Nacional de Ciberseguridad, publicly launched on 21 May 2026 and already issuing binding technical rules for government bodies.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Autoridades de la AAIP - titular de la Agencia
argentina.gob.ar
“Actualmente se desempeña como titular de la Agencia de Acceso a la Información Pública, propuesta mediante la Resolución 18/2022 de Jefatura de Gabinete de Ministros de la Nación y designada por Decreto Presidencial 110/2022”
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)La AAIP presidio la 50 reunion plenaria del Comite del Convenio 108 del Consejo de Europa (6 July 2026)
argentina.gob.ar
Link checked 18 August 2026
- Official sourceJefatura de Gabinete de MinistrosCentro Nacional de Ciberseguridad - presentation of the new agency (21 May 2026) and note on Decreto 269/2026
argentina.gob.ar
Link checked 18 August 2026
How long do I have to keep the data?
Argentina has strong floors and one hard ceiling. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years and produce it immediately on demand. The ceiling: credit-reporting data may only show the last five years, dropping to two years once the debt is paid.
Floors: Ley 25.246 article 21 (as amended by the 2024 reform, Ley 27.739) requires a minimum of ten years for all records needed to reconstruct transactions plus customer due-diligence files and business correspondence; Ley 26.529 article 18 sets ten years from the last entry for the clinical record, tied to the contractual limitation period; BCRA Comunicación A 7724 requires information supporting accounting entries and audit logs to be recoverable for no less than six years and available immediately to the supervisor. Ceilings: Ley 25.326 article 4.7 requires data to be destroyed once no longer necessary for the purpose collected, and article 26.4 limits credit-solvency data to the last five years, reduced to two years once the obligation is cancelled. Conflict is resolved in favour of the floor: article 16.3 excludes deletion where the data must be kept under a legal duty. The telecom ten-year retention duty is a special case - see the telecom rule below.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.246 (anti-money-laundering), consolidated text - article 21 record-keeping duty
argentina.gob.ar
“Conservar, por un período mínimo de DIEZ (10) años, en forma física o digital, todos los registros necesarios sobre las transacciones, tanto locales como internacionales”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 26.529 de Derechos del Paciente - consolidated text, article 18 (custody of the clinical record)
argentina.gob.ar
“La obligación impuesta en el párrafo precedente debe regir durante el plazo mínimo de DIEZ (10) años de prescripción liberatoria de la responsabilidad contractual.”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
What happens if there is a breach?
There is no general duty to report a data breach in Argentina, checked on 18 August 2026 - the privacy law has no deadline and the regulator's security rules are recommendations, not commands. Finance is the exception and the clock is brutal: banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted, keep sending updates, and file a closing report within five days.
The general law contains no breach-notification article; Resolución AAIP 47/2018 approved 'medidas de seguridad recomendadas' for computerised and non-computerised systems and is expressly advisory. For banks, payment service providers on the BCRA register and systemically important payment infrastructures, the consolidated RRCI text (Comunicación A 7266, last updated by A 8280, consolidated 17 July 2025) requires initial notification to the Gerencia de Auditoría Externa de Sistemas within the first hour, frequent updates while the incident lasts more than an hour, and a root-cause closing report within five calendar days, by email to audext.incidente@bcra.gob.ar. Reportable incidents expressly include loss or unauthorised disclosure of customer data, and incidents originating at a third party or anywhere in its supply chain. Public sector bodies report through CERT.ar under the cybersecurity dispositions. So a single incident at a bank using a foreign cloud provider can trigger the one-hour central bank clock with no privacy-regulator clock at all.
Sources
- Official sourceBanco Central de la República ArgentinaTexto ordenado - Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI), last communication A 8280, consolidated 17 July 2025
bcra.gob.ar
“Dentro de la primera hora de ocurrido o detectado el incidente; se deberá incluir toda la información disponible sobre el mismo.”
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaResolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de datos personales
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
What trips people up in Argentina?
Five things bite people. Answer times are very short: ten days for an access request and five working days to correct or delete. The maximum fine is one hundred thousand pesos, about seventy US dollars, so the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.
1. Ley 25.326 article 14 gives ten calendar days to answer an access request and article 16 gives five working days to correct, update or delete - far shorter than the one month common elsewhere, and missing the deadline opens the door to a habeas data court action. 2. Article 31 caps administrative fines at 100,000 pesos, worth about 67 US dollars at the central bank's official rate of 1,487.50 pesos per dollar on 14 August 2026; the same article allows suspension and closure or cancellation of the database, and article 32 inserted criminal offences into the Penal Code (articles 117 bis and 157 bis) carrying prison terms that attach to individuals, doubled for public officials. 3. Registration in the Registro Nacional de Bases de Datos remains a live obligation under article 21 - a paperwork duty that foreign-owned local entities routinely forget. 4. Ley 22.963 (the Ley de la Carta) prohibits publishing any map or publication depicting Argentine territory, in whole or in part, without prior approval by the Instituto Geográfico Nacional, requires the official version including the insular and Antarctic territories, requires an 'Aprobado por el Instituto Geográfico Nacional' credit line, and lets customs stop non-approved publications at the border. 5. BCRA Comunicación A 7724 requires technology and information-security management functions to be performed in Argentina and outsourcing to be notified to the supervisor before it starts - a people-and-process localisation rule that offshoring plans miss because it is not a data rule. 6. Bonus: more than half of all final privacy penalties are for calling numbers on the Registro Nacional No Llame under Ley 26.951, not for data-handling failures.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaCotizaciones oficiales - official US dollar reference rate, 14 August 2026 (1 USD = 1,487.50 pesos)
api.bcra.gob.ar
Link checked 18 August 2026
- Official sourceInstituto Geográfico NacionalLey 22.963 (Ley de la Carta), articles 18 to 24 - official copy published by the national mapping agency
ign.gob.ar
“Prohíbese la publicidad de cualquier carta, folleto, mapa o publicación de cualquier tipo que describa o represente, en forma total o parcial, el territorio de la República Argentina, sea en forma aislada o integrando una obra mayor, sin la aprobación previa del Instituto Geográfico Nacional.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
What is changing soon in Argentina?
Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law; the regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity: public bodies have about 180 days from 13 May 2026 to have contingency plans and a working alternative data centre, which lands around November 2026, and a new national cybersecurity centre started issuing rules in 2026.
Pending: the 2023 reform bill (Mensaje 87/2023) would have added extraterritorial reach, a representative duty, breach notification and turnover-based fines; it was never enacted and the agency's own page on it was last updated in May 2025, while the agency continues to publish material to build support for reform. Dated items: Disposición 1/2026 of the Centro Nacional de Ciberseguridad (published 13 May 2026) gives national public sector bodies with data centres 180 days to adjust infrastructure, policies and contingency plans and to file a disaster-recovery report with at least one failover test - roughly 9 November 2026; Decreto 269/2026 is currently reshaping the cybersecurity bodies' remits. Dormant switches, which matter more than the bill: the regulator can add or remove countries from the approved-destinations list by resolution, with no consultation, so a destination can stop being usable overnight; the agency itself was created by decree under a law that lets the executive restructure it, and its head's term runs from a 2022 appointment; and Argentina's own adequacy status in the European Union is periodically reviewed by the European Commission, so an unfavourable review would change flows into Argentina rather than out of it.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Proyecto de Ley de Protección de Datos Personales - Mensaje 87/2023
argentina.gob.ar
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaDisposición 1/2026 del Centro Nacional de Ciberseguridad - contingency plans and alternative data processing centres (published 13 May 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceJefatura de Gabinete de MinistrosCentro Nacional de Ciberseguridad - presentation of the new agency (21 May 2026) and note on Decreto 269/2026
argentina.gob.ar
Link checked 18 August 2026
- Official sourceCentro Nacional de Ciberseguridad, Jefatura de Gabinete de MinistrosNormativa de ciberseguridad - official list of Argentine cybersecurity laws, decrees and dispositions
argentina.gob.ar
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
Ley 25.326 de Protección de los Datos Personales (Ley de Hábeas Data), reglamentada por el Decreto 1558/2001
Act of parliament · Ley 25.326, B.O. 2 November 2000; Decreto 1558/2001
Argentina's general privacy law. Personal data may not be sent to a country that does not protect it adequately, but there is no duty to keep anything inside Argentina. Rights must be answered in days, not weeks, and databases must be registered.
Enforced by Agency for Access to Public Information
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest, Someone's life is at risk, Legal claims
What it makes you do
- Get consentConsent must be free, express and informed and, as a rule, in writing or by an equivalent means.
- Tell people what you do
- Let people see their data — within 240 hoursTen calendar days to answer, free of charge at intervals of not less than six months.
- Let people correct their data — within 120 hoursFive working days to correct, update or delete, and to pass the correction on to anyone the data was given to.
- Let people delete their data — within 120 hours
- Register or notifyRegistration of the database in the Registro Nacional de Bases de Datos.
- Secure the data
- Put a transfer safeguard in place
- Delete data after a periodData must be destroyed once no longer necessary for the purpose it was collected for.
What it costs if you get it wrong
- Fixed maximum fine: 100.000 pesos argentinos — about $67Any breach of the data protection law; the same provision also allows a warning or suspension.
- Order to stopClosure or cancellation of the file, register or database.
- Criminal liabilityKnowingly inserting false data, passing on false data, or unlawfully accessing or disclosing data from a database - Penal Code articles 117 bis and 157 bis.
- Claims by individualsDamages claims and the constitutional habeas data action.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceInfoLEG, Ministerio de Justicia de la NaciónLey 25.326 - official InfoLEG text
servicios.infoleg.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
Disposición DNPDP 60-E/2016 (modelos de contrato y países con protección adecuada), Resolución AAIP 159/2018, Resolución AAIP 34/2019 y Resolución AAIP 198/2023
Government rules · Disposición 60-E/2016; Res. AAIP 159/2018; Res. AAIP 34/2019; Res. AAIP 198/2023
The approved-destination list is populated: the European Union and European Economic Area, the United Kingdom, Switzerland, Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand, Uruguay, Israel for automated processing and Canada for the private sector. Everywhere else needs the regulator's model contract.
Enforced by Agency for Access to Public Information
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Put a transfer safeguard in placeUse the published model contract for a country not on the approved list. Two models exist: transfer of data to another controller, and transfer to a service provider.
- Written vendor contractA contract that departs from the published wording must be filed with the regulator within 30 days of signature.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
Resolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de los datos personales
Regulator guideline · RESOL-2018-47-APN-AAIP, Boletin Oficial 25 July 2018
Argentina's security rules for personal data are recommendations, not commands, and they set no breach-reporting deadline. That is why a company can suffer a data breach in Argentina and owe the privacy regulator nothing at all, while a bank in the same position owes the central bank a report within an hour.
Enforced by Agency for Access to Public Information
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataRecommended, not mandatory: two annexes, one for computerised systems and one for paper systems. The binding duty is the general one in the law to adopt technical and organisational measures.
Sources
- Official sourceBoletín Oficial de la República ArgentinaResolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de datos personales
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
Industry rules7 rules
Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI)
Regulator directive · Comunicación A 7266 (17 April 2021), consolidated text to 17 July 2025, last communication A 8280 (18 July 2025) · Banking
Banks, registered payment service providers and systemically important payment infrastructures must report a cyber incident to the banking supervisor within one hour, including loss or unauthorised disclosure of customer data. This is the shortest reporting clock in Argentina and it applies whether or not the incident is a privacy breach.
Enforced by Central Bank of Argentina
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 1 hourInitial notification within the first hour of the incident happening or being detected; frequent updates while it lasts; closing root-cause report within five calendar days. Incidents at third parties anywhere in the supply chain count.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Superintendencia de Entidades Financieras y Cambiarias for breach of central bank rules.
Sources
- Official sourceBanco Central de la República ArgentinaTexto ordenado - Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI), last communication A 8280, consolidated 17 July 2025
bcra.gob.ar
“Dentro de la primera hora de ocurrido o detectado el incidente; se deberá incluir toda la información disponible sobre el mismo.”
Link checked 18 August 2026
Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información
Regulator directive · Comunicación A 7724, Circular RUNOR 1-1785, 10 March 2023 · Finance
Banks may use foreign cloud and foreign suppliers, but the people managing technology and security must sit in Argentina, the supervisor must be told before any outsourcing begins, and the supervisor's access rights must follow the data into every subcontractor wherever it sits.
Enforced by Central Bank of Argentina
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Appoint a local representativeNot a data representative: the technology and information-security management functions themselves must be carried out in Argentina.
- Written vendor contractBefore outsourcing starts, the bank must inform the supervisor's systems audit unit. Contracts and every subcontract must give the supervisor unrestricted access to premises, controls and documentation regardless of geographic location, and must set out how the bank's data is deleted when the relationship ends.
- Keep logs — 6 yearsInformation supporting accounting entries and audit logs must be recoverable for at least six years and produced immediately on request.
- Independent audit
Sources
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
Ley 19.798 de Telecomunicaciones, artículos 45 bis, 45 ter y 45 quáter (incorporados por la Ley 25.873)
Act of parliament · Ley 25.873, B.O. 9 February 2004, adding articles 45 bis to 45 quáter to Ley 19.798; implementing Decreto 1563/2004 suspended by Decreto 357/2005; articles struck down by the Supreme Court in Halabi (24 February 2009, Fallos 332:111) · Telecoms
The official consolidated telecommunications law still prints a duty to keep subscriber and call-traffic records for ten years for judicial and prosecutorial access. It is not enforceable: the implementing decree was suspended in 2005 and the Supreme Court struck the provisions down in 2009, yet Congress never removed them from the text. A plain reading of the statute would wrongly report a ten-year telecom retention mandate.
Enforced by National Communications Entity
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsTen-year retention of subscriber identity and address details and of traffic records. Printed in the official consolidated law but not enforceable.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 19.798 de Telecomunicaciones - consolidated text still printing articles 45 bis, 45 ter and 45 quáter
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.873 - original text adding the ten-year telecom data retention duty
argentina.gob.ar
“La información referida en el presente deberá ser conservada por los prestadores de servicios de telecomunicaciones por el plazo de diez años.”
Link checked 18 August 2026
Ley 26.529 de Derechos del Paciente en su relación con los profesionales e instituciones de la salud, artículo 18
Act of parliament · Ley 26.529, B.O. 20 November 2009, as amended by Ley 26.742 · Health and social care
Clinical records are inviolable and must be kept for at least ten years counted from the last entry, by the hospital, clinic or doctor holding them. Health data is also sensitive data under the general privacy law, so it needs express consent. No rule requiring health records to stay inside Argentina was found, checked 18 August 2026.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsTen years from the last entry in the record. Hospitals, clinics and doctors in private practice are legal custodians of the record.
- Secure the dataCustodians must put means and resources in place to stop unauthorised people reaching the record.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 26.529 de Derechos del Paciente - consolidated text, article 18 (custody of the clinical record)
argentina.gob.ar
“La obligación impuesta en el párrafo precedente debe regir durante el plazo mínimo de DIEZ (10) años de prescripción liberatoria de la responsabilidad contractual.”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
Ley 25.246 de Encubrimiento y Lavado de Activos de origen delictivo, artículo 21, texto según la Ley 27.739
Act of parliament · Ley 25.246 as amended by Ley 27.739 (B.O. 15 March 2024) · Finance
Banks, insurers, virtual-asset providers, accountants, notaries, estate agents and other reporting entities must keep transaction records and customer files for at least ten years and produce them quickly for the financial intelligence unit. This is the retention floor that most often overrides a deletion request.
Enforced by Financial Information Unit
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsTen years, physical or digital, for all records needed to reconstruct local and international transactions, plus customer due-diligence files and business correspondence.
- Keep records of processing
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.246 (anti-money-laundering), consolidated text - article 21 record-keeping duty
argentina.gob.ar
“Conservar, por un período mínimo de DIEZ (10) años, en forma física o digital, todos los registros necesarios sobre las transacciones, tanto locales como internacionales”
Link checked 18 August 2026
Disposición 1/2026 del Centro Nacional de Ciberseguridad - reglamento técnico sobre políticas de planes de contingencia y centros de procesamiento de datos alternativos
Government rules · Disposición 1/2026 CNC, Boletin Oficial 13 May 2026; framework created by Decreto 941/2025 (B.O. 2 January 2026) · Government
Argentina's new national cybersecurity centre now sets binding technical rules for government bodies. The first one requires contingency plans and a working alternative data centre, tested, with the deadline landing around 9 November 2026. It is a resilience rule, not a residency rule.
Enforced by National Cybersecurity Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the data — from 9 November 2026National public sector bodies running data centres get 180 days to align infrastructure, policies and contingency plans, file a disaster-recovery compliance report, run at least one failover test and set recovery time and recovery point objectives. The rule requires an alternative processing centre and asks bodies to state its location, but does not say it must be in Argentina.
Sources
- Official sourceBoletín Oficial de la República ArgentinaDisposición 1/2026 del Centro Nacional de Ciberseguridad - contingency plans and alternative data processing centres (published 13 May 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaDecreto 941/2025 - creates the Centro Nacional de Ciberseguridad (published 2 January 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceCentro Nacional de Ciberseguridad, Jefatura de Gabinete de MinistrosNormativa de ciberseguridad - official list of Argentine cybersecurity laws, decrees and dispositions
argentina.gob.ar
Link checked 18 August 2026
Ley 22.963 (Ley de la Carta), artículos 18 a 24, con el artículo 19 bis incorporado por la Ley 24.943
Act of parliament · Ley 22.963 (1983); Ley 24.943, B.O. 1 April 1998 · Mapping and location
Anyone publishing a map showing Argentina must get the national mapping agency's approval first, and the map must follow the official version, which includes the island and Antarctic territories. Customs can stop unapproved publications at the border and the copyright office will not register them.
Enforced by National Geographic Institute
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyPrior approval by the national mapping agency before publishing any map or publication showing Argentine territory, in whole or in part, alone or inside a larger work. Approved works must carry an 'Aprobado por el Instituto Geográfico Nacional' line with the file number.
What it costs if you get it wrong
- Fixed maximum finePublishing, importing or distributing an unapproved depiction of Argentine territory; customs may block the publication and the copyright registry will refuse to register the work.
Sources
- Official sourceInstituto Geográfico NacionalLey 22.963 (Ley de la Carta), articles 18 to 24 - official copy published by the national mapping agency
ign.gob.ar
“Prohíbese la publicidad de cualquier carta, folleto, mapa o publicación de cualquier tipo que describa o represente, en forma total o parcial, el territorio de la República Argentina, sea en forma aislada o integrando una obra mayor, sin la aprobación previa del Instituto Geográfico Nacional.”
Link checked 18 August 2026
- Official sourceInstituto Geográfico NacionalMarco legal institucional - Ley 22.963 and Ley 24.943
ign.gob.ar
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Supreme Court's 2009 Halabi ruling struck down the telecom retention articles, cited to the court's own site
The Supreme Court's own domains (csjn.gov.ar, sjconsulta.csjn.gov.ar, cij.gov.ar) returned 403 or blocked automated fetching on 18 August 2026. The claim rests on the official consolidated statute text plus the well-documented ruling; the rule is therefore marked medium confidence.
The current parliamentary status of the 2023 data protection reform bill (Mensaje 87/2023)
The regulator's page on the bill was last updated in May 2025 and says nothing about committee stages. Argentine bills lapse if not passed within a set period, but this was not verified on Congress's own site, so the record only asserts that the bill never became law.
Whether the 100,000 peso maximum fine has been raised by a later resolution or index mechanism
Only the statutory figure in Ley 25.326 article 31 was found. No updating instrument was located, but the absence of one was not proven.
Whether Resolución AAIP 47/2018 recommends notifying the regulator of security incidents
The annexes to the resolution were not retrieved in full. The operative text of the resolution contains no notification duty or deadline, so the record states there is no binding deadline rather than that no recommendation exists.
Whether any national public procurement or public cloud rule requires hosting inside Argentina
Decision Administrativa 641/2021 sets minimum information security requirements for national public bodies, but its full annex was not read. The 2026 resilience rule expressly does not fix a location for the alternative data centre.
Whether any province imposes its own data storage or residency rules
Argentina is a federal country and provinces regulate their own public sector files. Provincial instruments were not searched in this pass.
The exact date the 2026 public sector resilience deadline falls
The rule gives 180 days from entry into force and was published on 13 May 2026. The record uses 9 November 2026 as a working date; a one or two day difference is possible depending on how commencement is counted.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Argentina versus Armenia
- Argentina versus Australia
- Argentina versus Austria
- Argentina versus Azerbaijan
- Argentina versus Brazil
- Argentina versus Bulgaria
- Argentina versus Cambodia
- Argentina versus Canada
- Argentina versus China
- Argentina versus Croatia
- Argentina versus Cyprus
- Argentina versus Estonia
- Argentina versus France
- Argentina versus Georgia
- Argentina versus Germany
- Argentina versus Greece
- Argentina versus Hong Kong SAR
- Argentina versus Hungary
- Argentina versus Iceland
- Argentina versus India
- Argentina versus Indonesia
- Argentina versus Ireland
- Argentina versus Israel
- Argentina versus Italy
- Argentina versus Japan
- Argentina versus Latvia
- Argentina versus Lithuania
- Argentina versus Luxembourg
- Argentina versus Malta
- Argentina versus Mexico
- Argentina versus Mongolia
- Argentina versus Nepal
- Argentina versus Netherlands
- Argentina versus Poland
- Argentina versus Russia
- Argentina versus Saudi Arabia
- Argentina versus Serbia
- Argentina versus Singapore
- Argentina versus Slovakia
- Argentina versus Slovenia
- Argentina versus South Korea
- Argentina versus Spain
- Argentina versus Sri Lanka
- Argentina versus Sweden
- Argentina versus Switzerland
- Argentina versus Taiwan
- Argentina versus Thailand
- Argentina versus Turkey
- Argentina versus Ukraine
- Argentina versus United Arab Emirates
- Argentina versus United Kingdom
- Argentina versus United States
- Argentina versus Uzbekistan