Skip to the content
Global Data RulesData governance rules, country by country

Argentina

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Argentina — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

You can send personal data out of Argentina, but only on the terms Argentina sets. Either you send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars. But the regulator can order a database shut down, and some misuse is a crime.

Data governance in Argentina

The eight things that decide how you handle data about people in Argentina. Same eight on every country page, so you can compare.

Who has to follow these rules

The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size cut-off, no revenue cut-off, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina. So far the regulator has acted against local subsidiaries of global firms rather than against foreign companies directly.

Where the data is allowed to live

Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts. For everywhere else, you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina. We checked banking, payments, insurance, securities, health, telecoms, government cloud and mapping. We found none as of 18 August 2026.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses

What to do: Get the paperwork for one of the routes below signed before any data leaves Argentina.

Sending data out of the country

You send data to countries on an approved list, and the list is full today. It has about a dozen places on it, including the whole European Union. If your destination is not on it, use the regulator's published model contract. There are two versions. One is for handing data to another company that decides how to use it. The other is for a supplier that handles it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Important public interest · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Agency for Access to Public Information, known by its Spanish initials AAIP. It enforces both privacy and freedom of information. It is real and working. It has a named head. It publishes a register of final penalties, updated on 3 July 2026. It opened a public investigation into debt-collection calls in April 2026. It chaired an international data protection committee in July 2026. Its 244 final penalties are mostly small. More than half are for calling people on the do-not-call list.

How long you must keep it — and when to delete it

Argentina has strong minimum keep-times and one firm limit. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years, and produce it immediately on demand. The limit: credit-reporting data may only show the last five years. That drops to two years once the debt is paid.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no general duty to report a data breach in Argentina, checked on 18 August 2026. The privacy law sets no deadline, and the regulator's security rules are recommendations, not commands. Finance is the exception, and the deadline is brutal. Banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted. They must keep sending updates, and file a closing report within five days.

What you have to do here:
Report cyber incidents · Secure the data

What catches people out

Five things catch people out. Answer times are very short: ten days for an access request, and five working days to correct or delete. The largest fine is one hundred thousand pesos, about seventy US dollars. So the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.

What you have to do here:
Register or notify · Let people see their data
What it costs if you get it wrong:
Fixed maximum fine · Criminal liability · Order to stop

What's changing next

Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law. The regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity. Public bodies have about 180 days from 13 May 2026 to have contingency plans and a working second data centre. That lands around November 2026. A new national cybersecurity centre also started issuing rules in 2026.

What to do: Diarise 9 November 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Payment data rules

Official name: Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI) · Comunicación A 7266 (17 April 2021), consolidated text to 17 July 2025, last communication A 8280 (18 July 2025) · Regulator directive

In forceYes — store it anywhere

Banks, registered payment service providers and systemically important payment infrastructures must report a cyber incident to the banking supervisor within one hour. That includes loss or unauthorised disclosure of customer data. This is the shortest reporting deadline in Argentina. It applies whether or not the incident is a privacy breach.

In force since 17 April 2021

Enforced by Central Bank of Argentina

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Finance

Cloud and outsourcing rules

Official name: Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información · Comunicación A 7724, Circular RUNOR 1-1785, 10 March 2023 · Regulator directive

In forceYes — store it anywhere

Banks may use a foreign cloud and foreign suppliers. But the people managing technology and security must sit in Argentina. You must tell the supervisor before any outsourcing begins. The supervisor's access rights must follow the data into every subcontractor, wherever it sits.

In force since 10 March 2023

Enforced by Central Bank of Argentina

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Health and social care

Health data rules

Official name: Ley 26.529 de Derechos del Paciente en su relación con los profesionales e instituciones de la salud, artículo 18 · Ley 26.529, B.O. 20 November 2009, as amended by Ley 26.742 · Act of parliament

In forceYes — store it anywhere

Clinical records cannot be altered and must be kept for at least ten years from the last entry. The hospital, clinic or doctor holding the record keeps it. Health data is also sensitive data under the general privacy law, so it needs express consent. We found no rule requiring health records to stay inside Argentina, checked 18 August 2026.

In force since 19 February 2010

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley 25.326 de Protección de los Datos Personales (Ley de Hábeas Data), reglamentada por el Decreto 1558/2001 · Ley 25.326, B.O. 2 November 2000; Decreto 1558/2001 · Act of parliament

In forceYes, with paperwork

Argentina's general privacy law. You may not send personal data to a country that does not protect it well enough. But nothing has to be kept inside Argentina. You must answer people's requests in days, not weeks. Databases must be registered.

In force since 2 November 2000

Enforced by Agency for Access to Public Information

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest, To save someone’s life, Legal claims

Data rules

Official name: Disposición DNPDP 60-E/2016 (modelos de contrato y países con protección adecuada), Resolución AAIP 159/2018, Resolución AAIP 34/2019 y Resolución AAIP 198/2023 · Disposición 60-E/2016; Res. AAIP 159/2018; Res. AAIP 34/2019; Res. AAIP 198/2023 · Government rules

In forceYes, with paperwork

The approved-destination list is full. It covers the European Union and European Economic Area, the United Kingdom and Switzerland. It also covers Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand and Uruguay. It also covers Israel for automated work and Canada for the private sector. Everywhere else needs the regulator's model contract.

In force since 18 November 2016

Enforced by Agency for Access to Public Information

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Banking rules (2018)

Official name: Resolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de los datos personales · RESOL-2018-47-APN-AAIP, Boletin Oficial 25 July 2018 · Regulator guideline

In forceYes — store it anywhere

Argentina's security rules for personal data are recommendations, not commands. They set no deadline for reporting a breach. That is why a company can suffer a data breach in Argentina and owe the privacy regulator nothing. A bank in the same position owes the central bank a report within an hour.

In force since 25 July 2018

Enforced by Agency for Access to Public Information

How this country controls where data goes: No restriction · Accepted routes: Nothing required

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Telecoms rules

Official name: Ley 19.798 de Telecomunicaciones, artículos 45 bis, 45 ter y 45 quáter (incorporados por la Ley 25.873) · Ley 25.873, B.O. 9 February 2004, adding articles 45 bis to 45 quáter to Ley 19.798; implementing Decreto 1563/2004 suspended by Decreto 357/2005; articles struck down by the Supreme Court in Halabi (24 February 2009, Fallos 332:111) · Act of parliament

UnenforceableYes — store it anywhere

The official consolidated telecommunications law still prints a duty to keep subscriber and call-traffic records for ten years, for judges and prosecutors to access. It cannot be enforced. The decree that implemented it was suspended in 2005, and the Supreme Court struck the rules down in 2009. Congress never removed them from the text. So reading the law on its face would wrongly tell you Argentina has a ten-year telecom keep-time.

In force since 9 February 2004

Enforced by National Communications Entity

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Agencia de Acceso a la Información Pública (AAIP)

    Personal data protection, freedom of information, and the national do-not-call register

    Fully operational. Head: Beatriz de Anchorena, appointed by Decreto 110/2022. She was still listed on the agency's own authorities page on 18 August 2026. Its register of final penalties was updated on 3 July 2026 and lists 244 penalties. That is 111 under the data protection law and 133 under the do-not-call law. It opened a public investigation into debt-collection calling in April 2026. It chaired the Council of Europe Convention 108 committee plenary in July 2026.

  • Banco Central de la República Argentina (BCRA)

    Banks, payment service providers and payment infrastructures; technology risk, outsourcing and cyber incident reporting through the Superintendencia de Entidades Financieras y Cambiarias

    Actively issuing rules. Its cyber incident text was last updated by Comunicación A 8280 in July 2025.

  • Centro Nacional de Ciberseguridad (CNC)

    Public sector cybersecurity, critical information infrastructure and the national incident response team CERT.ar

    Created by Decreto 941/2025, published 2 January 2026. Publicly launched on 21 May 2026 under executive director Ariel Waissbein. Already issuing binding technical rules, such as Disposición 1/2026. Its published content is being revised under Decreto 269/2026, so what it covers is still moving.

  • Unidad de Información Financiera (UIF)

    Anti-money-laundering record keeping and reporting by regulated entities

  • Comisión Nacional de Valores (CNV)

    Capital markets participants and, since Ley 27.739, virtual asset service providers

    Operational and publishing disciplinary decisions. We found no securities rule requiring data to stay inside Argentina.

  • Superintendencia de Seguros de la Nación (SSN)

    Insurers and reinsurers; record keeping at the registered office in Argentina

    Its consolidated rulebook was reissued on 7 August 2026. It has no chapter on cloud, cybersecurity or where data must sit.

  • Ente Nacional de Comunicaciónes (ENACOM)

    Telecommunications and audiovisual services

  • Instituto Geográfico Nacional (IGN)

    Approval of maps and any publication depicting Argentine territory

    Runs a live map-approval service. We did not establish how consistently the approval duty is enforced against digital and in-app maps.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Supreme Court's 2009 Halabi ruling struck down the telecom retention articles, cited to the court's own site

    The Supreme Court's own websites refused our requests on 18 August 2026. The claim rests on the official consolidated law text plus a well-documented ruling. So the rule is marked medium confidence. Take advice before relying on it.

  • The current parliamentary status of the 2023 data protection reform bill (Mensaje 87/2023)

    The regulator's page on the bill was last updated in May 2025 and says nothing about committee stages. Argentine bills lapse if they are not passed within a set period. We did not check this on Congress's own site. So this record says only that the bill never became law.

  • Whether the 100,000 peso maximum fine has been raised by a later resolution or index mechanism

    We found only the figure written into Ley 25.326 article 31. We found no later rule raising it, but we could not confirm that none exists. Check the current figure before you rely on it.

  • Whether Resolución AAIP 47/2018 recommends notifying the regulator of security incidents

    We did not read the annexes to the resolution in full. The main text of the resolution has no duty to notify and no deadline. So this record says there is no binding deadline. It does not say the annexes recommend nothing.

  • Whether any national public procurement or public cloud rule requires hosting inside Argentina

    Decision Administrativa 641/2021 sets minimum information security requirements for national public bodies. We did not read its full annex. The 2026 resilience rule expressly does not say where the second data centre must be. If you host for the Argentine government, check your contract and the annex.

  • Whether any province imposes its own data storage or residency rules

    Argentina is a federal country, and provinces regulate their own public sector files. We did not search provincial rules. If you work with a provincial government, check that province's own rules.

  • The exact date the 2026 public sector resilience deadline falls

    The rule gives 180 days from the day it starts, and it was published on 13 May 2026. This record uses 9 November 2026 as a working date. The real date could differ by a day or two, depending on how the count starts. Confirm the exact date before you plan around it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.