Argentina
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Argentina — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Argentina, but only on the terms Argentina sets. Either you send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars. But the regulator can order a database shut down, and some misuse is a crime.
Data governance in Argentina
The eight things that decide how you handle data about people in Argentina. Same eight on every country page, so you can compare.
Who has to follow these rules
The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size cut-off, no revenue cut-off, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina. So far the regulator has acted against local subsidiaries of global firms rather than against foreign companies directly.
Ley 25.326 article 1 covers data held in any file, register, database or other technical means, public or private. The Spanish text reads 'asentados en archivos, registros, bancos de datos, u otros medios tecnicos de tratamiento de datos'. It is grounded in article 43 of the Constitution, the habeas data right. Unlike Brazil's LGPD or Europe's GDPR, there is no clause applying it to companies with no presence in Argentina. There is no rule making you appoint a local representative either. The 2023 reform bill would have added both. Journalistic sources are expressly excluded. The law also applies to companies as well as people, 'in so far as relevant'. That is unusual internationally, and it means company data can be covered. The regulator's own register of final penalties shows action against Google Argentina SRL in 2020, which is a locally registered company.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceInfoLEG, Ministerio de Justicia de la NaciónLey 25.326 - official InfoLEG text
servicios.infoleg.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts. For everywhere else, you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina. We checked banking, payments, insurance, securities, health, telecoms, government cloud and mapping. We found none as of 18 August 2026.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses
Ley 25.326 article 12 bans sending data to countries or international bodies that do not protect it well enough. There are narrow exceptions. They cover court cooperation, medical and epidemiological exchange for treatment, banking and stock-exchange transfers, treaty duties, and intelligence work against organised crime and terrorism. The AAIP's approved destinations are the European Union and European Economic Area states, the United Kingdom and Switzerland. They also include Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand and Uruguay. Israel is approved for automated work only, and Canada for the private sector only. Our industry search turned up duties that sit near storage, rather than rules forcing data to stay in Argentina. The central bank requires technology and information-security management to be carried out in Argentina. It also requires you to tell the supervisor before you outsource any process. The supervisor must get unrestricted access, written into the contract and into every subcontract, 'con independencia de la ubicacion geografica'. The insurance rulebook requires records to be held at the company's registered office in Argentina and made available to the supervisor. It has no chapter on cloud, cybersecurity or where data must sit. The public sector's new resilience rule requires a second data centre. It does not say where that centre must be. We found no health, telecom or securities rule requiring data to stay in Argentina.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Seguros de la NaciónReglamento General de la Actividad Aseguradora, consolidated text of 7 August 2026
argentina.gob.ar
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Argentina.
Sending data out of the country
You send data to countries on an approved list, and the list is full today. It has about a dozen places on it, including the whole European Union. If your destination is not on it, use the regulator's published model contract. There are two versions. One is for handing data to another company that decides how to use it. The other is for a supplier that handles it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Important public interest · To save someone’s life
The rules are Disposición DNPDP 60-E/2016, which sets the model clauses and the approved-country list. Resolución AAIP 34/2019 updated that list, including for the United Kingdom. Resolución AAIP 159/2018 sets the criteria for company-wide binding rules. Those need no formal approval if they follow the published guidance. Resolución AAIP 198/2023, from October 2023, added another option. It adopted the Ibero-American Data Protection Network model clauses. There is one set for passing data to another company that decides how to use it, and one for passing it to a supplier. Non-standard contracts go to datospersonales@aaip.gob.ar within 30 days of signature. Traffic the other way matters commercially too. The European Commission treats Argentina as a safe destination, so European data can flow in with no extra paperwork.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Secondary sourceEuropean CommissionEuropean Commission adequacy decisions - Argentina listed as adequate
commission.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Agency for Access to Public Information, known by its Spanish initials AAIP. It enforces both privacy and freedom of information. It is real and working. It has a named head. It publishes a register of final penalties, updated on 3 July 2026. It opened a public investigation into debt-collection calls in April 2026. It chaired an international data protection committee in July 2026. Its 244 final penalties are mostly small. More than half are for calling people on the do-not-call list.
Beatriz de Anchorena has led the AAIP since Decreto 110/2022, following a public hearing process. The agency's own authorities page still showed her in post on 18 August 2026. Its structure includes a dedicated Dirección Nacional de Protección de Datos Personales. The register of final penalties lists 244 of them. That is 111 under the data protection law (Ley 25.326) and 133 under the do-not-call law (Ley 26.951). They run from 2016 to a most recent final decision in September 2025. Named targets include banks, telecoms operators, Google Argentina, Andreani Logística and Swiss Medical. So enforcement is steady and low-key rather than dramatic. For large firms the industry regulators matter more. They are the central bank (BCRA), through its Superintendencia de Entidades Financieras y Cambiarias, and the securities regulator (CNV). They also include the insurance regulator (SSN), the telecoms regulator (ENACOM) and the financial intelligence unit (UIF). Since Decreto 941/2025 there is also a new Centro Nacional de Ciberseguridad. It was publicly launched on 21 May 2026 and is already issuing binding technical rules for government bodies.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Autoridades de la AAIP - titular de la Agencia
argentina.gob.ar
“Actualmente se desempeña como titular de la Agencia de Acceso a la Información Pública, propuesta mediante la Resolución 18/2022 de Jefatura de Gabinete de Ministros de la Nación y designada por Decreto Presidencial 110/2022”
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)La AAIP presidio la 50 reunion plenaria del Comite del Convenio 108 del Consejo de Europa (6 July 2026)
argentina.gob.ar
Link checked 18 August 2026
- Official sourceJefatura de Gabinete de MinistrosCentro Nacional de Ciberseguridad - presentation of the new agency (21 May 2026) and note on Decreto 269/2026
argentina.gob.ar
Link checked 18 August 2026
How long you must keep it — and when to delete it
Argentina has strong minimum keep-times and one firm limit. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years, and produce it immediately on demand. The limit: credit-reporting data may only show the last five years. That drops to two years once the debt is paid.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUM KEEP-TIMES. Ley 25.246 article 21, as amended by the 2024 reform Ley 27.739, sets a minimum of ten years. It covers all records needed to reconstruct transactions, plus customer checks and business correspondence. Ley 26.529 article 18 sets ten years from the last entry for a clinical record, tied to the contract limitation period. BCRA Comunicación A 7724 requires information supporting accounting entries and audit logs to be recoverable for no less than six years. It must be available to the supervisor immediately. MAXIMUM KEEP-TIMES. Ley 25.326 article 4.7 makes you destroy data once you no longer need it for the purpose you collected it for. Article 26.4 limits credit-worthiness data to the last five years, dropping to two years once the debt is paid. CLASHES. The minimum keep-time wins. Article 16.3 blocks deletion where a law requires you to keep the data. The ten-year telecom keep-time is a special case. See the telecom rule below.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.246 (anti-money-laundering), consolidated text - article 21 record-keeping duty
argentina.gob.ar
“Conservar, por un período mínimo de DIEZ (10) años, en forma física o digital, todos los registros necesarios sobre las transacciones, tanto locales como internacionales”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 26.529 de Derechos del Paciente - consolidated text, article 18 (custody of the clinical record)
argentina.gob.ar
“La obligación impuesta en el párrafo precedente debe regir durante el plazo mínimo de DIEZ (10) años de prescripción liberatoria de la responsabilidad contractual.”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no general duty to report a data breach in Argentina, checked on 18 August 2026. The privacy law sets no deadline, and the regulator's security rules are recommendations, not commands. Finance is the exception, and the deadline is brutal. Banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted. They must keep sending updates, and file a closing report within five days.
- What you have to do here:
- Report cyber incidents · Secure the data
The general law has no article on reporting breaches. Resolución AAIP 47/2018 approved 'medidas de seguridad recomendadas' for computerised and paper systems. It says on its face that these are advice, not commands. Banks, payment service providers on the BCRA register and systemically important payment infrastructures are different. The consolidated RRCI text is Comunicación A 7266, last updated by A 8280 and consolidated on 17 July 2025. It requires a first notice to the Gerencia de Auditoría Externa de Sistemas within the first hour. You must send frequent updates while the incident lasts more than an hour. You must send a root-cause closing report within five calendar days, by email to audext.incidente@bcra.gob.ar. Reportable incidents expressly include loss or unauthorised disclosure of customer data. They also include incidents that start at a third party, or anywhere in its supply chain. Public sector bodies report through CERT.ar under the cybersecurity rules. So one incident at a bank using a foreign cloud provider can start the one-hour central bank clock. No clock runs to the privacy regulator at all.
Sources
- Official sourceBanco Central de la República ArgentinaTexto ordenado - Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI), last communication A 8280, consolidated 17 July 2025
bcra.gob.ar
“Dentro de la primera hora de ocurrido o detectado el incidente; se deberá incluir toda la información disponible sobre el mismo.”
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaResolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de datos personales
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
What catches people out
Five things catch people out. Answer times are very short: ten days for an access request, and five working days to correct or delete. The largest fine is one hundred thousand pesos, about seventy US dollars. So the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.
- What you have to do here:
- Register or notify · Let people see their data
- What it costs if you get it wrong:
- Fixed maximum fine · Criminal liability · Order to stop
1. Ley 25.326 article 14 gives you ten calendar days to answer an access request. Article 16 gives you five working days to correct, update or delete. That is far shorter than the one month common elsewhere. Miss the deadline and the person can bring a habeas data court action. 2. Article 31 caps administrative fines at 100,000 pesos. That was worth about 67 US dollars at the central bank's official rate of 1,487.50 pesos per dollar on 14 August 2026. The same article allows suspension, and closure or cancellation of the database. Article 32 added criminal offences to the Penal Code, at articles 117 bis and 157 bis. They carry prison terms that fall on individuals, doubled for public officials. 3. You must still register in the Registro Nacional de Bases de Datos under article 21. It is a paperwork duty that foreign-owned local companies routinely forget. 4. Ley 22.963, the Ley de la Carta, covers maps. You may not publish any map or publication showing Argentine territory, in whole or in part. You need approval from the Instituto Geográfico Nacional first. You must use the official version, including the island and Antarctic territories. You must carry an 'Aprobado por el Instituto Geográfico Nacional' credit line. Customs can stop unapproved publications at the border. 5. BCRA Comunicación A 7724 requires technology and information-security management to be carried out in Argentina. You must also tell the supervisor before outsourcing starts. This is a rule about where people and work sit, not about where data sits, so offshoring plans miss it. 6. One more. More than half of all final privacy penalties are for calling numbers on the Registro Nacional No Llame under Ley 26.951, not for mishandling data.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaCotizaciones oficiales - official US dollar reference rate, 14 August 2026 (1 USD = 1,487.50 pesos)
api.bcra.gob.ar
Link checked 18 August 2026
- Official sourceInstituto Geográfico NacionalLey 22.963 (Ley de la Carta), articles 18 to 24 - official copy published by the national mapping agency
ign.gob.ar
“Prohíbese la publicidad de cualquier carta, folleto, mapa o publicación de cualquier tipo que describa o represente, en forma total o parcial, el territorio de la República Argentina, sea en forma aislada o integrando una obra mayor, sin la aprobación previa del Instituto Geográfico Nacional.”
Link checked 18 August 2026
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Registro de Infractores - sanciones firmes al 3 de julio de 2026
argentina.gob.ar
Link checked 18 August 2026
What's changing next
Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law. The regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity. Public bodies have about 180 days from 13 May 2026 to have contingency plans and a working second data centre. That lands around November 2026. A new national cybersecurity centre also started issuing rules in 2026.
PENDING. The 2023 reform bill (Mensaje 87/2023) would have made the law apply to companies with no presence in Argentina. It would have added a local representative duty, breach reporting, and fines based on turnover. It was never passed. The agency's own page on it was last updated in May 2025. The agency keeps publishing material to build support for reform. DATED ITEMS. Disposición 1/2026 of the Centro Nacional de Ciberseguridad was published on 13 May 2026. It gives national public sector bodies with data centres 180 days to adjust infrastructure, policies and contingency plans. They must also file a disaster-recovery report with at least one failover test. That lands around 9 November 2026. Decreto 269/2026 is currently reshaping what the cybersecurity bodies each cover. POWERS ALREADY HELD, which matter more than the bill. The regulator can add or remove countries from the approved-destinations list by resolution, with no consultation. So a destination can stop being usable overnight. The agency itself was created by decree, under a law that lets the government restructure it. Its head's term runs from a 2022 appointment. The European Commission also reviews Argentina's own approved status from time to time. An unfavourable review would change data coming into Argentina rather than data leaving it.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Proyecto de Ley de Protección de Datos Personales - Mensaje 87/2023
argentina.gob.ar
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaDisposición 1/2026 del Centro Nacional de Ciberseguridad - contingency plans and alternative data processing centres (published 13 May 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceJefatura de Gabinete de MinistrosCentro Nacional de Ciberseguridad - presentation of the new agency (21 May 2026) and note on Decreto 269/2026
argentina.gob.ar
Link checked 18 August 2026
- Official sourceCentro Nacional de Ciberseguridad, Jefatura de Gabinete de MinistrosNormativa de ciberseguridad - official list of Argentine cybersecurity laws, decrees and dispositions
argentina.gob.ar
Link checked 18 August 2026
What to do: Diarise 9 November 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payment data rules
Official name: Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI) · Comunicación A 7266 (17 April 2021), consolidated text to 17 July 2025, last communication A 8280 (18 July 2025) · Regulator directive
Banks, registered payment service providers and systemically important payment infrastructures must report a cyber incident to the banking supervisor within one hour. That includes loss or unauthorised disclosure of customer data. This is the shortest reporting deadline in Argentina. It applies whether or not the incident is a privacy breach.
Enforced by Central Bank of Argentina
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 1 hourFirst notice within the first hour of the incident happening or being detected. Frequent updates while it lasts. Closing root-cause report within five calendar days. Incidents at third parties anywhere in the supply chain count.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Superintendencia de Entidades Financieras y Cambiarias for breach of central bank rules.
Sources
- Official sourceBanco Central de la República ArgentinaTexto ordenado - Lineamientos para la respuesta y recuperación ante ciberincidentes (RRCI), last communication A 8280, consolidated 17 July 2025
bcra.gob.ar
“Dentro de la primera hora de ocurrido o detectado el incidente; se deberá incluir toda la información disponible sobre el mismo.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información · Comunicación A 7724, Circular RUNOR 1-1785, 10 March 2023 · Regulator directive
Banks may use a foreign cloud and foreign suppliers. But the people managing technology and security must sit in Argentina. You must tell the supervisor before any outsourcing begins. The supervisor's access rights must follow the data into every subcontractor, wherever it sits.
Enforced by Central Bank of Argentina
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Appoint a representativeThis is not about a data representative. The technology and information-security management work itself must be carried out in Argentina.
- Written vendor contractBefore outsourcing starts, the bank must tell the supervisor's systems audit unit. Contracts and every subcontract must give the supervisor unrestricted access to premises, controls and documents, wherever they are. They must also set out how the bank's data is deleted when the relationship ends.
- Keep logs — 6 yearsInformation supporting accounting entries and audit logs must be recoverable for at least six years. You must produce it immediately on request.
- Independent audit
Sources
- Official sourceBanco Central de la República ArgentinaComunicación A 7724 - Requisitos mínimos para la gestión y control de los riesgos de tecnología y seguridad de la información (10 March 2023)
bcra.gob.ar
“Estas funciones deberán ejecutarse en la República Argentina.”
Link checked 18 August 2026
Health data rules
Official name: Ley 26.529 de Derechos del Paciente en su relación con los profesionales e instituciones de la salud, artículo 18 · Ley 26.529, B.O. 20 November 2009, as amended by Ley 26.742 · Act of parliament
Clinical records cannot be altered and must be kept for at least ten years from the last entry. The hospital, clinic or doctor holding the record keeps it. Health data is also sensitive data under the general privacy law, so it needs express consent. We found no rule requiring health records to stay inside Argentina, checked 18 August 2026.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsTen years from the last entry in the record. Hospitals, clinics and doctors in private practice are the legal keepers of the record.
- Secure the dataKeepers must put means and resources in place to stop unauthorised people reaching the record.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 26.529 de Derechos del Paciente - consolidated text, article 18 (custody of the clinical record)
argentina.gob.ar
“La obligación impuesta en el párrafo precedente debe regir durante el plazo mínimo de DIEZ (10) años de prescripción liberatoria de la responsabilidad contractual.”
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
Banking rules
Official name: Ley 25.246 de Encubrimiento y Lavado de Activos de origen delictivo, artículo 21, texto según la Ley 27.739 · Ley 25.246 as amended by Ley 27.739 (B.O. 15 March 2024) · Act of parliament
Banks, insurers, virtual-asset providers, accountants, notaries, estate agents and other reporting businesses must keep transaction records and customer files for at least ten years. They must produce them quickly for the financial intelligence unit. This is the keep-time that most often beats a deletion request.
Enforced by Financial Information Unit
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsTen years, on paper or digitally, for all records needed to reconstruct local and international transactions. That also covers customer checks and business correspondence.
- Keep records of how you use data
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.246 (anti-money-laundering), consolidated text - article 21 record-keeping duty
argentina.gob.ar
“Conservar, por un período mínimo de DIEZ (10) años, en forma física o digital, todos los registros necesarios sobre las transacciones, tanto locales como internacionales”
Link checked 18 August 2026
Cyber security rules
Official name: Disposición 1/2026 del Centro Nacional de Ciberseguridad - reglamento técnico sobre políticas de planes de contingencia y centros de procesamiento de datos alternativos · Disposición 1/2026 CNC, Boletin Oficial 13 May 2026; framework created by Decreto 941/2025 (B.O. 2 January 2026) · Government rules
Argentina's new national cybersecurity centre now sets binding technical rules for government bodies. The first one requires contingency plans and a working second data centre, tested. The deadline lands around 9 November 2026. It is about staying up and running, not about where data sits.
It is already law, so plan for it — but nobody can be penalised under it until 9 November 2026. A contract you sign may still hold you to it sooner.
Enforced by National Cybersecurity Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the data — from 9 November 2026National public sector bodies running data centres get 180 days to align infrastructure, policies and contingency plans. They must file a disaster-recovery compliance report and run at least one failover test. They must also set recovery time and recovery point targets. The rule requires a second data centre and asks bodies to say where it is. It does not say it must be in Argentina.
Sources
- Official sourceBoletín Oficial de la República ArgentinaDisposición 1/2026 del Centro Nacional de Ciberseguridad - contingency plans and alternative data processing centres (published 13 May 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceBoletín Oficial de la República ArgentinaDecreto 941/2025 - creates the Centro Nacional de Ciberseguridad (published 2 January 2026)
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceCentro Nacional de Ciberseguridad, Jefatura de Gabinete de MinistrosNormativa de ciberseguridad - official list of Argentine cybersecurity laws, decrees and dispositions
argentina.gob.ar
Link checked 18 August 2026
State and security data rules
Official name: Ley 22.963 (Ley de la Carta), artículos 18 a 24, con el artículo 19 bis incorporado por la Ley 24.943 · Ley 22.963 (1983); Ley 24.943, B.O. 1 April 1998 · Act of parliament
Anyone publishing a map showing Argentina must get the national mapping agency's approval first. The map must follow the official version, which includes the island and Antarctic territories. Customs can stop unapproved publications at the border. The copyright office will not register them.
Enforced by National Geographic Institute
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyGet approval from the national mapping agency before publishing any map or publication showing Argentine territory. That covers the whole territory or part of it, on its own or inside a larger work. Approved works must carry an 'Aprobado por el Instituto Geográfico Nacional' line with the file number.
What it costs if you get it wrong
- Fixed maximum finePublishing, importing or distributing an unapproved depiction of Argentine territory; customs may block the publication and the copyright registry will refuse to register the work.
Sources
- Official sourceInstituto Geográfico NacionalLey 22.963 (Ley de la Carta), articles 18 to 24 - official copy published by the national mapping agency
ign.gob.ar
“Prohíbese la publicidad de cualquier carta, folleto, mapa o publicación de cualquier tipo que describa o represente, en forma total o parcial, el territorio de la República Argentina, sea en forma aislada o integrando una obra mayor, sin la aprobación previa del Instituto Geográfico Nacional.”
Link checked 18 August 2026
- Official sourceInstituto Geográfico NacionalMarco legal institucional - Ley 22.963 and Ley 24.943
ign.gob.ar
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley 25.326 de Protección de los Datos Personales (Ley de Hábeas Data), reglamentada por el Decreto 1558/2001 · Ley 25.326, B.O. 2 November 2000; Decreto 1558/2001 · Act of parliament
Argentina's general privacy law. You may not send personal data to a country that does not protect it well enough. But nothing has to be kept inside Argentina. You must answer people's requests in days, not weeks. Databases must be registered.
Enforced by Agency for Access to Public Information
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest, To save someone’s life, Legal claims
What you have to do
- Get consentConsent must be freely given, express and informed. As a rule it must be in writing, or by an equivalent means.
- Tell people what you do
- Let people see their data — within 240 hoursTen calendar days to answer. Free of charge, at intervals of not less than six months.
- Let people correct their data — within 120 hoursFive working days to correct, update or delete. You must also pass the correction on to anyone you gave the data to.
- Let people delete their data — within 120 hours
- Register or notifyRegister the database in the Registro Nacional de Bases de Datos.
- Secure the data
- Put a transfer safeguard in place
- Delete data after a periodDestroy data once you no longer need it for the purpose you collected it for.
What it costs if you get it wrong
- Fixed maximum fine: 100.000 pesos argentinos — about $67Any breach of the data protection law; the same provision also allows a warning or suspension.
- Order to stopClosure or cancellation of the file, register or database.
- Criminal liabilityKnowingly inserting false data, passing on false data, or unlawfully accessing or disclosing data from a database - Penal Code articles 117 bis and 157 bis.
- Claims by individualsDamages claims and the constitutional habeas data action.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
- Official sourceInfoLEG, Ministerio de Justicia de la NaciónLey 25.326 - official InfoLEG text
servicios.infoleg.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
Data rules
Official name: Disposición DNPDP 60-E/2016 (modelos de contrato y países con protección adecuada), Resolución AAIP 159/2018, Resolución AAIP 34/2019 y Resolución AAIP 198/2023 · Disposición 60-E/2016; Res. AAIP 159/2018; Res. AAIP 34/2019; Res. AAIP 198/2023 · Government rules
The approved-destination list is full. It covers the European Union and European Economic Area, the United Kingdom and Switzerland. It also covers Guernsey, Jersey, the Isle of Man, the Faroe Islands, Andorra, New Zealand and Uruguay. It also covers Israel for automated work and Canada for the private sector. Everywhere else needs the regulator's model contract.
Enforced by Agency for Access to Public Information
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Put a transfer safeguard in placeUse the published model contract for a country not on the approved list. There are two models. One is for passing data to another company that decides how to use it. The other is for passing it to a service provider.
- Written vendor contractIf your contract departs from the published wording, file it with the regulator within 30 days of signing.
Sources
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Transferencias internacionales de datos personales - list of adequate countries and model contract clauses
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.326 de Protección de los Datos Personales - consolidated text (articles 1, 12, 14, 16, 21, 26, 31, 32)
argentina.gob.ar
“Es prohibida la transferencia de datos personales de cualquier tipo con países u organismos internacionales o supranacionales, que no proporcionen niveles de protección adecuados.”
Link checked 18 August 2026
Banking rules (2018)
Official name: Resolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de los datos personales · RESOL-2018-47-APN-AAIP, Boletin Oficial 25 July 2018 · Regulator guideline
Argentina's security rules for personal data are recommendations, not commands. They set no deadline for reporting a breach. That is why a company can suffer a data breach in Argentina and owe the privacy regulator nothing. A bank in the same position owes the central bank a report within an hour.
Enforced by Agency for Access to Public Information
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataRecommended, not compulsory. There are two annexes, one for computer systems and one for paper systems. The binding duty is the general one in the law to put technical and organisational measures in place.
Sources
- Official sourceBoletín Oficial de la República ArgentinaResolución AAIP 47/2018 - Medidas de seguridad recomendadas para el tratamiento y conservación de datos personales
boletinoficial.gob.ar
Link checked 18 August 2026
- Official sourceAgencia de Acceso a la Información Pública (AAIP)Obligaciones de los responsables de bases de datos personales
argentina.gob.ar
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Telecoms rules
Official name: Ley 19.798 de Telecomunicaciones, artículos 45 bis, 45 ter y 45 quáter (incorporados por la Ley 25.873) · Ley 25.873, B.O. 9 February 2004, adding articles 45 bis to 45 quáter to Ley 19.798; implementing Decreto 1563/2004 suspended by Decreto 357/2005; articles struck down by the Supreme Court in Halabi (24 February 2009, Fallos 332:111) · Act of parliament
The official consolidated telecommunications law still prints a duty to keep subscriber and call-traffic records for ten years, for judges and prosecutors to access. It cannot be enforced. The decree that implemented it was suspended in 2005, and the Supreme Court struck the rules down in 2009. Congress never removed them from the text. So reading the law on its face would wrongly tell you Argentina has a ten-year telecom keep-time.
Enforced by National Communications Entity
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsTen years for subscriber identity and address details, and for traffic records. Printed in the official consolidated law, but not enforceable.
Sources
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 19.798 de Telecomunicaciones - consolidated text still printing articles 45 bis, 45 ter and 45 quáter
argentina.gob.ar
Link checked 18 August 2026
- Official sourceMinisterio de Justicia / InfoLEG, República ArgentinaLey 25.873 - original text adding the ten-year telecom data retention duty
argentina.gob.ar
“La información referida en el presente deberá ser conservada por los prestadores de servicios de telecomunicaciones por el plazo de diez años.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Supreme Court's 2009 Halabi ruling struck down the telecom retention articles, cited to the court's own site
The Supreme Court's own websites refused our requests on 18 August 2026. The claim rests on the official consolidated law text plus a well-documented ruling. So the rule is marked medium confidence. Take advice before relying on it.
The current parliamentary status of the 2023 data protection reform bill (Mensaje 87/2023)
The regulator's page on the bill was last updated in May 2025 and says nothing about committee stages. Argentine bills lapse if they are not passed within a set period. We did not check this on Congress's own site. So this record says only that the bill never became law.
Whether the 100,000 peso maximum fine has been raised by a later resolution or index mechanism
We found only the figure written into Ley 25.326 article 31. We found no later rule raising it, but we could not confirm that none exists. Check the current figure before you rely on it.
Whether Resolución AAIP 47/2018 recommends notifying the regulator of security incidents
We did not read the annexes to the resolution in full. The main text of the resolution has no duty to notify and no deadline. So this record says there is no binding deadline. It does not say the annexes recommend nothing.
Whether any national public procurement or public cloud rule requires hosting inside Argentina
Decision Administrativa 641/2021 sets minimum information security requirements for national public bodies. We did not read its full annex. The 2026 resilience rule expressly does not say where the second data centre must be. If you host for the Argentine government, check your contract and the annex.
Whether any province imposes its own data storage or residency rules
Argentina is a federal country, and provinces regulate their own public sector files. We did not search provincial rules. If you work with a provincial government, check that province's own rules.
The exact date the 2026 public sector resilience deadline falls
The rule gives 180 days from the day it starts, and it was published on 13 May 2026. This record uses 9 November 2026 as a working date. The real date could differ by a day or two, depending on how the count starts. Confirm the exact date before you plan around it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.