Skip to the content
Global Data RulesData governance rules, country by country

Panama

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Waking up

Panama lets personal data leave the country. You do not need a permit and no destination country is banned. You just need one of thirteen legal reasons listed in the law, and since June 2026 there is an official model contract you can sign to cover yourself. The regulator writes rules and guidance but we found no published fines. Banks and government bodies face extra approval steps.

Data governance in Panama

The eight things that decide how you handle data about people in Panama. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably not, if you have nothing in Panama. The law reaches databases physically held in Panama, and it reaches anyone who is legally based in Panama. It does not say it reaches a company abroad that has no database and no office here just because it sells to Panamanians. There is no size or revenue cut-off, and we found no rule forcing a foreign firm to appoint a local representative.

High confidenceNational rules

Where the data is allowed to live

Yes. Nothing has to stay in Panama. We found no rule in any industry that forces personal data to be stored inside the country. Sending data abroad is lawful if you meet any one of thirteen conditions in the law, such as the person's consent, a contract with the person, a company group transfer, a destination with equal or better protection, or an approved model contract. Two industries add a permission step that is about who handles the data, not where it sits.

Medium confidenceYes, with paperworkNo restriction

Sending data out of the country

No government permission is needed, and there is no list of approved or banned countries. You pick one of the thirteen legal grounds and you keep evidence. Since 8 June 2026 there is an easier route: the regulator has published official model contract clauses. If you sign those, you do not have to ask the regulator for permission. Sensitive data, such as health or biometric records, needs the person's explicit agreement.

High confidenceNo restrictionStandard contract clausesOfficial 'this country is safe' decisionApproved group rulesExplicit consentNeeded for a contract

The regulator, and whether it actually acts

The National Authority for Transparency and Access to Information, through its Personal Data Protection Directorate. It exists, it is contactable, and it is clearly working: it issued a compliance circular in April 2026 and adopted official model contract clauses in June 2026. But we could not find a single published fine or enforcement decision on its own website. Treat it as waking up, not asleep and not aggressive.

Medium confidenceWaking up

How long you must keep it — and when to delete it

There is no general minimum keeping period in the privacy law, and there is one striking ceiling. You must not keep personal data longer than the purpose needs. On top of that, you must not pass on or share data about an identifiable person more than seven years after the legal duty to keep it ended, unless that person expressly asks you to. Separate rules bite elsewhere: electronic certificate records must be kept seven years, and a person can demand deletion of data that is out of date or held without a legal basis.

Medium confidenceDelete data after a periodLet people delete their dataKeep data for a minimum period

If something goes wrong

One main clock: 72 hours. If personal data is breached, you must tell the regulator within 72 hours of finding out, in writing, on paper or by email. The notice must set out what happened, which data was affected, what you fixed immediately, what the person should do, where they can get more information, when it happened and why. You must also record every breach, at any stage of processing.

High confidenceReport breaches to the regulatorSecure the dataKeep records of processing

What catches people out

Five things that catch people out. One: a person can sue you directly in court under the constitution using a fast-track action called habeas data, with no lawyer needed, whether or not the regulator ever acts. Two: the worst penalty is not a fine, it is an order shutting your database or suspending your processing. Three: if you are regulated by a special law, such as a bank, the general privacy law may not apply to you at all. Four: you must not pass on personal data more than seven years after your duty to keep it ended. Five: a bank cannot outsource sensitive data handling without written permission first.

High confidenceOrder to stopClaims by individualsDelete data after a periodWritten vendor contract

What's changing next

Nothing new is scheduled to start in the next twelve months that we could confirm from a government source. The important recent changes have already landed: official model contract clauses in June 2026, a compliance circular in April 2026, and two state technology rules in May and June 2026. Watch instead for powers the government already holds and can use at any time without warning.

Medium confidenceIn force

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Acuerdo No. 009-2005, por el cual se desarrolla la Tercerizacion u Outsourcing, aclarado por la Circular No. 064-2006 y complementado por el Acuerdo No. 003-2012 sobre riesgo de tecnologia de la informacion

Directly binding regulation · Gaceta Oficial No. 25420-A de 2 de noviembre de 2005

In forceYes, with paperwork

Panamanian banks face no requirement to keep data in Panama, and the regulator's own guidance openly assumes some banks process at group technology centres abroad. What they do face is a permission gate: any outsourcing that could affect the confidentiality, integrity, availability or custody of client assets needs the Superintendency's approval, with a draft contract filed before signature.

In force since 19 April 2006

Enforced by Superintendency of Banks of Panama

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Government

Resolucion No. 07 de 11 de mayo de 2026, por la cual se establecen los controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas

Directly binding regulation · Gaceta Oficial Digital No. 30524-B de 14 de mayo de 2026

In forceYes, with paperwork

Ten mandatory cybersecurity controls for every information system of the Panamanian state, binding on the executive, legislature, judiciary, autonomous and semi-autonomous bodies and state companies, and advisory for municipalities. Bodies had 30 days from mid-May 2026 to file a self-assessment and 45 days to close any gap.

In force since 14 May 2026But only enforceable from 13 June 2026

Enforced by National Authority for Government Innovation

Transfer model: No restriction

High confidence
Government

Resolucion No. 18 de 15 de junio de 2026, por la cual se establece que todas las plataformas digitales a ser desarrolladas o gestionadas por las instituciones del Estado deberan contar con evaluacion y autorizacion por parte de la AIG

Directly binding regulation · Gaceta Oficial Digital No. 30553-D de 24 de junio de 2026

In forceYes, with paperwork

Since 24 June 2026 no Panamanian state institution may put a citizen-facing digital platform into production without the state technology authority's written authorisation, backed by an independent cybersecurity test report. Going live without it means the platform must be suspended.

In force since 24 June 2026

Enforced by National Authority for Government Innovation

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales, reglamentada por el Decreto Ejecutivo No. 285 de 28 de mayo de 2021

Act of parliament · Gaceta Oficial Digital No. 28743-A de 29 de marzo de 2019

In forceYes, with paperwork

Panama's general privacy law. It reaches databases held in Panama and controllers domiciled here, not foreign firms merely selling into the country. Data may leave freely if one of thirteen listed grounds applies. Its sharpest edges are an order to shut a database, a seven-year ban on onward sharing, and a carve-out that removes entities governed by special laws from the statute altogether.

In force since 29 March 2021

Enforced by National Authority for Transparency and Access to Information

Transfer model: No restriction · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence

Resolucion No. ANTAI-DG-003-2026, por la cual se aprueba e implementa el uso de las Clausulas Contractuales Modelo de la Red Iberoamericana de Proteccion de Datos para Transferencias Internacionales de Datos Personales

Directly binding regulation · Gaceta Oficial Digital No. 30541-A de 8 de junio de 2026

In forceYes, with paperwork

Panama's first official transfer instrument. It adopts the Ibero-American Data Protection Network's model contractual clauses as a recognised adequate safeguard for sending personal data abroad, and states plainly that organisations using them do not need prior authorisation from the regulator. The clauses must be interpreted under Panamanian law and do not replace any other duty under the privacy law.

In force since 8 June 2026

Enforced by National Authority for Transparency and Access to Information

Transfer model: No restriction · Accepted routes: Standard contract clauses

High confidence
E-commerce

Ley 51 de 22 de julio de 2008, que define y regula los documentos electronicos y las firmas electronicas y la prestacion de servicios de almacenamiento tecnologico de documentos y de certificacion de firmas electronicas, modificada por la Ley 82 de 2012

Act of parliament · Gaceta Oficial Digital No. 26090 de 24 de julio de 2008

In forceYes — store it anywhere

A licensing regime that surprises foreign providers. If you offer document archiving or storage as a service to third parties in Panama, you must register with the electronic signature authority at the Public Registry, publish a practice statement, carry insurance and submit to annual technical inspection. Foreign-stored documents can still be recognised, but only through four specific routes.

In force since 24 July 2008

Enforced by National Electronic Signature Directorate, Public Registry of Panama

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • Autoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)

    General personal data protection, through its Personal Data Protection Directorate; also freedom of information and public ethics

    Staffed and contactable, and clearly issuing binding instruments in 2026: Circular No. DS-002-2026 of 15 April 2026 and Resolucion No. ANTAI-DG-003-2026 published on 8 June 2026. However, as at 19 August 2026 we could find no published sanction decision or fine on its own website, and no enforcement statistics. Rule-making yes, visible enforcement no.

  • Consejo de Proteccion de Datos Personales

    Advisory body created by article 34 of Law 81; its formal opinion is required before the regulator may impose the very serious sanctions of closing a database or suspending processing

    Composition is set in law: chaired by the Minister of Commerce and Industry, with the consumer protection authority, ANTAI, the Ombudsman, the private enterprise council, the bar association, the banking association, the Electoral Tribunal and the chamber of commerce. We found no published minutes, membership list or opinions, so we cannot evidence that it meets. That matters because the harshest sanctions cannot be imposed without it.

  • Superintendencia de Bancos de Panama

    Banking, banking secrecy, outsourcing approvals and technology risk

    Plainly active. Its own index shows six new banking Acuerdos issued in 2026 up to August, and it publishes a sanctions section.

  • Autoridad Nacional para la Innovacion Gubernamental (AIG)

    Technology standards for the Panamanian state, government cybersecurity, the Government Security Operations Centre, and authorisation of state digital platforms

    Very active. Issued the TIC management norms in June 2025, the mandatory cybersecurity controls in May 2026 and the platform authorisation regime in June 2026, all published in the Official Gazette.

  • Direccion Nacional de Firma Electronica, Registro Publico de Panama

    Registration and supervision of electronic signature certification providers and technological document storage providers under Law 51 of 2008 and Law 82 of 2012

    Maintains a live public site with the governing laws and the implementing decree. We did not verify how many storage providers are currently registered.

  • Autoridad Nacional de los Servicios Publicos (ASEP)

    Telecommunications, broadcasting, electricity, water; telecoms governed by Ley 31 de 1996

    Active regulator, but we found no telecoms-specific data localisation, subscriber data or call record retention rule on its own site as at 19 August 2026.

  • Superintendencia del Mercado de Valores (SMV)

    Securities markets, investment funds and pensions

    Active, with Acuerdos published up to 2026. We could not enumerate individual Acuerdos because the index page requires JavaScript, so any securities technology or localisation rule is unverified.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact fine amounts for breaches of the privacy law

    Law 81 article 43 only says serious breaches attract fines 'according to their proportionality' and does not state a figure. The amounts sit in Decreto Ejecutivo No. 285 of 2021, and the copy linked from ANTAI's own legislation page returns a 404 error. We could not open the decree text from any government source in this pass.

  • The precise day Law 81 became enforceable

    Article 47 says the law starts two years after its promulgation. Promulgation and gazette publication were on 29 March 2019, so we record 29 March 2021, but sources differ between 26 and 29 March 2021 depending on whether they count from signature or publication. Plan to the earlier date.

  • Whether private-sector controllers must appoint a Personal Data Protection Officer

    ANTAI's Circular No. DS-002-2026 imposes the duty on public entities and cites articles 42 to 45 of Decree 285. We could not open the decree itself, so whether the same articles bind private controllers, and at what threshold, is unresolved.

  • Whether ANTAI has ever imposed a sanction under the privacy law

    No decisions, fines or enforcement statistics appear on its website, and its search function returned no relevant results. We cannot prove a negative; we can only report that nothing is published.

  • Whether the Personal Data Protection Council has ever been convened

    No membership list, minutes or opinions found. This matters because its formal opinion is a precondition for the harshest sanction in the law.

  • Insurance sector rules on technology, outsourcing or data

    The Superintendency of Insurance and Reinsurance website would not render without JavaScript from our environment, so we could not read its index of Acuerdos.

  • Securities sector rules on technology, outsourcing or data

    The Superintendency of the Securities Market publishes its Acuerdos behind a JavaScript-driven index we could not enumerate.

  • Online gaming and mapping or geospatial rules

    The Gaming Control Board website was unreachable from our network. No geospatial data rule was located. Both sectors are therefore unchecked rather than confirmed clear.

  • Health sector rules on medical record retention and confidentiality

    We did not reach a Ministry of Health source in this pass. Panama has patient rights legislation, but we did not verify its record-keeping or storage provisions from a government domain.

  • Tax, accounting and company record retention floors

    Not verified from a government source in this pass. Panama also has accounting record obligations for legal entities and their resident agents that are commonly cited as five years, which we could not confirm officially.

  • The full text of the AIG TIC management norms, Resolucion No. 07-2025

    The gazette copy on the AIG website is a scanned image and we did not complete optical character recognition of all 40 pages. Any data location requirement inside it is therefore unchecked.

  • Whether ANTAI has recognised any country as offering equivalent or higher protection

    Article 33(2) of Law 81 allows it and Decree 285 gives ANTAI the power, but no list appears on ANTAI's site. We record the mechanism as available but unused.

60-day cadence. Panama moved three times in 2026 alone, and several powers can be exercised by a single resolution with no consultation: recognising or withdrawing an equivalent-protection finding, amending the model contractual clauses, and adding to the mandatory cybersecurity control list for state bodies. The first published enforcement decision would also change the enforcement rating overnight.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Panama versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.