Panama
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Panama lets personal data leave the country. You do not need a permit and no destination country is banned. You just need one of thirteen legal reasons listed in the law, and since June 2026 there is an official model contract you can sign to cover yourself. The regulator writes rules and guidance but we found no published fines. Banks and government bodies face extra approval steps.
Data governance in Panama
The eight things that decide how you handle data about people in Panama. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably not, if you have nothing in Panama. The law reaches databases physically held in Panama, and it reaches anyone who is legally based in Panama. It does not say it reaches a company abroad that has no database and no office here just because it sells to Panamanians. There is no size or revenue cut-off, and we found no rule forcing a foreign firm to appoint a local representative.
Article 5 of Law 81 of 2019 sets the reach: databases situated in Panamanian territory holding personal data of nationals or foreigners, or where the controller is domiciled in the country. This is a location-and-establishment test, not the 'targeting' test used by Europe's General Data Protection Regulation or by India. In practice most foreign cloud-using businesses are caught anyway, because their Panamanian customer, subsidiary or supplier is caught. Article 5 also carves out an important exception: databases of entities regulated by special laws are excluded from Law 81 where those special laws already set minimum technical standards for protecting and processing personal data. That is why banks are effectively governed by banking secrecy rules rather than by the general privacy law.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 5 (ambito de aplicacion)
antai.gob.pa
“Las bases de datos que se encuentren en el territorio de la Republica de Panama, que almacenen o contengan datos personales de nacionales o extranjeros o que el responsable del tratamiento de los datos este domiciliado en el pais quedan sujetas a las normas establecidas en esta Ley o su reglamentacion.”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Preguntas frecuentes sobre proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
Where the data is allowed to live
Yes. Nothing has to stay in Panama. We found no rule in any industry that forces personal data to be stored inside the country. Sending data abroad is lawful if you meet any one of thirteen conditions in the law, such as the person's consent, a contract with the person, a company group transfer, a destination with equal or better protection, or an approved model contract. Two industries add a permission step that is about who handles the data, not where it sits.
Article 33 of Law 81 lists thirteen alternative grounds. They are alternatives, not cumulative: meeting one is enough. Article 5 adds a general condition that whoever stores or transfers confidential, sensitive or restricted data originating in Panama must meet Panama's protection standards or show they meet equal or higher ones, with exceptions for consent, contract necessity, banking and securities transfers, and transfers required by ratified treaties. Sector by sector, checked on 19 August 2026: BANKING — no localisation, but outsourcing that touches confidentiality, integrity, availability or custody of client assets needs prior written approval from the Superintendency of Banks, and the regulator's own 2006 circular openly contemplates banks whose technology processing centres sit abroad. SECURITIES — no localisation rule found on the regulator's index of Acuerdos. INSURANCE — no localisation rule found; the regulator's site would not load without JavaScript, so this is a weaker finding. HEALTH — no localisation rule found. TELECOM — no localisation or call-record retention rule found on the regulator's own telecom pages. GOVERNMENT — no localisation rule found, but state bodies must pass a cybersecurity control checklist and get the state technology authority's authorisation before a citizen-facing platform goes live. GAMING and MAPPING — the gaming board's website was unreachable from our network, so those two are unverified.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 33 (transferencia licita) and articulo 5
antai.gob.pa
“Se entendera que toda transferencia de datos personales es licita si se cumple al menos una de las condiciones siguientes”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 de 4 de diciembre de 2006 — aclaraciones sobre el Acuerdo No. 9-2005 (tercerizacion tecnologica y centros de procesamiento en el extranjero)
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceASEPAutoridad Nacional de los Servicios Publicos — Direccion Nacional de Telecomunicaciones (sector governed by Ley 31 de 1996)
asep.gob.pa
Link checked 19 August 2026
- Official sourceSMVSuperintendencia del Mercado de Valores — Acuerdos (index, 2000 to 2026)
supervalores.gob.pa
Link checked 19 August 2026
Sending data out of the country
No government permission is needed, and there is no list of approved or banned countries. You pick one of the thirteen legal grounds and you keep evidence. Since 8 June 2026 there is an easier route: the regulator has published official model contract clauses. If you sign those, you do not have to ask the regulator for permission. Sensitive data, such as health or biometric records, needs the person's explicit agreement.
Resolucion No. ANTAI-DG-003-2026 of 26 March 2026, published in the Official Gazette on 8 June 2026, adopts the model contractual clauses of the Ibero-American Data Protection Network in two versions: controller-to-controller and controller-to-processor. Point TWO of the resolution states that users of the clauses do not need to seek prior authorisation from the Directorate General for international transfers, provided the transfer complies with Law 81, Decree 285 and other applicable rules. Point THREE requires the clauses to be used without altering their wording except for the personalisation the models themselves indicate. Point FOUR allows them to be embedded in wider contracts or supplemented with extra guarantees, so long as nothing contradicts them or lowers protection. Point FIVE recognises them as an adequate safeguard, without prejudice to the regulator's supervisory powers. The regulator can also recognise a destination as offering equivalent or higher protection, but we found no published list of such destinations, so in practice that route is unused.
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026, points PRIMERO to NOVENO — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
“entendiendo que quienes las utilicen no deberan solicitar autorizacion previa ante esta Direccion General para realizar transferencias internacionales”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 33
antai.gob.pa
Link checked 19 August 2026
The regulator, and whether it actually acts
The National Authority for Transparency and Access to Information, through its Personal Data Protection Directorate. It exists, it is contactable, and it is clearly working: it issued a compliance circular in April 2026 and adopted official model contract clauses in June 2026. But we could not find a single published fine or enforcement decision on its own website. Treat it as waking up, not asleep and not aggressive.
The authority is usually called ANTAI, from its Spanish name Autoridad Nacional de Transparencia y Acceso a la Informacion. Article 36 of Law 81 gives its data protection directorate the power to sanction both the controller and the database custodian. Article 43 grades penalties: minor breaches bring a summons; serious breaches bring proportionate fines; very serious breaches bring closure of the database registry or temporary or permanent suspension of data storage and processing, plus a fine. Very serious sanctions require a formal opinion from the Personal Data Protection Council before the authority can act, and the authority may call on the police to enforce a closure. That extra step, plus the absence of published decisions, is why we rate enforcement as waking rather than active. Sector regulators are a different story: the Superintendency of Banks and the state technology authority are both plainly operational and issuing binding instruments in 2026. Separately, individuals can bypass the regulator entirely and go to court through the constitutional habeas data action.
Sources
- Official sourceANTAIANTAI — Direccion de Proteccion de Datos Personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — Cumplimiento de obligaciones de proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 36, 42 and 43 (sanciones)
antai.gob.pa
“Faltas muy graves: a. Clausura de los registros de la base de datos, sin perjuicio de la multa correspondiente.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is no general minimum keeping period in the privacy law, and there is one striking ceiling. You must not keep personal data longer than the purpose needs. On top of that, you must not pass on or share data about an identifiable person more than seven years after the legal duty to keep it ended, unless that person expressly asks you to. Separate rules bite elsewhere: electronic certificate records must be kept seven years, and a person can demand deletion of data that is out of date or held without a legal basis.
The purpose-limitation principle in article 2(2) of Law 81 forbids keeping data for longer than needed. Article 28 is the unusual one and is easy to miss: it bans transferring or communicating data relating to an identified or identifiable person once seven years have passed since the legal obligation to keep it ended, unless the person expressly requests otherwise. Article 16 gives a person the right to demand deletion where storage has no legal basis, was never authorised, or the data has gone stale, and the response deadline for an access request is ten working days. Under Law 51 of 2008, records of electronic certificates must be kept for seven years, and providers of technological document storage must keep the records and practice statements at least as long as the law requires the stored document to be kept. We did not verify Panama's tax and commercial book-keeping floors from a government source in this pass, so treat those as open.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 2(2), 16 and 28
antai.gob.pa
“En ningun caso el responsable del tratamiento de datos personales y/o el custodio de la base de datos pueden transferir o comunicar los datos que se relacionen con una persona identificada o identificable, despues de transcurridos siete anos desde que se extinguio la obligacion legal de conservarla, salvo que el titular de los datos personales expresamente solicite lo contrario.”
Link checked 19 August 2026
- Official sourceRegistro Publico de PanamaLey 51 de 2008, articulo 28 (seven-year retention of certificate records) and articulo 55(7)
firmaelectronica.gob.pa
Link checked 19 August 2026
If something goes wrong
One main clock: 72 hours. If personal data is breached, you must tell the regulator within 72 hours of finding out, in writing, on paper or by email. The notice must set out what happened, which data was affected, what you fixed immediately, what the person should do, where they can get more information, when it happened and why. You must also record every breach, at any stage of processing.
The 72-hour deadline comes from the implementing decree, Decreto Ejecutivo No. 285 of 28 May 2021, and was restated in ANTAI's Circular No. DS-002-2026 of 15 April 2026. That circular is formally addressed to the public sector, from ministers down to mayors, but it recites the general obligation on any controller. Articles 36, 37 and 38 of the same decree require security measures to be established, operated, monitored, reviewed, maintained and continuously improved on a recurring basis. Watch for a second clock if you are a bank or a state body: state entities operate under the Government Security Operations Centre created by Decreto Ejecutivo No. 53 of 11 June 2025 and run by the state technology authority. We did not find a published nationwide cyber-incident reporting deadline separate from the 72-hour data breach rule, so unlike India or Singapore there does not appear to be a second, much shorter clock for the private sector.
Sources
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — 72-hour breach notification and data protection officer designation
antai.gob.pa
“en caso de producirse una violacion de seguridad de datos personales, el responsable del tratamiento debera notificar a esta Autoridad dentro de un plazo no mayor de setenta y dos (72) horas, contadas a partir del momento en que tenga conocimiento del incidente”
Link checked 19 August 2026
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
What catches people out
Five things that catch people out. One: a person can sue you directly in court under the constitution using a fast-track action called habeas data, with no lawyer needed, whether or not the regulator ever acts. Two: the worst penalty is not a fine, it is an order shutting your database or suspending your processing. Three: if you are regulated by a special law, such as a bank, the general privacy law may not apply to you at all. Four: you must not pass on personal data more than seven years after your duty to keep it ended. Five: a bank cannot outsource sensitive data handling without written permission first.
(1) Article 44 of the Constitution creates habeas data as a summary court process, expressly available without a lawyer, to obtain, correct, update, delete or keep confidential personal information held by public or private record-keepers, where the private holder is a business providing a service to the public or supplying information. Article 42 gives a constitutional right of access, rectification, protection and deletion. This runs in parallel with the regulator and is the more likely source of real-world exposure while the regulator is still warming up. (2) Article 43 of Law 81 makes closure of the database registry and temporary or permanent suspension of storage or processing the sanctions for very serious breaches. Commercially that outweighs any fine. (3) Article 5 of Law 81 excludes databases of entities governed by special laws where those laws already set minimum technical standards, which is a real carve-out and not a formality. (4) The seven-year onward-transfer ban in article 28 has no equivalent in most privacy laws and is easy to overlook. (5) Under the banking regulator's Acuerdo No. 009-2005 all outsourcing except a short list of administrative and general services needs prior authorisation, and its Circular No. 064-2006 requires a draft of the contract to be sent to the regulator before it is signed. The regulator has 30 working days to decide and the bank may not start until it is notified.
Sources
- Official sourceAsamblea Nacional / ANTAIConstitucion Politica de la Republica de Panama, articulos 29, 42, 43 and 44 (habeas data)
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 5, 28 and 43
antai.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 de 4 de diciembre de 2006 — aclaraciones sobre el Acuerdo No. 9-2005 (tercerizacion tecnologica y centros de procesamiento en el extranjero)
superbancos.gob.pa
Link checked 19 August 2026
What's changing next
Nothing new is scheduled to start in the next twelve months that we could confirm from a government source. The important recent changes have already landed: official model contract clauses in June 2026, a compliance circular in April 2026, and two state technology rules in May and June 2026. Watch instead for powers the government already holds and can use at any time without warning.
Dormant switches, all already in law and usable without consultation. First, the regulator can recognise a country or international body as offering equivalent or higher protection, or withdraw that view. No list has ever been published, so both directions are open. Second, the implementing decree lets the regulator validate and adopt model contractual clauses as a condition of lawfulness for transfers, inside and outside the country. It used that power for the first time in 2026 and can amend or replace the clauses the same way. Third, the state technology authority can add to the mandatory cybersecurity control list for public bodies by resolution, and did so in May 2026 with a 30-day self-assessment deadline and a 45-day remediation deadline. Fourth, since June 2026 it can refuse to authorise, or order the suspension of, any citizen-facing state digital platform. Fifth, the very serious sanctions in the privacy law, database closure and suspension of processing, have never been used publicly, so the first use will be a step change rather than a legal change.
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGResolucion No. 18 de 15 de junio de 2026 — Evaluacion y autorizacion por la AIG de las plataformas digitales del Estado — Gaceta Oficial Digital No. 30553-D, 24 June 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Acuerdo No. 009-2005, por el cual se desarrolla la Tercerizacion u Outsourcing, aclarado por la Circular No. 064-2006 y complementado por el Acuerdo No. 003-2012 sobre riesgo de tecnologia de la informacion
Directly binding regulation · Gaceta Oficial No. 25420-A de 2 de noviembre de 2005
Panamanian banks face no requirement to keep data in Panama, and the regulator's own guidance openly assumes some banks process at group technology centres abroad. What they do face is a permission gate: any outsourcing that could affect the confidentiality, integrity, availability or custody of client assets needs the Superintendency's approval, with a draft contract filed before signature.
Enforced by Superintendency of Banks of Panama
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractThe written contract must name the supplier, define the activity and the place where the service is performed, identify ownership of data and systems, and require the bank's prior approval of any sub-contracting.
- Extra vendor secrecy termsThe supplier must expressly acknowledge the banking secrecy duty in the Banking Law. A standard data processing agreement is not enough.
- Register or notifyPrior authorisation from the Superintendency for any outsourcing outside a short list of administrative activities, general services, marketing, logistics, cash transport, vehicle leasing, call centres and training. Decision within 30 working days; the bank may not start until notified.
- Independent auditInternal and external audit must be able to control outsourced activities and reach the relevant information.
What it costs if you get it wrong
- Fixed maximum fine: B/.1,000,000 (the balboa is fixed one-for-one with the United States dollar, so about one million US dollars) — about $1 millionSanctions under the Banking Law, article 185
Sources
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 — technology outsourcing and processing centres abroad
superbancos.gob.pa
“las entidades bancarias que tengan sus centros de procesamientos tecnologicos en el extranjero (casas matrices, etc.) deberan contar con acuerdos de servicio internos que garanticen el cumplimiento de estas disposiciones segun apliquen”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 003-2012 de 22 de mayo de 2012 — Lineamientos para la gestion del riesgo de la tecnologia de la informacion
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaLey Bancaria (Texto Unico del Decreto Ley 9 de 1998), articulos 111 (confidencialidad bancaria) and 185 (multas)
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaSuperintendencia de Bancos de Panama — index of banking Acuerdos to August 2026
superbancos.gob.pa
Link checked 19 August 2026
Resolucion No. 07 de 11 de mayo de 2026, por la cual se establecen los controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas
Directly binding regulation · Gaceta Oficial Digital No. 30524-B de 14 de mayo de 2026
Ten mandatory cybersecurity controls for every information system of the Panamanian state, binding on the executive, legislature, judiciary, autonomous and semi-autonomous bodies and state companies, and advisory for municipalities. Bodies had 30 days from mid-May 2026 to file a self-assessment and 45 days to close any gap.
Enforced by National Authority for Government Innovation
Transfer model: No restriction
What it makes you do
- Secure the data — from 14 May 2026Ten mandatory controls: internet-facing asset inventory, patching, multi-factor authentication for virtual private network access, external webmail and software-as-a-service platforms, supported operating systems, anti-malware, a demilitarised zone with a web application firewall, restricted administrative access from the internet, web filtering and email security.
- Independent audit — 1 year, from 14 May 2026At least one external penetration test each year covering internet-facing assets, with findings and remediation documented.
- Keep records of processing — from 13 June 2026Self-assessment compliance report to the state technology authority within 30 calendar days, with documentary evidence for each control met and a remediation plan to be completed within 45 calendar days for each control not met.
Sources
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGAIG — Estandares y Resoluciones (index of technology standards for the Panamanian state)
aig.gob.pa
Link checked 19 August 2026
Resolucion No. 18 de 15 de junio de 2026, por la cual se establece que todas las plataformas digitales a ser desarrolladas o gestionadas por las instituciones del Estado deberan contar con evaluacion y autorizacion por parte de la AIG
Directly binding regulation · Gaceta Oficial Digital No. 30553-D de 24 de junio de 2026
Since 24 June 2026 no Panamanian state institution may put a citizen-facing digital platform into production without the state technology authority's written authorisation, backed by an independent cybersecurity test report. Going live without it means the platform must be suspended.
Enforced by National Authority for Government Innovation
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notify — from 24 June 2026Written authorisation from the state technology authority before any citizen-facing state digital platform goes live. Decision within 15 days.
- Independent audit — from 24 June 2026Cybersecurity test report from an independent third party unconnected with the build, evidencing that critical and high vulnerabilities were fixed, plus functional and load and stress test results.
- Assess high-risk projects — from 24 June 2026The recitals state the authority must ensure compliance with cybersecurity, interoperability and personal data protection rules before authorising.
What it costs if you get it wrong
- Order to stopPutting a citizen-facing platform into production without authorisation — operation must be suspended temporarily or permanently
Sources
- Official sourceAIGResolucion No. 18 de 15 de junio de 2026 — Evaluacion y autorizacion por la AIG de las plataformas digitales del Estado — Gaceta Oficial Digital No. 30553-D, 24 June 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGAIG — Estandares y Resoluciones (index of technology standards for the Panamanian state)
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGResolucion No. 07-2025 — Normas Generales para la Gestion de las TIC, version 2.1 — Gaceta Oficial Digital No. 30308-B, 25 June 2025
aig.gob.pa
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales, reglamentada por el Decreto Ejecutivo No. 285 de 28 de mayo de 2021
Act of parliament · Gaceta Oficial Digital No. 28743-A de 29 de marzo de 2019
Panama's general privacy law. It reaches databases held in Panama and controllers domiciled here, not foreign firms merely selling into the country. Data may leave freely if one of thirteen listed grounds applies. Its sharpest edges are an order to shut a database, a seven-year ban on onward sharing, and a carve-out that removes entities governed by special laws from the statute altogether.
Enforced by National Authority for Transparency and Access to Information
Transfer model: No restriction · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Get consent
- Tell people what you do
- Let people see their dataTen working days to answer an access request (article 16 of Law 81).
- Let people correct their data
- Let people delete their dataAvailable where storage has no legal basis, was not authorised, or the data has gone stale.
- Let people object
- Let people take their data elsewhere
- Secure the dataDecree 285 articles 36 to 38 require security measures to be established, operated, monitored, reviewed, maintained and continuously improved on a recurring basis.
- Report breaches to the regulator — within 72 hoursIn writing, on paper or by email, with nine prescribed content items.
- Keep records of processingEvery security breach must be documented at any stage of processing.
- Delete data after a period — 7 yearsNo onward transfer or communication of data about an identifiable person more than seven years after the legal duty to keep it ended, unless the person expressly asks otherwise.
- Put a transfer safeguard in placeOne of the thirteen grounds in article 33 must be documented before data leaves Panama.
- Appoint a data protection officerDecree 285 articles 42 to 45 regulate the Personal Data Protection Officer. ANTAI's April 2026 circular requires public entities to notify their designation in writing; the position for private-sector controllers is not clearly stated in the sources we could open.
What it costs if you get it wrong
- Order to stopVery serious breach — closure of the database registry, or temporary or permanent suspension and disqualification of storage and processing. Requires a formal opinion from the Personal Data Protection Council; police assistance may be used to enforce.
- Fixed maximum fine: Not fixed in Law 81 — article 43 provides fines 'segun su proporcionalidad'; the amounts sit in the implementing decree, which we could not openSerious and very serious breaches
- Claims by individualsConstitutional habeas data action brought by the individual in court under article 44 of the Constitution
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales — Gaceta Oficial Digital No. 28743-A, 29 March 2019
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — Cumplimiento de obligaciones de proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
Resolucion No. ANTAI-DG-003-2026, por la cual se aprueba e implementa el uso de las Clausulas Contractuales Modelo de la Red Iberoamericana de Proteccion de Datos para Transferencias Internacionales de Datos Personales
Directly binding regulation · Gaceta Oficial Digital No. 30541-A de 8 de junio de 2026
Panama's first official transfer instrument. It adopts the Ibero-American Data Protection Network's model contractual clauses as a recognised adequate safeguard for sending personal data abroad, and states plainly that organisations using them do not need prior authorisation from the regulator. The clauses must be interpreted under Panamanian law and do not replace any other duty under the privacy law.
Enforced by National Authority for Transparency and Access to Information
Transfer model: No restriction · Accepted routes: Standard contract clauses
What it makes you do
- Put a transfer safeguard in place — from 8 June 2026Two model agreements: controller-to-controller and controller-to-processor. Must be used without altering the wording except for the personalisation the models indicate.
- Written vendor contract — from 8 June 2026The data subject is a third-party beneficiary of the contract and can enforce it without having signed it.
What it costs if you get it wrong
- Order to stopFailure to comply with the obligations flowing from the model clauses may be taken into account by ANTAI when exercising supervision and control under Law 81 and Decree 285
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
Ley 51 de 22 de julio de 2008, que define y regula los documentos electronicos y las firmas electronicas y la prestacion de servicios de almacenamiento tecnologico de documentos y de certificacion de firmas electronicas, modificada por la Ley 82 de 2012
Act of parliament · Gaceta Oficial Digital No. 26090 de 24 de julio de 2008
A licensing regime that surprises foreign providers. If you offer document archiving or storage as a service to third parties in Panama, you must register with the electronic signature authority at the Public Registry, publish a practice statement, carry insurance and submit to annual technical inspection. Foreign-stored documents can still be recognised, but only through four specific routes.
Enforced by National Electronic Signature Directorate, Public Registry of Panama
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyAnyone offering technological document storage to third parties in Panama must register and pay a fee, set by default at B/.1,000 (about one thousand US dollars). The authority has 90 days to decide; silence counts as approval.
- Secure the dataQualified staff, tamper-proof systems, confidentiality of user information, a contingency plan, and civil liability insurance no lower than the maximum fine the authority can impose.
- Keep data for a minimum periodRecords and practice statements must be kept at least as long as the law requires the stored document to be kept, counted from when the document was stored.
- Independent audit — 1 yearAt least one technical evaluation a year by the supervising authority.
- Tell people what you doA public, free-of-charge Declaration of Technological Storage Practices must be published.
Sources
- Official sourceDireccion Nacional de Firma Electronica, Registro Publico de PanamaLey 51 de 22 de julio de 2008 — documentos electronicos, firmas electronicas y almacenamiento tecnologico de documentos — Gaceta Oficial Digital No. 26090, 24 July 2008
firmaelectronica.gob.pa
Link checked 19 August 2026
- Official sourceRegistro Publico de PanamaDireccion Nacional de Firma Electronica — Registro Publico de Panama (Ley 51 de 2008, Ley 82 de 2012, Decreto Ejecutivo 684 de 2013)
firmaelectronica.gob.pa
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact fine amounts for breaches of the privacy law
Law 81 article 43 only says serious breaches attract fines 'according to their proportionality' and does not state a figure. The amounts sit in Decreto Ejecutivo No. 285 of 2021, and the copy linked from ANTAI's own legislation page returns a 404 error. We could not open the decree text from any government source in this pass.
The precise day Law 81 became enforceable
Article 47 says the law starts two years after its promulgation. Promulgation and gazette publication were on 29 March 2019, so we record 29 March 2021, but sources differ between 26 and 29 March 2021 depending on whether they count from signature or publication. Plan to the earlier date.
Whether private-sector controllers must appoint a Personal Data Protection Officer
ANTAI's Circular No. DS-002-2026 imposes the duty on public entities and cites articles 42 to 45 of Decree 285. We could not open the decree itself, so whether the same articles bind private controllers, and at what threshold, is unresolved.
Whether ANTAI has ever imposed a sanction under the privacy law
No decisions, fines or enforcement statistics appear on its website, and its search function returned no relevant results. We cannot prove a negative; we can only report that nothing is published.
Whether the Personal Data Protection Council has ever been convened
No membership list, minutes or opinions found. This matters because its formal opinion is a precondition for the harshest sanction in the law.
Insurance sector rules on technology, outsourcing or data
The Superintendency of Insurance and Reinsurance website would not render without JavaScript from our environment, so we could not read its index of Acuerdos.
Securities sector rules on technology, outsourcing or data
The Superintendency of the Securities Market publishes its Acuerdos behind a JavaScript-driven index we could not enumerate.
Online gaming and mapping or geospatial rules
The Gaming Control Board website was unreachable from our network. No geospatial data rule was located. Both sectors are therefore unchecked rather than confirmed clear.
Health sector rules on medical record retention and confidentiality
We did not reach a Ministry of Health source in this pass. Panama has patient rights legislation, but we did not verify its record-keeping or storage provisions from a government domain.
Tax, accounting and company record retention floors
Not verified from a government source in this pass. Panama also has accounting record obligations for legal entities and their resident agents that are commonly cited as five years, which we could not confirm officially.
The full text of the AIG TIC management norms, Resolucion No. 07-2025
The gazette copy on the AIG website is a scanned image and we did not complete optical character recognition of all 40 pages. Any data location requirement inside it is therefore unchecked.
Whether ANTAI has recognised any country as offering equivalent or higher protection
Article 33(2) of Law 81 allows it and Decree 285 gives ANTAI the power, but no list appears on ANTAI's site. We record the mechanism as available but unused.
60-day cadence. Panama moved three times in 2026 alone, and several powers can be exercised by a single resolution with no consultation: recognising or withdrawing an equivalent-protection finding, amending the model contractual clauses, and adding to the mandatory cybersecurity control list for state bodies. The first published enforcement decision would also change the enforcement rating overnight.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Panama versus
Compare