Panama
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Panama — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Panama. You do not need a permit. No destination country is banned. You just need one of thirteen legal reasons listed in the law. Since June 2026 you can also sign an official model contract to cover yourself. The regulator writes rules and guidance. We found no published fines. Banks and government bodies face extra approval steps.
Data governance in Panama
The eight things that decide how you handle data about people in Panama. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably not, if you have nothing in Panama. The law covers databases physically held in Panama. It also covers anyone legally based in Panama. It does not cover a company abroad that has no database and no office here, even if it sells to Panamanians. There is no size or revenue cut-off. We found no rule making a foreign firm appoint a local representative.
Article 5 of Law 81 of 2019 sets the reach. It covers databases in Panamanian territory that hold personal data of nationals or foreigners. It also covers the company that decides how data is used, if that company is based in Panama. The test is where you are and where the database is. It is not the 'targeting' test used by Europe's General Data Protection Regulation or by India. Most foreign businesses using cloud services get caught anyway, because their Panamanian customer, subsidiary or supplier is caught. Article 5 also has an important exception. Databases of companies covered by special laws fall outside Law 81, where those special laws already set minimum technical standards for protecting and using personal data. That is why banks answer to banking secrecy rules rather than to the general privacy law.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 5 (ambito de aplicacion)
antai.gob.pa
“Las bases de datos que se encuentren en el territorio de la Republica de Panama, que almacenen o contengan datos personales de nacionales o extranjeros o que el responsable del tratamiento de los datos este domiciliado en el pais quedan sujetas a las normas establecidas en esta Ley o su reglamentacion.”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Preguntas frecuentes sobre proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
Where the data is allowed to live
Yes. Nothing has to stay in Panama. We found no rule in any industry that forces personal data to be stored inside the country. Sending data abroad is lawful if you meet any one of thirteen conditions in the law. Examples: the person's consent, a contract with the person, a transfer inside your company group, a destination with equal or better protection, or an approved model contract. Two industries add a permission step. That step is about who handles the data, not where it sits.
Article 33 of Law 81 lists thirteen grounds. You only need one of them. Article 5 adds a general condition. Whoever stores or transfers confidential, sensitive or restricted data that comes from Panama must meet Panama's protection standards, or show they meet equal or higher ones. There are exceptions for consent, contract necessity, banking and securities transfers, and transfers required by ratified treaties. Here is what we found industry by industry, checked on 19 August 2026. BANKING: data does not have to stay in the country. But outsourcing that touches confidentiality, integrity, availability or custody of client assets needs prior written approval from the Superintendency of Banks. The regulator's own 2006 circular openly accepts that some banks run their technology centres abroad. SECURITIES: we found no rule about keeping data in the country on the regulator's index of Acuerdos. INSURANCE: we found no such rule. The regulator's site would not load without JavaScript, so this finding is weaker. HEALTH: we found no such rule. TELECOM: we found no rule about keeping data in the country and no call-record keeping rule on the regulator's own telecom pages. GOVERNMENT: we found no such rule. But state bodies must pass a cybersecurity control checklist and get the state technology authority's approval before a citizen-facing platform goes live. GAMING and MAPPING: the gaming board's website was unreachable from our network, so those two are unchecked.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 33 (transferencia licita) and articulo 5
antai.gob.pa
“Se entendera que toda transferencia de datos personales es licita si se cumple al menos una de las condiciones siguientes”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 de 4 de diciembre de 2006 — aclaraciones sobre el Acuerdo No. 9-2005 (tercerizacion tecnologica y centros de procesamiento en el extranjero)
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceASEPAutoridad Nacional de los Servicios Publicos — Direccion Nacional de Telecomunicaciones (sector governed by Ley 31 de 1996)
asep.gob.pa
Link checked 19 August 2026
- Official sourceSMVSuperintendencia del Mercado de Valores — Acuerdos (index, 2000 to 2026)
supervalores.gob.pa
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Panama.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
You do not need government permission. There is no list of approved or banned countries. Pick one of the thirteen legal grounds and keep evidence. Since 8 June 2026 there is an easier route. The regulator has published official model contract clauses. If you sign those, you do not have to ask the regulator for permission. Sensitive data, such as health or biometric records, needs the person's explicit agreement.
- Ways to send data out:
- Standard contract clauses · Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract
Resolucion No. ANTAI-DG-003-2026 of 26 March 2026 was published in the Official Gazette on 8 June 2026. It adopts the model contract clauses of the Ibero-American Data Protection Network. There are two versions. One is for two companies that each decide how the data is used. The other is for a company and the supplier that handles data on its behalf. Point TWO says that if you use the clauses you do not need prior permission from the Directorate General to send data abroad. The transfer must still follow Law 81, Decree 285 and other applicable rules. Point THREE says you must not change the wording, except where the models tell you to fill in your own details. Point FOUR lets you put the clauses inside a wider contract, or add extra guarantees. Nothing you add may contradict them or lower protection. Point FIVE recognises them as enough protection on their own. The regulator keeps its supervisory powers. The regulator can also recognise a destination country as offering equal or higher protection. We found no published list of such countries, so nobody uses that route.
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026, points PRIMERO to NOVENO — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
“entendiendo que quienes las utilicen no deberan solicitar autorizacion previa ante esta Direccion General para realizar transferencias internacionales”
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulo 33
antai.gob.pa
Link checked 19 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The National Authority for Transparency and Access to Information, through its Personal Data Protection Directorate. It exists and it is contactable. It is clearly working. It issued a compliance circular in April 2026 and adopted official model contract clauses in June 2026. But we could not find a single published fine or enforcement decision on its own website. Expect a regulator that is getting started, not one that is aggressive.
The authority is usually called ANTAI, from its Spanish name Autoridad Nacional de Transparencia y Acceso a la Informacion. Article 36 of Law 81 lets its data protection directorate punish two parties. One is the company that decides how the data is used. The other is whoever keeps the database. Article 43 grades penalties. Minor breaches bring a summons. Serious breaches bring fines set in proportion to the breach. Very serious breaches bring closure of the database registry, or a temporary or permanent ban on storing and using the data, plus a fine. Before imposing a very serious penalty, the authority needs a formal opinion from the Personal Data Protection Council. It may also call on the police to enforce a closure. That extra step, plus the lack of published decisions, is why we rate enforcement as getting started rather than active. Industry regulators are a different story. The Superintendency of Banks and the state technology authority are both clearly working and issuing binding rules in 2026. People can also skip the regulator and go straight to court, using the constitutional habeas data action.
Sources
- Official sourceANTAIANTAI — Direccion de Proteccion de Datos Personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — Cumplimiento de obligaciones de proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 36, 42 and 43 (sanciones)
antai.gob.pa
“Faltas muy graves: a. Clausura de los registros de la base de datos, sin perjuicio de la multa correspondiente.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is no general minimum keeping period in the privacy law. There is one unusual ceiling. You must not keep personal data for longer than your purpose needs. You must also not pass on or share data about an identifiable person more than seven years after your legal duty to keep it ended. The only exception is if that person expressly asks you to. Other rules apply elsewhere. Electronic certificate records must be kept seven years. A person can demand deletion of data that is out of date or held with no legal basis.
- What you have to do here:
- Delete data after a period · Let people delete their data · Keep data for a minimum period
Article 2(2) of Law 81 says you must not keep data for longer than you need it. Article 28 is the unusual one and is easy to miss. It bans transferring or sharing data about an identified or identifiable person once seven years have passed since your legal duty to keep it ended. The only exception is if the person expressly asks you to. Article 16 lets a person demand deletion where storing the data has no legal basis, was never authorised, or the data has gone out of date. You must answer an access request within ten working days. Under Law 51 of 2008, records of electronic certificates must be kept for seven years. Providers of technological document storage must keep the records and practice statements at least as long as the law requires the stored document to be kept. We did not check Panama's tax and book-keeping minimums against a government source, so treat those as open.
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 2(2), 16 and 28
antai.gob.pa
“En ningun caso el responsable del tratamiento de datos personales y/o el custodio de la base de datos pueden transferir o comunicar los datos que se relacionen con una persona identificada o identificable, despues de transcurridos siete anos desde que se extinguio la obligacion legal de conservarla, salvo que el titular de los datos personales expresamente solicite lo contrario.”
Link checked 19 August 2026
- Official sourceRegistro Publico de PanamaLey 51 de 2008, articulo 28 (seven-year retention of certificate records) and articulo 55(7)
firmaelectronica.gob.pa
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
One main clock: 72 hours. If personal data is breached, you must tell the regulator within 72 hours of finding out. Send it in writing, on paper or by email. The notice must say what happened, which data was affected, what you fixed immediately, what the person should do, where they can get more information, when it happened and why. You must also record every breach, at any stage of handling the data.
- What you have to do here:
- Report breaches to the regulator · Secure the data · Keep records of how you use data
The 72-hour deadline comes from the implementing decree, Decreto Ejecutivo No. 285 of 28 May 2021. ANTAI repeated it in Circular No. DS-002-2026 of 15 April 2026. That circular is formally addressed to the public sector, from ministers down to mayors. But it restates the general duty on any company that decides how data is used. Articles 36, 37 and 38 of the same decree say security measures must be set up, run, monitored, reviewed, maintained and improved on a repeating basis. Watch for a second clock if you are a bank or a state body. State bodies work under the Government Security Operations Centre, created by Decreto Ejecutivo No. 53 of 11 June 2025 and run by the state technology authority. We did not find a published nationwide cyber-incident reporting deadline separate from the 72-hour data breach rule. So unlike India or Singapore, there does not appear to be a second, much shorter clock for private companies.
Sources
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — 72-hour breach notification and data protection officer designation
antai.gob.pa
“en caso de producirse una violacion de seguridad de datos personales, el responsable del tratamiento debera notificar a esta Autoridad dentro de un plazo no mayor de setenta y dos (72) horas, contadas a partir del momento en que tenga conocimiento del incidente”
Link checked 19 August 2026
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
What to do: Your breach process has to reach Panama's regulator inside the deadline above.
What catches people out
Five things catch people out. One: a person can sue you directly in court under the constitution. The action is called habeas data, it is fast, and they need no lawyer. It works whether or not the regulator ever acts. Two: the worst penalty is not a fine. It is an order shutting your database or banning you from using the data. Three: if a special law covers you, such as a bank, the general privacy law may not apply to you at all. Four: you must not pass on personal data more than seven years after your duty to keep it ended. Five: a bank cannot outsource sensitive data work without written permission first.
- What you have to do here:
- Delete data after a period · Written vendor contract
- What it costs if you get it wrong:
- Order to stop · Claims by individuals
(1) Article 44 of the Constitution creates habeas data, a fast court process. You expressly do not need a lawyer. You can use it to get, correct, update, delete or keep confidential personal information held by public or private record-keepers. For a private holder, it applies where that holder is a business providing a service to the public or supplying information. Article 42 gives a constitutional right of access, correction, protection and deletion. This runs alongside the regulator. It is the more likely source of real trouble while the regulator is still getting started. (2) Article 43 of Law 81 punishes very serious breaches by closing the database registry and banning storage or use of the data, either for a time or permanently. That hurts a business more than any fine. (3) Article 5 of Law 81 excludes databases of companies governed by special laws, where those laws already set minimum technical standards. That is a real exclusion, not a formality. (4) The seven-year ban on passing data on, in article 28, has no equivalent in most privacy laws and is easy to miss. (5) Under the banking regulator's Acuerdo No. 009-2005, all outsourcing needs prior permission, apart from a short list of administrative and general services. Its Circular No. 064-2006 requires a draft of the contract to be sent to the regulator before it is signed. The regulator has 30 working days to decide. The bank may not start until it is told.
Sources
- Official sourceAsamblea Nacional / ANTAIConstitucion Politica de la Republica de Panama, articulos 29, 42, 43 and 44 (habeas data)
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 2019, articulos 5, 28 and 43
antai.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 de 4 de diciembre de 2006 — aclaraciones sobre el Acuerdo No. 9-2005 (tercerizacion tecnologica y centros de procesamiento en el extranjero)
superbancos.gob.pa
Link checked 19 August 2026
What's changing next
Nothing new is scheduled to start in the next twelve months that we could confirm from a government source. The important recent changes have already landed. Official model contract clauses arrived in June 2026. A compliance circular arrived in April 2026. Two state technology rules arrived in May and June 2026. Watch instead for powers the government already holds and can use at any time without warning.
These powers are already in the law and can be used without consultation. First, the regulator can recognise a country or international body as offering equal or higher protection, or withdraw that view. No list has ever been published, so it could go either way. Second, the implementing decree lets the regulator approve and adopt model contract clauses, and make them a condition of a lawful transfer, inside and outside the country. It used that power for the first time in 2026. It can change or replace the clauses the same way. Third, the state technology authority can add to the mandatory cybersecurity control list for public bodies by resolution. It did so in May 2026, with a 30-day self-assessment deadline and a 45-day fix deadline. Fourth, since June 2026 it can refuse to approve any citizen-facing state digital platform, or order it suspended. Fifth, the very serious penalties in the privacy law are closing a database and banning the use of data. Neither has ever been used publicly. The first use would be a big shift, even though the law itself would not change.
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGResolucion No. 18 de 15 de junio de 2026 — Evaluacion y autorizacion por la AIG de las plataformas digitales del Estado — Gaceta Oficial Digital No. 30553-D, 24 June 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Acuerdo No. 009-2005, por el cual se desarrolla la Tercerizacion u Outsourcing, aclarado por la Circular No. 064-2006 y complementado por el Acuerdo No. 003-2012 sobre riesgo de tecnologia de la informacion · Gaceta Oficial No. 25420-A de 2 de noviembre de 2005 · Directly binding regulation
Panamanian banks do not have to keep data in Panama. The regulator's own guidance openly assumes some banks use group technology centres abroad. What banks do face is a permission step. Any outsourcing that could affect the confidentiality, integrity, availability or custody of client assets needs the Superintendency's approval. You must file a draft contract before you sign it.
Enforced by Superintendency of Banks of Panama
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractThe written contract must name the supplier. It must define the activity and where the service is performed. It must say who owns the data and the systems. It must require the bank's approval before any sub-contracting.
- Extra vendor secrecy termsThe supplier must expressly accept the banking secrecy duty in the Banking Law. A standard data protection contract is not enough.
- Register or notifyYou need the Superintendency's permission before outsourcing. A short list is exempt: administrative activities, general services, marketing, logistics, cash transport, vehicle leasing, call centres and training. The decision comes within 30 working days. The bank may not start until it is told.
- Independent auditInternal and external auditors must be able to check the outsourced work and reach the relevant information.
What it costs if you get it wrong
- Fixed maximum fine: B/.1,000,000 (the balboa is fixed one-for-one with the United States dollar, so about one million US dollars) — about $1 millionSanctions under the Banking Law, article 185
Sources
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 009-2005 de 19 de octubre de 2005 — Tercerizacion u Outsourcing
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaCircular No. 064-2006 — technology outsourcing and processing centres abroad
superbancos.gob.pa
“las entidades bancarias que tengan sus centros de procesamientos tecnologicos en el extranjero (casas matrices, etc.) deberan contar con acuerdos de servicio internos que garanticen el cumplimiento de estas disposiciones segun apliquen”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaAcuerdo No. 003-2012 de 22 de mayo de 2012 — Lineamientos para la gestion del riesgo de la tecnologia de la informacion
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaLey Bancaria (Texto Unico del Decreto Ley 9 de 1998), articulos 111 (confidencialidad bancaria) and 185 (multas)
superbancos.gob.pa
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos de PanamaSuperintendencia de Bancos de Panama — index of banking Acuerdos to August 2026
superbancos.gob.pa
Link checked 19 August 2026
Cyber security rules
Official name: Resolucion No. 07 de 11 de mayo de 2026, por la cual se establecen los controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas · Gaceta Oficial Digital No. 30524-B de 14 de mayo de 2026 · Directly binding regulation
Ten cybersecurity controls that every information system of the Panamanian state must meet. They bind the executive, legislature, judiciary, autonomous and semi-autonomous bodies and state companies. For municipalities they are advice, not a rule. Bodies had 30 days from mid-May 2026 to file a self-assessment and 45 days to close any gap.
Enforced by National Authority for Government Innovation
How this country controls where data goes: No restriction
What you have to do
- Secure the data — from 14 May 2026Ten mandatory controls: internet-facing asset inventory, patching, multi-factor authentication for virtual private network access, external webmail and software-as-a-service platforms, supported operating systems, anti-malware, a demilitarised zone with a web application firewall, restricted administrative access from the internet, web filtering and email security.
- Independent audit — 1 year, from 14 May 2026At least one external penetration test each year covering internet-facing assets, with findings and remediation documented.
- Keep records of how you use data — from 13 June 2026Send a self-assessment report to the state technology authority within 30 calendar days. Include evidence for each control you meet. For each control you do not meet, include a fix plan to be completed within 45 calendar days.
Sources
- Official sourceAutoridad Nacional para la Innovacion Gubernamental (AIG)Resolucion No. 07 de 11 de mayo de 2026 — Controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas — Gaceta Oficial Digital No. 30524-B, 14 May 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGAIG — Estandares y Resoluciones (index of technology standards for the Panamanian state)
aig.gob.pa
Link checked 19 August 2026
Cyber security rules (Government)
Official name: Resolucion No. 18 de 15 de junio de 2026, por la cual se establece que todas las plataformas digitales a ser desarrolladas o gestionadas por las instituciones del Estado deberan contar con evaluacion y autorizacion por parte de la AIG · Gaceta Oficial Digital No. 30553-D de 24 de junio de 2026 · Directly binding regulation
Since 24 June 2026 no Panamanian state institution may launch a citizen-facing digital platform without written approval from the state technology authority. You also need an independent cybersecurity test report. If you go live without approval, the platform must be suspended.
Enforced by National Authority for Government Innovation
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notify — from 24 June 2026Get written approval from the state technology authority before a citizen-facing state digital platform goes live. The decision comes within 15 days.
- Independent audit — from 24 June 2026You need a cybersecurity test report from an independent outside firm that had no part in building the system. It must show that critical and high-risk weaknesses were fixed. You also need functional test results and load and stress test results.
- Assess high-risk projects — from 24 June 2026The opening text says the authority must check cybersecurity, interoperability and personal data protection rules before it approves.
What it costs if you get it wrong
- Order to stopPutting a citizen-facing platform into production without authorisation — operation must be suspended temporarily or permanently
Sources
- Official sourceAIGResolucion No. 18 de 15 de junio de 2026 — Evaluacion y autorizacion por la AIG de las plataformas digitales del Estado — Gaceta Oficial Digital No. 30553-D, 24 June 2026
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGAIG — Estandares y Resoluciones (index of technology standards for the Panamanian state)
aig.gob.pa
Link checked 19 August 2026
- Official sourceAIGResolucion No. 07-2025 — Normas Generales para la Gestion de las TIC, version 2.1 — Gaceta Oficial Digital No. 30308-B, 25 June 2025
aig.gob.pa
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales, reglamentada por el Decreto Ejecutivo No. 285 de 28 de mayo de 2021 · Gaceta Oficial Digital No. 28743-A de 29 de marzo de 2019 · Act of parliament
Panama's general privacy law. It covers databases held in Panama and companies based here. It does not cover foreign firms that merely sell into the country. Data may leave freely if one of thirteen listed grounds applies. Its sharpest edges are an order to shut a database, a seven-year ban on passing data on, and an exception that takes companies governed by special laws out of the law altogether.
Enforced by National Authority for Transparency and Access to Information
How this country controls where data goes: No restriction · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Get consent
- Tell people what you do
- Let people see their dataTen working days to answer an access request (article 16 of Law 81).
- Let people correct their data
- Let people delete their dataYou can use this where storing the data has no legal basis, was never authorised, or the data has gone out of date.
- Let people object
- Let people take their data elsewhere
- Secure the dataDecree 285 articles 36 to 38 say security measures must be set up, run, monitored, reviewed, maintained and improved on a repeating basis.
- Report breaches to the regulator — within 72 hoursSend it in writing, on paper or by email. It must contain nine set items.
- Keep records of how you use dataYou must record every security breach, at any stage of handling the data.
- Delete data after a period — 7 yearsDo not pass on or share data about an identifiable person more than seven years after your legal duty to keep it ended. The only exception is if the person expressly asks you to.
- Put a transfer safeguard in placeWrite down which of the thirteen grounds in article 33 you rely on before data leaves Panama.
- Appoint a data protection officerDecree 285 articles 42 to 45 cover the Personal Data Protection Officer. ANTAI's April 2026 circular makes public bodies notify their appointment in writing. What private companies must do is not clearly stated in the sources we could open.
What it costs if you get it wrong
- Order to stopVery serious breach — closure of the database registry, or temporary or permanent suspension and disqualification of storage and processing. Requires a formal opinion from the Personal Data Protection Council; police assistance may be used to enforce.
- Fixed maximum fine: Not fixed in Law 81 — article 43 provides fines 'segun su proporcionalidad'; the amounts sit in the implementing decree, which we could not openSerious and very serious breaches
- Claims by individualsConstitutional habeas data action brought by the individual in court under article 44 of the Constitution
Sources
- Official sourceAutoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales — Gaceta Oficial Digital No. 28743-A, 29 March 2019
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAICircular No. DS-002-2026 de 15 de abril de 2026 — Cumplimiento de obligaciones de proteccion de datos personales
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Guia practica sobre transferencias de datos personales a terceros (articulos 51 a 53 del Decreto Ejecutivo 285 de 2021)
antai.gob.pa
Link checked 19 August 2026
General data protection law (2026)
Official name: Resolucion No. ANTAI-DG-003-2026, por la cual se aprueba e implementa el uso de las Clausulas Contractuales Modelo de la Red Iberoamericana de Proteccion de Datos para Transferencias Internacionales de Datos Personales · Gaceta Oficial Digital No. 30541-A de 8 de junio de 2026 · Directly binding regulation
Panama's first official route for sending data abroad. It adopts the Ibero-American Data Protection Network's model contract clauses. Signing them counts as enough protection for sending personal data out of Panama. It says plainly that you then do not need prior permission from the regulator. The clauses are read under Panamanian law. They do not replace any other duty in the privacy law.
Enforced by National Authority for Transparency and Access to Information
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses
What you have to do
- Put a transfer safeguard in place — from 8 June 2026Two model agreements. One is for two companies that each decide how the data is used. One is for a company and the supplier that handles data for it. Use the wording as written, except where the models tell you to fill in your own details.
- Written vendor contract — from 8 June 2026The person the data is about can enforce the contract, even though they never signed it.
What it costs if you get it wrong
- Order to stopFailure to comply with the obligations flowing from the model clauses may be taken into account by ANTAI when exercising supervision and control under Law 81 and Decree 285
Sources
- Official sourceANTAIResolucion No. ANTAI-DG-003-2026 de 26 de marzo de 2026 — Clausulas Contractuales Modelo de la RIPD — Gaceta Oficial Digital No. 30541-A, 8 June 2026
antai.gob.pa
Link checked 19 August 2026
- Official sourceANTAIANTAI — Legislacion: Ley 81 de 2019, Decreto Ejecutivo 285 de 2021, Resolucion ANTAI-DG-003-2026, Circular DS-002-2026
antai.gob.pa
Link checked 19 August 2026
Insurance rules
Official name: Ley 51 de 22 de julio de 2008, que define y regula los documentos electronicos y las firmas electronicas y la prestacion de servicios de almacenamiento tecnologico de documentos y de certificacion de firmas electronicas, modificada por la Ley 82 de 2012 · Gaceta Oficial Digital No. 26090 de 24 de julio de 2008 · Act of parliament
A licence rule that surprises foreign providers. If you offer document archiving or storage as a service to others in Panama, you must register with the electronic signature authority at the Public Registry. You must also publish a practice statement, carry insurance and accept an annual technical inspection. Documents stored abroad can still be recognised, but only through four specific routes.
Enforced by National Electronic Signature Directorate, Public Registry of Panama
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyAnyone offering technological document storage to others in Panama must register and pay a fee, set by default at B/.1,000 (about one thousand US dollars). The authority has 90 days to decide. If it says nothing, that counts as approval.
- Secure the dataQualified staff, tamper-proof systems, confidentiality of user information, a contingency plan, and civil liability insurance no lower than the maximum fine the authority can impose.
- Keep data for a minimum periodRecords and practice statements must be kept at least as long as the law requires the stored document to be kept, counted from when the document was stored.
- Independent audit — 1 yearAt least one technical evaluation a year by the supervising authority.
- Tell people what you doA public, free-of-charge Declaration of Technological Storage Practices must be published.
Sources
- Official sourceDireccion Nacional de Firma Electronica, Registro Publico de PanamaLey 51 de 22 de julio de 2008 — documentos electronicos, firmas electronicas y almacenamiento tecnologico de documentos — Gaceta Oficial Digital No. 26090, 24 July 2008
firmaelectronica.gob.pa
Link checked 19 August 2026
- Official sourceRegistro Publico de PanamaDireccion Nacional de Firma Electronica — Registro Publico de Panama (Ley 51 de 2008, Ley 82 de 2012, Decreto Ejecutivo 684 de 2013)
firmaelectronica.gob.pa
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact fine amounts for breaches of the privacy law
Law 81 article 43 only says serious breaches attract fines 'according to their proportionality'. It gives no figure. The amounts sit in Decreto Ejecutivo No. 285 of 2021. We could not confirm those amounts against a government source. If the size of the fine matters to you, ask the regulator.
The precise day Law 81 became enforceable
Article 47 says the law starts two years after its promulgation. Promulgation and gazette publication were on 29 March 2019, so we record 29 March 2021. Sources differ between 26 and 29 March 2021, depending on whether they count from signature or from publication. Plan for the earlier date.
Whether private-sector controllers must appoint a Personal Data Protection Officer
ANTAI's Circular No. DS-002-2026 puts this duty on public bodies and cites articles 42 to 45 of Decree 285. We could not confirm whether those same articles bind private companies, or from what size. If you are a private company, check before you rely on this.
Whether ANTAI has ever imposed a sanction under the privacy law
We found no published decisions, fines or enforcement statistics from this regulator. That does not prove it has never acted. It only means nothing is published.
Whether the Personal Data Protection Council has ever been convened
We found no membership list, minutes or opinions for this council. That matters, because its formal opinion is required before the harshest penalty in the law can be imposed.
Insurance sector rules on technology, outsourcing or data
We could not confirm whether the Superintendency of Insurance and Reinsurance has its own rules here. If you are an insurer, check with the regulator before you rely on this.
Securities sector rules on technology, outsourcing or data
We could not confirm the full list of Acuerdos published by the Superintendency of the Securities Market. If you work in securities, check with the regulator before you rely on this.
Online gaming and mapping or geospatial rules
We found no rule for gaming, and none for mapping and location data. We could not confirm either against the Gaming Control Board. If you work in one of these areas, check before you rely on it.
Health sector rules on medical record retention and confidentiality
We could not confirm health record rules against a Ministry of Health source. Panama has patient rights legislation. We did not confirm its record-keeping or storage rules from a government website. If you handle health data, check first.
Tax, accounting and company record retention floors
We could not confirm this against a government source. Panama also has accounting record duties for legal entities and their resident agents. These are commonly cited as five years, which we could not confirm officially.
The full text of the AIG TIC management norms, Resolucion No. 07-2025
The gazette copy on the state technology authority's website is a scanned image, and we did not read all 40 pages. Any requirement inside it about where data must be kept is unchecked. Check before you rely on this.
Whether ANTAI has recognised any country as offering equivalent or higher protection
Article 33(2) of Law 81 allows this and Decree 285 gives ANTAI the power. No list appears on ANTAI's site. The power exists, but it has not been used.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.