Skip to the content
Global Data RulesData governance rules, country by country

Panama

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Panama — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Waking up

You can send personal data out of Panama. You do not need a permit. No destination country is banned. You just need one of thirteen legal reasons listed in the law. Since June 2026 you can also sign an official model contract to cover yourself. The regulator writes rules and guidance. We found no published fines. Banks and government bodies face extra approval steps.

Data governance in Panama

The eight things that decide how you handle data about people in Panama. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably not, if you have nothing in Panama. The law covers databases physically held in Panama. It also covers anyone legally based in Panama. It does not cover a company abroad that has no database and no office here, even if it sells to Panamanians. There is no size or revenue cut-off. We found no rule making a foreign firm appoint a local representative.

Where the data is allowed to live

Yes. Nothing has to stay in Panama. We found no rule in any industry that forces personal data to be stored inside the country. Sending data abroad is lawful if you meet any one of thirteen conditions in the law. Examples: the person's consent, a contract with the person, a transfer inside your company group, a destination with equal or better protection, or an approved model contract. Two industries add a permission step. That step is about who handles the data, not where it sits.

What to do: Get the paperwork for one of the routes below signed before any data leaves Panama.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

You do not need government permission. There is no list of approved or banned countries. Pick one of the thirteen legal grounds and keep evidence. Since 8 June 2026 there is an easier route. The regulator has published official model contract clauses. If you sign those, you do not have to ask the regulator for permission. Sensitive data, such as health or biometric records, needs the person's explicit agreement.

Ways to send data out:
Standard contract clauses · Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The National Authority for Transparency and Access to Information, through its Personal Data Protection Directorate. It exists and it is contactable. It is clearly working. It issued a compliance circular in April 2026 and adopted official model contract clauses in June 2026. But we could not find a single published fine or enforcement decision on its own website. Expect a regulator that is getting started, not one that is aggressive.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is no general minimum keeping period in the privacy law. There is one unusual ceiling. You must not keep personal data for longer than your purpose needs. You must also not pass on or share data about an identifiable person more than seven years after your legal duty to keep it ended. The only exception is if that person expressly asks you to. Other rules apply elsewhere. Electronic certificate records must be kept seven years. A person can demand deletion of data that is out of date or held with no legal basis.

What you have to do here:
Delete data after a period · Let people delete their data · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

One main clock: 72 hours. If personal data is breached, you must tell the regulator within 72 hours of finding out. Send it in writing, on paper or by email. The notice must say what happened, which data was affected, what you fixed immediately, what the person should do, where they can get more information, when it happened and why. You must also record every breach, at any stage of handling the data.

What you have to do here:
Report breaches to the regulator · Secure the data · Keep records of how you use data

What to do: Your breach process has to reach Panama's regulator inside the deadline above.

What catches people out

Five things catch people out. One: a person can sue you directly in court under the constitution. The action is called habeas data, it is fast, and they need no lawyer. It works whether or not the regulator ever acts. Two: the worst penalty is not a fine. It is an order shutting your database or banning you from using the data. Three: if a special law covers you, such as a bank, the general privacy law may not apply to you at all. Four: you must not pass on personal data more than seven years after your duty to keep it ended. Five: a bank cannot outsource sensitive data work without written permission first.

What you have to do here:
Delete data after a period · Written vendor contract
What it costs if you get it wrong:
Order to stop · Claims by individuals

What's changing next

Nothing new is scheduled to start in the next twelve months that we could confirm from a government source. The important recent changes have already landed. Official model contract clauses arrived in June 2026. A compliance circular arrived in April 2026. Two state technology rules arrived in May and June 2026. Watch instead for powers the government already holds and can use at any time without warning.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: Acuerdo No. 009-2005, por el cual se desarrolla la Tercerizacion u Outsourcing, aclarado por la Circular No. 064-2006 y complementado por el Acuerdo No. 003-2012 sobre riesgo de tecnologia de la informacion · Gaceta Oficial No. 25420-A de 2 de noviembre de 2005 · Directly binding regulation

In forceYes, with paperwork

Panamanian banks do not have to keep data in Panama. The regulator's own guidance openly assumes some banks use group technology centres abroad. What banks do face is a permission step. Any outsourcing that could affect the confidentiality, integrity, availability or custody of client assets needs the Superintendency's approval. You must file a draft contract before you sign it.

In force since 19 April 2006

Enforced by Superintendency of Banks of Panama

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Cyber security rules

Official name: Resolucion No. 07 de 11 de mayo de 2026, por la cual se establecen los controles minimos requeridos de Proteccion en Ciberseguridad para los Sistemas Informaticos de las Entidades Publicas · Gaceta Oficial Digital No. 30524-B de 14 de mayo de 2026 · Directly binding regulation

In forceYes, with paperwork

Ten cybersecurity controls that every information system of the Panamanian state must meet. They bind the executive, legislature, judiciary, autonomous and semi-autonomous bodies and state companies. For municipalities they are advice, not a rule. Bodies had 30 days from mid-May 2026 to file a self-assessment and 45 days to close any gap.

In force since 14 May 2026Enforced from 13 June 2026

Enforced by National Authority for Government Innovation

How this country controls where data goes: No restriction

Government

Cyber security rules (Government)

Official name: Resolucion No. 18 de 15 de junio de 2026, por la cual se establece que todas las plataformas digitales a ser desarrolladas o gestionadas por las instituciones del Estado deberan contar con evaluacion y autorizacion por parte de la AIG · Gaceta Oficial Digital No. 30553-D de 24 de junio de 2026 · Directly binding regulation

In forceYes, with paperwork

Since 24 June 2026 no Panamanian state institution may launch a citizen-facing digital platform without written approval from the state technology authority. You also need an independent cybersecurity test report. If you go live without approval, the platform must be suspended.

In force since 24 June 2026

Enforced by National Authority for Government Innovation

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley 81 de 26 de marzo de 2019, sobre Proteccion de Datos Personales, reglamentada por el Decreto Ejecutivo No. 285 de 28 de mayo de 2021 · Gaceta Oficial Digital No. 28743-A de 29 de marzo de 2019 · Act of parliament

In forceYes, with paperwork

Panama's general privacy law. It covers databases held in Panama and companies based here. It does not cover foreign firms that merely sell into the country. Data may leave freely if one of thirteen listed grounds applies. Its sharpest edges are an order to shut a database, a seven-year ban on passing data on, and an exception that takes companies governed by special laws out of the law altogether.

In force since 29 March 2021

Enforced by National Authority for Transparency and Access to Information

How this country controls where data goes: No restriction · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

General data protection law (2026)

Official name: Resolucion No. ANTAI-DG-003-2026, por la cual se aprueba e implementa el uso de las Clausulas Contractuales Modelo de la Red Iberoamericana de Proteccion de Datos para Transferencias Internacionales de Datos Personales · Gaceta Oficial Digital No. 30541-A de 8 de junio de 2026 · Directly binding regulation

In forceYes, with paperwork

Panama's first official route for sending data abroad. It adopts the Ibero-American Data Protection Network's model contract clauses. Signing them counts as enough protection for sending personal data out of Panama. It says plainly that you then do not need prior permission from the regulator. The clauses are read under Panamanian law. They do not replace any other duty in the privacy law.

In force since 8 June 2026

Enforced by National Authority for Transparency and Access to Information

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses

E-commerce

Insurance rules

Official name: Ley 51 de 22 de julio de 2008, que define y regula los documentos electronicos y las firmas electronicas y la prestacion de servicios de almacenamiento tecnologico de documentos y de certificacion de firmas electronicas, modificada por la Ley 82 de 2012 · Gaceta Oficial Digital No. 26090 de 24 de julio de 2008 · Act of parliament

In forceYes — store it anywhere

A licence rule that surprises foreign providers. If you offer document archiving or storage as a service to others in Panama, you must register with the electronic signature authority at the Public Registry. You must also publish a practice statement, carry insurance and accept an annual technical inspection. Documents stored abroad can still be recognised, but only through four specific routes.

In force since 24 July 2008

Enforced by National Electronic Signature Directorate, Public Registry of Panama

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Autoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI)

    General personal data protection, through its Personal Data Protection Directorate; also freedom of information and public ethics

    Staffed and contactable, and clearly issuing binding rules in 2026: Circular No. DS-002-2026 of 15 April 2026 and Resolucion No. ANTAI-DG-003-2026 published on 8 June 2026. But as at 19 August 2026 we could find no published penalty decision or fine on its own website, and no enforcement statistics. It makes rules. We see no enforcement.

  • Consejo de Proteccion de Datos Personales

    Advisory body created by article 34 of Law 81; its formal opinion is required before the regulator may impose the very serious sanctions of closing a database or suspending processing

    Its membership is set in law. The Minister of Commerce and Industry chairs it. The other members are the consumer protection authority, ANTAI, the Ombudsman, the private enterprise council, the bar association, the banking association, the Electoral Tribunal and the chamber of commerce. We found no published minutes, membership list or opinions, so we cannot show that it meets. That matters, because the harshest penalties cannot be imposed without it.

  • Superintendencia de Bancos de Panama

    Banking, banking secrecy, outsourcing approvals and technology risk

    Clearly active. Its own index shows six new banking Acuerdos issued in 2026 up to August, and it publishes a penalties section.

  • Autoridad Nacional para la Innovacion Gubernamental (AIG)

    Technology standards for the Panamanian state, government cybersecurity, the Government Security Operations Centre, and authorisation of state digital platforms

    Very active. It issued the information and communications technology management rules, known as the TIC norms, in June 2025. It issued the mandatory cybersecurity controls in May 2026 and the platform approval rules in June 2026. All were published in the Official Gazette.

  • Direccion Nacional de Firma Electronica, Registro Publico de Panama

    Registration and supervision of electronic signature certification providers and technological document storage providers under Law 51 of 2008 and Law 82 of 2012

    Runs a live public site with the governing laws and the implementing decree. We did not check how many storage providers are currently registered.

  • Autoridad Nacional de los Servicios Publicos (ASEP)

    Telecommunications, broadcasting, electricity, water; telecoms governed by Ley 31 de 1996

    Active regulator. But as at 19 August 2026 we found no telecoms rule on its own site about keeping data in the country, about subscriber data, or about keeping call records.

  • Superintendencia del Mercado de Valores (SMV)

    Securities markets, investment funds and pensions

    Active, with Acuerdos published up to 2026. So any securities technology rule, or rule about keeping data in the country, is unchecked.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact fine amounts for breaches of the privacy law

    Law 81 article 43 only says serious breaches attract fines 'according to their proportionality'. It gives no figure. The amounts sit in Decreto Ejecutivo No. 285 of 2021. We could not confirm those amounts against a government source. If the size of the fine matters to you, ask the regulator.

  • The precise day Law 81 became enforceable

    Article 47 says the law starts two years after its promulgation. Promulgation and gazette publication were on 29 March 2019, so we record 29 March 2021. Sources differ between 26 and 29 March 2021, depending on whether they count from signature or from publication. Plan for the earlier date.

  • Whether private-sector controllers must appoint a Personal Data Protection Officer

    ANTAI's Circular No. DS-002-2026 puts this duty on public bodies and cites articles 42 to 45 of Decree 285. We could not confirm whether those same articles bind private companies, or from what size. If you are a private company, check before you rely on this.

  • Whether ANTAI has ever imposed a sanction under the privacy law

    We found no published decisions, fines or enforcement statistics from this regulator. That does not prove it has never acted. It only means nothing is published.

  • Whether the Personal Data Protection Council has ever been convened

    We found no membership list, minutes or opinions for this council. That matters, because its formal opinion is required before the harshest penalty in the law can be imposed.

  • Insurance sector rules on technology, outsourcing or data

    We could not confirm whether the Superintendency of Insurance and Reinsurance has its own rules here. If you are an insurer, check with the regulator before you rely on this.

  • Securities sector rules on technology, outsourcing or data

    We could not confirm the full list of Acuerdos published by the Superintendency of the Securities Market. If you work in securities, check with the regulator before you rely on this.

  • Online gaming and mapping or geospatial rules

    We found no rule for gaming, and none for mapping and location data. We could not confirm either against the Gaming Control Board. If you work in one of these areas, check before you rely on it.

  • Health sector rules on medical record retention and confidentiality

    We could not confirm health record rules against a Ministry of Health source. Panama has patient rights legislation. We did not confirm its record-keeping or storage rules from a government website. If you handle health data, check first.

  • Tax, accounting and company record retention floors

    We could not confirm this against a government source. Panama also has accounting record duties for legal entities and their resident agents. These are commonly cited as five years, which we could not confirm officially.

  • The full text of the AIG TIC management norms, Resolucion No. 07-2025

    The gazette copy on the state technology authority's website is a scanned image, and we did not read all 40 pages. Any requirement inside it about where data must be kept is unchecked. Check before you rely on this.

  • Whether ANTAI has recognised any country as offering equivalent or higher protection

    Article 33(2) of Law 81 allows this and Decree 285 gives ANTAI the power. No list appears on ANTAI's site. The power exists, but it has not been used.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.