Skip to the content
Global Data RulesData governance rules, country by country

Peru

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Peru lets personal data leave the country, but only on conditions. You may send it to a country the government has judged to protect data properly - and it has judged none. So everyone uses the fallback: sign the regulator's model contract, then file the transfer on a public register. No industry has to keep data inside Peru. The regulator is real, staffed and fining people.

Data governance in Peru

The eight things that decide how you handle data about people in Peru. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Peru's privacy rules reach a company with no office in Peru if it offers goods or services to people in Peru, or if it watches their behaviour online or builds profiles of them. There is no size or revenue threshold that lets you escape. If you are caught this way you must appoint a representative for Peru, who is the contact point for the regulator. That representative can sit outside Peru, but must be named either in your public privacy notice or in a filing to the regulator.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

Yes, with conditions, and the same conditions apply to every industry. The rule is that you may only send personal data to a country that Peru has decided protects data properly. Peru has not yet decided that about any country, so almost every transfer runs on the backup route: give 'adequate guarantees', normally by signing the model contract the regulator published. Nothing has to physically stay in Peru - there is no localisation rule in banking, payments, insurance, securities, health, telecoms, government cloud, gambling or mapping that we could find.

High confidenceYes, with paperworkAllowlistStandard contract clausesOfficial 'this country is safe' decision

Sending data out of the country

The model is an allowlist, and the list is empty. Peru says you may only export to a country it has formally judged adequate, and we found no decision naming any country. So nearly everyone uses the escape hatch: sign the regulator's published model contract clauses, or an equivalent contract that imposes the same duties on the receiver. You do not need permission first. You do need to tell the regulator: every cross-border flow must be reported and entered on the National Registry of Personal Data Protection, and there is an online form for it. You can also ask the regulator for a formal opinion on your transfer, and it must answer within thirty days.

Medium confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesExplicit consentNeeded for a contractLegal claimsPut a transfer safeguard in place

The regulator, and whether it actually acts

The National Authority for the Protection of Personal Data, which sits inside the Ministry of Justice and Human Rights. It is genuinely operational, not a paper regulator. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty cases, issued 211 decisions and imposed about 11.3 million soles in fines, roughly 3.2 million dollars. It was still issuing decisions in May 2026. In finance and insurance the banking regulator enforces separately, and the cyber-incident regulator sits in the Prime Minister's Office.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

Peru is unusual because the privacy rules set both a floor and a hard ceiling. The floor: security and access logs must be kept at least two years, phone and internet records three years, tax and accounting records for as long as the tax can still be assessed - in practice five years or more - and patient records twenty years. The ceiling: a supplier processing data for you may keep it at most two years after the job ends, and keeping personal data forever is banned as a general rule. Where a specific law demands longer, the data goes back to the client and is kept only while that legal duty lasts.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsKeep records of processing

If something goes wrong

Two clocks, both 48 hours, and they are not the same clock. First: if personal data is exposed in bulk, or sensitive data is involved, or a lot of people are affected, you must tell the privacy authority within 48 hours of finding out - and you still must tell it even if you fixed the problem yourself. Miss the 48 hours and you may still file, but you must explain and evidence the delay. Second: public bodies and digital service providers in finance, utilities, health, transport, internet access, education and other critical activities must tell the National Digital Security Centre within 48 hours of a critical-level incident. A single breach can trigger both.

High confidenceReport breaches to the regulatorReport cyber incidentsSecure the data

What catches people out

Five things that catch people out. One: you must register every collection of personal data with the national register, and separately register the fact that you send data abroad - a filing duty most foreign companies do not know exists. Two: a supplier may only hold your data for two years after the work ends, so long-tail archives at vendors are unlawful by default. Three: a child under fourteen needs a parent's consent, but a fourteen to seventeen year old can consent alone for digital services - the opposite of what most global consent flows assume. Four: an online gambling licensee must give the trade ministry the usernames and passwords to its own servers and databases. Five: mishandling personal data can be a crime, not just a fine.

Medium confidenceRegister or notifyDelete data after a periodGet a parent's consent for childrenAppoint a data protection officerCriminal liability

What's changing next

One firm date in the next twelve months. On 30 November 2026 medium-sized companies - those with yearly sales between roughly 9.4 and 12.7 million soles, about 2.7 to 3.6 million dollars - must have appointed a Personal Data Officer. Small companies follow in 2027 and the smallest in 2028. Separately, a bill amending the privacy law cleared a congressional committee in November 2025 but is not law and must not be treated as binding. Watch three switches the government can flip without warning.

Medium confidenceIn forceProposedAppoint a data protection officer

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad

Directly binding regulation · Resolucion S.B.S. N.o 504-2021, as amended by Resolucion S.B.S. N.o 1515-2021

In forceYes, with paperwork

Banks, insurers, pension fund managers and other supervised financial firms may process and store data abroad, including in public cloud, but must notify the Superintendency within 30 days and must obtain prior authorisation - specific to provider, country and city - where foreign law would limit the Superintendency's access, audit or exit rights. This replaced the older rule that required authorisation for offshore main processing.

In force since 1 July 2021But only enforceable from 20 February 2021

Enforced by Superintendency of Banking, Insurance and Pension Fund Administrators

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Telecoms

Decreto Legislativo N.o 1182, que regula el uso de los datos derivados de las telecomunicaciones para la identificacion, localizacion y geolocalizacion de equipos de comunicacion

Act of parliament · Decreto Legislativo 1182, published 27 July 2015, amended by Ley 31284

In forceYes, with paperwork

Telecoms concession holders must keep call, connection and location metadata for three years - the first year live and queryable in real time by the Peruvian police, the next two in archive. There is no explicit rule saying the data must sit in Peru, but the real-time delivery duty makes offshore-only architectures hard to run.

In force since 28 July 2015

Enforced by Supervisory Agency for Private Investment in Telecommunications

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Online gaming

Reglamento de la Ley N.o 31557, Ley que regula la explotacion de los juegos a distancia y apuestas deportivas a distancia

Directly binding regulation · Decreto Supremo N.o 005-2023-MINCETUR, published 13 October 2023

In forceYes, with paperwork

Online gaming and sports betting operators do not have to keep servers in Peru, but they must be a Peruvian company or branch, must give the trade ministry logins to their own servers and databases, and must feed economic and technical data to the ministry's data centre every day of the year. That is regulator access rather than data residency, and it has the same practical effect on architecture.

In force since 14 October 2023But only enforceable from 9 February 2024

Enforced by Directorate General of Casino Games and Slot Machines, Ministry of Foreign Trade and Tourism

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley N.o 29733, Ley de Proteccion de Datos Personales, y su Reglamento aprobado por Decreto Supremo N.o 016-2024-JUS

Act of parliament · Ley 29733 (published 3 July 2011); D.S. 016-2024-JUS (published 30 November 2024)

Partly in forceYes, with paperwork

Peru's general privacy law and its 2024 Regulation. Data may leave Peru only to a country formally judged adequate - and none has been - so in practice everyone signs the regulator's model contract and files the transfer on the national register. Heavy on registration, consent, a mandatory local representative for foreign companies, a 48-hour breach clock and a two-year cap on how long a supplier may hold your data. Fines are low by international standards.

In force since 30 March 2025

Enforced by National Authority for the Protection of Personal Data

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest

High confidence
Government

Reglamento del Decreto de Urgencia N.o 007-2020, Marco de Confianza Digital

Directly binding regulation · Decreto Supremo N.o 126-2025-PCM, published 4 November 2025

Partly in forceYes, with paperwork

Public bodies and digital service providers in finance, electricity, water, gas, health, passenger transport, internet access, education and other critical activities must report critical digital security incidents to the National Digital Security Centre within 48 hours. This runs on top of, not instead of, the privacy authority's own 48-hour clock.

In force since 5 November 2025

Enforced by National Digital Security Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Autoridad Nacional de Proteccion de Datos Personales (Direccion General de Transparencia, Acceso a la Informacion Publica y Proteccion de Datos Personales, MINJUSDH)

    General personal data protection, all sectors

    Fully operational. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty proceedings, issued 211 first- and second-instance decisions and 212 rights-enforcement decisions, and imposed about S/ 11.3 million in fines. It was still confirming sanctions in May 2026. Director as of January 2026: Eduardo Luna Cervantes. Weakness is collection, not activity - only about S/ 1.9 million of the 2025 fines had been collected by January 2026.

  • Superintendencia de Banca, Seguros y Administradoras Privadas de Fondos de Pensiones (SBS)

    Banks, insurers, pension fund managers, e-money issuers, cooperatives

    Long-established prudential regulator; operates the authorisation regime for significant offshore data processing.

  • Centro Nacional de Seguridad Digital, Secretaria de Gobierno y Transformacion Digital, Presidencia del Consejo de Ministros

    Digital security incidents, national incident register, government digital security framework

    Operational and running the National Register of Digital Security Incidents. It launched a joint incident reporting form with the privacy authority in September 2025, but the incident classification and the notification deadlines for below-critical incidents were still pending as of 19 August 2026.

  • Direccion General de Juegos de Casino y Maquinas Tragamonedas (DGJCMT), MINCETUR

    Online gaming and remote sports betting licensing, technical standards and inspection

    Licensing and inspecting remote gaming operators; runs the data centre that receives daily operator feeds.

  • Organismo Supervisor de Inversion Privada en Telecomunicaciones (OSIPTEL)

    Telecommunications operators, including sanctions for failing to provide access to telecommunications-derived data

  • Ministerio de Salud (MINSA)

    Clinical record standards, electronic health record accreditation, the national electronic clinical record register

  • Superintendencia del Mercado de Valores (SMV)

    Securities market participants, operational and cyber risk

    Active regulator, but we found no securities-specific data localisation or cross-border storage rule on its own site; its operational risk regulation was not verified line by line in this pass.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no country has been declared to have an adequate level of protection by the Peruvian authority.

    We could find no adequacy resolution on the authority's own pages, but proving a negative from a website with no consolidated resolutions index is not possible. Treat the allowlist as empty and plan on model contractual clauses, but re-check before relying on adequacy for a specific destination.

  • The full text and current status of Directoral Resolution 100-2025-JUS/DGTAIPD, the Personal Data Officer Directive.

    Confirmed twice by the ministry's own press notes (31 December 2025 and 28 January 2026) but we could not open the instrument itself on a government domain. Its detailed triggers for when a Personal Data Officer is mandatory are therefore not quoted here.

  • That Article 154-A of the Criminal Code (illegal trafficking in personal data) is in force in its current wording.

    We could not open an official consolidated copy of the Criminal Code during this run. The criminal exposure is stated at medium confidence and should be re-verified against the official legal information system before being relied on.

  • Whether SBS Resolution 504-2021 has been amended after 2021.

    We verified the consolidated text hosted by the Superintendency itself, which records amendments up to Resolution 1515-2021. Later amendments, if any, were not located. The offshore authorisation rule in Article 25 is quoted from that text.

  • Whether any securities, education, defence or geospatial rule imposes data residency.

    Searched and nothing found, checked 19 August 2026. Absence of a found rule is not proof of absence, particularly for defence, where instruments are often not published.

  • The soles to dollars conversions used in this record.

    Converted at roughly 3.5 soles to the dollar for readability. The tax unit value of S/ 5,500 for 2026 is official; the exchange rate is not.

  • Whether the Digital Government Secretariat has now published the national digital security incident classification and the notification deadlines for below-critical incidents.

    Due within 90 to 120 working days of the November 2025 Regulation, which would place them in 2026, but no published version was located. Until then only the 48-hour critical-incident deadline is certain.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 90 days. Next check due 17 November 2026.

Read the exact prompt used to research this page

Put this next to another country

Peru versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.