Peru
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Peru — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Peru, but only on conditions. You may send it to a country the government has judged to protect data properly. It has judged none. So everyone uses the fallback. You sign the regulator's model contract, then file the transfer on a public register. No industry has to keep data inside Peru. The regulator is real, staffed and fining people.
Data governance in Peru
The eight things that decide how you handle data about people in Peru. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Peru's privacy rules reach a company with no office in Peru. They apply if you offer goods or services to people in Peru. They also apply if you watch their behaviour online or build profiles of them. There is no size or revenue threshold that lets you escape. If the rules catch you, you must appoint a representative for Peru. That person is the contact point for the regulator. They can sit outside Peru. You must name them in your public privacy notice or in a filing to the regulator.
- What you have to do here:
- Appoint a representative · Register or notify
Article VI of the Regulation approved by Supreme Decree 016-2024-JUS extends the rules to companies not established in Peru. It catches you if you offer goods or services to people located in Peru. It also catches you if you monitor their behaviour or build profiles of them. It catches you as well if Peruvian law applies to you by contract or by international law. Article VII then requires you to appoint a representative 'in Peruvian territory or for Peruvian territory'. The only exemption is where the data merely passes through. Registering every personal data bank with the National Registry of Personal Data Protection is a separate, long-standing duty under Article 34 of Law 29733.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento de la Ley N.o 29733, aprobado por Decreto Supremo N.o 016-2024-JUS, articulos VI y VII del Titulo Preliminar
cdn.www.gob.pe
“el titular del banco de datos personales o quien resulte responsable, ubicado en el territorio peruano o fuera de este, debe proveer los medios necesarios para el efectivo cumplimiento de las obligaciones previstas en la Ley y el Reglamento, y, designar un representante en el territorio peruano o para el territorio peruano”
Link checked 19 August 2026
- Official sourcePlataforma del Estado Peruano (gob.pe)Decreto Supremo N.o 016-2024-JUS - official record page, published 30 November 2024
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, Ley de Proteccion de Datos Personales - consolidated official text
diariooficial.elperuano.pe
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions. The same conditions apply to every industry. You may only send personal data to a country that Peru has decided protects data properly. Peru has not yet decided that about any country. So almost every transfer runs on the backup route. You give 'adequate guarantees', normally by signing the model contract the regulator published. Nothing has to physically stay in Peru. We found no rule forcing data to stay in the country in banking, payments, insurance, securities, health, telecoms, government cloud, gambling or mapping.
- Ways to send data out:
- Standard contract clauses · Official 'this country is safe' decision
Here is what we found industry by industry, checked 19 August 2026. BANKING, INSURANCE, PENSIONS (data can leave only if conditions are met): Resolution 504-2021 of the Superintendency of Banking, Insurance and Pension Funds allows data handling and cloud services abroad. But a supervised firm must ask the Superintendency for permission first before hiring a significant data-handling service abroad, where the foreign country's laws limit the Superintendency's access, audit or exit rights. The permission covers one named provider, country and city. Firms must also tell the Superintendency within 30 calendar days of starting any significant data work with a third party. For cloud they must show ISO/IEC 27001, 27017 and 27018 certification and a SOC 2 Type 2 report every year. SECURITIES (data can leave only if conditions are met): we found no separate rule about keeping data in the country on the site of the Superintendency of the Securities Market. The general rules and the operational risk rules apply. HEALTH (data can leave only if conditions are met): we found no rule about keeping data in the country. The binding limit is how long you keep records, not where they sit. TELECOMS (data can leave only if conditions are met): there is no rule about keeping data in the country. But Legislative Decree 1182 makes operators hold traffic and location data for 12 months, in systems that answer Peruvian police online and in real time. They then hold it for 24 months more in archive. That pulls you towards infrastructure inside Peru. GOVERNMENT CLOUD (data can leave only if conditions are met): the digital government rules tell public bodies to prefer cloud. The Digital Government Secretariat's cloud guidance expressly says rules restricting where data sits would breach Peru's free trade commitments. It only suggests that bodies holding large amounts of sensitive data linked to national security may choose to keep it in the country. GAMBLING (data can leave only if conditions are met): there is no rule about where servers must sit. But the operator must be a Peruvian company or a Peruvian branch. It must give the trade ministry usernames and passwords to its servers and databases within 10 working days of licensing. It must also send economic and technical data to the ministry's data centre every single day. GEOSPATIAL, EDUCATION, DEFENCE: we found no rule about storing data abroad, checked 19 August 2026, confidence medium.
Sources
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 15 (flujo transfronterizo de datos personales)
diariooficial.elperuano.pe
“El titular y el encargado de tratamiento de datos personales deben realizar el flujo transfronterizo de datos personales solo si el pais destinatario mantiene niveles de proteccion adecuados conforme a la presente Ley.”
Link checked 19 August 2026
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 18 a 21 (flujo transfronterizo, nivel adecuado, garantias y registro)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceSuperintendencia de Banca, Seguros y AFPResolucion S.B.S. N.o 504-2021, Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad, articulos 24 y 25
intranet2.sbs.gob.pe
“La empresa debe solicitar autorizacion de la Superintendencia, previo a la contratacion de un servicio significativo de procesamiento de datos provisto por terceros desde el exterior, en caso dicho servicio presente limitaciones para cumplir con los requerimientos establecidos en el parrafo 24.2”
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Segunda Disposicion Complementaria Final (conservacion de datos derivados de las telecomunicaciones)
busquedas.elperuano.pe
“deben conservar los datos derivados de las telecomunicaciones durante los primeros doce (12) meses en sistemas informaticos que permitan su consulta y entrega en linea y en tiempo real. Concluido el referido periodo, deberan conservar dichos datos por veinticuatro (24) meses adicionales”
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR, Reglamento de la Ley 31557 (juegos y apuestas deportivas a distancia), articulos 38 y 45
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceSecretaria de Gobierno Digital, Presidencia del Consejo de MinistrosLineamientos para el Uso de Servicios en la Nube para Entidades de la Administracion Publica, seccion 5.4 (localizacion del proceso y de los datos personales)
cdn.www.gob.pe
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Peru.
Sending data out of the country
You may only send data to a country Peru has formally judged safe enough. Peru has not named a single country. So nearly everyone uses the backup route. You sign the regulator's published model contract clauses. An equivalent contract that puts the same duties on the receiver also works. You do not need permission first. You do need to tell the regulator. Every flow of data out of Peru must be reported and entered on the National Registry of Personal Data Protection. There is an online form for it. You can also ask the regulator for a formal opinion on your transfer. It must answer within thirty days.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Explicit consent · Needed for a contract · Legal claims
Article 18 of the 2024 Regulation puts the safe-enough country first. Article 19 says the Directorate General issues a decision on whether a country is safe enough. It uses four tests: a set of laws, principles for using data, rights individuals can enforce, and a supervisory authority. That assessment can be skipped where the country has signed common data protection standards with Peru. Article 20 gives the fallback: model contract clauses, or another legal document that imposes at least the same duties. Those model clauses were approved back in 2022 by Directoral Resolution 0074-2022-JUS/DGTAIPD, adopting the Ibero-American network's model. Article 21.2 makes it compulsory to notify and register the flow in every case. Law 29733 Article 15 also carries seven exceptions that switch off the guarantee requirement entirely. They are international treaties, judicial cooperation, intelligence cooperation against serious crime, performing a contract with the individual, banking and stock-market transfers, medical treatment and epidemiological studies with names removed, and the individual's prior express consent. The contract exception expressly includes user authentication, service improvement and support, quality monitoring, maintenance and billing.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 19, 20 y 21
cdn.www.gob.pe
“En cualquier caso, el flujo transfronterizo de datos personales debe ponerse en conocimiento de la Direccion General de Transparencia, Acceso a la Informacion Publica y Proteccion de Datos Personales”
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos Personales, MINJUSDHResolucion Directoral N.o 0074-2022-JUS/DGTAIPD - approves the Model Contractual Clauses for International Transfers of Personal Data, 17 October 2022
gob.pe
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos PersonalesInscribir flujo transfronterizo de datos personales - official procedure page, last updated 22 May 2026
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 15, numerales 1 a 8 (exceptions to the guarantee requirement)
diariooficial.elperuano.pe
Link checked 19 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The National Authority for the Protection of Personal Data, which sits inside the Ministry of Justice and Human Rights. It really works. It is not a paper regulator. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty cases and issued 211 decisions. It imposed about 11.3 million soles in fines, roughly 3.2 million dollars. It was still issuing decisions in May 2026. In finance and insurance the banking regulator enforces separately. The cyber-incident regulator sits in the Prime Minister's Office.
The authority is legally the Directorate General for Transparency, Access to Public Information and Personal Data Protection. It sits inside the Ministry of Justice and Human Rights. Its director as of January 2026 was Eduardo Luna Cervantes. The 2024 figures were 454 entities inspected, 133 penalty proceedings and about 13.4 million soles in fines. Two things soften the impact. Collection is weak. Only about 1.9 million soles of the 2025 fines had been collected by January 2026, partly because of a 40 per cent discount for prompt payment and partly because of appeals. The maximum fine is also low. It is 100 tax units, about 550,000 soles or roughly 157,000 dollars, and never more than 10 per cent of the previous year's gross revenue. The authority runs a public register of punished organisations. It publishes a fine-calculation method adopted at the end of December 2025. It also reports advisory decisions. Other regulators enforce alongside it: the Superintendency of Banking, Insurance and Pension Funds, the National Digital Security Centre inside the Digital Government Secretariat, the trade ministry's gaming directorate, and the telecoms regulator OSIPTEL.
Sources
- Official sourceMinisterio de Justicia y Derechos HumanosANPD impuso multas por mas de S/ 11 millones ... durante el 2025 - official press note, 12 January 2026
gob.pe
“la ANPD fiscalizo a 760 entidades publicas y privadas ... se iniciaron 136 procedimientos administrativos sancionadores y se emitieron 211 resoluciones administrativas”
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosANPD impuso multas por mas de S/ 13 millones ... el ano 2024 - official press note, 10 January 2025
gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosMINJUSDH sanciona a empresa por uso indebido de datos personales y aplica multas de hasta S/ 194 mil - official press note, 20 May 2026
gob.pe
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos PersonalesConsultar instituciones sancionadas por la Autoridad Nacional de Proteccion de Datos Personales - public sanctions register
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 39 (administrative penalties, 0.5 to 100 tax units, capped at 10 per cent of gross annual revenue)
diariooficial.elperuano.pe
Link checked 19 August 2026
How long you must keep it — and when to delete it
Peru is unusual. The privacy rules set both a minimum and a maximum. The minimums: security and access logs must be kept at least two years. Phone and internet records must be kept three years. Tax and accounting records must be kept for as long as the tax can still be assessed, which is usually five years or more. Patient records must be kept twenty years. The maximum: a supplier handling data for you may keep it for at most two years after the job ends. Keeping personal data forever is banned as a general rule. Where a specific law demands longer, the data goes back to the client and is kept only while that legal duty lasts.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs · Keep records of how you use data
Maximum: Article 31.2 of the 2024 Regulation caps a supplier's keeping period at two years from the end of the last assignment. It says keeping data indefinitely is banned as a general rule. Minimums: Article 47 of the same Regulation requires logs of user accounts, sessions and actions on personal data to be kept for at least two years. Interaction logs must be generated continuously and be available immediately. Legislative Decree 1182 requires 12 months of telecoms data in live systems, plus 24 months in archive. Article 87(7) of the Tax Code requires books, records and supporting documents to be kept while the tax is not yet time-barred. Health Technical Standard 139-MINSA/2018 keeps a clinical record in the active file for five years after the last consultation, then fifteen years in the passive archive. That is twenty years in total before anyone can propose destroying it. A minimum summary must be kept even then. Occupational cancer records run forty years. Where a minimum and the maximum collide, the express legal duty wins and the general two-year cap gives way.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 31.2 y 47
cdn.www.gob.pe
“El plazo para la conservacion de datos personales al que hace referencia el articulo 30 de la Ley es como maximo de dos (2) anos contados desde la finalizacion del ultimo encargo realizado ... La conservacion indeterminada de los datos personales, por regla general, esta prohibida.”
Link checked 19 August 2026
- Official sourceSuperintendencia Nacional de Aduanas y de Administracion TributariaCodigo Tributario, articulo 87 numeral 7 (duty to keep books, records and supporting documents while the tax is not time-barred)
sunat.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de SaludNTS N.o 139-MINSA/2018/DGAIN, Norma Tecnica de Salud para la Gestion de la Historia Clinica (approved by Resolucion Ministerial 214-2018-MINSA)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Segunda Disposicion Complementaria Final
busquedas.elperuano.pe
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Two clocks, both 48 hours. They are not the same clock. First, tell the privacy authority within 48 hours of finding out, if personal data is exposed in bulk, sensitive data is involved, or a lot of people are affected. You must tell it even if you fixed the problem yourself. If you miss the 48 hours you may still file, but you must explain the delay and prove it. Second, public bodies and digital service providers must tell the National Digital Security Centre within 48 hours of a critical-level incident. That covers finance, utilities, health, transport, internet access, education and other critical activities. A single breach can trigger both.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents · Secure the data
The privacy clock is Article 34.1 of the 2024 Regulation. The notice must describe what happened, the types and rough number of people affected, the contact point, the likely consequences and what you are doing to fix it. Article 36 requires a supplier to tell its client immediately. The digital security clock is Article 32.1 of the Regulation of the Digital Trust Framework, Supreme Decree 126-2025-PCM, published 4 November 2025. Article 18 expressly says telling the Digital Security Centre does not excuse you from telling the privacy authority. The government made this a little easier in September 2025 by launching a single online incident form that feeds both. A third, softer clock sits in finance. Resolution 504-2021 of the Superintendency of Banking, Insurance and Pension Funds requires firms to report a significant data-handling arrangement with a third party within 30 calendar days of it starting.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulo 34
cdn.www.gob.pe
“debe notificar a la Autoridad Nacional de Proteccion de Datos Personales como maximo dentro de las 48 horas posteriores a haber tomado conocimiento o constancia de ello”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosReglamento del Decreto de Urgencia N.o 007-2020 (Marco de Confianza Digital), aprobado por D.S. 126-2025-PCM, articulos 18 y 32
cdn.www.gob.pe
“Los incidentes de seguridad digital clasificados con nivel critico son notificados al CNSD, de manera obligatoria, dentro de un plazo maximo de cuarenta y ocho (48) horas, contado desde que el PSD toma conocimiento del incidente.”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 126-2025-PCM - official record page, 4 November 2025
gob.pe
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosPCM y Ministerio de Justicia presentan herramienta digital para reportar incidentes de seguridad - official press note, 19 September 2025
gob.pe
Link checked 19 August 2026
What to do: Your breach process has to reach Peru's regulator inside the deadline above.
What catches people out
Five things catch people out. One: you must register every collection of personal data with the national register. You must separately register the fact that you send data abroad. Most foreign companies do not know this filing duty exists. Two: a supplier may only hold your data for two years after the work ends. Old archives sitting at a supplier are unlawful by default. Three: a child under fourteen needs a parent's consent. But a fourteen to seventeen year old can consent alone for digital services. That is the opposite of what most global consent flows assume. Four: an online gambling licensee must give the trade ministry the usernames and passwords to its own servers and databases. Five: mishandling personal data can be a crime, not just a fine.
- What you have to do here:
- Register or notify · Delete data after a period · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
(1) Registering: Article 34 of Law 29733, plus Articles 41 to 44 of the 2024 Regulation, plus the separate filing for flows out of Peru under Article 21.2. (2) How long a supplier may keep data: Article 31.2. (3) Children: Articles 22 and 25 of the Regulation. A parent or guardian must consent for under-14s. Children of 14 to 17 may consent themselves for digital services, if the information is written in language they can understand. The company must make reasonable efforts to check who is giving consent. Article 23 also bans collecting data about the rest of a child's family through the child. (4) Gambling: Article 38(r) of the gaming Regulation requires logins to servers and databases within 10 working days of licensing. Article 48 requires the same on demand during inspections. There is also a daily data feed to the ministry's data centre, 365 days a year. (5) Crime: Peru punishes illegal trafficking in personal data under Article 154-A of the Criminal Code. That sits separately from the fines. We could not confirm that article against an official consolidated copy, so it is flagged as unconfirmed. A sixth item is worth knowing. The duty to appoint a Personal Data Officer arrives in waves by company size. The first wave already passed on 30 November 2025.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 22, 23, 25, 31.2, 37, 41 a 44 y Primera Disposicion Complementaria Final
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR, articulos 38 y 48
cdn.www.gob.pe
“Proporciona al MINCETUR los usuarios y/o claves de acceso a los servidores y base de datos en un plazo no mayor de diez (10) dias habiles de otorgada la autorizacion”
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosANPD refuerza el rol del Oficial de Datos Personales y presenta balance de gestion 2018-2025 - official press note, 28 January 2026, confirming Directoral Resolution 100-2025-JUS/DGTAIPD in force from late December 2025
gob.pe
Link checked 19 August 2026
What's changing next
One firm date in the next twelve months. By 30 November 2026, medium-sized companies must have appointed a Personal Data Officer. That means companies with yearly sales between roughly 9.4 and 12.7 million soles, about 2.7 to 3.6 million dollars. Small companies follow in 2027 and the smallest in 2028. Separately, a bill amending the privacy law cleared a congressional committee in November 2025. It is not law and you must not treat it as binding. Watch three powers the government can use without warning.
The staggered Personal Data Officer deadlines run from publication of the Regulation on 30 November 2024. Large firms above 2,300 tax units of annual sales had to comply by 30 November 2025. Medium firms between 1,700 and 2,300 units must comply by 30 November 2026. Small firms between 150 and 1,700 units must comply by 30 November 2027. Micro firms must comply by 30 November 2028. The Personal Data Officer Directive, Directoral Resolution 100-2025-JUS/DGTAIPD, took effect at the end of December 2025, alongside a new fine-calculation method. Peru's artificial intelligence law regulation, Supreme Decree 115-2025-PCM of 9 September 2025, is now in force. It interacts with the rules on profiling and automated decisions. POWERS THE GOVERNMENT CAN USE WITH NO CONSULTATION. (1) Under Article 19 the authority can issue a decision declaring any country safe enough, or decline to. The list is currently empty. (2) Article 19.3 lets Peru skip the assessment entirely for any country that signs common data protection standards with it. A single treaty could open a route overnight. (3) The Digital Government Secretariat has not yet published the national classification of digital security incidents, or the notification protocols. Both were promised within 90 to 120 working days of the November 2025 Digital Trust Regulation. They will set the deadlines for everything below critical level. PROPOSED, NOT LAW: Bill 07919/2023-CR was approved by the Congressional Economy Committee on 5 November 2025. It would amend Article 28 of Law 29733 to make companies run prevention, education and digital security programmes.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, Primera Disposicion Complementaria Final (staggered Personal Data Officer commencement table)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosMINJUSDH refuerza la proteccion de datos personales con nueva directiva y metodologia de calculo de multas - official press note, 31 December 2025
gob.pe
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 115-2025-PCM, Reglamento de la Ley N.o 31814 (artificial intelligence), 9 September 2025
gob.pe
Link checked 19 August 2026
- Official sourceCongreso de la Republica del PeruComision de Economia aprueba dictamenes ... proteccion de datos personales - Congress news office, 5 November 2025 (Proyecto de Ley 07919/2023-CR)
comunicaciones.congreso.gob.pe
Link checked 19 August 2026
What to do: Diarise 30 November 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad · Resolucion S.B.S. N.o 504-2021, as amended by Resolucion S.B.S. N.o 1515-2021 · Directly binding regulation
Banks, insurers, pension fund managers and other supervised financial firms may handle and store data abroad, including in public cloud. They must tell the Superintendency within 30 days. They must also get permission first where foreign law would limit the Superintendency's access, audit or exit rights. That permission names the provider, the country and the city. This replaced an older rule that required permission for main data handling abroad.
Enforced by Superintendency of Banking, Insurance and Pension Fund Administrators
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Put a transfer safeguard in placeYou need permission from the Superintendency of Banking, Insurance and Pension Funds before hiring a significant data-handling service abroad, where the foreign country's laws limit the required controls. The permission names the provider, the country and the city. The Superintendency answers within 60 working days.
- Keep records of how you use data — within 720 hoursReport the service, the provider, the service levels and the technology used to the Superintendency within 30 calendar days of the work starting.
- Independent auditAnnual verification that the provider maintains information security controls.
- Hold a security certificateFor cloud, annual evidence of live ISO/IEC 27001, 27017 and 27018 certification plus a SOC 2 Type 2 report or equivalent for the region providing the service.
- Written vendor contractYou must guarantee that the Superintendency, internal audit and external audit can reach the information on request. You also need an exit plan, a list of any sub-contractors, and permanent deletion when the contract ends.
- Make switching cloud provider possibleA documented exit strategy allowing migration back in-house or to another provider is mandatory.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory measures for breach of prudential regulation; the resolution itself sets controls rather than a fine schedule
Sources
- Official sourceSuperintendencia de Banca, Seguros y AFPResolucion S.B.S. N.o 504-2021, articulos 23, 24 y 25 and Articulo Decimo (entry into force)
intranet2.sbs.gob.pe
“La autorizacion que conceda esta Superintendencia es especifica al proveedor del servicio y, al pais y ciudad desde el que se recibe”
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoAprueban el Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad - Resolucion N.o 504-2021, official gazette entry
busquedas.elperuano.pe
Link checked 19 August 2026
Telecoms rules
Official name: Decreto Legislativo N.o 1182, que regula el uso de los datos derivados de las telecomunicaciones para la identificacion, localizacion y geolocalizacion de equipos de comunicacion · Decreto Legislativo 1182, published 27 July 2015, amended by Ley 31284 · Act of parliament
Telecoms concession holders must keep call, connection and location records for three years. The first year must be live and searchable by the Peruvian police in real time. The next two years sit in archive. No rule says the data must stay in Peru. But the real-time delivery duty makes it hard to run everything abroad.
Enforced by Supervisory Agency for Private Investment in Telecommunications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 1 yearFirst 12 months must sit in systems that allow query and delivery online and in real time.
- Keep logs — 3 yearsA further 24 months in electronic archive, delivered within 7 days of judicial authorisation. Total 36 months.
- Do not hand data to foreign authorities on demandOperators must build access channels reserved for the Peruvian police specialised unit.
What it costs if you get it wrong
- Loss of your licenceInfringements and sanctions for failing to give access are set jointly by the transport ministry and OSIPTEL by supreme decree
Sources
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Primera y Segunda Disposiciones Complementarias Finales
busquedas.elperuano.pe
“los concesionarios de servicios publicos de telecomunicaciones y las entidades publicas o privadas relacionadas con estos servicios, implementan mecanismos de acceso exclusivo a la unidad especializada de la Policia Nacional del Peru”
Link checked 19 August 2026
Online gaming data rules
Official name: Reglamento de la Ley N.o 31557, Ley que regula la explotacion de los juegos a distancia y apuestas deportivas a distancia · Decreto Supremo N.o 005-2023-MINCETUR, published 13 October 2023 · Directly binding regulation
Online gaming and sports betting operators do not have to keep servers in Peru. But they must be a Peruvian company or branch. They must give the trade ministry logins to their own servers and databases. They must also feed economic and technical data to the ministry's data centre every day of the year. That is regulator access, not a rule about where data sits. It shapes your systems the same way.
Enforced by Directorate General of Casino Games and Slot Machines, Ministry of Foreign Trade and Tourism
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyLicence holders must be Peruvian companies or Peruvian branches of foreign companies.
- Keep records of how you use dataUsernames and passwords for the operator's servers and databases must be handed to the trade ministry within 10 working days of licensing, and again on demand during inspections.
- Keep logsEconomic and technical counters must be transmitted to the ministry's data centre at least once a day, 365 days a year, with retry every 5 minutes on failure.
- Tell people what you doThe privacy policy must meet Law 29733 and set out access, rectification, objection and cancellation rights.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 150 UIT (S/ 825,000 at the 2026 tax unit value) — about $236 thousandFailure to transmit technical and economic data in real time
- Fixed maximum fine: 50 UIT (S/ 275,000) — about $79 thousandServer, data transmission and information security breaches
- Loss of your licenceCancellation or disqualification for up to 10 years
Sources
- Official sourceMinisterio de Comercio Exterior y Turismo / Diario Oficial El PeruanoDecreto Supremo N.o 005-2023-MINCETUR, articulos 4, 38, 45 y 48 y regimen de infracciones
cdn.www.gob.pe
“Los datos economicos y tecnicos almacenados en el servidor de la Plataforma Tecnologica no podran dejar de ser transmitidos al Data Center del MINCETUR los trescientos sesenta y cinco (365) dias del ano.”
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR - official record page
gob.pe
Link checked 19 August 2026
Health data rules (Health and social care)
Official name: NTS N.o 139-MINSA/2018/DGAIN, Norma Tecnica de Salud para la Gestion de la Historia Clinica · Approved by Resolucion Ministerial N.o 214-2018-MINSA, 13 March 2018 · Regulator guideline
Patient records must be kept for twenty years in total. That is five years active and fifteen years archived, before anyone can even propose destroying them. A summary survives destruction. Health data is sensitive data, so the general transfer rules matter most here. We found no rule requiring health data to be stored in Peru, checked 19 August 2026.
Enforced by Ministry of Health
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, To save someone’s life
What you have to do
- Keep data for a minimum period — 20 yearsFive years in the active file after the last consultation, then fifteen years in the passive archive. A minimum summary must be preserved even after destruction is approved.
- Secure the dataElectronic clinical record systems must meet confidentiality, availability, integrity and authenticity requirements and use digital signatures with full traceability.
- Keep records of how you use data
What it costs if you get it wrong
- Order to stopHealth supervisory action against the provider; privacy fines run separately through the data protection authority
Sources
- Official sourceMinisterio de SaludNTS N.o 139-MINSA/2018/DGAIN, seccion 4.3 (archivo activo, archivo pasivo y eliminacion)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de SaludResolucion Ministerial N.o 214-2018-MINSA - official record page
gob.pe
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Ley N.o 29733, Ley de Proteccion de Datos Personales, y su Reglamento aprobado por Decreto Supremo N.o 016-2024-JUS · Ley 29733 (published 3 July 2011); D.S. 016-2024-JUS (published 30 November 2024) · Act of parliament
Peru's general privacy law and its 2024 Regulation. Data may leave Peru only to a country formally judged safe enough, and no country has been judged so. So everyone signs the regulator's model contract and files the transfer on the national register. The law is heavy on registration and consent. Foreign companies must appoint a local representative. There is a 48-hour breach clock and a two-year cap on how long a supplier may hold your data. Fines are low by international standards.
Enforced by National Authority for the Protection of Personal Data
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest
What you have to do
- Get consentConsent is the default basis. The exceptions sit in Article 14 of Law 29733.
- Tell people what you do
- Register or notifyEnter every personal data bank on the National Registry of Personal Data Protection. File and register flows of data out of Peru separately.
- Appoint a representativeIf the rules catch you even though you have no office in Peru, you must name a representative in or for Peruvian territory. That person is the regulator's contact point.
- Appoint a data protection officer — applies at: Public bodies; large-volume or sensitive-data processing; and firms whose core business is sensitive data. Private-sector commencement is staggered by company size to 30 November 2028., from 30 November 2025
- Put a transfer safeguard in placeEither a decision that the country is safe enough, or model contract clauses or an equal contract. You must also notify and register the flow.
- Report breaches to the regulator — within 48 hoursThis applies to large-volume exposure, sensitive data, many affected people, or clear harm. If you file late, you must justify the delay with evidence.
- Secure the data
- Keep logs — 2 yearsMinimum two years for account, session and data-action logs.
- Delete data after a period — 2 yearsA supplier may keep your data for at most two years after the last assignment ends. Keeping data forever is banned as a general rule.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere — from 30 September 2025Portability under Article 76 took effect six months after the Regulation entered into force.
- Limit automated decisions
- Get a parent's consent for children — applies at: Parental consent under 14; 14 to 17 year olds may consent themselves for digital services.
- Written vendor contract
- Assess high-risk projectsOptional, not mandatory. The Regulation says the impact assessment is a choice.
What it costs if you get it wrong
- Fixed maximum fine: 100 UIT (S/ 550,000 at the 2026 tax unit value of S/ 5,500) — about $157 thousandVery serious infringement
- Fixed maximum fine: 50 UIT (S/ 275,000) — about $79 thousandSerious infringement
- Fixed maximum fine: 5 UIT (S/ 27,500) — about $8 thousandMinor infringement
- Percentage of global turnover: 10 per cent of the previous year's gross annual revenueAbsolute ceiling on any fine, whatever the tier
Sources
- Official sourceDiario Oficial El PeruanoLey N.o 29733, Ley de Proteccion de Datos Personales - consolidated official text, articles 15, 16, 34 and 39
diariooficial.elperuano.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento de la Ley N.o 29733, aprobado por D.S. 016-2024-JUS
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourcePlataforma del Estado Peruano (gob.pe)Decreto Supremo N.o 016-2024-JUS - official record page, 30 November 2024
gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Economia y FinanzasValor de la UIT en el ano 2026 - S/ 5,500
gob.pe
Link checked 19 August 2026
Health data rules
Official name: Reglamento del Decreto de Urgencia N.o 007-2020, Marco de Confianza Digital · Decreto Supremo N.o 126-2025-PCM, published 4 November 2025 · Directly binding regulation
Public bodies and digital service providers must report critical digital security incidents to the National Digital Security Centre within 48 hours. This covers finance, electricity, water, gas, health, passenger transport, internet access, education and other critical activities. It runs on top of the privacy authority's own 48-hour clock, not instead of it.
Enforced by National Digital Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 48 hoursReport critical-level digital security incidents to the National Digital Security Centre. Deadlines for less severe levels are still pending. The classification and protocols were due within 90 to 120 working days of the rules starting.
- Report breaches to the regulatorYou must do both. Reporting to the Digital Security Centre does not excuse reporting the same incident to the privacy authority.
- Secure the data
- Hold a security certificateAuthentication assurance levels must be implemented in proportion to service risk.
What it costs if you get it wrong
- Order to stopSector regulators enforce within their own regimes; the Regulation itself does not set a fine schedule
Sources
- Official sourcePresidencia del Consejo de MinistrosReglamento aprobado por D.S. 126-2025-PCM, articulos 18, 32 y disposiciones complementarias finales sexta y setima
cdn.www.gob.pe
“Lo dispuesto en el presente literal no exime al PSD de cumplir con notificar a la ANPD si advierte que el incidente comprometio los datos personales de sus usuarios”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 126-2025-PCM - official record page
gob.pe
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no country has been declared to have an adequate level of protection by the Peruvian authority.
We found no decision naming any country as safe enough on the authority's own pages. The authority publishes no consolidated index of decisions, so we could not confirm this. Assume no country is approved and plan on model contract clauses. Re-check before you rely on an approval for a specific destination.
The full text and current status of Directoral Resolution 100-2025-JUS/DGTAIPD, the Personal Data Officer Directive.
Two press notes from the ministry confirm this, dated 31 December 2025 and 28 January 2026. We could not confirm the text itself on a government website. So we do not quote its detailed triggers for when a Personal Data Officer is required.
That Article 154-A of the Criminal Code (illegal trafficking in personal data) is in force in its current wording.
We could not confirm Article 154-A against an official consolidated copy of the Criminal Code. We state the criminal exposure at medium confidence. Check it against the official legal information system before you rely on it.
Whether SBS Resolution 504-2021 has been amended after 2021.
We checked the consolidated text hosted by the Superintendency itself. It records amendments up to Resolution 1515-2021. We could not confirm whether there are later amendments. The rule on permission for data handling abroad, in Article 25, is quoted from that text.
Whether any securities, education, defence or geospatial rule imposes where data has to be stored.
We found no rule here, checked 19 August 2026. That is not proof that none exists. Defence rules in particular are often not published. If you work in defence, education or geospatial data, check before you rely on this.
The soles to dollars conversions used in this record.
Converted at roughly 3.5 soles to the dollar so it is easier to read. The tax unit value of S/ 5,500 for 2026 is official. The exchange rate is not.
Whether the Digital Government Secretariat has now published the national digital security incident classification and the notification deadlines for below-critical incidents.
These were due within 90 to 120 working days of the November 2025 Regulation, which would put them in 2026. We found no published version. Until they appear, only the 48-hour critical-incident deadline is certain.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 90 days. Next check due 17 November 2026.