Skip to the content
Global Data RulesData governance rules, country by country

Peru

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Peru — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

You can send personal data out of Peru, but only on conditions. You may send it to a country the government has judged to protect data properly. It has judged none. So everyone uses the fallback. You sign the regulator's model contract, then file the transfer on a public register. No industry has to keep data inside Peru. The regulator is real, staffed and fining people.

Data governance in Peru

The eight things that decide how you handle data about people in Peru. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Peru's privacy rules reach a company with no office in Peru. They apply if you offer goods or services to people in Peru. They also apply if you watch their behaviour online or build profiles of them. There is no size or revenue threshold that lets you escape. If the rules catch you, you must appoint a representative for Peru. That person is the contact point for the regulator. They can sit outside Peru. You must name them in your public privacy notice or in a filing to the regulator.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

Yes, with conditions. The same conditions apply to every industry. You may only send personal data to a country that Peru has decided protects data properly. Peru has not yet decided that about any country. So almost every transfer runs on the backup route. You give 'adequate guarantees', normally by signing the model contract the regulator published. Nothing has to physically stay in Peru. We found no rule forcing data to stay in the country in banking, payments, insurance, securities, health, telecoms, government cloud, gambling or mapping.

Ways to send data out:
Standard contract clauses · Official 'this country is safe' decision

What to do: Get the paperwork for one of the routes below signed before any data leaves Peru.

Sending data out of the country

You may only send data to a country Peru has formally judged safe enough. Peru has not named a single country. So nearly everyone uses the backup route. You sign the regulator's published model contract clauses. An equivalent contract that puts the same duties on the receiver also works. You do not need permission first. You do need to tell the regulator. Every flow of data out of Peru must be reported and entered on the National Registry of Personal Data Protection. There is an online form for it. You can also ask the regulator for a formal opinion on your transfer. It must answer within thirty days.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Explicit consent · Needed for a contract · Legal claims

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The National Authority for the Protection of Personal Data, which sits inside the Ministry of Justice and Human Rights. It really works. It is not a paper regulator. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty cases and issued 211 decisions. It imposed about 11.3 million soles in fines, roughly 3.2 million dollars. It was still issuing decisions in May 2026. In finance and insurance the banking regulator enforces separately. The cyber-incident regulator sits in the Prime Minister's Office.

How long you must keep it — and when to delete it

Peru is unusual. The privacy rules set both a minimum and a maximum. The minimums: security and access logs must be kept at least two years. Phone and internet records must be kept three years. Tax and accounting records must be kept for as long as the tax can still be assessed, which is usually five years or more. Patient records must be kept twenty years. The maximum: a supplier handling data for you may keep it for at most two years after the job ends. Keeping personal data forever is banned as a general rule. Where a specific law demands longer, the data goes back to the client and is kept only while that legal duty lasts.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Two clocks, both 48 hours. They are not the same clock. First, tell the privacy authority within 48 hours of finding out, if personal data is exposed in bulk, sensitive data is involved, or a lot of people are affected. You must tell it even if you fixed the problem yourself. If you miss the 48 hours you may still file, but you must explain the delay and prove it. Second, public bodies and digital service providers must tell the National Digital Security Centre within 48 hours of a critical-level incident. That covers finance, utilities, health, transport, internet access, education and other critical activities. A single breach can trigger both.

What you have to do here:
Report breaches to the regulator · Report cyber incidents · Secure the data

What to do: Your breach process has to reach Peru's regulator inside the deadline above.

What catches people out

Five things catch people out. One: you must register every collection of personal data with the national register. You must separately register the fact that you send data abroad. Most foreign companies do not know this filing duty exists. Two: a supplier may only hold your data for two years after the work ends. Old archives sitting at a supplier are unlawful by default. Three: a child under fourteen needs a parent's consent. But a fourteen to seventeen year old can consent alone for digital services. That is the opposite of what most global consent flows assume. Four: an online gambling licensee must give the trade ministry the usernames and passwords to its own servers and databases. Five: mishandling personal data can be a crime, not just a fine.

What you have to do here:
Register or notify · Delete data after a period · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

One firm date in the next twelve months. By 30 November 2026, medium-sized companies must have appointed a Personal Data Officer. That means companies with yearly sales between roughly 9.4 and 12.7 million soles, about 2.7 to 3.6 million dollars. Small companies follow in 2027 and the smallest in 2028. Separately, a bill amending the privacy law cleared a congressional committee in November 2025. It is not law and you must not treat it as binding. Watch three powers the government can use without warning.

What to do: Diarise 30 November 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad · Resolucion S.B.S. N.o 504-2021, as amended by Resolucion S.B.S. N.o 1515-2021 · Directly binding regulation

In forceYes, with paperwork

Banks, insurers, pension fund managers and other supervised financial firms may handle and store data abroad, including in public cloud. They must tell the Superintendency within 30 days. They must also get permission first where foreign law would limit the Superintendency's access, audit or exit rights. That permission names the provider, the country and the city. This replaced an older rule that required permission for main data handling abroad.

In force since 1 July 2021Enforced from 20 February 2021

Enforced by Superintendency of Banking, Insurance and Pension Fund Administrators

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Telecoms

Telecoms rules

Official name: Decreto Legislativo N.o 1182, que regula el uso de los datos derivados de las telecomunicaciones para la identificacion, localizacion y geolocalizacion de equipos de comunicacion · Decreto Legislativo 1182, published 27 July 2015, amended by Ley 31284 · Act of parliament

In forceYes, with paperwork

Telecoms concession holders must keep call, connection and location records for three years. The first year must be live and searchable by the Peruvian police in real time. The next two years sit in archive. No rule says the data must stay in Peru. But the real-time delivery duty makes it hard to run everything abroad.

In force since 28 July 2015

Enforced by Supervisory Agency for Private Investment in Telecommunications

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Online gaming

Online gaming data rules

Official name: Reglamento de la Ley N.o 31557, Ley que regula la explotacion de los juegos a distancia y apuestas deportivas a distancia · Decreto Supremo N.o 005-2023-MINCETUR, published 13 October 2023 · Directly binding regulation

In forceYes, with paperwork

Online gaming and sports betting operators do not have to keep servers in Peru. But they must be a Peruvian company or branch. They must give the trade ministry logins to their own servers and databases. They must also feed economic and technical data to the ministry's data centre every day of the year. That is regulator access, not a rule about where data sits. It shapes your systems the same way.

In force since 14 October 2023Enforced from 9 February 2024

Enforced by Directorate General of Casino Games and Slot Machines, Ministry of Foreign Trade and Tourism

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Ley N.o 29733, Ley de Proteccion de Datos Personales, y su Reglamento aprobado por Decreto Supremo N.o 016-2024-JUS · Ley 29733 (published 3 July 2011); D.S. 016-2024-JUS (published 30 November 2024) · Act of parliament

Partly in forceYes, with paperwork

Peru's general privacy law and its 2024 Regulation. Data may leave Peru only to a country formally judged safe enough, and no country has been judged so. So everyone signs the regulator's model contract and files the transfer on the national register. The law is heavy on registration and consent. Foreign companies must appoint a local representative. There is a 48-hour breach clock and a two-year cap on how long a supplier may hold your data. Fines are low by international standards.

In force since 30 March 2025

Enforced by National Authority for the Protection of Personal Data

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest

Government

Health data rules

Official name: Reglamento del Decreto de Urgencia N.o 007-2020, Marco de Confianza Digital · Decreto Supremo N.o 126-2025-PCM, published 4 November 2025 · Directly binding regulation

Partly in forceYes, with paperwork

Public bodies and digital service providers must report critical digital security incidents to the National Digital Security Centre within 48 hours. This covers finance, electricity, water, gas, health, passenger transport, internet access, education and other critical activities. It runs on top of the privacy authority's own 48-hour clock, not instead of it.

In force since 5 November 2025

Enforced by National Digital Security Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Autoridad Nacional de Proteccion de Datos Personales (Direccion General de Transparencia, Acceso a la Informacion Publica y Proteccion de Datos Personales, MINJUSDH)

    General personal data protection, all sectors

    Fully operational. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty proceedings, and issued 211 first- and second-instance decisions plus 212 rights-enforcement decisions. It imposed about S/ 11.3 million in fines. It was still confirming penalties in May 2026. Its director as of January 2026 was Eduardo Luna Cervantes. The weakness is collection, not activity. Only about S/ 1.9 million of the 2025 fines had been collected by January 2026.

  • Superintendencia de Banca, Seguros y Administradoras Privadas de Fondos de Pensiones (SBS)

    Banks, insurers, pension fund managers, e-money issuers, cooperatives

    Long-established financial regulator. It runs the permission system for significant data handling abroad.

  • Centro Nacional de Seguridad Digital, Secretaria de Gobierno y Transformacion Digital, Presidencia del Consejo de Ministros

    Digital security incidents, national incident register, government digital security framework

    Operational, and running the National Register of Digital Security Incidents. It launched a joint incident reporting form with the privacy authority in September 2025. But the incident classification and the deadlines for less than critical incidents were still pending as of 19 August 2026.

  • Direccion General de Juegos de Casino y Maquinas Tragamonedas (DGJCMT), MINCETUR

    Online gaming and remote sports betting licensing, technical standards and inspection

    Licenses and inspects remote gaming operators. It runs the data centre that receives daily operator feeds.

  • Organismo Supervisor de Inversion Privada en Telecomunicaciones (OSIPTEL)

    Telecommunications operators, including sanctions for failing to provide access to telecommunications-derived data

  • Ministerio de Salud (MINSA)

    Clinical record standards, electronic health record accreditation, the national electronic clinical record register

  • Superintendencia del Mercado de Valores (SMV)

    Securities market participants, operational and cyber risk

    Active regulator. But we found no securities rule on its own site about keeping data in the country or storing it abroad. We did not check its operational risk rules line by line.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no country has been declared to have an adequate level of protection by the Peruvian authority.

    We found no decision naming any country as safe enough on the authority's own pages. The authority publishes no consolidated index of decisions, so we could not confirm this. Assume no country is approved and plan on model contract clauses. Re-check before you rely on an approval for a specific destination.

  • The full text and current status of Directoral Resolution 100-2025-JUS/DGTAIPD, the Personal Data Officer Directive.

    Two press notes from the ministry confirm this, dated 31 December 2025 and 28 January 2026. We could not confirm the text itself on a government website. So we do not quote its detailed triggers for when a Personal Data Officer is required.

  • That Article 154-A of the Criminal Code (illegal trafficking in personal data) is in force in its current wording.

    We could not confirm Article 154-A against an official consolidated copy of the Criminal Code. We state the criminal exposure at medium confidence. Check it against the official legal information system before you rely on it.

  • Whether SBS Resolution 504-2021 has been amended after 2021.

    We checked the consolidated text hosted by the Superintendency itself. It records amendments up to Resolution 1515-2021. We could not confirm whether there are later amendments. The rule on permission for data handling abroad, in Article 25, is quoted from that text.

  • Whether any securities, education, defence or geospatial rule imposes where data has to be stored.

    We found no rule here, checked 19 August 2026. That is not proof that none exists. Defence rules in particular are often not published. If you work in defence, education or geospatial data, check before you rely on this.

  • The soles to dollars conversions used in this record.

    Converted at roughly 3.5 soles to the dollar so it is easier to read. The tax unit value of S/ 5,500 for 2026 is official. The exchange rate is not.

  • Whether the Digital Government Secretariat has now published the national digital security incident classification and the notification deadlines for below-critical incidents.

    These were due within 90 to 120 working days of the November 2025 Regulation, which would put them in 2026. We found no published version. Until they appear, only the 48-hour critical-incident deadline is certain.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 90 days. Next check due 17 November 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.