Peru
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Peru lets personal data leave the country, but only on conditions. You may send it to a country the government has judged to protect data properly - and it has judged none. So everyone uses the fallback: sign the regulator's model contract, then file the transfer on a public register. No industry has to keep data inside Peru. The regulator is real, staffed and fining people.
Data governance in Peru
The eight things that decide how you handle data about people in Peru. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Peru's privacy rules reach a company with no office in Peru if it offers goods or services to people in Peru, or if it watches their behaviour online or builds profiles of them. There is no size or revenue threshold that lets you escape. If you are caught this way you must appoint a representative for Peru, who is the contact point for the regulator. That representative can sit outside Peru, but must be named either in your public privacy notice or in a filing to the regulator.
Article VI of the Regulation approved by Supreme Decree 016-2024-JUS extends the regime to controllers not established in Peru that offer goods or services to people located in Peru, or that monitor behaviour or build profiles of them, and to controllers to whom Peruvian law applies by contract or by international law. Article VII then requires the appointment of a representative 'in Peruvian territory or for Peruvian territory', with the only exemption being processing purely for transit. Registration of every personal data bank with the National Registry of Personal Data Protection is a separate, long-standing duty under Article 34 of Law 29733.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento de la Ley N.o 29733, aprobado por Decreto Supremo N.o 016-2024-JUS, articulos VI y VII del Titulo Preliminar
cdn.www.gob.pe
“el titular del banco de datos personales o quien resulte responsable, ubicado en el territorio peruano o fuera de este, debe proveer los medios necesarios para el efectivo cumplimiento de las obligaciones previstas en la Ley y el Reglamento, y, designar un representante en el territorio peruano o para el territorio peruano”
Link checked 19 August 2026
- Official sourcePlataforma del Estado Peruano (gob.pe)Decreto Supremo N.o 016-2024-JUS - official record page, published 30 November 2024
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, Ley de Proteccion de Datos Personales - consolidated official text
diariooficial.elperuano.pe
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions, and the same conditions apply to every industry. The rule is that you may only send personal data to a country that Peru has decided protects data properly. Peru has not yet decided that about any country, so almost every transfer runs on the backup route: give 'adequate guarantees', normally by signing the model contract the regulator published. Nothing has to physically stay in Peru - there is no localisation rule in banking, payments, insurance, securities, health, telecoms, government cloud, gambling or mapping that we could find.
Sector by sector, checked 19 August 2026. BANKING, INSURANCE, PENSIONS (data can leave with paperwork): SBS Resolution 504-2021 permits offshore processing and cloud, but a regulated firm must ask the Superintendency for prior authorisation before hiring a significant offshore data-processing service where the foreign legal framework limits the Superintendency's access, audit or exit rights; the authorisation is specific to the provider, country and city. Firms must also notify the Superintendency within 30 calendar days of starting any significant third-party data processing, and evidence ISO/IEC 27001, 27017, 27018 and a SOC 2 Type 2 report annually for cloud. SECURITIES (data can leave with paperwork): no separate localisation rule found on the SMV's own site; the general regime and operational-risk rules apply. HEALTH (data can leave with paperwork): no localisation rule found; the binding constraint is retention, not location. TELECOMS (data can leave with paperwork): no localisation rule, but Legislative Decree 1182 requires operators to hold traffic and location data for 12 months in systems that answer Peruvian police online and in real time, then 24 months more in archive - a practical pull towards in-country infrastructure. GOVERNMENT CLOUD (data can leave with paperwork): the digital government regulation tells public bodies to prefer cloud, and the Digital Government Secretariat's cloud guidance expressly says restrictive data-location rules would breach Peru's free trade commitments; it only suggests that bodies holding mass sensitive data with national security characteristics may choose to keep those in-country. GAMBLING (data can leave with paperwork): no server-location rule, but the operator must be a Peruvian company or a Peruvian branch, must give the trade ministry usernames and passwords to its servers and databases within 10 working days of licensing, and must transmit economic and technical data to the ministry's data centre every single day. GEOSPATIAL, EDUCATION, DEFENCE: no cross-border storage rule located, checked 19 August 2026, confidence medium.
Sources
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 15 (flujo transfronterizo de datos personales)
diariooficial.elperuano.pe
“El titular y el encargado de tratamiento de datos personales deben realizar el flujo transfronterizo de datos personales solo si el pais destinatario mantiene niveles de proteccion adecuados conforme a la presente Ley.”
Link checked 19 August 2026
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 18 a 21 (flujo transfronterizo, nivel adecuado, garantias y registro)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceSuperintendencia de Banca, Seguros y AFPResolucion S.B.S. N.o 504-2021, Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad, articulos 24 y 25
intranet2.sbs.gob.pe
“La empresa debe solicitar autorizacion de la Superintendencia, previo a la contratacion de un servicio significativo de procesamiento de datos provisto por terceros desde el exterior, en caso dicho servicio presente limitaciones para cumplir con los requerimientos establecidos en el parrafo 24.2”
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Segunda Disposicion Complementaria Final (conservacion de datos derivados de las telecomunicaciones)
busquedas.elperuano.pe
“deben conservar los datos derivados de las telecomunicaciones durante los primeros doce (12) meses en sistemas informaticos que permitan su consulta y entrega en linea y en tiempo real. Concluido el referido periodo, deberan conservar dichos datos por veinticuatro (24) meses adicionales”
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR, Reglamento de la Ley 31557 (juegos y apuestas deportivas a distancia), articulos 38 y 45
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceSecretaria de Gobierno Digital, Presidencia del Consejo de MinistrosLineamientos para el Uso de Servicios en la Nube para Entidades de la Administracion Publica, seccion 5.4 (localizacion del proceso y de los datos personales)
cdn.www.gob.pe
Link checked 19 August 2026
Sending data out of the country
The model is an allowlist, and the list is empty. Peru says you may only export to a country it has formally judged adequate, and we found no decision naming any country. So nearly everyone uses the escape hatch: sign the regulator's published model contract clauses, or an equivalent contract that imposes the same duties on the receiver. You do not need permission first. You do need to tell the regulator: every cross-border flow must be reported and entered on the National Registry of Personal Data Protection, and there is an online form for it. You can also ask the regulator for a formal opinion on your transfer, and it must answer within thirty days.
Article 18 of the 2024 Regulation sets the adequacy-first rule; Article 19 says the Directorate General issues a resolution determining whether a country is adequate, using four criteria (a legal framework, processing principles, enforceable individual rights, and a supervisory authority), and that the assessment is dispensable where the country has signed common data protection standards with Peru. Article 20 supplies the fallback: model contractual clauses or other legal instruments imposing at least the same obligations. Those model clauses were approved back in 2022 by Directoral Resolution 0074-2022-JUS/DGTAIPD, adopting the Ibero-American network's model. Article 21.2 makes notification and registration of the flow mandatory in every case. Law 29733 Article 15 also carries seven statutory exceptions that switch off the guarantee requirement entirely - international treaties, judicial cooperation, intelligence cooperation against serious crime, performance of a contract with the individual (expressly including user authentication, service improvement and support, quality monitoring, maintenance and billing), banking and stock-market transfers, medical treatment and epidemiological studies with disassociation, and the individual's prior express consent.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 19, 20 y 21
cdn.www.gob.pe
“En cualquier caso, el flujo transfronterizo de datos personales debe ponerse en conocimiento de la Direccion General de Transparencia, Acceso a la Informacion Publica y Proteccion de Datos Personales”
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos Personales, MINJUSDHResolucion Directoral N.o 0074-2022-JUS/DGTAIPD - approves the Model Contractual Clauses for International Transfers of Personal Data, 17 October 2022
gob.pe
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos PersonalesInscribir flujo transfronterizo de datos personales - official procedure page, last updated 22 May 2026
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 15, numerales 1 a 8 (exceptions to the guarantee requirement)
diariooficial.elperuano.pe
Link checked 19 August 2026
The regulator, and whether it actually acts
The National Authority for the Protection of Personal Data, which sits inside the Ministry of Justice and Human Rights. It is genuinely operational, not a paper regulator. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty cases, issued 211 decisions and imposed about 11.3 million soles in fines, roughly 3.2 million dollars. It was still issuing decisions in May 2026. In finance and insurance the banking regulator enforces separately, and the cyber-incident regulator sits in the Prime Minister's Office.
The authority is legally the Directorate General for Transparency, Access to Public Information and Personal Data Protection within MINJUSDH; its director as of January 2026 was Eduardo Luna Cervantes. Comparable 2024 figures were 454 entities inspected, 133 penalty proceedings and about 13.4 million soles in fines. Two caveats on how hard it actually bites: collection is weak (about 1.9 million soles of the 2025 fines had been collected by January 2026, partly because of a 40 per cent prompt-payment discount and appeals), and the statutory ceiling is low - 100 tax units, about 550,000 soles or roughly 157,000 dollars, and never more than 10 per cent of the previous year's gross revenue. The authority also runs a public register of sanctioned organisations, publishes a fine-calculation methodology adopted at the end of December 2025, and reports advisory decisions. Sector regulators that enforce in parallel: the Superintendency of Banking, Insurance and Pension Funds, the National Digital Security Centre inside the Digital Government Secretariat, the trade ministry's gaming directorate, and the telecoms regulator OSIPTEL.
Sources
- Official sourceMinisterio de Justicia y Derechos HumanosANPD impuso multas por mas de S/ 11 millones ... durante el 2025 - official press note, 12 January 2026
gob.pe
“la ANPD fiscalizo a 760 entidades publicas y privadas ... se iniciaron 136 procedimientos administrativos sancionadores y se emitieron 211 resoluciones administrativas”
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosANPD impuso multas por mas de S/ 13 millones ... el ano 2024 - official press note, 10 January 2025
gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosMINJUSDH sanciona a empresa por uso indebido de datos personales y aplica multas de hasta S/ 194 mil - official press note, 20 May 2026
gob.pe
Link checked 19 August 2026
- Official sourceAutoridad Nacional de Proteccion de Datos PersonalesConsultar instituciones sancionadas por la Autoridad Nacional de Proteccion de Datos Personales - public sanctions register
gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoLey N.o 29733, articulo 39 (administrative penalties, 0.5 to 100 tax units, capped at 10 per cent of gross annual revenue)
diariooficial.elperuano.pe
Link checked 19 August 2026
How long you must keep it — and when to delete it
Peru is unusual because the privacy rules set both a floor and a hard ceiling. The floor: security and access logs must be kept at least two years, phone and internet records three years, tax and accounting records for as long as the tax can still be assessed - in practice five years or more - and patient records twenty years. The ceiling: a supplier processing data for you may keep it at most two years after the job ends, and keeping personal data forever is banned as a general rule. Where a specific law demands longer, the data goes back to the client and is kept only while that legal duty lasts.
Ceiling: Article 31.2 of the 2024 Regulation caps a processor's retention at two years from the end of the last assignment and states that indefinite retention is prohibited as a general rule. Floor: Article 47 of the same Regulation requires logs of user accounts, sessions and actions on personal data to be kept for a minimum of two years, and interaction logs to be generated continuously and available immediately. Legislative Decree 1182 requires 12 months of telecoms-derived data in live systems plus 24 months archived. Article 87(7) of the Tax Code requires books, records and supporting documents to be kept while the tax is not yet time-barred. Health Technical Standard 139-MINSA/2018 keeps a clinical record in the active file for five years after the last consultation, then fifteen years in the passive archive - twenty years in total before it can be proposed for destruction, and a minimum summary must be preserved even then; occupational cancer records run forty years. Where floor and ceiling collide, the express legal duty wins and the general two-year cap yields.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 31.2 y 47
cdn.www.gob.pe
“El plazo para la conservacion de datos personales al que hace referencia el articulo 30 de la Ley es como maximo de dos (2) anos contados desde la finalizacion del ultimo encargo realizado ... La conservacion indeterminada de los datos personales, por regla general, esta prohibida.”
Link checked 19 August 2026
- Official sourceSuperintendencia Nacional de Aduanas y de Administracion TributariaCodigo Tributario, articulo 87 numeral 7 (duty to keep books, records and supporting documents while the tax is not time-barred)
sunat.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de SaludNTS N.o 139-MINSA/2018/DGAIN, Norma Tecnica de Salud para la Gestion de la Historia Clinica (approved by Resolucion Ministerial 214-2018-MINSA)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Segunda Disposicion Complementaria Final
busquedas.elperuano.pe
Link checked 19 August 2026
If something goes wrong
Two clocks, both 48 hours, and they are not the same clock. First: if personal data is exposed in bulk, or sensitive data is involved, or a lot of people are affected, you must tell the privacy authority within 48 hours of finding out - and you still must tell it even if you fixed the problem yourself. Miss the 48 hours and you may still file, but you must explain and evidence the delay. Second: public bodies and digital service providers in finance, utilities, health, transport, internet access, education and other critical activities must tell the National Digital Security Centre within 48 hours of a critical-level incident. A single breach can trigger both.
The privacy clock is Article 34.1 of the 2024 Regulation. The notification must describe the nature of the incident, the types and approximate number of people affected, the contact point, the likely consequences and the remedial measures. Article 36 requires a processor to tell its client immediately. The digital security clock is Article 32.1 of the Regulation of the Digital Trust Framework, Supreme Decree 126-2025-PCM, published 4 November 2025; Article 18 expressly says notifying the Digital Security Centre does not excuse you from notifying the privacy authority. Government has made this slightly easier by launching a single online incident form in September 2025 that feeds both regimes. A third, softer clock sits in finance: SBS Resolution 504-2021 requires firms to report a significant third-party data processing arrangement within 30 calendar days of it starting.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulo 34
cdn.www.gob.pe
“debe notificar a la Autoridad Nacional de Proteccion de Datos Personales como maximo dentro de las 48 horas posteriores a haber tomado conocimiento o constancia de ello”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosReglamento del Decreto de Urgencia N.o 007-2020 (Marco de Confianza Digital), aprobado por D.S. 126-2025-PCM, articulos 18 y 32
cdn.www.gob.pe
“Los incidentes de seguridad digital clasificados con nivel critico son notificados al CNSD, de manera obligatoria, dentro de un plazo maximo de cuarenta y ocho (48) horas, contado desde que el PSD toma conocimiento del incidente.”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 126-2025-PCM - official record page, 4 November 2025
gob.pe
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosPCM y Ministerio de Justicia presentan herramienta digital para reportar incidentes de seguridad - official press note, 19 September 2025
gob.pe
Link checked 19 August 2026
What catches people out
Five things that catch people out. One: you must register every collection of personal data with the national register, and separately register the fact that you send data abroad - a filing duty most foreign companies do not know exists. Two: a supplier may only hold your data for two years after the work ends, so long-tail archives at vendors are unlawful by default. Three: a child under fourteen needs a parent's consent, but a fourteen to seventeen year old can consent alone for digital services - the opposite of what most global consent flows assume. Four: an online gambling licensee must give the trade ministry the usernames and passwords to its own servers and databases. Five: mishandling personal data can be a crime, not just a fine.
(1) Registration: Article 34 of Law 29733 plus Articles 41 to 44 of the 2024 Regulation, and the separate cross-border flow filing under Article 21.2. (2) Processor retention: Article 31.2. (3) Children: Articles 22 and 25 of the Regulation - consent of the parent or guardian for under-14s, but 14 to 17 year olds may consent themselves for digital services if the information is put in language they can understand, and the controller must make reasonable efforts to verify who is giving consent. Article 23 also bans collecting data about the rest of a child's family through the child. (4) Gambling: Article 38(r) of the gaming Regulation - credentials to servers and databases within 10 working days of licensing, plus Article 48 requiring the same on demand during inspections, plus a daily data feed to the ministry's data centre 365 days a year. (5) Criminal exposure: Peru punishes illegal trafficking in personal data under Article 154-A of the Criminal Code, separately from the administrative fine regime; we have not been able to open an official consolidated copy of that article, so it is flagged as unconfirmed. A sixth item worth knowing: the duty to appoint a Personal Data Officer arrives in waves by company size, and the first wave already passed on 30 November 2025.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, articulos 22, 23, 25, 31.2, 37, 41 a 44 y Primera Disposicion Complementaria Final
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR, articulos 38 y 48
cdn.www.gob.pe
“Proporciona al MINCETUR los usuarios y/o claves de acceso a los servidores y base de datos en un plazo no mayor de diez (10) dias habiles de otorgada la autorizacion”
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosANPD refuerza el rol del Oficial de Datos Personales y presenta balance de gestion 2018-2025 - official press note, 28 January 2026, confirming Directoral Resolution 100-2025-JUS/DGTAIPD in force from late December 2025
gob.pe
Link checked 19 August 2026
What's changing next
One firm date in the next twelve months. On 30 November 2026 medium-sized companies - those with yearly sales between roughly 9.4 and 12.7 million soles, about 2.7 to 3.6 million dollars - must have appointed a Personal Data Officer. Small companies follow in 2027 and the smallest in 2028. Separately, a bill amending the privacy law cleared a congressional committee in November 2025 but is not law and must not be treated as binding. Watch three switches the government can flip without warning.
The staggered Personal Data Officer deadlines run from publication of the Regulation on 30 November 2024: large firms above 2,300 tax units of annual sales had to comply by 30 November 2025, medium firms between 1,700 and 2,300 units by 30 November 2026, small firms between 150 and 1,700 units by 30 November 2027, and micro firms by 30 November 2028. The Personal Data Officer Directive, Directoral Resolution 100-2025-JUS/DGTAIPD, took effect at the end of December 2025 alongside a new fine-calculation methodology. Peru's artificial intelligence law regulation, Supreme Decree 115-2025-PCM of 9 September 2025, is now in force and interacts with profiling and automated decision rules. DORMANT SWITCHES, each of which can change the picture with no consultation: (1) the authority can issue a resolution declaring any country adequate - or by implication decline to - under Article 19, and the list is currently empty; (2) Article 19.3 lets Peru bypass assessment entirely for any country that signs common data protection standards with it, so a single treaty could open a corridor overnight; (3) the Digital Government Secretariat has yet to publish the national classification of digital security incidents and the notification protocols promised within 90 to 120 working days of the November 2025 Digital Trust Regulation, and those will set the deadlines for everything below critical level. PROPOSED, NOT LAW: Bill 07919/2023-CR, approved by the Congressional Economy Committee on 5 November 2025, would amend Article 28 of Law 29733 to oblige controllers and processors to run prevention, education and digital security programmes.
Sources
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento aprobado por D.S. 016-2024-JUS, Primera Disposicion Complementaria Final (staggered Personal Data Officer commencement table)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Justicia y Derechos HumanosMINJUSDH refuerza la proteccion de datos personales con nueva directiva y metodologia de calculo de multas - official press note, 31 December 2025
gob.pe
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 115-2025-PCM, Reglamento de la Ley N.o 31814 (artificial intelligence), 9 September 2025
gob.pe
Link checked 19 August 2026
- Official sourceCongreso de la Republica del PeruComision de Economia aprueba dictamenes ... proteccion de datos personales - Congress news office, 5 November 2025 (Proyecto de Ley 07919/2023-CR)
comunicaciones.congreso.gob.pe
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad
Directly binding regulation · Resolucion S.B.S. N.o 504-2021, as amended by Resolucion S.B.S. N.o 1515-2021
Banks, insurers, pension fund managers and other supervised financial firms may process and store data abroad, including in public cloud, but must notify the Superintendency within 30 days and must obtain prior authorisation - specific to provider, country and city - where foreign law would limit the Superintendency's access, audit or exit rights. This replaced the older rule that required authorisation for offshore main processing.
Enforced by Superintendency of Banking, Insurance and Pension Fund Administrators
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Put a transfer safeguard in placePrior SBS authorisation is required before contracting a significant offshore data-processing service where the foreign legal framework limits the required controls. Authorisation is specific to the provider, the country and the city, and the SBS answers within 60 working days.
- Keep records of processing — within 720 hoursThe firm must report the service, provider, service levels and technology used to the SBS within 30 calendar days of the processing starting.
- Independent auditAnnual verification that the provider maintains information security controls.
- Hold a security certificateFor cloud, annual evidence of live ISO/IEC 27001, 27017 and 27018 certification plus a SOC 2 Type 2 report or equivalent for the region providing the service.
- Written vendor contractMust secure SBS, internal audit and external audit access to the information on request, an exit strategy, a chain-outsourcing inventory and definitive deletion on termination.
- Make switching cloud provider possibleA documented exit strategy allowing migration back in-house or to another provider is mandatory.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory measures for breach of prudential regulation; the resolution itself sets controls rather than a fine schedule
Sources
- Official sourceSuperintendencia de Banca, Seguros y AFPResolucion S.B.S. N.o 504-2021, articulos 23, 24 y 25 and Articulo Decimo (entry into force)
intranet2.sbs.gob.pe
“La autorizacion que conceda esta Superintendencia es especifica al proveedor del servicio y, al pais y ciudad desde el que se recibe”
Link checked 19 August 2026
- Official sourceDiario Oficial El PeruanoAprueban el Reglamento para la Gestion de la Seguridad de la Informacion y la Ciberseguridad - Resolucion N.o 504-2021, official gazette entry
busquedas.elperuano.pe
Link checked 19 August 2026
Decreto Legislativo N.o 1182, que regula el uso de los datos derivados de las telecomunicaciones para la identificacion, localizacion y geolocalizacion de equipos de comunicacion
Act of parliament · Decreto Legislativo 1182, published 27 July 2015, amended by Ley 31284
Telecoms concession holders must keep call, connection and location metadata for three years - the first year live and queryable in real time by the Peruvian police, the next two in archive. There is no explicit rule saying the data must sit in Peru, but the real-time delivery duty makes offshore-only architectures hard to run.
Enforced by Supervisory Agency for Private Investment in Telecommunications
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 1 yearFirst 12 months must sit in systems that allow query and delivery online and in real time.
- Keep logs — 3 yearsA further 24 months in electronic archive, delivered within 7 days of judicial authorisation. Total 36 months.
- Do not hand data to foreign authorities on demandNot a resistance duty but its mirror image: operators must build exclusive access mechanisms for the Peruvian police specialised unit.
What it costs if you get it wrong
- Loss of your licenceInfringements and sanctions for failing to give access are set jointly by the transport ministry and OSIPTEL by supreme decree
Sources
- Official sourceDiario Oficial El PeruanoDecreto Legislativo N.o 1182, Primera y Segunda Disposiciones Complementarias Finales
busquedas.elperuano.pe
“los concesionarios de servicios publicos de telecomunicaciones y las entidades publicas o privadas relacionadas con estos servicios, implementan mecanismos de acceso exclusivo a la unidad especializada de la Policia Nacional del Peru”
Link checked 19 August 2026
Reglamento de la Ley N.o 31557, Ley que regula la explotacion de los juegos a distancia y apuestas deportivas a distancia
Directly binding regulation · Decreto Supremo N.o 005-2023-MINCETUR, published 13 October 2023
Online gaming and sports betting operators do not have to keep servers in Peru, but they must be a Peruvian company or branch, must give the trade ministry logins to their own servers and databases, and must feed economic and technical data to the ministry's data centre every day of the year. That is regulator access rather than data residency, and it has the same practical effect on architecture.
Enforced by Directorate General of Casino Games and Slot Machines, Ministry of Foreign Trade and Tourism
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyLicence holders must be Peruvian companies or Peruvian branches of foreign companies.
- Keep records of processingUsernames and passwords for the operator's servers and databases must be handed to the trade ministry within 10 working days of licensing, and again on demand during inspections.
- Keep logsEconomic and technical counters must be transmitted to the ministry's data centre at least once a day, 365 days a year, with retry every 5 minutes on failure.
- Tell people what you doThe privacy policy must meet Law 29733 and set out access, rectification, objection and cancellation rights.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 150 UIT (S/ 825,000 at the 2026 tax unit value) — about $236 thousandFailure to transmit technical and economic data in real time
- Fixed maximum fine: 50 UIT (S/ 275,000) — about $79 thousandServer, data transmission and information security breaches
- Loss of your licenceCancellation or disqualification for up to 10 years
Sources
- Official sourceMinisterio de Comercio Exterior y Turismo / Diario Oficial El PeruanoDecreto Supremo N.o 005-2023-MINCETUR, articulos 4, 38, 45 y 48 y regimen de infracciones
cdn.www.gob.pe
“Los datos economicos y tecnicos almacenados en el servidor de la Plataforma Tecnologica no podran dejar de ser transmitidos al Data Center del MINCETUR los trescientos sesenta y cinco (365) dias del ano.”
Link checked 19 August 2026
- Official sourceMinisterio de Comercio Exterior y TurismoDecreto Supremo N.o 005-2023-MINCETUR - official record page
gob.pe
Link checked 19 August 2026
NTS N.o 139-MINSA/2018/DGAIN, Norma Tecnica de Salud para la Gestion de la Historia Clinica
Regulator guideline · Approved by Resolucion Ministerial N.o 214-2018-MINSA, 13 March 2018
Patient records must be kept for twenty years in total - five years active, fifteen years archived - before they can even be proposed for destruction, and a summary survives destruction. Health data is sensitive data, so the general privacy transfer rules bite hardest here. No rule requiring health data to be stored in Peru was found, checked 19 August 2026.
Enforced by Ministry of Health
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Someone's life is at risk
What it makes you do
- Keep data for a minimum period — 20 yearsFive years in the active file after the last consultation, then fifteen years in the passive archive. A minimum summary must be preserved even after destruction is approved.
- Secure the dataElectronic clinical record systems must meet confidentiality, availability, integrity and authenticity requirements and use digital signatures with full traceability.
- Keep records of processing
What it costs if you get it wrong
- Order to stopHealth supervisory action against the provider; privacy fines run separately through the data protection authority
Sources
- Official sourceMinisterio de SaludNTS N.o 139-MINSA/2018/DGAIN, seccion 4.3 (archivo activo, archivo pasivo y eliminacion)
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de SaludResolucion Ministerial N.o 214-2018-MINSA - official record page
gob.pe
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley N.o 29733, Ley de Proteccion de Datos Personales, y su Reglamento aprobado por Decreto Supremo N.o 016-2024-JUS
Act of parliament · Ley 29733 (published 3 July 2011); D.S. 016-2024-JUS (published 30 November 2024)
Peru's general privacy law and its 2024 Regulation. Data may leave Peru only to a country formally judged adequate - and none has been - so in practice everyone signs the regulator's model contract and files the transfer on the national register. Heavy on registration, consent, a mandatory local representative for foreign companies, a 48-hour breach clock and a two-year cap on how long a supplier may hold your data. Fines are low by international standards.
Enforced by National Authority for the Protection of Personal Data
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest
What it makes you do
- Get consentConsent is the default basis; the statutory exemptions sit in Article 14 of Law 29733.
- Tell people what you do
- Register or notifyEvery personal data bank must be entered on the National Registry of Personal Data Protection, and cross-border flows must be filed and registered separately.
- Appoint a local representativeForeign controllers caught by the extraterritorial test must designate a representative in or for Peruvian territory as the regulator's contact point.
- Appoint a data protection officer — applies at: Public bodies; large-volume or sensitive-data processing; and firms whose core business is sensitive data. Private-sector commencement is staggered by company size to 30 November 2028., from 30 November 2025
- Put a transfer safeguard in placeAdequacy resolution, or model contractual clauses / equivalent instrument, plus mandatory notification and registration of the flow.
- Report breaches to the regulator — within 48 hoursTriggered by large-volume exposure, sensitive data, many affected people, or evident harm. Late filing must be justified with evidence.
- Secure the data
- Keep logs — 2 yearsMinimum two years for account, session and data-action logs.
- Delete data after a period — 2 yearsProcessor retention capped at two years after the last assignment ends; indefinite retention prohibited as a general rule.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere — from 30 September 2025Portability under Article 76 took effect six months after the Regulation entered into force.
- Limit automated decisions
- Get a parent's consent for children — applies at: Parental consent under 14; 14 to 17 year olds may consent themselves for digital services.
- Written vendor contract
- Assess high-risk projectsOptional, not mandatory - the Regulation frames the impact assessment as facultative.
What it costs if you get it wrong
- Fixed maximum fine: 100 UIT (S/ 550,000 at the 2026 tax unit value of S/ 5,500) — about $157 thousandVery serious infringement
- Fixed maximum fine: 50 UIT (S/ 275,000) — about $79 thousandSerious infringement
- Fixed maximum fine: 5 UIT (S/ 27,500) — about $8 thousandMinor infringement
- Percentage of global turnover: 10 per cent of the previous year's gross annual revenueAbsolute ceiling on any fine, whatever the tier
Sources
- Official sourceDiario Oficial El PeruanoLey N.o 29733, Ley de Proteccion de Datos Personales - consolidated official text, articles 15, 16, 34 and 39
diariooficial.elperuano.pe
Link checked 19 August 2026
- Official sourceDiario Oficial El Peruano / Plataforma del Estado Peruano (gob.pe)Reglamento de la Ley N.o 29733, aprobado por D.S. 016-2024-JUS
cdn.www.gob.pe
Link checked 19 August 2026
- Official sourcePlataforma del Estado Peruano (gob.pe)Decreto Supremo N.o 016-2024-JUS - official record page, 30 November 2024
gob.pe
Link checked 19 August 2026
- Official sourceMinisterio de Economia y FinanzasValor de la UIT en el ano 2026 - S/ 5,500
gob.pe
Link checked 19 August 2026
Reglamento del Decreto de Urgencia N.o 007-2020, Marco de Confianza Digital
Directly binding regulation · Decreto Supremo N.o 126-2025-PCM, published 4 November 2025
Public bodies and digital service providers in finance, electricity, water, gas, health, passenger transport, internet access, education and other critical activities must report critical digital security incidents to the National Digital Security Centre within 48 hours. This runs on top of, not instead of, the privacy authority's own 48-hour clock.
Enforced by National Digital Security Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 48 hoursCritical-level digital security incidents to the National Digital Security Centre. Deadlines for lower-severity levels are still pending - the classification and protocols were due within 90 to 120 working days of commencement.
- Report breaches to the regulatorExpressly cumulative: reporting to the Digital Security Centre does not excuse reporting the same incident to the privacy authority.
- Secure the data
- Hold a security certificateAuthentication assurance levels must be implemented in proportion to service risk.
What it costs if you get it wrong
- Order to stopSector regulators enforce within their own regimes; the Regulation itself does not set a fine schedule
Sources
- Official sourcePresidencia del Consejo de MinistrosReglamento aprobado por D.S. 126-2025-PCM, articulos 18, 32 y disposiciones complementarias finales sexta y setima
cdn.www.gob.pe
“Lo dispuesto en el presente literal no exime al PSD de cumplir con notificar a la ANPD si advierte que el incidente comprometio los datos personales de sus usuarios”
Link checked 19 August 2026
- Official sourcePresidencia del Consejo de MinistrosDecreto Supremo N.o 126-2025-PCM - official record page
gob.pe
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no country has been declared to have an adequate level of protection by the Peruvian authority.
We could find no adequacy resolution on the authority's own pages, but proving a negative from a website with no consolidated resolutions index is not possible. Treat the allowlist as empty and plan on model contractual clauses, but re-check before relying on adequacy for a specific destination.
The full text and current status of Directoral Resolution 100-2025-JUS/DGTAIPD, the Personal Data Officer Directive.
Confirmed twice by the ministry's own press notes (31 December 2025 and 28 January 2026) but we could not open the instrument itself on a government domain. Its detailed triggers for when a Personal Data Officer is mandatory are therefore not quoted here.
That Article 154-A of the Criminal Code (illegal trafficking in personal data) is in force in its current wording.
We could not open an official consolidated copy of the Criminal Code during this run. The criminal exposure is stated at medium confidence and should be re-verified against the official legal information system before being relied on.
Whether SBS Resolution 504-2021 has been amended after 2021.
We verified the consolidated text hosted by the Superintendency itself, which records amendments up to Resolution 1515-2021. Later amendments, if any, were not located. The offshore authorisation rule in Article 25 is quoted from that text.
Whether any securities, education, defence or geospatial rule imposes data residency.
Searched and nothing found, checked 19 August 2026. Absence of a found rule is not proof of absence, particularly for defence, where instruments are often not published.
The soles to dollars conversions used in this record.
Converted at roughly 3.5 soles to the dollar for readability. The tax unit value of S/ 5,500 for 2026 is official; the exchange rate is not.
Whether the Digital Government Secretariat has now published the national digital security incident classification and the notification deadlines for below-critical incidents.
Due within 90 to 120 working days of the November 2025 Regulation, which would place them in 2026, but no published version was located. Until then only the 48-hour critical-incident deadline is certain.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 90 days. Next check due 17 November 2026.
Put this next to another country
Peru versus
Compare