• English
  • Español

Argentina Debates Increasing Fines for Infringing the Personal Data Protection Law The Current Penalty Regime in Argentina

Law No. 25,326, enacted in 2000, established a penalty regime empowering the enforcement authority (currently, the Access to Public Information Agency, or “AAIP”) to impose various types of penalties, including suspensions, fines, and the closure or cancellation of non-compliant databases. Fines were set at fixed amounts. Over the years, successive periods of inflation in Argentina have rendered these amounts largely symbolic, and they are now equivalent to a range between USD 0.66 and USD 66. This is well below the maximum fines applicable in neighboring countries, such as Brazil (USD 9,800,000), Uruguay (USD 82,000), Paraguay (USD 170,000), and Chile under its new law (USD 1,500,000).

This scenario may have discouraged many organizations from developing privacy programs, since the cost of the maximum fine would be substantially lower than the cost of implementing such a program. Several legislative proposals to reform the Law have contemplated higher penalties. The most recent bill submitted by the Executive Branch, in 2023, proposed fines of up to 4% of the annual turnover generated in Argentina by the organization responsible for the infringement. Meanwhile, a recent draft prepared by the Executive Branch would establish fines of up to 3% of that turnover.

However, consensus for an integral reform has not yet been reached. Against this backdrop, the AAIP has sought alternatives to address the significant disparity between high compliance costs and the low cost of facing a penalty.

In 2023, for example, together with the Anti-Corruption Office, the authority implemented the Personal Data Protection Module of the Registry of Integrity and Transparency for Companies and Entities (RITE). This innovative tool was designed to help organizations conduct self-assessments and align their internal operations with privacy regulations and best practices, thereby reducing compliance costs. The AAIP also issued internal resolutions to classify infringements by severity and regulate the aggregation of fines when conduct subject to penalties occurs within the same proceeding. The current rules governing the aggregation of fines were designed for investigations by the authority involving proceedings in which an organization faces a large number of individual complaints, provided that the cases can proceed concurrently because they are at the same investigation stage. In such cases, aggregated fines may reach a maximum of approximately USD 33,000.

The Reform Proposed under the 2027 Budget Bill Discussion

On September 15, 2026, the Executive Branch submitted to the National Congress the General Budget Bill for Fiscal Year 2027. The bill includes an amendment to the current privacy penalty regime through the creation of a “mobile unit” valued at approximately USD 13. The bill provides that fines for infringing the Personal Data Protection Law could range from five to one million mobile units, amounting to approximately USD 13,000,000. If the current criteria for assessing fines were maintained, this cap would be reserved for “very serious” transgressions. The most serious infringements include deliberate acts or omissions intended to obstruct the exercise of the rights of access, rectification, or deletion; the collection of personal data through deception or fraudulent means; and the processing of sensitive data without a valid lawful basis. The highest penalty tier would also apply to the unlawful transfer or disclosure of data to third parties, as well as to international data transfers to countries or jurisdictions that do not provide an adequate level of protection without the safeguards required by law.

If enacted, Argentina would have the highest maximum fine among MERCOSUR countries, surpassing Brazil, which currently leads the bloc. Argentina would also move closer to the maximum fines under the European General Data Protection Regulation, although without adopting fines calculated as a percentage of the organization’s turnover, a mechanism that was also contemplated in the domestic legislative proposals mentioned above. In addition, a mobile unit adjusted annually for inflation would prevent the real value of fines from eroding again, as occurred under the current regime.

Higher penalties could also strengthen the AAIP’s operations, as the Personal Data Protection Law’s Regulatory Decree provides that amounts collected through fines are to be used to finance the authority. This could increase AAIP’s budget and, in turn, its human and technological resources and enforcement capacity.

If the bill is approved, the increase in fines would require particularly rigorous application of the principles of proportionality and reasonableness when these penalties are imposed. The bill delegates to the enforcement authority the power to establish the conditions and procedures for determining penalties, while requiring that they be assessed based on the severity and scope of the violation and the direct and indirect harm arising from it. The enforcement authority’s current resolutions already include, among the factors to be considered when assessing a penalty, the nature of the harm caused, the economic benefit obtained by the organization, previous infringements, and the organization’s financial condition.

The bill does not amend any other aspects of the Personal Data Protection Law, leaving Argentina’s regulatory framework outside the region’s current trend. For example, Argentina still lacks legitimate interest as a legal basis for processing personal data, mandatory notifications of personal data breaches to subjects, mandatory designation of Data Protection Officers in certain cases, or privacy impact assessments. In comparison, other regulatory modernization processes in the region have addressed organizations’ obligations and the penalty framework simultaneously. These reforms have generally included transition periods before the new rules enter into force, facilitating gradual adaptation by organizations.

Although the government’s proposal does not update the substantive aspects of the Law or expressly introduce new obligations for companies, the AAIP’s current criteria for assessing penalties already take into account the adoption of measures, mechanisms, and internal procedures capable of minimizing the impact of harm caused to data subjects. Accordingly, if the legislative proposal is enacted, privacy programs are expected to become a central component of any organization’s risk management. In this new context, accountability will be a critical element of any defense strategy in potential enforcement proceedings.