TL;DR: Argentina’s data protection framework, Ley 25.326, predates both GDPR and CCPA by well over a decade, and it holds something neither of those frameworks has with each other: an active EU adequacy decision, reconfirmed by the European Commission as recently as January 2024, making Argentina the only Latin American jurisdiction with that status. But the law’s penalty structure has not kept pace with modern standards, and a genuine reform bill is currently moving through Argentina’s Congress that would bring it much closer to GDPR’s model. If your business operates across Argentina, the EU, and the US, understanding exactly where these three frameworks agree and where they genuinely diverge matters for how you structure compliance, not just for Argentina in isolation.
Quick overview: This guide compares Argentina’s Ley 25.326 against the GDPR and the CCPA across the dimensions that actually matter for a business operating across these jurisdictions: legal basis for processing, penalties, cross-border transfer rules, and what’s currently changing. For the broader question of what makes any contract enforceable in Argentina, our complete guide to contract enforceability in Argentina covers that separately.
Argentina’s starting point: an early, EU-aligned law
Argentina enacted Ley de Protección de los Datos Personales, Ley 25.326, in October 2000, regulated by Decreto 1558/2001, making it one of the earliest comprehensive data protection laws in Latin America, alongside Chile and Uruguay. It was deliberately modelled on the European legislative approach that predates even the GDPR, the EU’s 1995 Data Protection Directive, and Argentina’s Agencia de Acceso a la Información Pública, the AAIP, has enforced it ever since.
This early, EU-aligned design produced a genuinely significant result: in 2003, and reconfirmed by the European Commission as recently as January 2024, Argentina received an EU adequacy decision, meaning the European Commission has formally determined Argentina’s data protection standards are equivalent to the EU’s own. This makes Argentina the only country in Latin America with that status. Practically, it means personal data can generally flow from the EU to Argentina without the additional safeguards, standard contractual clauses, binding corporate rules, that GDPR requires for transfers to non-adequate countries. Neither the GDPR framework nor the CCPA framework has this kind of bilateral adequacy relationship with each other; adequacy is specifically an EU mechanism, and the US, notably, does not appear on Argentina’s own adequacy list either.
Legal basis for processing: consent-centric versus multiple grounds
This is one of the more meaningful structural differences. Ley 25.326, as currently written, relies on consent as its near-exclusive legal basis for processing personal data. GDPR, by contrast, recognises six separate lawful bases, consent, contractual necessity, legal obligation, vital interests, public interest, and legitimate interests, giving businesses considerably more flexibility to process data without needing to obtain explicit consent for every activity. CCPA takes a different approach again, built around an opt-out model for the sale or sharing of personal information rather than an upfront consent requirement for processing generally, reflecting its origins as a consumer-rights statute rather than a general processing framework.
Argentina’s current reform bill, discussed below, would specifically expand this, introducing six lawful bases of its own, closely mirroring GDPR’s structure and moving away from consent as the almost exclusive foundation.
Penalties: where Argentina currently lags, and what’s about to change
Under Ley 25.326 as it stands today, penalties for non-compliance are genuinely modest by current international standards, ranging from ARS 1,000 to ARS 100,000 depending on the severity classification the AAIP applies. Given currency depreciation, this cap is a small fraction of what GDPR or CCPA enforcement can impose. GDPR’s maximum penalty reaches the greater of €20 million or 4% of global annual turnover. CCPA imposes civil penalties per violation, and, distinctively among the three, grants consumers a private right of action for certain data breaches, a mechanism neither Ley 25.326 nor GDPR provides directly to individuals in the same form.
This gap is exactly what Argentina’s pending reform is designed to close. The most advanced current proposal, a 2026 bill that would repeal and replace Ley 25.326 entirely, proposes increasing the maximum penalty to as much as 1,000,000 units, expressed as 2% to 4% of global annual turnover, a figure explicitly modelled on GDPR’s own penalty structure. As of this guide’s writing, no reform bill has been enacted, and Ley 25.326 remains the governing law, but the direction is clear enough that businesses should not treat today’s modest penalty cap as a reliable indicator of tomorrow’s exposure.
What the pending reform would actually add
Beyond the expanded lawful-basis framework and higher penalties, Argentina’s most advanced reform proposal would introduce several requirements that currently have no equivalent under Ley 25.326, but do exist under GDPR: a mandatory Data Protection Officer for organisations processing sensitive data at scale or engaging in systematic profiling, a defined breach notification timeline, and a formal mechanism analogous to GDPR’s binding corporate rules, allowing multinational groups to establish approved intra-group transfer frameworks rather than negotiating transfers on an ad hoc basis. None of this exists as binding law yet, but the AAIP has already been signalling this direction through its guidance and enforcement priorities, which is itself worth factoring into how a growing business builds its compliance posture now rather than waiting for enactment.
The requirement foreign companies consistently miss
This is a genuinely practical point that catches foreign businesses off guard, and it has nothing to do with the pending reform, it’s already in force. Since AAIP Resolution 132/2018, any foreign data controller processing the personal data of Argentine residents must register its databases with the AAIP’s National Registry of Databases, the RNBD, even without any physical presence in Argentina. Ley 25.326 applies extraterritorially in this way, similar in spirit to how GDPR reaches non-EU companies targeting EU data subjects, and CCPA reaches out-of-state companies meeting its threshold tests for California consumers. A foreign company with Argentine customers or users, assuming its GDPR or CCPA compliance programme automatically covers Argentina, is a common and genuinely avoidable mistake.
A quick comparison
| Argentina (Ley 25.326) | GDPR | CCPA | |
|---|---|---|---|
| Core model | Consent-centric, reform pending to add multiple bases | Six lawful bases | Opt-out for sale/sharing |
| EU adequacy | Has EU adequacy status | N/A, is the EU standard | No EU adequacy |
| Current maximum penalty | ARS 100,000 (modest) | Greater of €20M or 4% of turnover | Civil penalties per violation, private right of action for breaches |
| DPO requirement | Not currently mandatory; proposed in reform | Mandatory in defined circumstances | Not required |
| Extraterritorial reach | Yes, RNBD registration required for foreign controllers | Yes, for entities targeting EU data subjects | Yes, based on revenue/data volume thresholds |
Frequently asked questions
Does Argentina have an adequacy decision with the European Union?
Yes. Argentina received an EU adequacy decision in 2003, reconfirmed by the European Commission as recently as January 2024, making it the only Latin American country with that status. This generally allows personal data to flow from the EU to Argentina without the additional transfer safeguards GDPR requires for non-adequate countries.
Do foreign companies need to register with Argentina’s data protection authority?
Yes, if they process personal data of Argentine residents. Since AAIP Resolution 132/2018, foreign data controllers must register their databases with the AAIP’s National Registry of Databases, the RNBD, even without any physical presence in Argentina.
Is Argentina’s data protection law about to change significantly?
A reform bill currently before Argentina’s Congress would repeal and replace Ley 25.326 entirely, introducing six lawful bases for processing similar to GDPR, a mandatory Data Protection Officer requirement, defined breach notification timelines, and a substantial increase in maximum penalties. As of this guide’s writing, no reform has been enacted, and the current law remains in force.
How do Argentina’s penalties for non-compliance compare to GDPR’s?
Significantly lower under current law. Ley 25.326 currently caps penalties at ARS 100,000, a modest figure compared to GDPR’s maximum of the greater of €20 million or 4% of global annual turnover. Argentina’s pending reform proposes raising its own maximum to a comparable 2% to 4% of global turnover.
If my business is already GDPR-compliant, does that cover Argentina automatically?
Not automatically. While Argentina’s framework shares GDPR’s underlying philosophy and the two hold an adequacy relationship, Ley 25.326 has its own distinct requirements, including the RNBD registration obligation for foreign controllers, and its own enforcement authority. GDPR compliance is a strong foundation, not a substitute for an Argentina-specific review.
This article is general information, not legal advice. Argentina’s data protection framework is currently under active legislative reform, and the specific provisions described here may change before or if any reform bill is enacted. For advice on your organisation’s specific compliance position, speak to a qualified lawyer.
Written by Prakhar Rai, Attorney. Connect on LinkedIn. Reviewed by María Laura Cristín,
If your business operates in Argentina, or handles the personal data of Argentine residents from abroad, our team can help you navigate Ley 25.326 alongside GDPR and CCPA compliance. Speak to our contract lawyers in Argentina, or get a legal opinion on your specific cross-border data position.






