What Is Peru’s Data Protection Law and Who Must Comply With It?

Share:
Learn how Peru's Law No. 29733 and its 2025 regulation set consent, security, and breach rules for any organization processing personal data of people in Peru.

Peru’s data protection framework has specific requirements that organizations cannot assume are covered by GDPR compliance. These include personal data bank registration, written consent requirements for certain financial and sensitive data, and specific breach obligations.

For companies expanding into Peru, understanding the country’s distinct privacy requirements early can help identify compliance gaps, avoid regulatory issues, and prevent delays during market entry.

What Is Data Protection Law in Peru?

Peru’s Data Protection Law is Law No. 29733, known as the Personal Data Protection Law, enacted in 2011 and amended by Legislative Decree No. 1353 in 2017. The law sets out the principles, obligations, and rights that govern how personal data is collected, stored, and used in Peru. A new implementing regulation, Supreme Decree No. 016-2024-JUS, took effect on March 30, 2025, and replaced the older 2013 regulation. This update added obligations around artificial intelligence, e-commerce, data protection officers, and mandatory breach notification, bringing Peru’s framework closer to global privacy standards.

Who Must Comply With Peru’s Data Protection Law?

Any public or private entity that holds or processes a personal data bank connected to Peru must comply with Law No. 29733. This includes Peruvian companies, government agencies, and foreign organizations that collect or process the personal data of individuals located in Peru, such as through e-commerce platforms, mobile apps, or digital services offered into the country. The law does not exempt a company simply because its servers or headquarters sit outside Peru. If the data belongs to a person in Peru and the organization determines how that data is used, compliance obligations apply.

What Are The Core Principles Behind The Law?

The law is built on principles that every data controller and processor must follow, including legality, consent, purpose limitation, proportionality, data quality, security, and confidentiality. Personal data cannot be collected through fraudulent or unfair means, and it must be used only for the purpose disclosed at collection. Consent must be prior, informed, express, and unequivocal, and processing sensitive categories such as health, biometric, genetic, or union membership data requires written consent. These principles apply equally to public agencies and private companies operating in Peru.

What Rights Does The Law Give To Data Subjects?

Individuals in Peru hold rights of access, rectification, cancellation, and opposition over their personal data, often called ARCO rights together. A person can ask an organization what data it holds about them, request corrections to inaccurate records, ask for deletion when data is no longer needed, and object to specific processing activities. Organizations must also inform individuals, before collection, about the purpose of processing, the identity of the controller, and how long the data will be retained.

four-key-rights-under-data-privacy

When Must Organizations Appoint A Data Protection Officer?

Peru’s new regulation requires many data controllers and processors to appoint a Data Protection Officer, with the deadline depending on company size and annual revenue. Large companies with revenue above S/ 12.65 million had to comply by November 30, 2025. Medium companies face a November 30, 2026 deadline, small companies must comply by November 30, 2027, and micro businesses have until November 30, 2028. Public entities, organizations processing large volumes of personal data, and those whose core business involves sensitive data must appoint a DPO regardless of size. The DPO can sit inside the organization or be contracted externally, and the appointment must be reported to the authority within 15 business days.
For organizations that need to close this gap quickly, Ampcus Cyber’s DPO as a Service provides an experienced data protection officer without the cost of a full-time hire.

How Does Breach Notification Work Under The Law?

Organizations must notify Peru’s data protection authority within 48 hours of becoming aware of a security incident that exposes large volumes of data, involves sensitive personal data, or creates real risk to a person’s fundamental rights. Affected individuals must also be informed within the same 48-hour window, in clear and simple language, along with the steps the organization is taking to limit harm. If the incident occurs through a digital channel, it must also be reported to Peru’s National Center for Digital Security. Missing the deadline requires the organization to explain the delay and provide supporting evidence.

report-a-data-breach-with-48-hrs

What Penalties Apply For Non-Compliance?

Peru’s data protection authority applies a three-tier fine structure based on the severity of the violation.

  • Minor infringements carry fines roughly between S/ 2,750 and S/ 27,500.
  • Severe infringements range from S/ 27,500 to S/ 275,000.
  • Very severe infringements, such as processing sensitive data without consent, can reach S/ 550,000.

No fine can exceed 10% of the offending organization’s annual net revenue from the prior year, which caps exposure for smaller companies while still allowing significant penalties for large-scale violations. Beyond fines, the authority can issue corrective orders requiring a company to change how it collects, stores, or shares personal data.

How Does Peru’s Law Compare To GDPR And Other Regional Frameworks?

Peru’s law shares common ground with the EU’s GDPR and Brazil’s LGPD, including consent-based processing, data subject rights, breach notification, and DPO requirements. It differs in scope and enforcement mechanics. Peru does not hold an adequacy decision from the European Union, so transfers of EU personal data into Peru require added safeguards such as standard contractual clauses. Fine ceilings are also lower in absolute terms than GDPR’s, though the revenue-based cap keeps penalties proportionate. Companies operating across Latin America often find it more efficient to build one governance framework that maps to each country’s requirements instead of managing separate, siloed programs.

Organizations already managing frameworks like GDPR or Brazil’s LGPD can extend their existing data governance structure to cover Peru rather than starting from scratch, which shortens the compliance timeline considerably.

How Can Organizations Prepare For Compliance?

Preparation starts with an accurate map of where personal data lives, how it moves, and who touches it. Organizations should register applicable data banks with Peru’s National Registry, review consent language against the written consent standard for sensitive data, confirm whether the DPO threshold applies to them, and build an incident response plan that meets the 48-hour notification window. A Data Privacy Impact Assessment is a practical first step for finding gaps before a regulator or a customer does. Companies working with vendors that touch Peruvian data should extend third-party risk management practices to those relationships, since the law holds controllers accountable for how their processors handle personal data.

Healthcare, financial services, and other regulated sectors carry additional obligations that intersect with Peru’s privacy requirements, a pattern explored further in how privacy laws apply to healthcare organizations beyond HIPAA.

Peru’s regulatory timeline is moving fast, and the gap between what a company assumes and what the law actually requires is where most compliance failures start.

Talk to Ampcus Cyber about building a Peru-ready data protection program before a regulator, a customer, or a breach forces the conversation.

People Also Ask

Is Peru’s Data Protection Law similar to GDPR?

Who enforces Peru’s Data Protection Law?

Does a small business need a Data Protection Officer in Peru?

What counts as sensitive personal data under the law?

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

Contact Us
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.