Argentina data protection

A Río Negro Court Shows Argentina's 26-Year-Old Privacy Law Still Works — Its Fine Schedule Doesn't

A General Roca judge ordered BBVA Francés to erase a fraudulent $6M-peso debt, proving habeas data delivers relief even as AAIP's penalty caps stay frozen since 2000.

The General Roca Habeas Data Ruling People of Internet Research · Argentina $6M+ pesos Fraudulent debt registered Debt BBVA Francés reported under t… 5 business days Compliance deadline ordered Time the court gave BBVA to erase … 100,000 pesos AAIP maximum fine, since 2000 Statutory ceiling on data-protecti… 24 months Debtor registry lookback window How far back BCRA's Central de Deu… peopleofinternet.com
The General Roca Habeas Data Ruling People of Internet Research · Argentina $6M+ pesos Fraudulent debt registered 5 business days Compliance deadline ordered 100,000 pesos AAIP maximum fine, since 2000 24 months Debtor registry lookback window peopleofinternet.com

Key Takeaways

A phantom debtor, a working remedy

A civil court in General Roca, Río Negro, ruled on July 2, 2026 that Banco BBVA Francés must erase all records it held on a man who says he never opened an account there — and correct the false "debtor" status the bank had reported to the Banco Central de la República Argentina (BCRA). The man discovered the problem only when a routine credit-limit request at his real bank was rejected: a check of his own file showed BBVA Francés had registered him as holding active financial products and a debt exceeding 6 million pesos. The judge found the underlying account paperwork lacked his signature, concluded the data was not truthful, and ordered suppression of the records plus notice to the BCRA within five days — backed by a daily fine for every day of delay (BarilocheOpina; Bariloche2000).

This is habeas data doing exactly what Argentina's 1994 constitutional reform and its implementing Ley 25.326 (2000) designed it to do: give a private citizen a direct, judicially enforceable route to erase inaccurate personal data and force a correction upstream, at the systemic registry that actually determines his creditworthiness. The court declined to order Veraz, the private credit bureau, to correct its file — Veraz wasn't a party to the case — a reminder that habeas data relief is case-by-case, not systemic, and victims of the same fraud pattern have to litigate each downstream registry separately.

The steelman: a 2000-era fine schedule in a 2026 economy

Consumer advocates have a fair complaint here, and it predates this case. Ley 25.326 empowers Argentina's data protection authority, the Agencia de Acceso a la Información Pública (AAIP), to fine violators — but the statutory range is 1,000 to 100,000 pesos (Ley 25.326, via Argentina.gob.ar), unchanged since the law's enactment. After 26 years of Argentine inflation, a 100,000-peso ceiling is not a deterrent to an institution the size of BBVA Francés; it's a rounding error. A 2023 bill to modernize the law — including GDPR-style penalties pegged to a violator's revenue — lost parliamentary status in 2025, and the AAIP says it is now running a fresh public-private drafting process before sending Congress another version. Meanwhile the agency's own enforcement toolkit hasn't kept pace with the harm a single bad data entry can do to someone's ability to borrow, rent, or get hired.

That's a real gap, and it's worth stating plainly before arguing against overcorrecting for it: a regulator whose maximum fine is functionally symbolic has weaker leverage over repeat offenders than one whose penalties scale with the violation.

Why the fix is the fine schedule, not the framework

But the General Roca ruling actually undercuts the case for a wholesale legislative overhaul, because it shows the remedy that matters most to an individual victim — erasure, correction at the systemic registry, and a coercive daily fine for noncompliance — already exists, and a court used it in a matter of months without waiting for Congress. BCRA's own consumer-facing process for disputing Central de Deudores entries runs on the same legal foundation, letting anyone file a rectification claim against a reporting bank and escalate to the central bank itself if unsatisfied (BCRA, Situación crediticia: acceso y rectificación). The architecture works. What failed here was upstream — a bank that let an account get opened without a genuine signature — not the remedy.

Argentina's fintech and open-banking sector, still recovering account-to-account payment volumes after years of capital controls and currency instability, doesn't need a GDPR-scale compliance regime bolted on overnight; that would raise fixed costs disproportionately for the smaller lenders and payment platforms competing against incumbent banks like BBVA, without doing much for a fraud victim whose real problem is a five-day wait and a coercive fine measured in pesos that erode by the week. The proportionate fix is narrower: index the AAIP's fine ceiling to inflation (or peg it to a percentage of the violating entity's revenue, as the failed 2023 bill proposed, reserved for the AAIP's own enforcement track rather than every habeas data suit), and require the BCRA to accept and act on a court-ordered correction the moment it's filed rather than waiting for the next monthly Central de Deudores publication cycle — the same page that tells consumers to simply "wait for the next update" even after a court has already ruled.

The broader signal

For a publication that covers financial-data governance across emerging markets, the takeaway isn't that Argentina needs European-style data law. It's that a judiciary willing to move fast on individual habeas data claims, paired with a regulator whose penalties actually bite, gets most of the deterrent value without the compliance drag of a rules rewrite. Río Negro's court did its part in five days. The AAIP's fine schedule is the piece still stuck in 2000.

Sources & Citations

  1. BarilocheOpina: court ruling report
  2. Bariloche2000: court ruling report
  3. Ley 25.326 (Habeas Data), Argentina.gob.ar
  4. BCRA: credit record access and rectification
  5. AAIP: sanctions under Ley 25.326