A 26-year-old law meets a refiled bill
On July 16, 2026, Deputy Agustín Rossi filed Expediente 3397-D-2026 in Argentina's Chamber of Deputies, proposing to repeal Ley 25.326 (2000) and its 2008 amendment, Ley 26.343, and replace them with a comprehensive new data-protection statute. The bill is not new text: it reproduces, article for article, the bill the national executive sent to Congress in June 2023 as Mensaje 87/2023 — signed by then-President Alberto Fernández and then-Chief of Cabinet Rossi himself — which lapsed after failing to pass within Congress's parliamentary-status window (abogados.com.ar). The underlying draft came from the Agencia de Acceso a la Información Pública (AAIP), Argentina's privacy regulator, following a 2022 public consultation that drew 173 submissions from 123 participants (argentina.gob.ar/aaip).
The substance matters more than the recycling. Ley 25.326 is a consent-first statute: Article 5 makes processing unlawful "cuando el titular no hubiere prestado su consentimiento libre, expreso e informado," with narrow carve-outs for public sources, legal obligations, and contract necessity (Ley 25.326, Infoleg). The new bill replaces that single gate with six lawful bases: consent, state functions, legal obligation, performance of a contract, protection of vital interests, and — the consequential addition — legitimate interest, which requires a documented prior assessment before it can be invoked. AAIP stays the enforcer, but its bite changes dramatically: today's fines top out at 100,000 pesos, a ceiling inflation has reduced to near-irrelevance; the new regime runs from 5 up to 1,000,000 "unidades móviles" (indexed to CPI) or 2-4% of a company's annual global turnover, whichever framework applies (abogados.com.ar).
The steelman: consent erosion is a real risk
Privacy advocates have a legitimate objection to legitimate interest as a catch-all basis. In the EU, Article 6(1)(f) of the GDPR — the direct model for Argentina's new ground — is the most litigated and least predictable of the lawful bases, because the balancing test between a company's interest and a user's rights is inherently judgment-heavy and has taken years of case law to calibrate. Argentina's courts and AAIP have far less adjudicated experience with that balancing exercise than European regulators do. A regulator moving from bright-line consent to a discretionary standard, without years of enforcement precedent to anchor it, risks becoming exactly the loophole critics fear: a basis invoked by default for behavioral advertising, scoring, and data brokering that never asks users anything at all. That risk is real and shouldn't be waved away.
Why the trade is still worth making
But a pure-consent regime has its own well-documented failure mode: consent fatigue. Forcing every ordinary processing purpose — fraud prevention, network security, internal analytics, business-to-business servicing — through a consent click-through that users don't read produces theater, not control. That is precisely the gap the European Commission flagged when it completed its four-year review of Argentina's adequacy status on January 15, 2024: the Commission confirmed Argentina still meets EU adequacy standards, but explicitly recommended "enshrining in legislation the protections that have been developed at sub-legislative level," and pointed to Argentina's then-pending Data Protection Bill as the opportunity to do exactly that (European Commission, COM(2024) 7 final). Codifying legitimate interest with a mandatory, auditable assessment gives AAIP something to actually inspect — a paper trail — where today comparable processing sits in an undefined gray zone with no textual basis whatsoever.
The penalty redesign cuts the other way from "deregulation." A cap of 100,000 pesos is not deterrence for a multinational platform; a 4%-of-global-turnover exposure, modeled on the GDPR's own Article 83 formula, is. Local commentary has already flagged that today's fines are "bajas en comparación con estándares actuales" and that keeping pace with international standards is what preserves adequacy (Diario Judicial). Broader lawful bases paired with sharply higher enforcement stakes is a coherent modernization, not a giveaway — it mirrors what GDPR itself does.
The bill's real obstacle is procedural, not substantive
The more interesting story may be that Argentina keeps re-filing the same text without changing it. A bill that already lost parliamentary status once, reintroduced verbatim by an opposition deputy under a government that has not made data protection a legislative priority, faces long odds regardless of its merits. Adequacy is not at immediate risk — the Commission reaffirmed it in 2024 and merely flagged reform as an opportunity, not a condition — but every cycle this bill lapses without a vote is a cycle Argentina's 20-year-old statute keeps setting the actual compliance bar, fines and all.