Argentina's Congress is once again trying to replace a data protection law written before Facebook existed. On July 16, 2026, lawmakers in the Chamber of Deputies reintroduced Bill No. 3397-D-2026, reviving a comprehensive overhaul of Ley 25.326 that originated as a 2023 Executive Branch submission (Message 87/2023) built from a preliminary text drafted by the Agencia de Acceso a la Información Pública, or AAIP — Argentina's data protection authority (argentina.gob.ar). Among its most consequential provisions: any controller relying on "legitimate interest" as a legal basis for processing personal data would have to conduct — and be able to produce on AAIP request — a documented proportionality-and-reasonableness assessment.
A Genuinely Old Law
Ley 25.326 was enacted in 2000, making it over 25 years old and one of the last major Latin American data laws never substantially rewritten since the pre-smartphone era. The AAIP's own reform page describes the goal as updating a framework that predates cloud computing, adtech real-time bidding, and most of the AI-driven processing that now runs on personal data by default. The current bill isn't a new idea dropped into 2026 — it's the product of a genuine participatory process: the AAIP ran public consultations from September 12 to October 11, 2022 under Resolution 119/2022, drawing 173 submissions from 123 participants before the Executive Branch formally sent the text to Congress in 2023 (argentina.gob.ar). That the bill needed reintroduction in 2026 says less about the policy than about Argentina's turbulent legislative calendar — bills routinely lapse between sessions and get refiled by sympathetic deputies.
The Steelman for a Proportionality Test
The case for requiring documented justification isn't manufactured. "Legitimate interest" is, by design, the most elastic legal basis in any GDPR-style framework — it doesn't require the data subject's consent, only the controller's own judgment that its interest outweighs the individual's privacy expectations. Left undocumented, that judgment is unfalsifiable: a regulator investigating a complaint has no way to know whether a company actually weighed necessity and proportionality, or simply asserted "legitimate interest" as a label to avoid asking for consent. The EU's own supervisory body reached exactly this conclusion. The European Data Protection Board's Guidelines 1/2024 on Article 6(1)(f) GDPR, adopted in October 2024 after considering the CJEU's October 2024 ruling in Case C-621/22, formalized a three-part test — a lawful, clearly articulated purpose; genuine necessity; and a balancing exercise against the individual's rights — that controllers must be able to demonstrate, not merely assert (edpb.europa.eu). Argentina's bill is, structurally, importing that same accountability logic. For a country whose current law leans almost entirely on consent as the default lawful basis, adding a defensible legitimate-interest pathway — paired with a documentation duty — is a reasonable trade, not regulatory overreach on its face.
Where the Design Needs Discipline
The risk is in the execution, not the concept. "Documented" and "demonstrable on request" are doing a lot of work in the hook, and the bill's fate will turn on how AAIP regulations eventually define them. If the assessment obligation ends up requiring exhaustive, GDPR-grade Legitimate Interest Assessments for every processing purpose — including low-risk, low-volume uses by small and mid-size Argentine businesses that never touch sensitive categories of data — the compliance burden falls hardest on exactly the companies least equipped to absorb it, while well-resourced multinationals treat it as a rounding error. The EU learned this lesson gradually, through a decade of Article 29 Working Party and then EDPB guidance narrowing what a proportionate LIA actually requires case by case; Argentina would be wise to import that graduated, risk-tiered approach rather than a one-size-fits-all documentation mandate from day one.
The stakes are compounded by a parallel reform track. A related 2023 proposal (Article 77 of a companion bill) would replace the current fine ceiling — a modest ARS 100,000 — with a mechanism pegged to an inflation-indexed accounting unit capable of reaching roughly ARS 10 billion, with an alternative formula tying penalties to 2–4% of a violator's annual turnover, deliberately mirroring the GDPR's up to-4%-of-global-turnover ceiling (iapp.org). Pairing an ambiguously scoped documentation duty with fines of that magnitude raises the cost of getting the definition wrong substantially. Legal commentary on the broader reform push has already flagged that Argentina's 26-year-old law faces genuine pressure to modernize, with accountability and expanded controller obligations cited as the core gaps (diariojudicial.com).
The Sensible Path
None of this argues against the bill's core premise. A legitimate-interest basis without any accountability mechanism is not a real legal basis — it's a loophole with a Latin name. But Congress and the AAIP should write proportionality into the assessment requirement itself: light-touch, template-based documentation for routine, low-risk processing, with the fuller balancing exercise reserved for higher-risk or large-scale uses. Coupling that tiering with clear AAIP guidance — published before enforcement, not litigated case by case afterward — would let Argentina modernize Ley 25.326 without repeating the early years of GDPR confusion that turned every business into either an over-compliant paperwork shop or an under-compliant gamble. Broader legislative interest in the reform, including parallel bills from Deputy Pablo Carro and Senator Martín Doñate aiming to align Argentine law with GDPR and Brazil's LGPD, suggests the political will to get this right exists (iapp.org). The AAIP's implementing rules, not the bill's text alone, will determine whether this becomes proportionate accountability or a compliance tax on Argentina's digital economy.