Argentina Argentina AAIP data protection Ley 25326

Argentina's Revived Data Protection Bill Tightens Legitimate-Interest and Erasure Rules Beyond the 2023 Draft

Bill 3397-D-2026 reintroduces AAIP's GDPR-style overhaul of Ley 25.326 but narrows the erasure exceptions and stiffens the legitimate-interest test that businesses had lobbied to keep.

Argentina's Data Protection Reform, By the Numbers People of Internet Research · Argentina 2000 Year Ley 25.326 enacted Argentina's current data protectio… 2003 Year of EU adequacy status Argentina was the first Latin Amer… 173 Public submissions to AAIP draft The 2022 consultation behind the o… peopleofinternet.com
Argentina's Data Protection Reform, By… People of Internet Research · Argentina 2000 Year Ley 25.326 enacted 2003 Year of EU adequacy status 173 Public submissions to A… peopleofinternet.com

Key Takeaways

Argentina's 26-year-old data protection law is getting a third run at reform. On July 16, 2026, legislators reintroduced Bill 3397-D-2026 in the Chamber of Deputies, reviving the comprehensive rewrite of Ley 25.326 that the Executive Branch first sent to Congress as Message 87/2023 and that lapsed when it lost parliamentary status at the end of 2024. The new text is built on the same foundation — a project drafted by the Agencia de Acceso a la Información Pública (AAIP), Argentina's data protection authority, after a 2022 public consultation that drew 173 submissions from more than 120 participants (AAIP) — but with a meaningfully tighter compliance posture than the version that died in committee.

What Changed From 2023

The headline shift is in Article 6's treatment of "legitimate interest" as a lawful basis for processing personal data, a concept entirely absent from the current 2000-era law, which relies almost exclusively on consent. The 2026 bill keeps legitimate interest but conditions it on a documented, prior proportionality-and-reasonableness assessment that the controller must be able to produce for the AAIP on demand — not a self-certifying checkbox, but a file that has to survive a regulator's audit (Allende & Brea). The bill also strips out several of the 2023 draft's exceptions to the right of erasure — specifically the carve-outs that let a controller reject a deletion request by citing a third party's legitimate interest or ongoing research activity. Those exceptions survive in GDPR's Article 17(3); removing them from the Argentine text sets a narrower bar than the European model Argentina is nominally converging toward.

That convergence is the point. The bill imports GDPR-style architecture wholesale: proactive and demonstrable accountability, privacy by default and by design, data portability, and a right to object to fully automated decisions that produce legal or similarly significant effects — all new to Argentine law and modeled explicitly on the EU regime and Brazil's LGPD (AAIP).

The Case For Going This Far

The AAIP's own diagnosis has merit and deserves a fair hearing before dismissing the bill's stricter turn. Ley 25.326 was written for a world of static, registered databases; it has no breach-notification regime, no portability right, and no rule for automated decision-making, and the AAIP itself has described its enforcement model as reactive — dependent on individual complaints rather than proactive supervision (IAPP). Twenty-six years on, a law with no concept of profiling or algorithmic scoring is genuinely under-equipped for the platforms it's supposed to govern, and a documented legitimate-interest test is a defensible way to stop "legitimate interest" from becoming the loophole it has become in some GDPR practice — a catch-all invoked after the fact rather than assessed before processing begins.

Why the Narrower Draft Is the Wrong Fix

But removing the third-party and research exceptions to erasure, rather than simply requiring a proportionality test for legitimate interest, overcorrects. A controller processing data for bona fide research, or holding data because deleting it would concretely harm another identifiable person's own rights, is not the same case as a data broker resisting a deletion request for commercial convenience — yet the 2026 text no longer distinguishes them. The 2023 draft's exceptions existed precisely to handle that distinction; deleting them wholesale, rather than tightening the conditions under which they apply, trades a workable balance for a blunter one. GDPR itself kept a research exception for this reason. A law meant to bring Argentina into alignment with the European model should not be more restrictive than that model on the narrow point where Europe's own drafters chose nuance over a flat rule.

There is also a strategic asymmetry the bill's drafters have underweighted: Argentina has held a European Commission adequacy decision since June 30, 2003 — the first granted to any Latin American country, and reaffirmed as recently as the Commission's periodic review of standing adequacy findings under GDPR's four-year cycle (EUR-Lex, Decision 2003/490/EC). That status is valuable to Argentine exporters of data-processing services precisely because it lets EU personal data flow south without extra contractual safeguards. Modernizing Ley 25.326 to bring it closer to GDPR strengthens the case for keeping that status; over-tightening erasure rules beyond what GDPR itself requires does nothing to protect adequacy and only adds compliance friction that Brazil's LGPD — Argentina's regional competitor for data-processing investment — does not impose in the same form.

What to Watch

Bill 3397-D-2026 is not the only reform vehicle in play: deputies have also filed rival texts, including a 72-article rewrite from deputy Martín Yeza (Bill 1751-D-2026) that leans further toward a business-friendly "pro-responsible-innovation" interpretive principle (IAPP). Whichever text advances, the committee process is where the erasure-exception question should get revisited — restoring a narrower, better-defined third-party and research carve-out rather than the current all-or-nothing framing would keep the reform aligned with the EU standard it is chasing, without handing every deletion dispute to a case-by-case AAIP adjudication the agency's own reactive enforcement model is not resourced to handle at scale.

Sources & Citations

  1. AAIP: Proyecto de Ley de Protección de Datos Personales
  2. AAIP: Protección de Datos Personales overview
  3. EUR-Lex: Commission Decision 2003/490/EC (Argentina adequacy)
  4. Allende & Brea: reform bill reintroduced in Congress
  5. IAPP: nuevo proyecto de reforma del régimen de protección de datos