Argentina's Personal Data Protection Law, Ley 25.326, has now outlasted three attempts to replace it. A 2018 predecessor bill lost parliamentary status. The data protection authority's own draft, submitted to Congress by the Executive via Message 87/2023 after a year of public consultation that drew 173 submissions, followed it into the graveyard at the end of 2024 (AAIP, Argentina.gob.ar). Now there are three bills competing to be attempt number four — and for the first time, the fight isn't just about updating a 26-year-old statute. It's about whether Argentina regulates AI training data the way Brussels does, or the way it wants tech investment to.
Three bills, one dead ancestor
Deputy Pablo Carro's bill (1948-D-2025) and Senator Martín Doñate's bill (644-S-2025) both trace their DNA to the AAIP's lapsed draft, and both hew closely to the EU's General Data Protection Regulation: mandatory 72-hour breach notification to the regulator, fines reaching 2–5% of global annual turnover, and a Doñate-specific twist requiring Senate confirmation of the data protection authority's chief (Marval O'Farrell Mairal).
Deputy Martín Yeza's bill, filed April 22, 2026 as expediente 1751-D-2026, breaks from that template. It's a full repeal-and-replace: 72 articles across 13 titles, invoking comparative frameworks from South Korea, the UK and Singapore alongside the GDPR (Cámara de Diputados, official bill record). It caps fines at 1% of local annual revenue rather than global turnover, allows breach notification within a "reasonable time" rather than a fixed 72 hours, and tiers obligations by an organization's data-processing scale — basic, intermediate, advanced — with a lighter regime for startups (Marval O'Farrell Mairal).
The bill's most consequential move is procedural rather than punitive: it adds "legitimate interest" as a lawful basis for processing personal data, explicitly extending it to cover AI system training, subject to a balancing test against individual rights. It pairs that with a "pro-innovation interpretation principle" instructing regulators that ambiguity should be resolved toward permitting technologically viable practices rather than defaulting to restriction (IAPP, June 2, 2026). It also proposes regulatory sandboxes — time-limited, supervised authorizations letting AI pilot projects process personal data under relaxed rules while regulators observe outcomes before writing permanent ones.
The case for the GDPR-styled bills
Carro and Doñate's approach deserves a fair hearing before it gets a rebuttal. Argentina has held an EU adequacy decision since 2003 — the first Latin American country to earn one, reaffirmed after GDPR-era review in January 2024 (IAPP). That status lets Argentine firms move EU personal data across the Atlantic without the standard contractual clauses and transfer-impact assessments that non-adequate countries must layer on top of every contract — a genuine trade advantage for a services-exporting economy. A reform that visibly loosens consent requirements and lets "legitimate interest" swallow AI training risks inviting exactly the kind of adequacy review that cost the UK years of uncertainty post-Brexit. Fixed 72-hour breach notification and Senate confirmation of the regulator's chief are also defensible on their own terms: they harden institutional independence and give victims of a breach a predictable clock rather than a vague "reasonable time" a company can stretch indefinitely.
Why Yeza's approach is still the better bet
But the GDPR-replication bills import a design built for a 27-country trading bloc into a single mid-sized economy trying to attract AI investment against Brazil, Chile and Uruguay, all of which are simultaneously loosening their own regimes for exactly that reason. Global-turnover fines of up to 5% are a blunt instrument calibrated for Google and Meta; applied to an Argentine fintech startup with a single foreign investor, it's an existential threat scaled to the wrong company. Yeza's tiered obligations and startup carve-outs solve a real problem the Carro/Doñate bills ignore: a small legal department cannot run the same DPIA process as a multinational.
The sandbox provision is the strongest piece of the bill. Rather than legislating AI training rules by guesswork — freezing today's assumptions about model architectures into a statute that will look dated within two product cycles — a sandbox lets the AAIP watch real pilot projects and calibrate permanent rules against evidence. Chile, the UK's ICO and Singapore's PDPC have all run comparable sandboxes without triggering adequacy reviews or rights collapse, which undercuts the fear that Yeza's bill invites EU retaliation.
The honest risk is the "reasonable time" breach clause, which is vague enough to invite slow-walking and should be tightened to a fixed outer bound during committee markup — a specific, fixable defect rather than grounds to prefer a rewrite modeled on a bloc ten times Argentina's size. None of the three bills has cleared committee, and Argentina's history suggests a real chance this attempt also lapses. If it does, it will be because legislators spent another cycle importing a foreign template instead of writing rules for the economy actually in front of them.