ARTICLE

New Bill to Replace the Data Protection Law

Representative Rossi reintroduced a data protection bill that would expand privacy rights, impose new compliance duties, and extend the law's reach abroad.

August 27, 2026
New Bill to Replace the Data Protection Law

On July 16, 2026, Representative Agustin Rossi reintroduced a personal data protection bill after the original proposal lost parliamentary status earlier this year. The bill, originally drafted by the Argentine Agency for Access to Public Information (AAIP), had been introduced in 2023 during Rossi’s tenure as Chief of Staff.

The most significant changes in the bill include substantially expanding the territorial scope of the Argentine Data Protection Law, making it applicable not only to controllers and processors located in Argentina, but also to those located abroad that process personal data in Argentina through physical or electronic means, offer goods or services to individuals in Argentina or carry out profiling or monitoring activities in connection with such individuals’ behaviors, or operate in jurisdictions where Argentine law applies by virtue of international law or contractual agreements.
 

The proposal also introduces several substantive changes aimed at modernizing Argentina’s privacy regime and aligning it more closely with international standards. Accordingly, it would:

  • Expand data subjects’ rights by introducing the right to data portability, the right to object to certain types of processing conducted without consent, and the right to restrict processing under specific circumstances.
  • Broaden the definition of sensitive data to include additional protected categories such as political opinions, gender identity, and genetic and biometric data.
  • Strengthen protections against automated decision-making and profiling by granting individuals the right not to be subject to decisions based wholly or partially on automated processing when those decisions produce legal effects, significantly affect their interests, or result in discriminatory outcomes. Individuals would also have the right to obtain meaningful human review of such decisions.
  • Recognize legitimate interests as a lawful basis for processing, subject to a balancing test and a documented assessment demonstrating that the controller’s interests do not outweigh the rights and freedoms of the data subject.
  • Introduce mandatory data breach notification regime, requiring controllers to notify the supervisory authority within 72 hours of becoming aware of a security incident.
  • Expand transparency obligations by requiring controllers to disclose—among other things—the legal basis for processing, applicable retention periods, international data transfers, recipients of personal data, automated decision-making practices, and the rights available to data subjects.
  • Strengthen accountability obligations by requiring public authorities and organizations engaged in large-scale or systematic monitoring of individuals to appoint a Data Protection Officer (DPO).
     

Taken together, these reforms would represent a significant modernization of Argentina's data protection framework. If enacted, it would bring Argentina's legislation closer to international standards, while introducing new tools to address the challenges arising from artificial intelligence, cross-border data processing, and the concentration of personal data in the hands of a small number of multinational corporations.