ARTICLE

Personal Data Protection: new system of infringements and sanctions

On November 8, 2005 the Argentine Direction of Protection of Personal Data enacted Executive Order No 7/05, which approves a new system for the classification of infringements and the ranking of sanctions applicable for violations to Law No 25,326 on Personal Data Protection.
November 30, 2005
Personal Data Protection: new system of infringements and sanctions

The order, published in the Official Gazette on November 11, 2005, (i) revokes previous Executive Order No 1/2003 which ruled the current infringements and sanctions system, (ii) approves the new classification of infringements and the corresponding sanctions, and (iii) establishes a Registry of Offenders to the Law No 25,326 on Personal Data Protection (the “Law”).

Regarding the different classes of infringements, the Argentine Direction of Protection of Personal Data (“DPPD”) added new classes to the ones established by the previous norm. Nevertheless, this new classification cannot be considered a strict description of the infractions, as the DPPD may consider other conducts as infringements to the Law as well. With respect to the sanctions, the order includes the sanctions already stated by the Law: warning, suspension, shut down or cancellation of the database, as well as fines.

In particular, the following actions are considered minor infringements:

a) to ignore requests for access, rectification or removal of personal data when it is legally required;

b) not to provide the information requested by the DPPD when exercising its duties;

c) not to register a database when there is a legal requirement to do so;

d) to collect personal data without providing the owner with the information required by the Law or without their free, express and informed consent, whenrequired;

e) not to fulfill the legal duty of secret set forth in Section 10 of the Law, unless it constitutes a more serious infringement or the criminal offense of Section 157 bis, # 2 of the Criminal Code;

f) not to observe the principle of free processing set forth in Section 19 of the Law;

g) to maintain for a period longer than allowed significant personal data to evaluate the economic and financial situation of its owners;

h) to handle, regarding credit information services, personal data that exceeds the information related to the economic reliability of its owner;

i) to handle, regarding marketing information services, personal data exceeding that which is necessary to establish consumer profiles;

j) not to cease in the illegitimate use of personal data when its owner requires so;

k) to handle uncertain, inadequate, irrelevant or excessive personal data in relation with the field and purpose for which they have been obtained.

Small infringements are sanctioned with up to two warnings and/or $ 1,000 to $ 3,000 fines.

The following actions configure major infringements:

a) to handle personal data illegitimately or ignore legal principles and rights.

b) to impede or hinder the exercise of the right of the owner to access their personal data or to refuse to provide the information the owner requests;

c) to keep inaccurate personal data or not to correct, update or remove such data when it has been legally required by the DPPD;

d) to infringe the duty of confidentiality set forth in Section 10 of the Law regarding personal data incorporated to registers, banks or databases;

e) to keep local databases, software or hardware containing personal data without the security conditions established by law;

f) to impede an inspection and control of duties in charge of the DPPD;

g) not to register the personal data database in the corresponding register, when the DPPD has required to do so;

h) not to cease in the illegitimate use of personal data when required by the DPPD;

i) to collect personal data by deception.

Major infringements are sanctioned with up to four warnings, suspension and/or $ 3,001 to $ 50,000 fines.

The following activities constitute extreme infringements:

a) to create a database with a purpose opposed to law or public morals;

b) to transfer personal data of any kind to countries or international or supranational organizations which do not provide an adequate protection level, except for legal exceptions;

c) to illegitimately hand over personal data beyond the cases in which it is permitted;

d) to collect and handle sensitive data when there is no public interest authorized by law or to handle them with statistical or scientific purposes without dissociating the sensitive data;

e) to create files, banks or registers keeping information that directly or indirectly reveals sensitive data, except for the cases specifically established by the Law;

f) to handle personal data illegitimately or ignore constitutional principles and rights, when this also hinders or attacks the exercise of fundamental rights;

g) to infringe the duty of keeping sensitive data secret, as well as personal data which has been obtained and handled for criminal purposes.

Extreme infringements are sanctioned with up to six warnings, 31 to 365 days of suspension, shut down or cancellation of the database and/or $ 50,001 to $ 100,000 fines.

The norm also establishes that after six warnings, this type of penalty cannot be applied again.

Sanctions established in this rule are applicable to owners and users of public and private databases, notwithstanding the administrative responsibilities that correspond to the owners or users of public databases, the responsibilities for damages derived from the failure to comply with the Law and the criminal penalties that arise.

Finally, relapsing is defined when an entity that has already been sanctioned for one of the infringements established in the Law and/or its regulation incurs a similar infringement within the term of three years, counted as from the application of the sanction.

© 2023 Marval O´Farrell Mairal. All Rights Reserved. Please do not copy.