Argentina — Personal Data Protection Act (Law 25,326): AI Compliance Requirements
Argentina's Personal Data Protection Act (Law 25,326) has been in force since 2001 and is enforced by the AAIP. Argentina has EU adequacy status. The law applies to any organization processing personal data of Argentine residents, including through AI automated decision systems. Argentine courts have applied Law 25,326 to AI credit scoring and profiling. A new AI regulatory framework is under development through Argentina's National AI Plan (2023).
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
January 1, 2001
January 1, 2001
ARS 1,000–100,000 per violation (approx. USD $1,000–$100,000) — enforced by AAIP; criminal penalties may also apply
What Your Business Must Do
3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Register AI Databases with AAIP
High PriorityArgentina Law 25,326 requires registration of personal data databases (including AI training datasets and profiling systems) with the AAIP at aaip.gob.ar. Register any database used by AI that contains personal data of Argentine residents.
Deadline: January 1, 2001
Law 25,326Automated Decision Transparency (Art. 20)
High PriorityArgentina Law 25,326 Art. 20 prohibits significant decisions based solely on automated AI processing without human involvement. AI systems making consequential decisions (credit, employment, insurance, access to services) must: (1) disclose the automated nature, (2) provide the logic used, (3) allow individuals to contest and request human review.
Deadline: January 1, 2001
Law 25,326 Art. 20Monitor Argentine AI Regulation
Medium PriorityAs of 2026 Argentina has NOT enacted a dedicated AI law; it relies on its existing Personal Data Protection Act (Law 25,326) plus soft-law instruments — chiefly AAIP Resolution 161/23 (the nonbinding "Transparency and Protection of Personal Data in the use of AI" program, 4 Sep 2023). Several AI bills are pending in Congress, including: Bill 3003-D-2024 ("Régimen jurídico aplicable para el uso responsable de la Inteligencia Artificial") — a four-tier risk-classification framework (unacceptable/high/medium/low risk) that would create a national public registry for high- and medium-risk AI systems administered by INTI, require mandatory human-rights impact assessments before deployment, and give the regulator audit powers (request documentation, order independent testing); and Bill 4243-D-2025 (introduced 2025-08-07), a narrower AI-specific personal-data-protection bill (extraterritorial reach, 180-day compliance grace period for AI systems already operating when enacted, effective 30 days post-publication) — distinct in scope from 3003-D-2024, not a registry/audit bill. Neither has been enacted and no economy-wide framework has been adopted. Monitor AAIP (aaip.gob.ar) and the Argentine Congress (hcdn.gob.ar). [R169 CORRECTION 2026-06-08: web-verified — replaced the stale "new AI-specific legislation expected in 2025-2026" prediction with the verified no-dedicated-law status. Sources: Global Legal Insights AI Laws 2026 — Argentina; IAPP on AAIP Res. 161/23.] [CYCLE 19 CORRECTION 2026-08-22: fresh WebSearch found the registry/risk-assessment/audit-powers description had been attached to the WRONG bill — it belongs to 3003-D-2024 (confirmed via regulations.ai's detailed breakdown: INTI registry, mandatory Human-Rights Impact Assessments, audit powers, four-tier risk classification, Argentinos-Oro-denominated fines), not 4243-D-2025 (confirmed via Digital Policy Alert and the bill's own HCDN text to be a narrower AI-specific personal-data-protection bill with a 180-day compliance grace period, unrelated to registries or audits). This is the "two real, unrelated events merged into one false compound claim" bug shape — here two real, contemporaneous 2024/2025 Argentine AI bills, not two news events.]
Who Does This Apply To?
Applies to any organisation that processes the personal data of individuals in Argentina, including through AI automated-decision and profiling systems, under the Personal Data Protection Act (Law 25,326, in force since 2001) — Argentina holds EU adequacy status, and the law reaches controllers regardless of size or location wherever Argentine residents' data is processed. Core duties: register personal-data databases (including AI training datasets and profiling systems) with the data-protection authority (AAIP); and, under Art. 20, do not make significant decisions about a person based solely on automated processing without human involvement — AI systems making consequential decisions (credit, employment, insurance, access to services) must disclose the automated nature, provide the logic used, and allow the individual to contest and obtain human review. Enforced by the Agencia de Acceso a la Información Pública (AAIP), with administrative fines and possible criminal penalties. STATUS NOTE: three bills to replace Law 25,326 (including 644-S-2025 and 1948-D-2025) are pending in the Argentine Congress as of 2026 and would add explicit anonymisation, biometric, profiling and automated-decision rules — none is yet enacted, so Law 25,326 remains the governing statute.
Recent Enforcement Actions
Recent Regulatory Guidance
AAIP — Guidance on AI and Automated Decision-Making under Law 25,326 (2023)
AAIP published guidance applying Argentina's Personal Data Protection Act to AI automated decisions: Art. 20 prohibits significant decisions (credit, employment, insurance, access to services) based solely on automated processing without human involvement; all AI databases containing Argentine personal data must be registered with AAIP; AI profiling systems must provide individuals the logic of automated decisions and the right to contest them. [R169 update 2026-06-08: as of 2026 no dedicated AI statute has been enacted in Argentina; several AI bills (e.g. Bill 3003-D-2024 — national AI registry/risk assessments/audit powers; Bill 4243-D-2025 — narrower AI-specific data-protection bill) remain pending in Congress — verified, not yet law. CYCLE 19 (2026-08-22): corrected which bill carries the registry/risk-assessment/audit-powers content — see the requirement-level correction above for full sourcing.]
Frequently Asked Questions
Does Argentina — Personal Data Protection Act (Law 25,326) apply to my business?
Argentina's Personal Data Protection Act (Law 25,326) has been in force since 2001 and is enforced by the AAIP. Argentina has EU adequacy status. The law applies to any organization processing personal data of Argentine residents, including through… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Argentina — Personal Data Protection Act (Law 25,326) is: ARS 1,000–100,000 per violation (approx. USD $1,000–$100,000) — enforced by AAIP; criminal penalties may also apply. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Argentina — Personal Data Protection Act (Law 25,326)?
The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.aaip.gob.ar/proteccion-de-datos-personales/Last updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan