Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
Latin AmericaMEDIUM coverage1 enforcement action

Peru Personal Data Protection Law No. 29733: AI Compliance Requirements

Peru's PDPL (Law No. 29733) is now implemented by DS 016-2024-JUS (published Nov 30, 2024, effective March 30, 2025), which entirely replaced the 2013 implementing decree with a 135-article modernized framework — including a mandatory Data Protection Officer duty (public entities and large-scale/sensitive-data processors), 48-hour breach notification, expanded data-subject rights (including portability, effective Sept 30, 2025, and search-engine de-indexing), explicit extraterritorial reach, and cookies/location data as personal data. Peru's National AI Strategy (DS 009-2021-PCM) sits alongside this data-protection regime. The ANPD (Autoridad Nacional de Protección de Datos Personales) enforces; data subjects have a right to contest automated decisions.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

July 3, 2013

Maximum Penalty

UIT-indexed tiers (2026 UIT = S/5,500): Minor 0.5-5 UIT (S/2,750-27,500), Serious 5-50 UIT (S/27,500-275,000), Very Serious 50-100 UIT (S/275,000-550,000, ~$148,000 USD) — capped at 10% of the offending entity's prior-year annual net revenue, whichever is lower.

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Data Protection Officer + 48-Hour Breach Notification (DS 016-2024-JUS)

High Priority

Appoint a Data Protection Officer if a public entity, or if processing sensitive personal data at scale (relevant to most AI systems trained on or inferring sensitive attributes). Notify ANPD and affected individuals within 48 hours of a breach involving large data volumes or sensitive information.

Deadline: March 30, 2025

DS 016-2024-JUS (effective 2025-03-30)

Register AI Data Processing with Peru ANPD

Medium Priority

AI systems collecting or analyzing Peruvian personal data must be registered with ANPD's personal-data-bank registry. Document legal basis and data subject rights implementation.

Peru PDPL (Law No. 29733), implemented by DS 016-2024-JUS

Who Does This Apply To?

Applies to: any public or private entity that processes the personal data of individuals in Peru, or that processes through means located in Peru, under the Personal Data Protection Law No. 29733 as implemented by DS 016-2024-JUS (effective 2025-03-30, replacing the 2013 implementing decree in full) — including explicit extraterritorial reach over foreign companies targeting Peruvian residents. The substantive duties apply regardless of company size; entities must also register their personal-data banks with the National Authority for Personal Data Protection (ANPD). AI-relevant obligations: a lawful basis and prior, informed, express consent (heightened for sensitive data); data-subject rights, including the right to contest decisions based solely on automated processing that significantly affect the individual, portability (effective 2025-09-30), and search-engine de-indexing; a mandatory DPO for public entities and large-scale/sensitive-data processors; 48-hour breach notification; security measures proportionate to risk; and cross-border-transfer safeguards. Peru's National AI Strategy (DS 009-2021-PCM) sits alongside the data-protection regime. Enforced by the ANPD; fines are UIT-indexed, up to 100 UIT for very serious violations, capped at 10% of annual net revenue.

Recent Enforcement Actions

Autoridad Nacional de Protección de Datos Personales (ANPD), Ministerio de Justicia2025-01Source verified· as of 2026-08-22

Against: Banco de Crédito del Perú (BCP)

Source

Recent Regulatory Guidance

guidance2024-11-30

Peru DS 016-2024-JUS — New PDPL implementing regulation (published Nov 30, 2024, effective March 30, 2025)

Supreme Decree DS 016-2024-JUS entirely replaced Peru's 2013 PDPL implementing decree with a 135-article modernized framework: mandatory Data Protection Officer for public entities and large-scale/sensitive-data processors; 48-hour breach notification to ANPD and affected individuals; expanded data-subject rights including portability (effective Sept 30, 2025) and search-engine de-indexing; explicit extraterritorial reach over foreign companies targeting Peruvian residents; and cookies/location data expressly treated as personal data.

guidance2023-08

ANPD Peru — Guidelines on AI Automated Decision-Making under PDPL No. 29733 (2023)

Peru's ANPD published guidance on applying PDPL No. 29733 to AI automated decisions: all AI databases containing Peruvian personal data must be registered with ANPD; data subjects have the right to contest automated decisions and request human review; Peru's National AI Strategy (DS 009-2021-PCM) establishes principles of transparency and human oversight that inform ANPD enforcement; organizations processing Peruvian data in AI systems must document legal basis and implement data subject rights mechanisms. (Superseded in substantial part by DS 016-2024-JUS, above — kept for historical context.)

Frequently Asked Questions

Does Peru Personal Data Protection Law No. 29733 apply to my business?

Peru's PDPL (Law No. 29733) is now implemented by DS 016-2024-JUS (published Nov 30, 2024, effective March 30, 2025), which entirely replaced the 2013 implementing decree with a 135-article modernized framework — including a mandatory Data… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Peru Personal Data Protection Law No. 29733 is: UIT-indexed tiers (2026 UIT = S/5,500): Minor 0.5-5 UIT (S/2,750-27,500), Serious 5-50 UIT (S/27,500-275,000), Very Serious 50-100 UIT (S/275,000-550,000, ~$148,000 USD) — capped at 10% of the offending entity's prior-year annual net revenue, whichever is lower.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Peru Personal Data Protection Law No. 29733?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.gob.pe/andis

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan