Editora Perú
Personal Data Protection Law
Law No. 29733
REGULATIONS OF LAW NO. 29733,
PERSONAL DATA PROTECTION LAW
Supreme Decree No. 003-2013-JUS
LEGAL NORMS
UPDATED
2 LEGAL NORMS updated
PERSONAL DATA PROTECTION LAW
LAW NO. 29733
THE PRESIDENT OF THE REPUBLIC
WHEREAS:
The Congress of the Republic
has enacted the following Law:
THE CONGRESS OF THE REPUBLIC;
Has enacted the following Law:
PERSONAL DATA PROTECTION LAW
Preliminary Title: General Provisions.
Title I: Guiding Principles.
Title II: Processing of personal data.
Title III: Rights of the data subject.
Title IV: Obligations of the data controller and the data processor.
Title V: Personal data banks.
Title VI: National Authority for the Protection of Personal Data.
Title VII: Infractions and administrative sanctions.
Final complementary provisions
PRELIMINARY TITLE
GENERAL PROVISIONS
Article 1. Object of the Law
This Law aims to guarantee the fundamental right to the protection of personal data, provided for in Article 2, numeral 6 of the Political Constitution of Peru, through its proper processing, within a framework of respect for the other fundamental rights recognized therein.
"Article 2. Definitions
For all purposes of this Law, the following are understood:
- Personal data bank. Organized set of personal data, automated or not, regardless of the medium, whether physical, magnetic, digital, optical or others that are created, regardless of the form or modality of its creation, formation, storage, organization and access.
- Private administration personal data bank. Personal data bank whose ownership belongs to a natural person or a private law legal entity, insofar as the bank is not strictly linked to the exercise of public law powers.
- Public administration personal data bank. Personal data bank whose ownership belongs to a public entity.
- Personal data. Any information about a natural person that identifies them or makes them identifiable through means that can reasonably be used.
- Sensitive data. Personal data consisting of biometric data that by themselves can identify the holder; data referring to racial and ethnic origin; economic income; opinions or political, religious, philosophical or moral convictions; union affiliation; and information related to health or sexual life.
- Days. Business days.
- Data processing agent. Any natural person, private law legal entity or public entity that alone or acting jointly with another performs the processing of personal data on behalf of the holder of the personal data bank by virtue of a legal relationship that links them to the same and delimits the scope of their action. Includes those who perform the processing without the existence of a personal data bank.
- Processing mandate. Delivery by the holder of the personal data bank to a data processing agent by virtue of a legal relationship that links them. Such legal relationship delimits the scope of action of the data processing agent.
- Public entity. Entity included in Article I of the Preliminary Title of Law 27444, General Administrative Procedure Law, or the one that replaces it.
- Cross-border flow of personal data. International transfer of personal data to a recipient located in a country different from the country of origin of the personal data, regardless of the medium in which they are located, the means by which the transfer was carried out nor the treatment they receive.
- Sources accessible to the public. Personal data banks of public or private administration, which can be consulted by any person, prior to payment of the corresponding consideration, if applicable. Sources accessible to the public are determined in the regulations.
- Sufficient level of protection for personal data. Level of protection that covers at least the recording and respect of the guiding principles of this Law, as well as appropriate technical security and confidentiality measures, according to the category of data involved.
- Private law legal entity. For the purposes of this Law, the legal entity not included in the scope of Article I of the Preliminary Title of Law 27444, General Administrative Procedure Law.
- Anonymization procedure. Processing of personal data that prevents identification or makes the holder unidentifiable. The procedure is irreversible.
LEGAL NORMS updated 3
15. Disassociation procedure. Processing of personal data that prevents identification or makes the holder unidentifiable. The procedure is reversible.
16. Data subject. Natural person to whom the personal data belongs.
17. Holder of the personal data bank. Natural person, private law legal entity or public entity that determines the purpose and content of the personal data bank, the processing of these and the security measures.
18. Transfer of personal data. Any transmission, supply or manifestation of personal data, of a national or international nature, to a private law legal entity, to a public entity or to a natural person other than the data subject.
19. Processing of personal data. Any technical operation or procedure, automated or not, that allows the collection, registration, organization, storage, conservation, elaboration, modification, extraction, consultation, use, blocking, suppression, communication by transfer or by dissemination or any other form of processing that facilitates access, correlation or interconnection of personal data".
(*) Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
"Article 3. Scope of application
This Law applies to personal data contained or intended to be contained in personal data banks of public and private administration, whose processing is carried out within the national territory. Sensitive data are subject to special protection.
The provisions of this Law do not apply to the following personal data:
- Those contained or intended to be contained in personal data banks created by natural persons for purposes exclusively related to their private or family life.
- Those contained or intended to be contained in public administration data banks, only insofar as their processing is necessary for the strict compliance with the competencies assigned by law to the respective public entities, for national defense, public security, and for the development of activities in criminal matters for the investigation and repression of crime". (*) Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
TITLE I
GUIDING PRINCIPLES
Article 4. Principle of legality
The processing of personal data is carried out in accordance with what is established by law. The collection of personal data by fraudulent, unfair or illegal means is prohibited.
Article 5. Principle of consent
The consent of the data subject must be obtained for the processing of personal data.
Article 6. Principle of purpose
Personal data must be collected for a specific, explicit and lawful purpose. The processing of personal data must not extend to another purpose that has not been unequivocally established as such at the time of its collection, excluding cases of activities of historical, statistical or scientific nature when a disassociation or anonymization procedure is used.
Article 7. Principle of proportionality
Any processing of personal data must be adequate, relevant and not excessive to the purpose for which they were collected.
Article 8. Principle of quality
Personal data to be processed must be truthful, accurate and, as far as possible, updated, necessary, pertinent and adequate with respect to the purpose for which they were collected. They must be stored in such a way as to guarantee their security and only for the time necessary to fulfill the purpose of the processing.
Article 9. Principle of security
The holder of the personal data bank and the agent of its processing must adopt the necessary technical, organizational and legal measures to guarantee the security of personal data. Security measures must be appropriate and in accordance with the processing to be carried out and with the category of personal data involved.
Article 10. Principle of right to remedy
Every data subject must have the necessary administrative or jurisdictional channels to claim and enforce their rights, when these are violated by the processing of their personal data.
Article 11. Principle of adequate protection level
For the cross-border flow of personal data, a sufficient level of protection for the personal data to be processed must be guaranteed, or at least equivalent to that provided for by this Law or by international standards in the matter.
"Article 12. Value of the principles
The actions of the holders and agents of processing of personal data and, in general, of all those who intervene in relation to personal data, must be adjusted to the guiding principles referred to in this Title. This list of guiding principles is illustrative.
4 LEGAL NORMS updated
The guiding principles mentioned also serve as an interpretative criterion to resolve the issues that may arise in the application of this Law and its regulations, as well as a parameter for the elaboration of other provisions and to fill gaps in the legislation on the matter".
(*) Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
TITLE II
PROCESSING OF PERSONAL DATA
Article 13. Scope regarding the processing of personal data
13.1 The processing of personal data must be carried out with full respect for the fundamental rights of their holders and the rights conferred by this Law. The same rule applies to their use by third parties.
13.2 Limitations on the exercise of the fundamental right to the protection of personal data can only be established by law, respecting its essential content and being justified by reason of respect for other fundamental rights or constitutionally protected goods.
13.3 Special measures for the processing of personal data of children and adolescents, as well as for the protection and guarantee of their rights, are issued by regulation. For the exercise of the rights recognized by this Law, children and adolescents act through their legal representatives, the regulation being able to determine the applicable exceptions, if applicable, taking into account the best interests of the child and the adolescent.
13.4 Communications, telecommunications, computer systems or their instruments, when they are of a private nature or private use, can only be opened, seized, intercepted or intervened by motivated order of the judge or with the authorization of their holder, with the guarantees provided by law. Secrecy is kept on matters unrelated to the fact that motivates their examination.
Personal data obtained in violation of this provision have no legal effect.
13.5 Personal data can only be subject to processing with the consent of their holder, unless a law authorizes it. The consent must be prior, informed, express and unequivocal.
13.6 In the case of sensitive data, the consent for the purposes of their processing must also be made in writing. Even if the consent of the holder is not present, the processing of sensitive data can be carried out when the law authorizes it, provided that it attends to important reasons of public interest.
13.7 The data subject can revoke their consent at any time, observing for this purpose the same requirements as those occasioned by its granting.
13.8 The processing of personal data related to the commission of criminal or administrative offenses can only be carried out by the competent public entities, unless there is a management outsourcing agreement in accordance with Law 27444, General Administrative Procedure Law, or the one that replaces it. When the cancellation of criminal, judicial, police and administrative records has occurred, these data cannot be supplied unless they are requested by the Judiciary or the Public Ministry, in accordance with the law.
13.9 The commercialization of personal data contained or intended to be contained in personal data banks is subject to the principles provided for in this Law.
"Article 14. Limitations on consent for the processing of personal data
The consent of the data subject is not required, for the purposes of their processing, in the following cases:
- When personal data are collected or transferred for the exercise of the functions of public entities within the scope of their competencies.
- When it concerns personal data contained or intended to be contained in sources accessible to the public.
- When it concerns personal data related to financial solvency and credit, in accordance with the law.
- When there is a norm for the promotion of competition in regulated markets issued in the exercise of the regulatory function by the regulatory bodies referred to in Law 27332, Framework Law of the Regulatory Bodies of Private Investment in Public Services, or the one that replaces it, provided that the information provided is not used to the detriment of user privacy.
- When personal data are necessary for the preparation, celebration and execution of a contractual relationship in which the data subject is a party, or when it concerns personal data that derive from a scientific or professional relationship of the holder and are necessary for its development or compliance.
- When it concerns personal data related to health and it is necessary, in circumstances of risk, for the prevention, diagnosis and medical or surgical treatment of the holder, provided that such processing is carried out in health establishments or by professionals in health sciences, observing professional secrecy; or when there are reasons of public interest provided for by law or when they must be treated for reasons of public health, both reasons must be qualified as such by the Ministry of Health; or for the realization of epidemiological or similar studies, as long as appropriate disassociation procedures are applied.
- When the processing is carried out by non-profit organizations whose purpose is political, religious or union and refers to the personal data collected from their respective members, which must be related to the purpose to which their activities are circumscribed, and cannot be transferred without the consent of those.
LEGAL NORMS updated 5
purpose to which their activities are circumscribed, and cannot be transferred without the consent of those.
8. When an anonymization or disassociation procedure has been applied.
9. When the processing of personal data is necessary to safeguard legitimate interests of the data subject by the data subject or by the data processing agent.
10. When the processing is for purposes linked to the system for the prevention of money laundering and terrorist financing or others that respond to a legal mandate.
11. In the case of economic groups formed by companies that are considered obligated subjects to report, in accordance with the regulations that regulate the Financial Intelligence Unit, that they can share information among themselves from their respective clients for purposes of prevention of money laundering and terrorist financing, as well as other regulatory compliance purposes, establishing adequate safeguards on the confidentiality and use of the exchanged information.
12. When the processing is carried out in the exercise of the constitutionally valid fundamental right to freedom of information.
13. Others that derive from the exercise of competencies expressly established by Law".
(*) Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
"Article 15. Cross-border flow of personal data
The holder and the agent of processing of personal data must carry out the cross-border flow of personal data only if the recipient country maintains adequate levels of protection in accordance with this Law.
In the event that the recipient country does not have an adequate level of protection, the sender of the cross-border flow of personal data must guarantee that the processing of personal data is carried out in accordance with what is provided for by this Law.
The provisions of the second paragraph do not apply in the following cases:
- Agreements within the framework of international treaties on the matter in which the Republic of Peru is a party.
- International judicial cooperation.
- International cooperation between intelligence agencies for the fight against terrorism, illicit drug trafficking, money laundering, corruption, human trafficking and other forms of organized crime.
- When personal data are necessary for the execution of a contractual relationship in which the data subject is a party, including what is necessary for activities such as user authentication, improvement and support of the service, monitoring of service quality, support for maintenance and billing of the account and those activities that the management of the contractual relationship requires.
- When it concerns banking or stock transactions, with respect to the respective transactions and in accordance with the applicable law.
- When the cross-border flow of personal data is carried out for the protection, prevention, diagnosis or medical or surgical treatment of its holder; or when it is necessary for the realization of epidemiological or similar studies, as long as appropriate disassociation procedures are applied.
- When the data subject has given their prior, informed, express and unequivocal consent.
- Others that the regulations of this Law establish, subject to what is provided for in Article 12". () Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
Article 16. Security of the processing of personal data
For the purposes of the processing of personal data, the holder of the personal data bank must adopt technical, organizational and legal measures that guarantee its security and prevent its alteration, loss, unauthorized processing or access.
The requirements and conditions that personal data banks must meet in terms of security are established by the National Authority for the Protection of Personal Data, unless there are special provisions contained in other laws.
The processing of personal data in data banks that do not meet the requirements and security conditions referred to in this article is prohibited.
Article 17. Confidentiality of personal data
The holder of the personal data bank, the agent and those who intervene in any part of its processing are obliged to keep confidentiality regarding them and their background. This obligation subsists even after the relationships with the holder of the personal data bank have ended.
The obligated party can be released from the obligation of confidentiality when there is prior, informed, express and unequivocal consent of the data subject, a consented or final judicial resolution, or when there are well-founded reasons related to national defense, public security or public health, without prejudice to the right to keep professional secrecy.
TITLE III
RIGHTS OF THE DATA SUBJECT
"Article 18. Right to information of the data subject The data subject has the right to be informed in a detailed, simple, express, unequivocal and prior manner to their collection, about the purpose for which their personal data will be processed; who are or may be its recipients, the existence of the data bank in which they will be stored, as well as the identity and domicile of its holder and, if applicable, of the or the agents of the processing of their personal data; the mandatory or optional nature of their answers to the questionnaire proposed to them, especially regarding sensitive data; the transfer of personal data; the consequences of providing their personal data and of their refusal to do so; the time during which their personal data will be preserved; and the possibility of exercising the rights that the law grants them and the means provided for it.
If personal data are collected online through electronic communication networks, the obligations of this article can be satisfied through the publication of privacy policies, which must be easily accessible and identifiable.
In the event that the holder of the data bank establishes a link with a processing agent after the consent, the action of the agent remains under the responsibility of the Data Bank Holder, who must establish a personalized information mechanism for the data subject regarding said new processing agent.
If after the consent the transfer of personal data occurs by merger, portfolio acquisition, or similar situations, the new holder of the data bank must establish an effective information mechanism for the data subject regarding said new processing agent". () Article modified by the Third Complementary Modifying Provision of Legislative Decree No. 1353, published on January 7, 2017.
Article 19. Right of access of the data subject
6 LEGAL NORMS updated
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 163,436-character original (15% of the document). The remainder was not translated. The complete original-language text is stored with this document.]