El Salvador Pairs Data Protection With a New Cybersecurity Framework
El Salvador enacted privacy and cybersecurity legislation together, placing the protection of personal information and the security of public digital systems under a connected institutional model.
El Salvador published two linked statutes on 15 November 2024: Legislative Decree No. 143, the Cybersecurity and Information Security Law, and Legislative Decree No. 144, the Personal Data Protection Law.
Publishing the laws together was more than legislative convenience. It reflects the fact that privacy rights depend on secure systems and that cybersecurity governance regularly involves personal information.
One agency sits at the intersection
The Cybersecurity and Information Security Law creates the State Cybersecurity Agency, or ACE. The agency develops national policy, standards and protocols; maintains a national register of threats and incidents; supports response; audits compliance; and exercises enforcement powers.
The data-protection law assigns ACE special responsibilities for personal data and provides for a Director of Personal Data Protection within the structure. This integrated model can reduce coordination gaps, but regulated organisations should still distinguish the legal tests. A cyber incident is not automatically a personal-data violation, and a privacy failure can occur without an external attacker.
The data law covers the processing lifecycle
The Personal Data Protection Law regulates collection, use, processing, storage, transfer and other operations involving information about natural persons. It applies to public and private-sector actors subject to its scope and establishes rules for legitimate and informed processing.
Controllers need to communicate how data is used, choose an appropriate legal basis, respect individual rights and implement security. Processors need written instructions and controls. Sensitive data requires enhanced care.
The burden of proving consent or delivery of the privacy notice rests with the controller. For international transfers, the organisation responsible for the transfer must be able to demonstrate that the transfer complied with the law or applicable international standards.
That makes evidence design important. A checkbox without the notice version, purpose and timestamp may not prove what the person agreed to. A vendor agreement that says only “data may be processed globally” may not demonstrate lawful transfer safeguards.
Rights need a working interface
The law provides individuals with a range of controls over their data and requires mechanisms through which those rights can be exercised. Organisations were also given implementation periods tied to rules issued by ACE.
Rights handling should be built as a case-management process with identity verification, deadlines, data discovery, processor communication and reasoned outcomes. Customer support should know how to identify a legal rights request even when the person does not use statutory terminology.
Cybersecurity becomes institutional policy
The cybersecurity law is focused heavily on public-sector information and national coordination. It requires policies, risk management, standards, incident processes and oversight.
Private suppliers can still be affected through contracts, services provided to public institutions and personal-data obligations. A supplier hosting government information needs to understand which party detects, records and reports an incident and how rapidly evidence can be shared with ACE.
The agency was directed to develop technical rules, protocols and standards within statutory periods. Compliance teams should therefore monitor secondary instruments rather than treating the two Acts as complete technical specifications.
Build one control framework with two legal views
An efficient organisation can use common capabilities for both laws:
- Maintain one inventory of systems, data, owners and suppliers.
- Classify systems by public-service importance and personal-data sensitivity.
- Perform security and privacy risk assessment during design.
- Use access control, encryption, logging, backup and recovery according to risk.
- Create separate decision paths for cyber reporting and personal-data notification.
- Preserve consent, notice, transfer and incident evidence.
- Require suppliers to escalate events and support individual rights.
- Track ACE standards, guidance and public enforcement decisions.
Integration should not erase accountability
Combining cybersecurity and privacy governance can create a stronger programme, but only if the two perspectives remain visible. Security asks whether information and services are protected. Privacy also asks whether the information should have been collected, shared or retained in the first place.
El Salvador’s paired laws provide an opportunity to make both questions part of the same technology lifecycle.
Official sources
- El Salvador Official Journal, 15 November 2024: Decrees No. 143 and 144
- Legislative Assembly of El Salvador: Personal Data Protection Law, Decree No. 144
- Legislative Assembly of El Salvador: Cybersecurity and Information Security Law, Decree No. 143
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


