Peru’s New Privacy Regulation Brings a 48-Hour Breach Clock
Peru’s replacement data-protection regulation turns security incidents, advertising consent and privacy governance into defined operating processes.
Peru’s new Regulation of Law No. 29.733 entered into force on 31 March 2025. Approved by Supreme Decree No. 016-2024-JUS, it replaces the earlier implementing regulation and updates the country’s privacy regime for digital processing.
The regulation is broader than a breach-notification rule. It develops proactive accountability, impact assessment, data-protection officers, processor duties and commercial-contact consent. Its practical message is that organisations must be able to demonstrate how privacy rules work inside their systems.
Certain incidents trigger a 48-hour notification
A controller must notify Peru’s National Authority for the Protection of Personal Data within 48 hours after becoming aware of an incident when it exposes large volumes of data, affects many people, involves sensitive data or creates evident harm to other rights or freedoms.
The notification remains required even if the organisation believes it has already contained the event. If it is sent after 48 hours, the delay must be explained and supported.
Individuals must also be informed within 48 hours when the event could affect their rights. The communication should be clear and describe the exposure and mitigation. Incidents that do not create the specified harm and have been fully controlled may not require individual notice, but the underlying assessment should be recorded.
Processors must inform the controller immediately. This makes supplier escalation speed a compliance requirement, not simply a service-quality metric.
Documentation is mandatory even when notification is not
The regulation requires controllers to document security incidents, including the facts, effects and measures adopted. That record allows the authority to test whether the organisation assessed and handled the event correctly.
A technical ticket alone will often be insufficient. The record should connect forensic facts to affected data, people, risks, legal thresholds, communications and mitigation. It should also show when the organisation first had enough knowledge to start the clock.
Advertising calls need explicit control
The regulation restricts calls made to obtain consent for advertising or commercial-prospecting purposes. A first call may be made to request consent only under defined conditions, including use of data obtained from a lawful source. People must be able to refuse, revoke or oppose further use.
This has direct system implications. Organisations need a suppression capability that operates across call centres, messaging providers, CRM systems and outsourced campaigns. A refusal recorded by one vendor cannot remain invisible to another.
Consent evidence should identify the person, purpose, channel, notice, timestamp and method. Buying a list does not transfer valid consent unless the collection and subsequent use satisfy the law.
Data-protection officers arrive progressively
The new framework expands the role of the data-protection officer for organisations whose core activity involves large-scale processing or sensitive information. Implementation follows a progressive schedule rather than applying identically to every organisation on the first day.
The officer should be positioned to advise and monitor, with access to management and product decisions. The role cannot compensate for absent ownership by engineering, marketing, HR or procurement.
Impact assessments and codes of conduct also form part of the accountability model. Their value is not the existence of another document; it is the identification of risk before a processing activity becomes difficult to change.
What organisations should test
- Can a processor reach the controller immediately at any hour?
- Can the incident team determine the affected people and data within 48 hours?
- Are regulator and individual notices drafted and approved in advance?
- Is every incident decision documented, including decisions not to notify?
- Does an advertising objection propagate to every contact channel and supplier?
- Are large-scale and sensitive activities identified for officer and impact-assessment duties?
- Can the organisation prove the origin and legal use of prospecting data?
Peru’s regulation connects privacy to everyday operational systems: the incident queue, call-centre dialler, vendor contract and product review. Compliance will be visible in how those systems behave under pressure.
Official sources
- Peruvian Government: Supreme Decree No. 016-2024-JUS
- Peruvian Data Protection Authority: New Data Protection Regulation
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


