Paraguay Enacts a Comprehensive Data Protection Law With a Two-Year Runway

Paraguay’s first comprehensive personal-data law creates a regulator, reaches some overseas processing and gives organisations 24 months from official publication before the regime takes effect.

Paraguay’s Law No. 7.593/2025 represents a major change from a privacy landscape previously centred on constitutional protection and sector-specific rules, including credit data.

The complete law was made available through the congressional legal database in March 2026. It creates a general framework for the processing of personal data and an enforcement authority with supervisory, regulatory and sanctioning powers.

The law enters into force 24 months after its official publication. The same period is provided for executive regulation. Organisations should treat that as an implementation runway, not a reason to wait for the final months.

The law can reach organisations outside Paraguay

The territorial provisions cover controllers and processors established in Paraguay. They can also reach overseas organisations that process data about people in Paraguay in connection with offering goods or services or monitoring behaviour there.

This matters for regional platforms that operate through one legal entity or cloud environment. The absence of a Paraguayan office does not automatically remove the activity from scope.

An initial assessment should identify users, employees and customers located in Paraguay, the services offered to them and any tracking, scoring or profiling that evaluates their behaviour.

Processing needs a defensible basis

The law recognises several bases for processing, including consent, legal obligation, contracts, public functions, legal claims, vital interests and legitimate interests subject to protection of individual rights.

Consent must be prior, free, informed and unambiguous. A controller relying on legitimate interests needs evidence of necessity and balance rather than a generic label in the data inventory.

Sensitive information—including health, biometric, genetic, political, religious and sexual-life data—receives additional protection. Product teams should be able to explain why that information is necessary and why a less intrusive design would not meet the purpose.

Accountability is written into the principles

The law’s due-diligence principle expressly points toward privacy by design and default, impact assessment and appointment of a data-protection officer.

This moves compliance upstream. Default profiles, access settings, log retention, model inputs and data-export functions should be reviewed before release. A policy written after deployment cannot correct a design that collects excessive information or exposes it to unnecessary recipients.

The law also provides individual rights and establishes an administrative route to the new agency. Rights handling will require a reliable way to locate data and communicate instructions to processors.

International transfers require a mechanism

Transfers to destinations without adequate protection need appropriate safeguards. The law anticipates contractual clauses, binding corporate rules, codes, certifications and other mechanisms, as well as specified exceptions.

The new agency is empowered to make adequacy decisions and issue standard clauses. Until the implementation detail is settled, organisations should at least build an accurate transfer map and avoid assuming that existing EU or Brazilian documentation automatically satisfies Paraguayan requirements.

A new regulator changes the evidence expected

The National Personal Data Protection Agency will sit within the Ministry of Information and Communication Technologies as a decentralised unit with functional autonomy. It is empowered to audit, investigate, issue rules, handle complaints and impose administrative sanctions.

The law also transfers relevant functions under the existing credit-data framework to the agency when the new regime takes effect. Financial and credit-data organisations will need to map the interaction carefully.

Use the runway in four phases

  1. Discover: identify Paraguay-related data, systems, suppliers, transfers and accountable owners.
  2. Decide: assign purposes and legal bases; classify sensitive, children’s and profiling activities.
  3. Build: implement rights, retention, incident, contract and privacy-review workflows.
  4. Test: exercise requests and breaches, sample production settings and close evidence gaps.

Paraguay’s law gives organisations time to build a programme designed for the local framework. The advantage belongs to those that use the two years to change systems, not those that reserve the final quarter for paperwork.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *