- Brazil: Comprehensive, actively enforced
Lei Geral de Protecao de Dados Pessoais, Lei 13.709/2018. In force with an active regulator that has been issuing binding resolutions steadily since 2023. The most built-out regime in the region and the closest in structure to the GDPR.
Authority: Autoridade Nacional de Protecao de Dados (ANPD)
Processing on your behalf: The LGPD splits the controlador from the operador and imposes direct security obligations on both, so a staffing supplier processing on your instructions carries its own statutory duties rather than only contractual ones.
Breach reporting: Communication to the ANPD and to affected individuals is required, and the regulator has fixed a short reporting window by resolution rather than leaving it to a reasonableness test.
EU adequacy: The European Commission adopted an adequacy decision for Brazil on 26 January 2026, with a reciprocal recognition adopted by the ANPD. It is the first mutual arrangement of its kind in the region and it removes the need for standard contractual clauses on flows between the EU and Brazil.
Source: ANPD
- Uruguay: Comprehensive, EU recognised
Ley 18.331 de Proteccion de Datos Personales, with Ley 19.670 and Decreto 64/020. In force since 2008 and amended to add accountability duties, breach notification, data protection officers, and impact assessments for defined categories of processing.
Authority: Unidad Reguladora y de Control de Datos Personales (URCDP)
Processing on your behalf: Processors act on the controller's instructions under written terms, and the 2020 decree tightened what those terms and the surrounding security duties have to cover.
Breach reporting: Notification to the regulator is required promptly once a breach affecting personal data is identified, with communication to affected individuals where the impact warrants it.
EU adequacy: Uruguay has held a European Commission adequacy decision since 2012, one of only two in the region for over a decade until Brazil joined in 2026.
Source: URCDP
- Colombia: Comprehensive, registry obligations
Ley 1581 de 2012, with Decreto 1074 de 2015. In force and actively enforced, with a national database registry that catches foreign companies by surprise more often than the substantive rules do.
Authority: Superintendencia de Industria y Comercio, Delegatura para la Proteccion de Datos Personales
Processing on your behalf: The statute separates the responsable from the encargado and requires the arrangement to be documented, with the encargado processing only under instruction and applying a security duty of its own.
Breach reporting: Incidents affecting the administration of data must be reported to the Superintendencia, which operates a reporting channel for the purpose.
EU adequacy: No adequacy decision. Colombia does maintain its own list of countries it recognises as offering adequate protection, which matters for data leaving Colombia rather than for data arriving.
Source: Superintendencia de Industria y Comercio
- Argentina: Comprehensive, EU recognised, ageing text
Ley 25.326 de Proteccion de los Datos Personales. In force since 2000 and the oldest comprehensive regime in the region. A modernising bill has been in and out of Congress for years without passing, so the operative text remains the original statute plus regulator guidance.
Authority: Agencia de Acceso a la Informacion Publica (AAIP)
Processing on your behalf: Processing on behalf of a controller requires written terms, and the data may not be used for any purpose other than the one instructed or retained after the relationship ends.
Breach reporting: The statute predates the modern notification model, and the reporting expectations come from regulator guidance rather than from a statutory clock. Treat your contractual clock as the operative one.
EU adequacy: Argentina has held a European Commission adequacy decision since 2003, which was maintained following the Commission's review of pre-GDPR decisions.
Source: AAIP
- Mexico: Comprehensive, newly reorganised authority
Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published 20 March 2025. A completely new statute rather than an amendment. It replaced the 2010 law of the same name and took effect the day after publication, following the dissolution of INAI and the move of enforcement into the executive branch.
Authority: Secretaria Anticorrupcion y Buen Gobierno, through Transparencia para el Pueblo
Processing on your behalf: The new text addresses processors directly, so a supplier handling personal data on your behalf has obligations under the statute and not only under your contract. This is a change from the 2010 position and is the detail most likely to be missing from a supplier's template.
Breach reporting: Security breaches materially affecting the rights of data subjects must be reported to those subjects without delay so they can act. Penalties are set in multiples of the Unidad de Medida y Actualizacion, with a higher band for sensitive data.
EU adequacy: No adequacy decision. Where EU or UK personal data is involved, the transfer needs its own mechanism.
Source: Diario Oficial de la Federacion
- Peru: Comprehensive, recently modernised
Ley 29733, with the regulation approved by Decreto Supremo 016-2024-JUS. The statute dates from 2011, and the regulation that gives it teeth was replaced in 2024 and took effect on 30 March 2025. The most significant change to Peruvian data protection practice since the law was passed.
Authority: Autoridad Nacional de Proteccion de Datos Personales, Ministerio de Justicia y Derechos Humanos
Processing on your behalf: The new regulation sets out processor duties in detail, adds a data protection officer requirement in defined cases, and raises the transparency and security standard across the board.
Breach reporting: The regulation sets a 48 hour window for notifying the authority of a security incident, which is shorter than most contracts in this market currently provide for.
EU adequacy: No adequacy decision, though the 2024 regulation was explicitly drafted to move Peruvian practice toward the European standard.
Source: Ministerio de Justicia y Derechos Humanos
- Chile: Modern statute, effective December 2026
Ley 21.719, published 13 December 2024. Published and not yet fully operative. Law 19.628 of 1999 continues to apply until the end of November 2026, and Law 21.719 takes effect on 1 December 2026 with a new regulator, GDPR-style roles, and a penalty regime the old law never had.
Authority: Agencia de Proteccion de Datos Personales, being established
Processing on your behalf: The new statute introduces the controller and processor split that Chilean law has lacked, with written terms and direct security obligations. Contracts written against the 1999 law will need revisiting before the changeover.
Breach reporting: Law 21.719 introduces breach notification to the new agency and to affected individuals, which the current statute does not require. Build the process now rather than in the last quarter of 2026.
EU adequacy: No adequacy decision. Chile has been open about wanting one, and the 2024 statute was drafted with that in view.
Source: Biblioteca del Congreso Nacional de Chile
- Costa Rica: Comprehensive, registration duties
Ley 8968 de Proteccion de la Persona frente al tratamiento de sus datos personales. In force since 2011 with an established regulator. Compact by regional standards, and notable for a database registration duty that applies to private parties distributing or trading in personal data.
Authority: Agencia de Proteccion de Datos de los Habitantes (PRODHAB)
Processing on your behalf: Transfers to a processor require the data subject's informed consent under the statute's transfer rules, which is a stricter default than the instruction-based model most of the region has moved to.
Breach reporting: The controller must inform the data subject and the agency of irregularities in the handling or storage of personal data within five working days of becoming aware.
EU adequacy: No adequacy decision.
Source: PRODHAB
- Ecuador: Modern statute, young authority
Ley Organica de Proteccion de Datos Personales, published 26 May 2021. A modern GDPR-influenced statute whose sanctions regime became applicable two years after publication, with the supervisory authority established more recently. The text is strong and the enforcement history is short.
Authority: Superintendencia de Proteccion de Datos Personales
Processing on your behalf: The statute uses the controller and processor split, requires written terms, and imposes a security duty proportionate to the risk of the processing.
Breach reporting: Breach notification to the authority is required within a short window of becoming aware, with communication to affected individuals where the risk warrants it.
EU adequacy: No adequacy decision.
Source: Superintendencia de Proteccion de Datos Personales
- Dominican Republic: Statute in force, limited supervision
Ley 172-13 sobre Proteccion de Datos de Caracter Personal. A comprehensive statute on paper without the general supervisory apparatus the rest of the region has built. Reform has been discussed for years. Treat the statute as binding and the contract as your practical enforcement mechanism.
Authority: No dedicated general-purpose authority. Oversight of credit reporting bodies sits with the Superintendencia de Bancos.
Processing on your behalf: The statute contemplates processing on a controller's behalf, but there is no regulator issuing the detailed processor guidance that Brazil, Colombia, and Peru now publish.
Breach reporting: No general statutory notification clock comparable to Peru's or Brazil's. Set the clock in the contract, because nothing else will set it for you.
EU adequacy: No adequacy decision.
Source: Superintendencia de Bancos
- Guatemala: No general statute
No comprehensive private-sector data protection statute. The country has no general data protection law in force. Decreto 57-2008 on access to public information covers personal data held by public bodies and provides a habeas data mechanism against those bodies, which does not reach a private employer. A comprehensive bill has been before Congress since 2022 without passing.
Authority: None for private-sector processing
Processing on your behalf: There is no statutory processor concept to rely on. Everything you want to be true has to be in the contract, and the contract is the only instrument that will be enforced.
Breach reporting: No statutory notification duty. Your obligations here come entirely from your own customer contracts and from the law governing the data subjects rather than the worker.
EU adequacy: No adequacy decision.
Source: Congreso de la Republica de Guatemala
Two entries on that list deserve a second look before you plan around them. Chile's Law 21.719 was published on 13 December 2024 and takes effect on 1 December 2026, with Law 19.628 of 1999 continuing to apply until the end of November 2026. It introduces the controller and processor split, a new supervisory agency, and a penalty regime that Chilean data protection law has never had, so an agreement drafted against the current statute will need revisiting rather than renewing. Mexico is the other: the statute in force is not an amended version of the 2010 law but an entirely new one, published on 20 March 2025 and effective the following day, with enforcement moved out of the dissolved INAI and into the executive branch. A supplier template written against the old regime will name a regulator that no longer exists.