Saltar a contenido

Argentina Ley 25.326 (PDPA) Compliance — EPPA

AAIP database registration is mandatory

Under Ley 25.326 Art. 21, every database that stores personal data requires registration with the Agencia de Acceso a la Información Pública (AAIP) — Registro Nacional de Bases de Datos. Sensitive health data attracts heightened scrutiny under Art. 7 inc. 3. EPPA, as LABIS UCA's research instrument, must be on this register before any non-research production deployment in Argentina.

1. Document identity

Field Value
Document title Argentina Ley 25.326 Compliance — EPPA
Document ID EPPA-AR-PDPA-001
Version 0.1 (draft)
Status Draft — not approved
Effective date n/a
Owner LABIS UCA — Argentina Privacy lead (pending)
Linked documents 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md

2. Regulatory anchors

  • Ley 25.326 — Ley de Protección de los Datos Personales (2000).
  • Decreto 1558/2001 — Reglamentación de la Ley 25.326.
  • Disposición DNPDP 11/2006 — Medidas de seguridad para el tratamiento y conservación de los datos personales (security measures, Levels 1, 2, 3).
  • Resolución AAIP 159/2018 — Modelos de cláusulas contractuales para la transferencia internacional de datos personales.
  • Resolución AAIP 47/2018 — Criterios orientadores e indicadores de mejores prácticas en la aplicación de la Ley 25.326.
  • Ley 26.529 — Derechos del paciente (clinical records retention: 10 años).
  • Ley 27.275 — Derecho de acceso a la información pública.
  • EU Commission Decision 2003/490/EC — adequacy decision recognising Argentina for cross-border transfers from the EEA.
  • Forthcoming: The "Proyecto de Ley de Protección de Datos Personales" modernisation that would update Ley 25.326 to align with GDPR remains pending in Congress as of the date of this document. Monitor for status changes.

3. Categories of data and lawful basis

3.1 Sensitive data (Art. 2)

EPPA processes "datos sensibles" under Art. 2 of Ley 25.326 — health data is sensitive. This triggers:

  • Art. 7 inc. 3 — sensitive data may only be collected and processed when there are circumstances of general interest authorised by law, or for statistical / scientific purposes provided the data subjects cannot be identified.
  • Art. 7 inc. 4 — sensitive data concerning racial, ethnic, sexual, political, religious or trade-union information may be processed only with the explicit consent of the data subject or under specific legal exceptions.
  • Art. 8 — public and private health establishments and professionals may process personal health data of patients in compliance with professional-secrecy obligations.

3.2 Lawful basis options for EPPA in Argentina

Basis Ley 25.326 reference EPPA applicability
Explicit informed consent Art. 5 + Art. 6 + Art. 7 inc. 3 Default in private-clinic research deployments; consent obtained at intake.
Public-interest research with pseudonymisation Art. 7 inc. 3 second clause Available for academic research where re-identification is prevented.
Health-care necessity Art. 8 Available in a treating-clinician context — outside current intended use.
Legal obligation Art. 5 inc. 2(b) Not applicable.

3.3 Data subject rights (Art. 14 to Art. 18)

Right Article EPPA SLA
Información (information) Art. 13, Art. 14 Privacy notice at intake.
Acceso (access) Art. 14, Art. 15 10 días corridos desde la solicitud (Art. 14 inc. 3).
Rectificación, actualización, supresión, confidencialidad Art. 16 5 días hábiles para evaluar y proceder.
Habeas data Art. 33 to 43 Constitutional remedy — Art. 43 of the Constitution.

4. AAIP database registration (Art. 21 + Disp. 1/2003 + Disp. 2/2005)

4.1 What must be registered

Per Art. 21 and the AAIP technical instructions, every base de datos that contains personal data — whether public or private — must be enrolled in the Registro Nacional de Bases de Datos Personales.

For EPPA, at least the following databases require registration:

  • EPPA-CLINICAL-AR — the clinical record store (Patient, Marker, Analysis, ConsentRecord). Level 3 (sensitive health data).
  • EPPA-USERS-AR — the clinician account store (User, Role). Level 2.
  • EPPA-AUDIT-AR — the audit log. Level 3 (because it references Level 3 records).

4.2 Registration form content (per AAIP)

  1. Datos del responsable: identification of the controller (LABIS UCA), CUIT, address, contact person.
  2. Datos del usuario / encargado del tratamiento: any processor (e.g. the hosting provider) operating on behalf of the controller.
  3. Datos de la base: name, purpose, retention, type (private), security level under Disp. 11/2006.
  4. Cobertura: geographic and sectorial scope.
  5. Categorías de datos: identifying data, health data, biometric data (face), academic / professional data.
  6. Transferencias internacionales: enumerated by destination country and transfer mechanism.
  7. Cesiones: any disclosures to third parties.

Renewals are annual. Failure to register is a Class B violation under Disp. AAIP 71/2010 (sanctions regime).

5. Security measures — Disposición AAIP 11/2006

Disp. 11/2006 (still the operative security-measures regulation despite the body's rebranding from DNPDP to AAIP) defines three security levels. Level 3 applies to databases containing sensitive data, including health data — and therefore to EPPA's clinical store.

5.1 Level-3 security measures (summary)

Measure Disp. 11/2006 reference EPPA status
Documento de seguridad describing the database, treatment circuits, controls and incident procedures §3.1 Missing
Identification of personnel with access §3.2 Not implemented — to be addressed by Epic E3 RBAC
Restricted physical access §3.3 Inherited from hosting provider in cloud deployment
Encrypted transmission of sensitive data §3.4 Partial — TLS 1.3 in transit
Backups stored in a different physical location §3.5 Not implemented
Restoration procedure with at least semi-annual drill §3.5 Not implemented
Incident log: nature, date, person, recovery procedure §3.6 Not implemented
Cryptographic measures for the data at rest, with key management §3.7 (added in Level 3) Not implementedpgcrypto planned in Epic E3
Audit trail of access to the data (read + write), with bi-monthly review §3.8 (Level 3) Not implemented — AuditLog planned in Epic E3
Periodic security review by an external auditor (annual minimum for Level 3) §3.9 (Level 3) Not implemented

5.2 Mapping to OWASP ASVS L2

Many Level-3 controls map directly to OWASP ASVS L2 items maintained in 50-secdev-checklist.md. The mapping is maintained per-row in that file.

6. Trans-border data transfers (Art. 12 + Resolución AAIP 159/2018)

6.1 The general rule (Art. 12)

Art. 12 of Ley 25.326 prohibits the transfer of personal data to any country that does not provide an "adequate level of protection", subject to enumerated exceptions including:

  • The data subject's consent.
  • International judicial cooperation.
  • Banking or stock-exchange exchanges to the extent of the operation.
  • Health emergencies.
  • Treaty-based exchanges.
  • Transfers between affiliated companies of the same multinational group, or to international organisations, under a contractual mechanism approved by the AAIP.

6.2 Adequate countries

The AAIP maintains a list of countries deemed adequate. Notably:

  • European Union member states (Disp. AAIP 60/2016 historically; aligned with EU's reciprocal adequacy for Argentina under Commission Decision 2003/490/EC).
  • Switzerland, Iceland, Norway, Liechtenstein.
  • United Kingdom (post-Brexit, per AAIP confirmation).
  • Canada (for private-sector data — historical position).

Not adequate:

  • United States (no adequacy decision; transfers require contractual safeguards).
  • Brazil (despite LGPD; no AAIP adequacy decision as of the date of this document).

6.3 Resolución AAIP 159/2018 — model clauses

When transferring to a non-adequate country (e.g. US-based hosting), the controller and the importer must execute the model contractual clauses appended to Resolución AAIP 159/2018:

  • Modelo A — controller to controller.
  • Modelo B — controller to processor.

These clauses parallel the EU Standard Contractual Clauses in structure but have Argentina-specific provisions, including AAIP jurisdiction for disputes and Argentina-recognised data-subject rights.

6.4 EPPA transfer scenarios

Flow Origin Destination Adequacy? Mechanism
App + image hosting (current AR-only) AR clinic LABIS UCA on-premise n/a (no transfer) n/a
App + image hosting (future cloud, EU region) AR clinic EU member state Yes Adequate; consent + Art. 21 registration of recipient
App + image hosting (future cloud, US region) AR clinic US No Resolución AAIP 159/2018 Modelo B + data subject consent + AAIP notification
Research-data sharing with a co-investigator AR EU member state Yes Adequate; research-protocol + consent
Research-data sharing with a US co-investigator AR US No Modelo A + research-protocol + consent + DPIA

7. Data subject privacy notice (Art. 6, Art. 13)

A privacy notice must be provided to the patient at the moment of collection. Required content per Art. 6:

  • Purpose of collection.
  • Recipients or categories of recipients.
  • Existence of the database; identification of the controller and its address.
  • The mandatory or optional nature of replies.
  • The consequences of providing or refusing the data.
  • The right of access, rectification and suppression.

Template (Spanish, draft):

[Logotipo LABIS UCA]
Aviso de Privacidad — EPPA (Evaluación Postural Fotográfica Asistida)

LABIS UCA, Universidad Católica Argentina, con domicilio en [TBD],
CUIT [TBD], es el responsable de la base de datos personales en la que se
incorporarán sus imágenes y datos asociados al uso del software EPPA.

Finalidad. La información se recaba con la finalidad de documentar y analizar
su postura corporal, en el marco de un protocolo de investigación clínica
aprobado, sin que ello constituya un acto de diagnóstico médico.

Categorías de datos. Datos identificatorios, imágenes fotográficas (de cuerpo
entero, incluyendo rostro), datos derivados (mediciones angulares,
clasificaciones cualitativas).

Carácter facultativo. El suministro de estos datos es voluntario; su negativa
no impedirá la continuidad de su atención clínica habitual fuera del
protocolo de investigación EPPA.

Cesiones. Sus datos no serán cedidos a terceros, salvo a procesadores
contratados por LABIS UCA bajo cláusulas contractuales aprobadas por la
AAIP.

Transferencias internacionales. [Detallar por despliegue.]

Derechos. Le asisten los derechos de acceso, rectificación, actualización y
supresión, de manera gratuita una vez por semestre, conforme a la Ley 25.326,
Arts. 14 y 16. Puede ejercerlos enviando un correo a privacy@labis-uca.com.ar. <!-- L21 auto-filled 2026-05-22 -->

La Agencia de Acceso a la Información Pública, órgano de control de la Ley
25.326, tiene la atribución de atender las denuncias y reclamos que se
interpongan con relación al incumplimiento de las normas sobre protección de
datos personales. La AAIP recibe denuncias en
<https://www.argentina.gob.ar/aaip>.

8. Cross-reference to ANMAT software disposition

ANMAT (the device regulator) and AAIP (the data-protection regulator) are distinct authorities with parallel jurisdiction over EPPA:

  • ANMAT regulates EPPA as a software-as-a-medical-device candidate — registration under Disposición 2318/2002 plus the software-specific disposition (Disp. 9/2023 in current draft form). See 00-overview.md §2 row "AR (ANMAT)".
  • AAIP regulates the processing of personal data by EPPA — registration of the database, security level, transfers.

Both registrations must be in place before commercial deployment.

9. Ley 27.275 (Transparency) — implications

Ley 27.275, "Derecho de acceso a la información pública", establishes the right of every person to request information held by public bodies. AAIP is the enforcement authority for both Ley 27.275 and Ley 25.326.

Implications for EPPA, which is operated by Universidad Católica Argentina (a private university, not a public body) and LABIS UCA:

  • LABIS UCA is not a sujeto obligado under Ley 27.275 unless it receives public funds for the EPPA work, in which case it may be obligated to disclose certain non-personal information (research outputs, aggregated datasets, methodology).
  • Sensitive personal data remains protected under Ley 25.326 and is excepted from disclosure under Ley 27.275 Art. 8 inc. i (data exception).

The interaction is therefore manageable: research-output transparency without disclosure of individual records.

10. Sanctions regime (Art. 31, Disp. AAIP 71/2010)

Class Violation Sanction
Apercibimiento Minor breach Warning
Multa Various breaches ARS [TBD — Disp. AAIP 71/2010 amended several times for inflation]
Suspensión Severe / repeat Suspension of the database
Clausura Highly severe Closure of the database
Cancelación Final Cancellation of the database from the register

Note that ARS amounts are periodically updated by AAIP resolution due to inflation; verify the current schedule before sign-off.

11. Open questions

  1. Confirm Ley modernisation status. Project of law modernising Ley 25.326 (drafted to align with GDPR) — monitor parliamentary status.
  2. Confirm AAIP registration scope. Whether the audit log requires a separate database entry or is covered by the clinical-store entry.
  3. Confirm international transfer to US hosting. If US hosting is in scope, prepare Resolución AAIP 159/2018 Modelo B at engagement time.
  4. Confirm sanctions schedule. Current ARS amounts under the latest AAIP resolution.

References