Argentina Ley 25.326 (PDPA) Compliance — EPPA¶
AAIP database registration is mandatory
Under Ley 25.326 Art. 21, every database that stores personal data requires registration with the Agencia de Acceso a la Información Pública (AAIP) — Registro Nacional de Bases de Datos. Sensitive health data attracts heightened scrutiny under Art. 7 inc. 3. EPPA, as LABIS UCA's research instrument, must be on this register before any non-research production deployment in Argentina.
1. Document identity¶
| Field | Value |
|---|---|
| Document title | Argentina Ley 25.326 Compliance — EPPA |
| Document ID | EPPA-AR-PDPA-001 |
| Version | 0.1 (draft) |
| Status | Draft — not approved |
| Effective date | n/a |
| Owner | LABIS UCA — Argentina Privacy lead (pending) |
| Linked documents | 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md |
2. Regulatory anchors¶
- Ley 25.326 — Ley de Protección de los Datos Personales (2000).
- Decreto 1558/2001 — Reglamentación de la Ley 25.326.
- Disposición DNPDP 11/2006 — Medidas de seguridad para el tratamiento y conservación de los datos personales (security measures, Levels 1, 2, 3).
- Resolución AAIP 159/2018 — Modelos de cláusulas contractuales para la transferencia internacional de datos personales.
- Resolución AAIP 47/2018 — Criterios orientadores e indicadores de mejores prácticas en la aplicación de la Ley 25.326.
- Ley 26.529 — Derechos del paciente (clinical records retention: 10 años).
- Ley 27.275 — Derecho de acceso a la información pública.
- EU Commission Decision 2003/490/EC — adequacy decision recognising Argentina for cross-border transfers from the EEA.
- Forthcoming: The "Proyecto de Ley de Protección de Datos Personales" modernisation that would update Ley 25.326 to align with GDPR remains pending in Congress as of the date of this document. Monitor for status changes.
3. Categories of data and lawful basis¶
3.1 Sensitive data (Art. 2)¶
EPPA processes "datos sensibles" under Art. 2 of Ley 25.326 — health data is sensitive. This triggers:
- Art. 7 inc. 3 — sensitive data may only be collected and processed when there are circumstances of general interest authorised by law, or for statistical / scientific purposes provided the data subjects cannot be identified.
- Art. 7 inc. 4 — sensitive data concerning racial, ethnic, sexual, political, religious or trade-union information may be processed only with the explicit consent of the data subject or under specific legal exceptions.
- Art. 8 — public and private health establishments and professionals may process personal health data of patients in compliance with professional-secrecy obligations.
3.2 Lawful basis options for EPPA in Argentina¶
| Basis | Ley 25.326 reference | EPPA applicability |
|---|---|---|
| Explicit informed consent | Art. 5 + Art. 6 + Art. 7 inc. 3 | Default in private-clinic research deployments; consent obtained at intake. |
| Public-interest research with pseudonymisation | Art. 7 inc. 3 second clause | Available for academic research where re-identification is prevented. |
| Health-care necessity | Art. 8 | Available in a treating-clinician context — outside current intended use. |
| Legal obligation | Art. 5 inc. 2(b) | Not applicable. |
3.3 Data subject rights (Art. 14 to Art. 18)¶
| Right | Article | EPPA SLA |
|---|---|---|
| Información (information) | Art. 13, Art. 14 | Privacy notice at intake. |
| Acceso (access) | Art. 14, Art. 15 | 10 días corridos desde la solicitud (Art. 14 inc. 3). |
| Rectificación, actualización, supresión, confidencialidad | Art. 16 | 5 días hábiles para evaluar y proceder. |
| Habeas data | Art. 33 to 43 | Constitutional remedy — Art. 43 of the Constitution. |
4. AAIP database registration (Art. 21 + Disp. 1/2003 + Disp. 2/2005)¶
4.1 What must be registered¶
Per Art. 21 and the AAIP technical instructions, every base de datos that contains personal data — whether public or private — must be enrolled in the Registro Nacional de Bases de Datos Personales.
For EPPA, at least the following databases require registration:
- EPPA-CLINICAL-AR — the clinical record store (Patient, Marker, Analysis, ConsentRecord). Level 3 (sensitive health data).
- EPPA-USERS-AR — the clinician account store (User, Role). Level 2.
- EPPA-AUDIT-AR — the audit log. Level 3 (because it references Level 3 records).
4.2 Registration form content (per AAIP)¶
- Datos del responsable: identification of the controller (LABIS UCA), CUIT, address, contact person.
- Datos del usuario / encargado del tratamiento: any processor (e.g. the hosting provider) operating on behalf of the controller.
- Datos de la base: name, purpose, retention, type (private), security level under Disp. 11/2006.
- Cobertura: geographic and sectorial scope.
- Categorías de datos: identifying data, health data, biometric data (face), academic / professional data.
- Transferencias internacionales: enumerated by destination country and transfer mechanism.
- Cesiones: any disclosures to third parties.
Renewals are annual. Failure to register is a Class B violation under Disp. AAIP 71/2010 (sanctions regime).
5. Security measures — Disposición AAIP 11/2006¶
Disp. 11/2006 (still the operative security-measures regulation despite the body's rebranding from DNPDP to AAIP) defines three security levels. Level 3 applies to databases containing sensitive data, including health data — and therefore to EPPA's clinical store.
5.1 Level-3 security measures (summary)¶
| Measure | Disp. 11/2006 reference | EPPA status |
|---|---|---|
| Documento de seguridad describing the database, treatment circuits, controls and incident procedures | §3.1 | Missing |
| Identification of personnel with access | §3.2 | Not implemented — to be addressed by Epic E3 RBAC |
| Restricted physical access | §3.3 | Inherited from hosting provider in cloud deployment |
| Encrypted transmission of sensitive data | §3.4 | Partial — TLS 1.3 in transit |
| Backups stored in a different physical location | §3.5 | Not implemented |
| Restoration procedure with at least semi-annual drill | §3.5 | Not implemented |
| Incident log: nature, date, person, recovery procedure | §3.6 | Not implemented |
| Cryptographic measures for the data at rest, with key management | §3.7 (added in Level 3) | Not implemented — pgcrypto planned in Epic E3 |
| Audit trail of access to the data (read + write), with bi-monthly review | §3.8 (Level 3) | Not implemented — AuditLog planned in Epic E3 |
| Periodic security review by an external auditor (annual minimum for Level 3) | §3.9 (Level 3) | Not implemented |
5.2 Mapping to OWASP ASVS L2¶
Many Level-3 controls map directly to OWASP ASVS L2 items maintained in
50-secdev-checklist.md. The mapping is
maintained per-row in that file.
6. Trans-border data transfers (Art. 12 + Resolución AAIP 159/2018)¶
6.1 The general rule (Art. 12)¶
Art. 12 of Ley 25.326 prohibits the transfer of personal data to any country that does not provide an "adequate level of protection", subject to enumerated exceptions including:
- The data subject's consent.
- International judicial cooperation.
- Banking or stock-exchange exchanges to the extent of the operation.
- Health emergencies.
- Treaty-based exchanges.
- Transfers between affiliated companies of the same multinational group, or to international organisations, under a contractual mechanism approved by the AAIP.
6.2 Adequate countries¶
The AAIP maintains a list of countries deemed adequate. Notably:
- European Union member states (Disp. AAIP 60/2016 historically; aligned with EU's reciprocal adequacy for Argentina under Commission Decision 2003/490/EC).
- Switzerland, Iceland, Norway, Liechtenstein.
- United Kingdom (post-Brexit, per AAIP confirmation).
- Canada (for private-sector data — historical position).
Not adequate:
- United States (no adequacy decision; transfers require contractual safeguards).
- Brazil (despite LGPD; no AAIP adequacy decision as of the date of this document).
6.3 Resolución AAIP 159/2018 — model clauses¶
When transferring to a non-adequate country (e.g. US-based hosting), the controller and the importer must execute the model contractual clauses appended to Resolución AAIP 159/2018:
- Modelo A — controller to controller.
- Modelo B — controller to processor.
These clauses parallel the EU Standard Contractual Clauses in structure but have Argentina-specific provisions, including AAIP jurisdiction for disputes and Argentina-recognised data-subject rights.
6.4 EPPA transfer scenarios¶
| Flow | Origin | Destination | Adequacy? | Mechanism |
|---|---|---|---|---|
| App + image hosting (current AR-only) | AR clinic | LABIS UCA on-premise | n/a (no transfer) | n/a |
| App + image hosting (future cloud, EU region) | AR clinic | EU member state | Yes | Adequate; consent + Art. 21 registration of recipient |
| App + image hosting (future cloud, US region) | AR clinic | US | No | Resolución AAIP 159/2018 Modelo B + data subject consent + AAIP notification |
| Research-data sharing with a co-investigator | AR | EU member state | Yes | Adequate; research-protocol + consent |
| Research-data sharing with a US co-investigator | AR | US | No | Modelo A + research-protocol + consent + DPIA |
7. Data subject privacy notice (Art. 6, Art. 13)¶
A privacy notice must be provided to the patient at the moment of collection. Required content per Art. 6:
- Purpose of collection.
- Recipients or categories of recipients.
- Existence of the database; identification of the controller and its address.
- The mandatory or optional nature of replies.
- The consequences of providing or refusing the data.
- The right of access, rectification and suppression.
Template (Spanish, draft):
[Logotipo LABIS UCA]
Aviso de Privacidad — EPPA (Evaluación Postural Fotográfica Asistida)
LABIS UCA, Universidad Católica Argentina, con domicilio en [TBD],
CUIT [TBD], es el responsable de la base de datos personales en la que se
incorporarán sus imágenes y datos asociados al uso del software EPPA.
Finalidad. La información se recaba con la finalidad de documentar y analizar
su postura corporal, en el marco de un protocolo de investigación clínica
aprobado, sin que ello constituya un acto de diagnóstico médico.
Categorías de datos. Datos identificatorios, imágenes fotográficas (de cuerpo
entero, incluyendo rostro), datos derivados (mediciones angulares,
clasificaciones cualitativas).
Carácter facultativo. El suministro de estos datos es voluntario; su negativa
no impedirá la continuidad de su atención clínica habitual fuera del
protocolo de investigación EPPA.
Cesiones. Sus datos no serán cedidos a terceros, salvo a procesadores
contratados por LABIS UCA bajo cláusulas contractuales aprobadas por la
AAIP.
Transferencias internacionales. [Detallar por despliegue.]
Derechos. Le asisten los derechos de acceso, rectificación, actualización y
supresión, de manera gratuita una vez por semestre, conforme a la Ley 25.326,
Arts. 14 y 16. Puede ejercerlos enviando un correo a privacy@labis-uca.com.ar. <!-- L21 auto-filled 2026-05-22 -->
La Agencia de Acceso a la Información Pública, órgano de control de la Ley
25.326, tiene la atribución de atender las denuncias y reclamos que se
interpongan con relación al incumplimiento de las normas sobre protección de
datos personales. La AAIP recibe denuncias en
<https://www.argentina.gob.ar/aaip>.
8. Cross-reference to ANMAT software disposition¶
ANMAT (the device regulator) and AAIP (the data-protection regulator) are distinct authorities with parallel jurisdiction over EPPA:
- ANMAT regulates EPPA as a software-as-a-medical-device candidate —
registration under Disposición 2318/2002 plus the software-specific
disposition (Disp. 9/2023 in current draft form). See
00-overview.md§2 row "AR (ANMAT)". - AAIP regulates the processing of personal data by EPPA — registration of the database, security level, transfers.
Both registrations must be in place before commercial deployment.
9. Ley 27.275 (Transparency) — implications¶
Ley 27.275, "Derecho de acceso a la información pública", establishes the right of every person to request information held by public bodies. AAIP is the enforcement authority for both Ley 27.275 and Ley 25.326.
Implications for EPPA, which is operated by Universidad Católica Argentina (a private university, not a public body) and LABIS UCA:
- LABIS UCA is not a sujeto obligado under Ley 27.275 unless it receives public funds for the EPPA work, in which case it may be obligated to disclose certain non-personal information (research outputs, aggregated datasets, methodology).
- Sensitive personal data remains protected under Ley 25.326 and is excepted from disclosure under Ley 27.275 Art. 8 inc. i (data exception).
The interaction is therefore manageable: research-output transparency without disclosure of individual records.
10. Sanctions regime (Art. 31, Disp. AAIP 71/2010)¶
| Class | Violation | Sanction |
|---|---|---|
| Apercibimiento | Minor breach | Warning |
| Multa | Various breaches | ARS [TBD — Disp. AAIP 71/2010 amended several times for inflation] |
| Suspensión | Severe / repeat | Suspension of the database |
| Clausura | Highly severe | Closure of the database |
| Cancelación | Final | Cancellation of the database from the register |
Note that ARS amounts are periodically updated by AAIP resolution due to inflation; verify the current schedule before sign-off.
11. Open questions¶
- Confirm Ley modernisation status. Project of law modernising Ley 25.326 (drafted to align with GDPR) — monitor parliamentary status.
- Confirm AAIP registration scope. Whether the audit log requires a separate database entry or is covered by the clinical-store entry.
- Confirm international transfer to US hosting. If US hosting is in scope, prepare Resolución AAIP 159/2018 Modelo B at engagement time.
- Confirm sanctions schedule. Current ARS amounts under the latest AAIP resolution.
References¶
- Ley 25.326 — Protección de los Datos Personales — https://www.argentina.gob.ar/normativa/nacional/ley-25326-64790
- Decreto 1558/2001 (Reglamentación) — https://www.argentina.gob.ar/normativa/nacional/decreto-1558-2001-70368
- Disposición DNPDP 11/2006 (security measures) — https://www.argentina.gob.ar/normativa/nacional/disposici%C3%B3n-11-2006-119249
- Resolución AAIP 159/2018 (international transfers) — https://www.argentina.gob.ar/normativa/nacional/resoluci%C3%B3n-159-2018-316329
- Resolución AAIP 47/2018 (best practices) — https://www.argentina.gob.ar/normativa/nacional/resoluci%C3%B3n-47-2018-312662
- Disposición AAIP 71/2010 (sanctions regime) — https://www.argentina.gob.ar/normativa/nacional
- Ley 26.529 — Derechos del paciente — https://www.argentina.gob.ar/normativa/nacional/ley-26529-160432
- Ley 27.275 — Acceso a la información pública — https://www.argentina.gob.ar/normativa/nacional/ley-27275-265949
- AAIP — Agencia de Acceso a la Información Pública — https://www.argentina.gob.ar/aaip
- AAIP — Registro Nacional de Bases de Datos — https://www.argentina.gob.ar/aaip/datospersonales/registrobasesdatos
- EU Commission Decision 2003/490/EC (adequacy of Argentina) — https://eur-lex.europa.eu/eli/dec/2003/490/oj
- ANMAT Disp. 2318/2002 — https://www.argentina.gob.ar/normativa/nacional/disposici%C3%B3n-2318-2002-anmat-73892