Skip to content

El Salvador's new Personal Data Protection Law: key points for businesses

LegalOctober 29, 2025

The entry into force of the Personal Data Protection Law sets new rules for organizations that collect, store or use personal information in El Salvador. The law seeks to strengthen privacy and informational self-determination, establishing responsibilities for both public and private entities.

For companies, this means reviewing how they obtain, use, store and protect the data of clients, employees, suppliers and third parties. Compliance is no longer limited to having a privacy policy: it also involves setting up processes and measures to manage information properly.

Its main provisions include informed consent, protection of sensitive data, implementation of security measures, handling of data subjects' rights and notification of security incidents.

Who does the new law apply to?

The law covers a range of organizations that carry out activities involving the processing of personal data.


Public entities: Includes State bodies, municipalities and other institutions that manage public resources or assets

Private companies and individuals: Applies to companies and individuals who collect, store or process personal data for commercial or professional purposes.

Contracted third parties: It also covers those who process data on behalf of another organization, for example, suppliers that handle personal information for a company.

Some specific types of processing, such as those related to public security or official registries, fall outside the scope defined in the law.

The law's main principles

The law sets out a series of principles that should guide the processing of personal data:

  • Informed consent
  • Transparency
  • Data minimization
  • Information security
  • Demonstrated accountability

These principles aim to ensure that organizations not only collect information properly, but can also show they have controls in place to protect it and use it correctly.

Data subjects' rights: ARCO-POL

One of the core elements of the law is the set of ARCO-POL rights, which give people greater control over their personal information:

Access · Rectification · Cancellation · Objection · Portability · Erasure · Restriction

Organizations will need mechanisms to receive and handle requests related to these rights.


What will companies have to do?

Compliance means bringing these principles into day-to-day operations. The main obligations include:

01. Appoint a Data Protection Officer

This officer will oversee compliance with the law, handle requests from data subjects and act as the liaison with the State Cybersecurity Agency (ACE).

02. Obtain proper consent

Before collecting or processing personal data, the data subject's free, informed and specific consent must be obtained. For sensitive data, the source notes that consent must be given in writing.

03. Protect the information

Organizations must implement technological and organizational measures to prevent unauthorized access, loss or alteration of data.

04. Respond to data subjects' rights

Effective mechanisms will be needed so that people can exercise their rights over their data.

05. Manage security incidents

In the event of a data breach, data controllers must notify the ACE and the affected data subjects within the deadline set by the law: 72 hours.

06. Provide privacy notices

Policies and notices must clearly explain how data is collected and used, and what rights data subjects have.

A new challenge for business management

Data protection doesn't depend solely on the legal or IT department. It can involve contracts, internal processes, human resources, systems, suppliers and risk management. That's why a company that collects personal information should start by identifying what data it handles, who has access to it, where it is stored and what it is used for.

How to start preparing?

Before making changes, organizations can begin with an assessment of their current situation.

01. Identify your data
Determine what personal information your company collects, where it is kept and how it is used.

02. Review your processes
Analyze who can access the information and what measures are currently in place to protect it.

03. Update contracts and notices
Review agreements with employees, clients and suppliers, as well as your privacy policies and notices.

04. Prepare your team
Data protection also depends on the people who handle information understanding their responsibilities.

05. Define what to do in an incident
Set up protocols to detect, manage and report potential breaches.

06. Document the processing
Keep a record of activities related to the processing of personal data.


Implementation timeline

The law provides for different stages of application:

  • 3 months: the ACE must issue the necessary guidelines.
  • 3 additional months: obligated parties must adapt their processes and policies.
  • 6 months: the mechanisms needed to exercise ARCO-POL rights must be in place.

This makes it important for companies to start reviewing their processes early rather than waiting for an incident to act.


What does this mean for your company?

Data protection is becoming one more part of business management. Clear processes can help reduce risks, strengthen the trust of clients and business partners, and show that information is handled responsibly.

At CENTR4L we can help you review how your company collects, uses and protects personal data, identifying the legal and operational adjustments you need to make.

Is your company ready for the new law?

Let's talk and review what you need to adjust.

News and Success Stories

Related Trends and Results

The UIF updates its registry of Obligated Entities: what changes for your company?
LegalFebruary 17, 2026

The UIF updates its registry of Obligated Entities: what changes for your company?

The UIF updated its registry of Obligated Entities on its own initiative under the new Special Law for the Prevention, Control and Punishment of ML/TF/PF. Some sectors were deregistered, while others keep their compliance obligations.

El Salvador eliminates the 10% tariff on exports to the United States
LegalJanuary 29, 2026

El Salvador eliminates the 10% tariff on exports to the United States

El Salvador and the United States ratified a Reciprocal Trade Agreement that eliminates the 10% tariff on Salvadoran exports to the U.S. market, opening new opportunities for exporters and investors.

What does your company gain by outsourcing payroll and Human Resources?
Human ResourcesAugust 29, 2024

What does your company gain by outsourcing payroll and Human Resources?

Outsourcing payroll and Human Resources can reduce administrative workload, make labor compliance easier and give access to specialized talent, while the company stays focused on its operations.

When is a service performed in El Salvador considered an export?
AccountingJuly 22, 2024

When is a service performed in El Salvador considered an export?

Not every service provided from El Salvador qualifies as an export. Specific conditions apply regarding where it is performed, who contracts it and, above all, where the service is used and enjoyed.