Types of audits in El Salvador: objectives, scope and regulatory framework
New Personal Data Protection Law in El Salvador: Keys to its Compliance and Enforcement
The following is an exhaustive analysis of the main points, the obligated parties and practical recommendations to facilitate compliance with these regulations.
General Summary of the Personal Data Protection Law
- Informed consent,
- Transparency,
- Data minimization,
- Information security,
- and demonstrated responsibility.
These pillars grant citizens fundamental rights known as ARCO-POL rights(Access, Rectification, Cancellation, Opposition, Portability, Forgetfulness and Limitation), which allow them to manage their personal information effectively.
Most relevant provisions of the law:
- Obligation to notify any security breach within 72 hours of its detection.
- Strict regulation of the treatment of sensitive data, such as those related to health, political affiliations or religious beliefs.
- Classification of infractions as minor, serious and very serious, with penalties proportional to the level of non-compliance.
- Regulation of international data transfer, allowing it only to countries with an adequate level of protection.
Scope and Obligated Parties
1. Public Entities
2. Private Entities
Contracted Third Parties
Note: Some specific processing operations, such as those related to public security or official records, are outside the scope of this regulation.
Main Obligations of the Obligated Entities
1. Designation of a Data Protection Officer
2. Obtaining Consent
3. Implementation of Security Measures
4. Ensuring ARCO-POL Rights
5. Security Incident Notification
6. Elaboration of Privacy Policies
Timeline and Implementation Schedule
- Issuance of guidelines: The ACE must issue the necessary guidelines within three months of the law's entry into force.
- Adequacy of entities: Obligated entities have an additional three months to adjust their processes and policies.
- Enabling ARCO-POL mechanisms: Organizations have six months to ensure that holders can fully exercise their rights.
Important: The Personal Data Protection Law is based on articles 1 and 2 of the Constitution of El Salvador, which protect privacy, honor and moral integrity. In addition, it is aligned with international standards, strengthening the integration of El Salvador in the global environment of data protection.
Practical Recommendations for Compliance
1. Perform a Data Diagnostic
2. Internal Training
3. Review Contracts
4. Update Privacy Notices
5. Establish Response Protocols
6. Maintain a Treatment Record
Conclusion
We invite all organizations to start adapting to this regulation. If you need guidance or specialized support, our team is available to assist you.
At Centr4l, we are ready to help you take your business to the next level. Contact us today and find out how our legal solutions can transform your business management.