CiberLATAMbywhalemate

Paraguay moves on data and critical infrastructure

A new data protection law and a critical infrastructure bill put banks and financial firms under new compliance and incident-reporting duties.

Whalemate Labs · AI-assisted researchPublished:3 min read

Paraguay is moving on two regulatory fronts that directly affect the financial sector: Personal Data Protection Law No. 7593/2025, which takes full effect on Nov. 27, 2027, and a critical infrastructure bill that includes banks and requires response plans and 12-hour incident reporting.

Paraguay is advancing two regulatory changes that directly affect the financial sector. On one side, Personal Data Protection Law No. 7593/2025 will take full effect on Nov. 27, 2027, with a 24-month compliance period for organizations. On the other, the Senate is considering a critical infrastructure protection bill that includes banks and requires security plans, response measures, and incident reporting.

What changes with the new data protection law?

Law No. 7593/2025 expands Paraguay’s privacy framework and complements Law No. 6534/2020, which remains in force for credit-related personal data, credit bureaus, and supervised entities, including financial system institutions. According to El Nacional, the new regime is aimed at a specialized supervisory authority and will require companies to review their data processing and privacy practices.

InfoNegocios Paraguay said the law applies to any organization that processes the data of natural persons, regardless of size or sector. Última Hora added that the highest fines can reach up to 10,000 minimum daily wages, while organizations will have 24 months to comply after the law takes effect. In a post on X, InfoNegocios Paraguay reiterated that deadline and said penalties can reach 10,000 wages in cases involving sensitive data on minors.

Why is the financial sector especially exposed?

Banks and other financial institutions are among the most closely watched actors because they handle large volumes of personal and credit data. El Nacional said the new law requires companies to review privacy and data processing practices, and that firms are entering a new phase of privacy with integrated data governance, cybersecurity, and compliance programs, not just isolated changes to legal language.

That view also appears in local coverage describing how financial institutions will need to begin compliance work in 2025 and 2026 ahead of full implementation in 2027. The focus is not only on the legal notice, but on operational readiness, with information security, data governance, and compliance now linked fronts.

What does the critical infrastructure bill require?

Paraguay’s critical infrastructure protection bill would require public and private operators of critical infrastructure to have security and response plans for failures or attacks. Caaguazú Noticias Digital said that banks and state digital services are among the covered infrastructures.

The same report said the proposal calls for a national cybersecurity council to design a national strategy for protecting critical infrastructure. It also includes a group of critical infrastructure operators, banks among them, that would have to report incidents within 12 hours of the event and take part in drills organized by the state.

Coverage from Última Hora and ADN Digital stressed that the goal is to improve the country’s readiness for cyberattacks, natural disasters, or technical failures that could disrupt essential services for the public, including financial services. In that framework, cybersecurity is no longer presented only as a compliance requirement, but as an operational duty.

What benchmarks are banks using?

Specialized digital risk outlets have been citing DORA and NIS2 as benchmarks for the financial sector. MuyComputerPRO said DORA, applicable since January 2025, requires structured ICT risk management, incident reporting, resilience testing, and oversight of critical vendors, while NIS2 expands cybersecurity obligations to 18 critical sectors and strengthens top management accountability and incident cooperation.

La República said those European frameworks are being used as benchmarks by banks and financial institutions in Latin America, including operations in Paraguay when they are part of groups with a presence in the European Union. In parallel, GPEE reported that the Central Bank of Paraguay’s rules on digital CDA instruments require financial institutions to migrate to a unified electronic registration platform, and La República added that those instruments are recorded within the Central Bank’s infrastructure. La Nación, meanwhile, reported that banks such as BASA are supporting the implementation of the dematerialization of savings deposit certificates.

Sources

View all