CiberLATAMbywhalemate

Paraguay revisits cyber law debate

Gaspar renewed criticism of Paraguay’s draft cyber law, citing the lack of a national CERT, mandatory incident reporting and state funding.

Whalemate Labs · AI-assisted researchPublished:Updated 5 min read

Miguel Ángel Gaspar renewed criticism of Paraguay’s draft Cybersecurity Law and linked it to the delay in the full enforcement of the Personal Data Protection Law, now expected only in November 2027. The debate also returned to the lack of a national CERT, mandatory incident reporting and budget for the area.

Update August 29, 2026: Miguel Ángel Gaspar added public criticism of the draft Cybersecurity Law and tied it to the delay in the full enforcement of the Personal Data Protection Law, now scheduled for November 2027. Questions also intensified around bill D-2585561 and gaps such as the lack of an institutionalized national CERT, mandatory incident reporting and dedicated state funding for cybersecurity.

Miguel Ángel Gaspar has again put Paraguay’s draft Cybersecurity Law in the spotlight, linking it to the slow rollout of the Personal Data Protection Law, which, according to Última Hora, has already been approved but will not take full effect until November 2027. That timeline leaves lawmakers discussing cybersecurity rules in a long interim period without a fully formed legal framework for several compliance duties.

What happened in the Senate with the anti-cyberbullying bill?

The Senate’s Commission on Family, Children, Adolescents and Youth held an interinstitutional technical roundtable to review the bill that would prevent and punish school bullying and cyberbullying in educational institutions. The group proposed changes and agreed to meet again to discuss them.

The bill was introduced by Senator Lizarella Valiente of the ANR on April 20, 2026. According to 1000 Noticias, it aims to update the current rules on bullying and cyberbullying in early childhood, primary and secondary education. The fact that lawmakers asked for changes and scheduled another meeting shows the text is still under review and has not reached a final decision.

What did the Chamber of Deputies decide on the future Cybersecurity Law?

The Chamber of Deputies agreed to set up an interinstitutional technical roundtable to work on changes to the Cybersecurity Law draft and make the future law, according to the chamber’s own coverage, 100% enforceable.

The lower house said the initiative seeks to create a comprehensive legal framework to prevent, detect and respond to cyber threats and incidents, while protecting computer systems, information and critical infrastructure in the country. ABC Color also reported that during the public hearing several deputies demanded that the technical roundtable’s work be respected and criticized what happened with the Personal Data Protection Law, where, they said, the ruling majority discarded two years of debate to impose an alternative version that arrived the same day as the session.

The draft Cybersecurity Law was also discussed at a public hearing on Monday, August 17, 2026, in Congress, where different technical sectors took part. According to ABC Color and the Chamber of Deputies’ coverage, the initiative is still under study and the hearing ended with a call for another working group to keep reviewing the text.

La Tribuna later added another layer to the debate over bill D-2585561. In its analysis, the initiative goes beyond defending critical systems and also seeks to cover critical infrastructure, tariffs, military doctrine, artificial intelligence and nanotechnology, which shows the text is still being debated publicly.

That same article argued that the law should institutionalize a national CERT, require incident reporting for critical infrastructure and assign a specific budget to state cybersecurity. It also suggested, as a reasonable floor, setting aside 20% of FONTIC. These are opinion-based observations, but they reflect that the draft is still open to change and the debate is not over.

What regulatory gaps are showing up in the debate?

The debate exposed three concrete gaps, according to La Tribuna and Gaspar’s remarks in Última Hora: Paraguay has no national CERT institutionalized by law, there is no clear legal duty to report incidents in critical infrastructure, and there is no genuine, dedicated budget for state cybersecurity.

Gaspar also tied that picture to the Personal Data Protection Law, because the law has been passed but is still not fully operative. For the specialist, that leaves a long stretch in which data processing is not subject to full compliance obligations similar to standards such as the GDPR.

The combination of a Cybersecurity Law still under discussion and a data law delayed until November 2027 also affects compliance. Rules on incidents, the institutionalization of a national CERT and oversight of artificial intelligence in personal data processing remain fragmented and depend more on general rules, sector policies and voluntary best practices than on specific legal mandates.

How does this intersect with the personal data law and AI?

Law No. 7,593/2025 on Personal Data Protection was enacted as the country’s first comprehensive data law, but it is not yet fully in force and is expected to become enforceable only in November 2027, after a two-year vacatio legis.

According to the legal analysis by Diego Ceredi, the law is inspired by Europe’s GDPR and creates the National Personal Data Protection Agency, under MITIC, with inspection powers and administrative sanction authority. The same analysis says the planned fines range from 20 to 2,500 minimum wage units for general offenses, rise to 5,000 units when sensitive data is involved, and reach 10,000 units when violations affect the data of children and adolescents.

Economía Virtual Paraguay also reported that while Law 7,593/2025 waits for full implementation, two bills aimed at regulating artificial intelligence are being studied in Congress, and no specific AI law has yet been enacted. In the same vein, La Nación Paraguay said a bill to regulate and promote the creation, development, innovation and implementation of AI systems was introduced in the Senate in May 2025, with risk classification, prevention and mitigation measures, and protections for affected individuals’ rights.

Diario Libre added that the new legislative session included bills related to justice, water, cybersecurity and artificial intelligence, and that the president of the Chamber of Deputies stressed the need for specific AI legislation because of its impact on education, health, employment, justice, security and public services.

The public debate also picked up a social media criticism, where Gaspar described the draft as an attempt to "regulate Ironman." The phrase sharpened objections about the scope of bill D-2585561 and about the drafting approach used to cover advanced technologies without a clear breakdown of responsibilities.

Sources

View all