Peru advances on cybersecurity without a general law
Peru’s Congress is adding cybersecurity initiatives, but a general law with binding obligations is still pending.
Peru’s Congress added digital security and national cybersecurity to the 2026-2027 work plan of its Science, Innovation, Technology and Digital Society Committee. The move adds to other political signals, but no general cybersecurity law has been approved yet.
Peru’s Congress has added digital security and national cybersecurity to the 2026-2027 work plan of its Science, Innovation, Technology and Digital Society Committee. The step adds to a series of legislative and political initiatives already underway, but Peru still does not have a general cybersecurity law with substantive obligations for the private sector.
What legislative initiatives are moving forward?
An Apaxi analysis published on 2026-09-07 says Peru’s Congress is considering several scattered proposals on the issue, including a ruling that declares the creation of a High-Level State Cybersecurity Committee to be of national interest. According to that source, the text covers bills 8842/2024-CR and 9906/2024-CR.
The same publication adds that there is also an initiative to declare November 30 National Cybersecurity Day, tied to bills 13415/2025-CR and 13511/2025-CR. Apaxi also says Peru does not have a general cybersecurity law and that the measure is still pending parliamentary review, with no ruling approving a substantive obligations regime.
What recent political signals reinforce that agenda?
Peru’s Congress, through the Chamber of Deputies’ Science, Innovation, Technology and Digital Society Committee, approved its work plan for the annual 2026-2027 session period and included digital security and national cybersecurity as lines of action, according to its official X account on 2026-09-08. The post did not announce a general cybersecurity law.
That comes on top of a report from Peru Informa saying Congress and Meta evaluated a strategic partnership to promote artificial intelligence and digital security, and agreed to work on a joint roadmap aimed at strengthening national cybersecurity. The outreach shows political attention to the issue, but it still does not translate into an integrated regulatory regime for the private sector.
Why could this move forward through the executive branch?
The executive branch submitted Bill 00098-2026-2031-CD to Congress, asking for delegated legislative powers for 120 days across eight broad areas, including cybersecurity and digital governance. That opens the door for part of the regulation to arrive through legislative decrees rather than only through a general law debated in Congress.
A legal analysis by Cuatrecasas of that bill says the executive wants to legislate through that route on cybersecurity, digital governance, open finance, and financial inclusion, and describes the request as very urgent. In parallel, TV Perú and the PCM reported that the government is adjusting the regulatory quality framework for rules issued under delegated powers, by requiring ex ante regulatory impact analysis deadlines to be counted in calendar days instead of business days, which could speed up rulemaking in those areas.
Sources
- Normas de ciberseguridad para empresas en el Perú (2026)apaxi.info· Apaxi
- Congreso y 'Meta' evalúan alianza estratégica para impulsar la inteligencia artificial y la seguridad digitalperuinforma.com· Perú Informa
- Publicación sobre la aprobación del Plan de Trabajo 2026-2027 de la Comisión de Ciencia, Innovación Tecnológica y Sociedad Digitalx.com· Congreso del Perú (cuenta oficial en X)
- Delegación de facultades: ¿un “caballo de Troya”?servindi.org· Idehpucp / Servindi
- Proyecto de delegación de facultades legislativascuatrecasas.com· Cuatrecasas
- Ejecutivo alista marco normativo ágil para evaluar las próximas normas de las facultades delegadastvperu.gob.pe· TV Perú / PCMUnverified URL



