CiberLATAMbywhalemate

Peru updates Personal Data Law 29733

DS 016-2024-JUS expands data handling duties in Peru and adds rules on minors and the national register.

Whalemate Labs · AI-assisted researchPublished:3 min read

Peru updated the rules for Law No. 29733 on personal data protection through Supreme Decree No. 016-2024-JUS, according to an academic analysis published by PUCP’s Derecho & Sociedad journal. The new text adds obligations for controllers, new rights for data subjects, and strengthens the security principle and demonstrated accountability.

Peru updated the regulations for Personal Data Protection Law No. 29733 through Supreme Decree No. 016-2024-JUS, according to an academic analysis published by PUCP’s Derecho & Sociedad journal. The reform adds new obligations for data controllers, new rights for data subjects, and reinforces both the security principle and demonstrated accountability.

What changes under the new regulation?

The new regulation broadens the compliance framework for anyone processing personal data in Peru and raises the diligence standard required by law. According to the PUCP analysis, the emphasis is on strengthening security and requiring accountability to be not just stated, but demonstrable.

That means organizations subject to the law must better organize their internal processes and back up with evidence how they manage data. The academic text places these changes within the regulatory update approved by DS 016-2024-JUS.

What records does the Peruvian regulation require?

Law No. 29733 and its regulation create the National Registry of Personal Data Protection to register public and private personal data banks, cross-border personal data flows, and the sanctions, interim measures, or corrective measures imposed by the data protection authority, according to Mi Firma Digital.

That registry concentrates regulatory information relevant to the country’s data processing ecosystem. It also serves as a traceability mechanism for databases and for decisions adopted by the competent authority.

How are minors’ data handled?

Publishing or processing minors’ data requires the prior, express, and informed consent of parents or legal guardians, under Law No. 29733 and its regulation, the Ethical Journalism Foundation in Peru noted. The regulation allows people over 14 to give their own consent only if the information is explained to them in plain language.

That standard raises the bar for media outlets, companies, and any actor handling information linked to minors. The requirement is not limited to obtaining permission, it also covers how the processing is explained.

What incident reporting appears in the discussion?

An analysis by Proactivanet on cybersecurity rules in 2026 says that Peru’s data protection authority requires incident notifications within 48 hours and that fines totaling 11 million soles would have been imposed, although the article does not provide a direct reference to the resolution or official register detailing those sanctions.

That part of the material should be read cautiously, since the source itself does not include the corresponding official citation. At the same time, the compliance angle is becoming more relevant for companies operating in Peru and Brazil, where different frameworks may apply, including Brazil’s LGPD, although the Peruvian rules cited here still do not mention the ANPD directly.

Sources

View all