Data Protection and AI in Latin America: a country-by-country guide
If you're assessing your AI Governance maturity from Mexico City, São Paulo, or Santiago, the principles are the same as in the EU — but the name of the authority, the applicable law, and the deadlines are completely different. Here's what's actually in force today across 6 countries, verified one by one.
Why this matters now, not in the abstract
Most guides on data protection in LatAm circulating online have a problem: they take outdated information at face value. The clearest case is Mexico, where it's still common to read "check with INAI" when INAI hasn't existed for a year and a half. This guide is built on sources verified as of August 2026, country by country.
The landscape, at a glance
| Country | Data law | Authority | AI framework |
|---|---|---|---|
| Mexico | Federal / General Data Protection Law (2025) | Secretaría Anticorrupción y Buen Gobierno | No specific framework |
| Brazil | LGPD (Lei 13.709/2018) | ANPD | PL 2338 in progress |
| Argentina | Law 25.326 | AAIP | No specific framework |
| Colombia | Law 1581 of 2012 | SIC | Several bills, none approved |
| Chile | Law 21.719 (in force 1 Dec 2026) | Data Protection Agency (new) | Proposed AI Commission |
| Peru | Law 29733 + 2025 regulation | ANPDP | Law 31814 — in force ✓ |
Mexico — the change almost nobody has caught up on
On 28 November 2024, the Senate approved the "Organizational Simplification" reform, dissolving seven autonomous bodies, including INAI. On 20 February 2025, the new Federal Law on Protection of Personal Data Held by Private Parties and the General Law on Protection of Personal Data Held by Obligated Subjects were published, in force since 21 March 2025. Their functions moved to the Secretaría Anticorrupción y Buen Gobierno. ARCO rights and the substantive obligations didn't change materially — what changed is who you report to and who audits you.
Brazil — the LGPD and an ANPD with regional weight
The Lei Geral de Proteção de Dados (Lei 13.709/2018) remains the reference framework, with the ANPD as an active authority — it currently chairs the Ibero-American Data Protection Network (RIPD). Brazil doesn't yet have an approved AI law (bill PL 2338 is still in progress), but the ANPD has already published a preliminary study on generative AI as part of its technology radar — a sign the agency is preparing to regulate before a law exists.
Argentina — the AAIP and its role in regional coordination
Law 25.326 remains in force, with the Agencia de Acceso a la Información Pública (AAIP) as the authority. Argentina sits on the RIPD's executive committee and is leading the creation of the new Ibero-American Data Protection Observatory — a technical space for monitoring regulatory trends across the region. There is still no specific AI framework.
Colombia — the SIC as authority, no AI law yet
The Superintendencia de Industria y Comercio (SIC) regulates data protection under Law 1581 of 2012. On AI, several bills are in progress (PL 059/2023, PL 091/2023, PL 130/2023, PL 154/2024) but none has been approved — and only the latest even designates which agency would have jurisdiction.
Chile — the law that takes effect in 4 months
This is the most urgent of the six. Law 21.719 was published on 13 December 2024 and reaches full effect on 1 December 2026 — about four months from the date of this article. It replaces Law 19.628 (from 1999, with almost no enforcement power) and creates the Personal Data Protection Agency, with real authority to investigate on its own initiative, issue fines (up to 20,000 UTM, close to USD 1.4 million), and publish a public register of sanctions. It requires a DPO, a record of processing activities, DPIAs, and 72-hour breach notification — the same vocabulary as the European GDPR. SMEs get a one-year grace period with warnings only, no fines.
Peru — the first AI framework actually in force in LatAm
This is the fact least known outside Peru: Law 31814, approved in June 2023, and its implementing regulation (Supreme Decree 115-2025-PCM) have been in force since 22 January 2026. It's not a statement of intent — it classifies AI systems by risk level (including a prohibited "misuse" category, with mass biometric surveillance without a court order as an explicit example), requires principles of non-discrimination, privacy, and human oversight, and rolls out private-sector obligations in stages: health, education, justice, security, economy and finance first (10 September 2026), and the rest of the sectors through 2029.
On data protection, Peru also updated the regulation implementing Law 29733 in 2025 (Supreme Decree 016-2024-JUS, in force since 30 March 2025), adding the DPO figure and the right to data portability. The authority is the Autoridad Nacional de Protección de Datos Personales (ANPDP), under the Ministry of Justice.
What to do with this if you operate in several countries
- If you have a presence in Chile, prioritize it: the 1 December 2026 deadline isn't moving, and the grace period only applies to SMEs.
- If you use AI systems in Peru, check which sector you fall under — the enforcement timeline isn't the same for banking as it is for agriculture.
- If you operate in Mexico, update any internal document that still references INAI — citing it today is a sign the documentation hasn't been reviewed in over a year.
- The risk classification, data management, and human oversight methodology you've already built for the AI Act and GDPR serves as a foundation in all six countries — what changes is the name of the authority and some deadlines, not the principles.
Sources
Constitutional reform "Organizational Simplification," Official Gazette of the Federation of Mexico (20 December 2024); Federal Law and General Law on Protection of Personal Data of Mexico (Official Gazette, 20 February 2025); Law 21.719, Official Gazette of Chile (13 December 2024); Law 31814 and Supreme Decree 115-2025-PCM, El Peruano; Supreme Decree 016-2024-JUS, El Peruano.
The same principles, applicable in any country
Our free assessment and our risk classification and data governance templates are built on common regulatory principles — checkout shows the price in your local currency, wherever you buy from.