Skip to content
World Watch/Argentina/Cybersecurity

Cybersecurity · Argentina

Cybersecurity law & regulation in Argentina (2026)

Sectoral rulesCountry index 78 · B+

Argentina shaded by its cybersecurity status

Cybersecurity in Argentina: sectoral rules.

FrameworkSectoral patchwork anchored by Decree 941/2025 (Centro Nacional de Ciberseguridad — CNC) for public-sector cyber policy, BCRA Communication 'A' 8280 for the financial sector, ENACOM rules for telecoms, Resolution 580/2011 (Critical Information Infrastructure Program), Ley 26.388 (Cybercrime), and Ley 25.326 (Personal Data Protection). Overarching direction is set by the Second National Cybersecurity Strategy (Resolution 44/2023) and the Federal Plan for the Prevention of Cybercrime and Strategic Management of Cybersecurity (2025–2027).

Argentina does not yet have a single comprehensive NIS2-style cybersecurity law. Instead, obligations arise through sector-specific regulation — most prominently BCRA rules for banks and payment providers, and CNC Disposición 1/2026 setting technical requirements for the National Public Sector — layered on top of the 2008 cybercrime statute, the 2000 data-protection law (which still lacks a statutory breach-notification duty), and the Second National Cybersecurity Strategy approved in 2023. A new coordinating authority, the Centro Nacional de Ciberseguridad, was created by DNU 941/2025 (published 2 January 2026) and is progressively issuing binding technical rules.

Key points

National authority (CNC)

DNU 941/2025 (Boletín Oficial, 2 Jan 2026) created the Centro Nacional de Ciberseguridad as a decentralized agency within the Secretaría de Innovación, Ciencia y Tecnología of the Jefatura de Gabinete. The CNC is designated as national cybersecurity authority and Application Authority for the regulations in the field, tasked with protecting national cyberspace, critical information infrastructures and strategic digital assets of the National State.

Public-sector technical regulation

CNC Disposición 1/2026 approved a mandatory Technical Regulation for the entire National Public Sector (Ley 24.156), covering contingency policies, alternative data-processing centres and disaster-recovery plans. Covered entities have 180 days from entry into force to adapt infrastructure and submit a compliance report specifying RTO/RPO parameters and results of at least one failover test.

Financial sector — BCRA cyber incident reporting

BCRA Communication 'A' 8280 (October 2025) updated Guidelines for Response and Recovery from Cyber Incidents, mandatorily applicable to banks, payment service providers (digital wallets, aggregators, facilitators) and systemically important payment systems. Regulated entities must notify cyber incidents affecting service provision or the integrity/confidentiality/availability of information; critical incidents must be reported to the BCRA within one hour via [email protected].

Critical infrastructure program

Chief of Cabinet Resolution 580/2011 established the National Critical Information Infrastructure and Cybersecurity Program, identifying ICT, transport, energy, health, water, food, nuclear, banking, chemical and space sectors as critical. However, the resolution designates sectors but does not itself impose explicit binding cybersecurity obligations on operators — those largely depend on sectoral regulators such as BCRA and ENACOM.

Data breach notification — soft law only

Personal Data Protection Law 25.326 (2000) does not contain a statutory obligation to notify data breaches to the AAIP or affected individuals. AAIP Resolution 47/2018 only recommends notification as good practice and requires internal documentation of incidents. Argentina acceded to Convention 108+ via Law 27.699 (2022), which would impose a 72-hour notification duty, but it is not yet in force internationally; draft bills (S-0644/2025 and 1948-D-2025) propose introducing mandatory 72-hour notification but remain unenacted.

Cybercrime and national strategy

Law 26.388 (2008) inserted cybercrime offences into the Criminal Code, covering unauthorized access to data systems, interception of electronic communications, data-related fraud and child-abuse material online. The strategic overlay is Resolution 44/2023 (Second National Cybersecurity Strategy) and the Federal Plan for the Prevention of Cybercrime and Strategic Management of Cybersecurity (2025–2027), coordinating national, provincial and City of Buenos Aires action.

Timeline - major decisions & events

May 13, 2026guidanceofficial
National Cybersecurity Center issues Disposition 1/2026 on operational resilience

The newly created CNC set mandatory requirements for public agencies running data centers or technological infrastructure, covering continuity of operations, disaster recovery and digital resilience. It is the first binding rule from the new national cyber authority, giving agencies a compliance window to harden systems.

Boletín Oficial
Jan 2, 2026lawofficial
Decree 941/2025 creates the National Cybersecurity Center (CNC)

This DNU established the CNC as the national cybersecurity authority and application authority, consolidating incident response (CERT.AR), protection of critical information infrastructure and state digital assets under the Secretariat of Innovation, Science and Technology. It is the current cornerstone of Argentina's cyber governance.

Boletín Oficial
Dec 31, 2025lawofficial
Decreto 941/2025: Centro Nacional de Ciberseguridad (CNC) Created

President Milei signed a presidential decree creating the CNC as a decentralised entity under the Secretariat of Innovation, Science and Technology, separating civilian cybersecurity governance from intelligence functions and designating it the sole national cybersecurity authority and implementing body for all cybersecurity regulations.

Argentina.gob.ar – Normativa Nacional
Jan 8, 2025guidanceofficial
Resolución 19/2025: Federal Cybercrime Prevention Plan 2025-2027 Approved

The Ministry of Security adopted a three-year federal plan coordinating all security forces on cybercrime prevention, digital-forensic capacity-building, and regulatory modernisation; it invites all provincial governments and the City of Buenos Aires to formally adhere to the unified framework.

Boletín Oficial de la República Argentina
May 21, 2024decisionofficial
Resolución 50/2024: Management Unit for Second National Cybersecurity Strategy

The Chief of Cabinet formalised a dedicated Management and Cooperation Unit exclusively responsible for monitoring the Second Strategy's 42-action plan and assigned the Subsecretaría de Tecnologías de la Información as chair of the Cybersecurity Committee, accelerating implementation.

Boletín Oficial de la República Argentina
Oct 31, 2023guidanceofficial
AAIP Resolution 211/2023 sets information-security and breach-notification standards

The data protection authority approved a comprehensive information security policy framework (asset classification, access management, incident management, continuity) aligned with international 72-hour breach notification practice. It tightened obligations for entities handling personal data under Law 25.326.

Boletín Oficial / AAIP
Sep 1, 2023guidanceofficial
Second National Cybersecurity Strategy adopted (Resolution 44/2023)

The Public Innovation Secretariat approved Argentina's second national cybersecurity strategy and created the Cybersecurity Management and Cooperation Unit. It updated national objectives and governance structures established by the 2019 strategy.

Boletín Oficial
Nov 8, 2021enforcementofficial
AAIP opens ex-officio investigation into massive personal-data leak

Following the RENAPER breach, the data protection authority launched a formal probe into the alleged mass leak of citizens' personal data. It marked one of the most significant enforcement responses under the personal data protection regime.

AAIP
Oct 1, 2021incident
RENAPER national ID database breached

A hacker obtained ID-card data, names, addresses, birth dates and government photos, of effectively the entire Argentine population from the National Registry of Persons, after access via a Health Ministry VPN. The incident exposed weaknesses in the protection of state-held identity data.

The Record (Recorded Future)
Sep 1, 2021incident
RENAPER Database Breach: Identity Data of 45 Million Argentinians Exfiltrated

A threat actor used a compromised government VPN credential from another agency to access RENAPER (National Registry of Persons) and extract records on Argentina's entire population; the breach became public in October 2021 when biometric data of high-profile figures, including President Fernández, was posted on Twitter, triggering a congressional investigation.

Asociación por los Derechos Civiles (ADC)
Jul 9, 2021guidanceofficial
Administrative Decision 641/2021 sets minimum security requirements for the public sector

The government established mandatory minimum information-security requirements for national public-sector bodies, requiring each to adopt a risk-based information security policy reported to the National Cybersecurity Directorate. It became the baseline obligation for state agencies.

Argentina.gob.ar
Feb 22, 2021decisionofficial
Disposición 1/2021: CERT.ar National Incident Response Centre Established

Argentina created the Centro Nacional de Respuesta a Incidentes Informáticos (CERT.ar) under the Dirección Nacional de Ciberseguridad, replacing the legacy ONTI-based structure, and gave it a mandate to coordinate incident response across the public sector and critical information infrastructures nationally.

Boletín Oficial de la República Argentina
Jan 1, 2021guidanceofficial
Decisión Administrativa 641/2021: Minimum Information Security Requirements for Public Sector

This decision established mandatory baseline information security requirements (Requisitos Mínimos de Seguridad de la Información) for all entities of the National Public Sector, making cybersecurity compliance legally binding for government agencies for the first time.

InfoLEG – Ministerio de Justicia y Derechos Humanos
Sep 1, 2020incident
Netwalker ransomware halts immigration agency

Argentina's Dirección Nacional de Migraciones suffered a Netwalker ransomware attack that temporarily stopped border crossings, with attackers demanding a multimillion-dollar ransom. It was one of the highest-profile ransomware hits on Argentine government infrastructure.

BleepingComputer
May 28, 2019guidanceofficial
Resolución 829/2019: First National Cybersecurity Strategy Adopted

Argentina's Secretariat of Government of Modernization approved the country's inaugural National Cybersecurity Strategy, articulating principles for prevention, detection, response, and recovery, and establishing the Executive Unit of the Cybersecurity Committee to drive implementation.

Boletín Oficial de la República Argentina
May 24, 2019guidanceofficial
First National Cybersecurity Strategy approved (Resolution 829/2019)

Argentina adopted its first national cybersecurity strategy, defining guiding principles and central objectives for protecting national cyberspace. It laid the policy foundation for the country's modern cybersecurity framework.

UNODC
Jul 31, 2017lawofficial
Decreto 577/2017: National Cybersecurity Committee Created

President Macri's government established the Comité de Ciberseguridad under the Ministry of Modernization, the first dedicated national-level cybersecurity governance body, tasked with drafting Argentina's national cybersecurity strategy in coordination with the Ministries of Defense and Security.

Boletín Oficial de la República Argentina
Jul 28, 2017lawofficial
Decree 577/2017 creates the National Cybersecurity Committee

The executive established a Cybersecurity Committee tasked with drafting the National Cybersecurity Strategy, the first institutional step toward coordinated national cyber policy. It set the stage for the 2019 strategy.

Argentina.gob.ar
Jun 25, 2008lawofficial
Cybercrime Law 26.388 amends the Criminal Code

Argentina criminalized computer-related offenses, unauthorized access, computer fraud and damage, data interception, falsification of digital documents and distribution of malware, by reforming the Criminal Code. It remains the principal basis for prosecuting cyber offenses.

Argentina.gob.ar
Nov 2, 2000lawofficial
Personal Data Protection Law 25.326 (Habeas Data) enacted

Argentina established its foundational data protection regime, granting individuals rights over their personal data and imposing data-security duties on controllers, later overseen by the AAIP. It underpins data-security and breach obligations applicable to cybersecurity today.

Argentina.gob.ar
Oct 4, 2000lawofficial
Ley 25.326: Personal Data Protection Act Enacted

Argentina enacted one of Latin America's first comprehensive data protection statutes, establishing rights of access, rectification, and deletion over personal data held in public and private databases; the law later earned EU adequacy status (2003) and, enforced by the AAIP, remains the cornerstone data-security obligation, with a legislative reform draft pending in Congress since 2022.

InfoLEG – Ministerio de Justicia y Derechos Humanos

Argentina - other topics

Cybersecurity in other countries

Last verified 7/21/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →