Cybersecurity · Argentina
Cybersecurity law & regulation in Argentina (2026)
Argentina shaded by its cybersecurity status
Cybersecurity in Argentina: sectoral rules.
FrameworkSectoral patchwork anchored by Decree 941/2025 (Centro Nacional de Ciberseguridad — CNC) for public-sector cyber policy, BCRA Communication 'A' 8280 for the financial sector, ENACOM rules for telecoms, Resolution 580/2011 (Critical Information Infrastructure Program), Ley 26.388 (Cybercrime), and Ley 25.326 (Personal Data Protection). Overarching direction is set by the Second National Cybersecurity Strategy (Resolution 44/2023) and the Federal Plan for the Prevention of Cybercrime and Strategic Management of Cybersecurity (2025–2027).
Argentina does not yet have a single comprehensive NIS2-style cybersecurity law. Instead, obligations arise through sector-specific regulation — most prominently BCRA rules for banks and payment providers, and CNC Disposición 1/2026 setting technical requirements for the National Public Sector — layered on top of the 2008 cybercrime statute, the 2000 data-protection law (which still lacks a statutory breach-notification duty), and the Second National Cybersecurity Strategy approved in 2023. A new coordinating authority, the Centro Nacional de Ciberseguridad, was created by DNU 941/2025 (published 2 January 2026) and is progressively issuing binding technical rules.
Key points
DNU 941/2025 (Boletín Oficial, 2 Jan 2026) created the Centro Nacional de Ciberseguridad as a decentralized agency within the Secretaría de Innovación, Ciencia y Tecnología of the Jefatura de Gabinete. The CNC is designated as national cybersecurity authority and Application Authority for the regulations in the field, tasked with protecting national cyberspace, critical information infrastructures and strategic digital assets of the National State.
CNC Disposición 1/2026 approved a mandatory Technical Regulation for the entire National Public Sector (Ley 24.156), covering contingency policies, alternative data-processing centres and disaster-recovery plans. Covered entities have 180 days from entry into force to adapt infrastructure and submit a compliance report specifying RTO/RPO parameters and results of at least one failover test.
BCRA Communication 'A' 8280 (October 2025) updated Guidelines for Response and Recovery from Cyber Incidents, mandatorily applicable to banks, payment service providers (digital wallets, aggregators, facilitators) and systemically important payment systems. Regulated entities must notify cyber incidents affecting service provision or the integrity/confidentiality/availability of information; critical incidents must be reported to the BCRA within one hour via [email protected].
Chief of Cabinet Resolution 580/2011 established the National Critical Information Infrastructure and Cybersecurity Program, identifying ICT, transport, energy, health, water, food, nuclear, banking, chemical and space sectors as critical. However, the resolution designates sectors but does not itself impose explicit binding cybersecurity obligations on operators — those largely depend on sectoral regulators such as BCRA and ENACOM.
Personal Data Protection Law 25.326 (2000) does not contain a statutory obligation to notify data breaches to the AAIP or affected individuals. AAIP Resolution 47/2018 only recommends notification as good practice and requires internal documentation of incidents. Argentina acceded to Convention 108+ via Law 27.699 (2022), which would impose a 72-hour notification duty, but it is not yet in force internationally; draft bills (S-0644/2025 and 1948-D-2025) propose introducing mandatory 72-hour notification but remain unenacted.
Law 26.388 (2008) inserted cybercrime offences into the Criminal Code, covering unauthorized access to data systems, interception of electronic communications, data-related fraud and child-abuse material online. The strategic overlay is Resolution 44/2023 (Second National Cybersecurity Strategy) and the Federal Plan for the Prevention of Cybercrime and Strategic Management of Cybersecurity (2025–2027), coordinating national, provincial and City of Buenos Aires action.
Timeline - major decisions & events
The newly created CNC set mandatory requirements for public agencies running data centers or technological infrastructure, covering continuity of operations, disaster recovery and digital resilience. It is the first binding rule from the new national cyber authority, giving agencies a compliance window to harden systems.
Boletín Oficial ↗This DNU established the CNC as the national cybersecurity authority and application authority, consolidating incident response (CERT.AR), protection of critical information infrastructure and state digital assets under the Secretariat of Innovation, Science and Technology. It is the current cornerstone of Argentina's cyber governance.
Boletín Oficial ↗President Milei signed a presidential decree creating the CNC as a decentralised entity under the Secretariat of Innovation, Science and Technology, separating civilian cybersecurity governance from intelligence functions and designating it the sole national cybersecurity authority and implementing body for all cybersecurity regulations.
Argentina.gob.ar – Normativa Nacional ↗The Ministry of Security adopted a three-year federal plan coordinating all security forces on cybercrime prevention, digital-forensic capacity-building, and regulatory modernisation; it invites all provincial governments and the City of Buenos Aires to formally adhere to the unified framework.
Boletín Oficial de la República Argentina ↗The Chief of Cabinet formalised a dedicated Management and Cooperation Unit exclusively responsible for monitoring the Second Strategy's 42-action plan and assigned the Subsecretaría de Tecnologías de la Información as chair of the Cybersecurity Committee, accelerating implementation.
Boletín Oficial de la República Argentina ↗The data protection authority approved a comprehensive information security policy framework (asset classification, access management, incident management, continuity) aligned with international 72-hour breach notification practice. It tightened obligations for entities handling personal data under Law 25.326.
Boletín Oficial / AAIP ↗The Public Innovation Secretariat approved Argentina's second national cybersecurity strategy and created the Cybersecurity Management and Cooperation Unit. It updated national objectives and governance structures established by the 2019 strategy.
Boletín Oficial ↗Following the RENAPER breach, the data protection authority launched a formal probe into the alleged mass leak of citizens' personal data. It marked one of the most significant enforcement responses under the personal data protection regime.
AAIP ↗A hacker obtained ID-card data, names, addresses, birth dates and government photos, of effectively the entire Argentine population from the National Registry of Persons, after access via a Health Ministry VPN. The incident exposed weaknesses in the protection of state-held identity data.
The Record (Recorded Future) ↗A threat actor used a compromised government VPN credential from another agency to access RENAPER (National Registry of Persons) and extract records on Argentina's entire population; the breach became public in October 2021 when biometric data of high-profile figures, including President Fernández, was posted on Twitter, triggering a congressional investigation.
Asociación por los Derechos Civiles (ADC) ↗The government established mandatory minimum information-security requirements for national public-sector bodies, requiring each to adopt a risk-based information security policy reported to the National Cybersecurity Directorate. It became the baseline obligation for state agencies.
Argentina.gob.ar ↗Argentina created the Centro Nacional de Respuesta a Incidentes Informáticos (CERT.ar) under the Dirección Nacional de Ciberseguridad, replacing the legacy ONTI-based structure, and gave it a mandate to coordinate incident response across the public sector and critical information infrastructures nationally.
Boletín Oficial de la República Argentina ↗This decision established mandatory baseline information security requirements (Requisitos Mínimos de Seguridad de la Información) for all entities of the National Public Sector, making cybersecurity compliance legally binding for government agencies for the first time.
InfoLEG – Ministerio de Justicia y Derechos Humanos ↗Argentina's Dirección Nacional de Migraciones suffered a Netwalker ransomware attack that temporarily stopped border crossings, with attackers demanding a multimillion-dollar ransom. It was one of the highest-profile ransomware hits on Argentine government infrastructure.
BleepingComputer ↗Argentina's Secretariat of Government of Modernization approved the country's inaugural National Cybersecurity Strategy, articulating principles for prevention, detection, response, and recovery, and establishing the Executive Unit of the Cybersecurity Committee to drive implementation.
Boletín Oficial de la República Argentina ↗Argentina adopted its first national cybersecurity strategy, defining guiding principles and central objectives for protecting national cyberspace. It laid the policy foundation for the country's modern cybersecurity framework.
UNODC ↗President Macri's government established the Comité de Ciberseguridad under the Ministry of Modernization, the first dedicated national-level cybersecurity governance body, tasked with drafting Argentina's national cybersecurity strategy in coordination with the Ministries of Defense and Security.
Boletín Oficial de la República Argentina ↗The executive established a Cybersecurity Committee tasked with drafting the National Cybersecurity Strategy, the first institutional step toward coordinated national cyber policy. It set the stage for the 2019 strategy.
Argentina.gob.ar ↗Argentina criminalized computer-related offenses, unauthorized access, computer fraud and damage, data interception, falsification of digital documents and distribution of malware, by reforming the Criminal Code. It remains the principal basis for prosecuting cyber offenses.
Argentina.gob.ar ↗Argentina established its foundational data protection regime, granting individuals rights over their personal data and imposing data-security duties on controllers, later overseen by the AAIP. It underpins data-security and breach obligations applicable to cybersecurity today.
Argentina.gob.ar ↗Argentina enacted one of Latin America's first comprehensive data protection statutes, establishing rights of access, rectification, and deletion over personal data held in public and private databases; the law later earned EU adequacy status (2003) and, enforced by the AAIP, remains the cornerstone data-security obligation, with a legislative reform draft pending in Congress since 2022.
InfoLEG – Ministerio de Justicia y Derechos Humanos ↗Argentina - other topics
Cybersecurity in other countries
Last verified 7/21/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →