Data & Privacy · El Salvador
Data protection & privacy law in El Salvador (2026)
El Salvador shaded by its data & privacy status
Data protection in El Salvador: comprehensive law.
FrameworkLey de Protección de Datos Personales, Decreto Legislativo No. 144 (November 12, 2024; in force November 23, 2024), enforced by the Agencia de Ciberseguridad del Estado (ACE), established by the companion Ley de Ciberseguridad y Seguridad de la Información, Decreto Legislativo No. 143
El Salvador enacted its first comprehensive personal-data protection law (Decreto 144) in November 2024, covering both public and private sector entities that process personal data within or outside national territory. The law is modelled on GDPR-style principles, lawful basis, data minimisation, transparency, accountability, and grants data subjects ARCO-POL rights. Enforcement and supervision are delegated to the newly created State Cybersecurity Agency (ACE).
Key points
Legislative Decree No. 144 was approved on 12 November 2024, published in the Diario Oficial on 15 November 2024, and entered into force on 23 November 2024, making El Salvador the first Central American country with both a data-protection and a cybersecurity law simultaneously enacted.
The Agencia de Ciberseguridad del Estado (ACE), created by Decreto No. 143, is the sole supervisory body; it controls, inspects, and sanctions obligated entities, issues binding guidelines within three months of the law's effective date, and manages data-protection certification seals.
The law recognises six rights: Access, Rectification, Cancellation, Opposition, Portability, and the right to be Forgotten/Limitation (Olvido y Limitación). Entities must enable full exercise of these rights within six months of the law's effective date.
Obligated entities must: appoint a Data Protection Officer; obtain informed (written for sensitive data) consent before processing; implement technical and organisational security measures; and notify the ACE, the Attorney General's Office, and affected individuals of a data breach within 72 hours.
Cross-border transfers are permitted only when the destination country guarantees a level of protection equivalent to or greater than that of El Salvador; transfers to third parties generally require the data subject's express consent.
Administrative fines range from approximately USD 408.80 (minor infractions) to USD 16,352 (serious infractions), calibrated by gravity, recurrence, and damage caused; the ACE is the sanctioning authority.
Timeline - major decisions & events
Parliament approved a $12 million budget transfer to stand up the Agencia de Ciberseguridad del Estado (ACE), the authority designated under Decree 143/144 to enforce the data-protection and cybersecurity laws. ACE must issue implementing regulations within three months of becoming operational.
Asamblea Legislativa de El Salvador ↗HRW published a detailed report arguing that Decree 144's sweeping 'right to erasure' of online content deemed 'inadequate' and Decree 143's surveillance powers threaten independent journalism and political opposition. Civil-society organizations filed complementary objections with the Legislative Assembly.
Human Rights Watch ↗El Salvador's first comprehensive data-protection statute took effect, conferring ARCO-POL rights (access, rectification, cancellation, opposition, portability, erasure, limitation), requiring mandatory Data Protection Officers, regulating cross-border transfers, and designating ACE as the sanctioning supervisory authority for both public and private sectors.
Asamblea Legislativa de El Salvador – Decreto No. 144 ↗With 57 votes in favour, the Asamblea approved both instruments published in Official Gazette No. 219, Vol. 445 on 15 November 2024, making El Salvador the first Central American country to enact a dedicated cybersecurity law alongside a standalone personal-data protection regime.
Asamblea Legislativa de El Salvador ↗Hacking group CiberInteligenciaSV published source code of the state Bitcoin-ATM network and internal VPN access credentials on BreachForums; the Bukele government issued no public statement, exposing the absence of a mandatory breach-notification framework and amplifying calls for data-protection legislation.
The Block ↗CiberInteligenciaSV leaked a 144 GB database containing full names, national ID numbers, birth dates, home addresses, and high-resolution facial photographs of approximately 5.1 million adults — nearly the entire adult population — gathered during Chivo wallet KYC onboarding. No law at that time required the government to notify affected individuals.
The Cryptonomist ↗The Instituto de Acceso a la Información Pública adopted a binding resolution tightening data-minimisation, access, and disclosure obligations for government agencies under the LAIP framework — the most substantive regulatory action on data protection between the 2021 veto and the 2024 statute.
IAIP / Centro de Documentación Judicial de El Salvador ↗Legislative Decree No. 57 (June 2021) made Bitcoin legal tender and backed the Chivo wallet, whose KYC onboarding collected biometric photographs, national ID numbers, and addresses from citizens at national scale. This mass data collection occurred with no sector-specific data-protection statute in place following the May 2021 veto.
Banco Central de Reserva de El Salvador ↗Bukele returned the bill passed by the outgoing assembly on 22 April 2021, citing misalignment with the broader legal framework, lack of technical expertise in the proposed supervisory authority, and no budget appropriation. The veto left El Salvador without a dedicated data-protection statute for three years.
El Salvador.com ↗The pre-Bukele legislature approved a comprehensive GDPR-inspired personal data protection bill days before the new Nuevas Ideas-dominated assembly was sworn in; the bill was subsequently vetoed, marking the start of a three-year legislative gap during which large-scale biometric data collection began via Chivo.
VOCES Diario Digital (El Salvador) ↗The constitutional chamber elaborated on Article 2 protections, holding that citizens have judicially enforceable rights to control how personal data held by third parties is collected, stored, and transmitted. This ruling became the primary legal instrument for data-rights claims in the absence of a dedicated statute.
Sala de lo Constitucional – Corte Suprema de Justicia de El Salvador ↗Legislative Decree No. 534 (approved 2 December 2010) was published in Official Gazette No. 70, Vol. 391, creating the first legal framework governing personal data held by public bodies and establishing the IAIP as El Salvador's inaugural data-rights oversight institution; the implementing regulation followed in September 2011.
Fiscalía General de la República de El Salvador – LAIP Text ↗The constitutional chamber held that Article 2 of the 1983 Constitution shields individuals against arbitrary use of their personal data in public or private records, establishing the constitutional foundation for data-rights litigation and shaping jurisprudence for the two decades before a dedicated statute was enacted.
Sala de lo Constitucional – Corte Suprema de Justicia de El Salvador ↗The 1983 Constitution guaranteed every person the right to honour, personal and family privacy, and self-image under Article 2. This clause served as the sole constitutional anchor for data-protection and privacy claims for four decades until dedicated legislation was finally enacted in 2024.
OAS – Constitución de la República de El Salvador (1983) ↗El Salvador - other topics
Data & Privacy in other countries
Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →