The legal framework
Article 43 of the Constitution (1994) enshrines the action of habeas data (hábeas data), and Law 25.326 (2000), implemented by Decree 1558/2001, governs the processing of personal data by public and private bodies: free, express and informed consent (in writing or by equivalent means); a ban on processing sensitive data (sexual orientation, health, beliefs) without consent or a legal basis; rights of access (reply within 10 days), rectification, updating and deletion (within 5 days); registration of databases with the authority; and sanctions ranging from a warning to fines of up to 100,000 pesos (raised by resolution to higher but still modest amounts), suspension and the closure of databases. The Agencia de Acceso a la Información Pública (AAIP, the agency for access to public information), the authority since 2017, issues resolutions (2018 on biometric data and consent, 2023 on cookies) and receives complaints; the European Union recognised Argentina's adequacy in 2003. In 2022 the Supreme Court rejected a 'right to be forgotten' for lawful information of public interest (Denegri). Law 27.736 (October 2023, Argentina's 'Ley Olimpia') added digital violence to Law 26.485: the dissemination of intimate images, harassment and impersonation as violence against women, with removal measures ordered by a judge; there is no separate offence of disseminating intimate images of adults (several bills), except the production and dissemination of images of minors (article 128 of the Código Penal, the Penal Code) and extortion. A bill for a new data protection law aligned with the GDPR (independent authority, proportionate fines, data breaches) was sent to Congress in 2023 and has not been debated; the government elected in 2023 cut the AAIP's resources.
In 2003 Argentina became the first country in Latin America recognised as 'adequate' by the European Commission, a decision reviewed in 2024 and kept; the UK retained the EU's existing adequacy decisions when it left the EU. Personal data can therefore move freely from the UK — and from Ireland, as an EU member — to Argentina without special contractual clauses: this is what allows the Argentine subsidiaries of British groups, UK dating sites and Argentine platforms used by Britons to operate without transfer formalities. The 2000 law is nevertheless far less protective than the UK GDPR: modest fines, registration of databases rather than accountability, no general duty to report data breaches, and a regulator whose budget was cut in 2024. Its strengths lie elsewhere: access within 10 days and deletion within 5 — shorter than the GDPR's month — and the constitutional action of habeas data, a quick court remedy with no direct British equivalent.
A British or Irish resident who uses an Argentine service (a dating app, a bank, a university) has the Argentine rights — access, deletion, habeas data — and, if the service is established in the UK or the EU or targets those markets, the protection of the UK GDPR or the GDPR as well, with complaints to the ICO (the Information Commissioner's Office) or to Ireland's Data Protection Commission. For the sharing of intimate images, the UK and Ireland are better armed than Argentina: sharing an intimate image without consent is an offence throughout the UK (in England and Wales under the Sexual Offences Act 2003 as amended by the Online Safety Act 2023), and in Ireland under 'Coco's Law' of 2020, whereas in Argentina the civil route of digital violence and the offence of extortion are the only levers where the victim is an adult. A victim living in the UK can report to the UK police even if the perpetrator is in Argentina, although any investigation then depends on cooperation with Argentina.
Key points
| Law | Law 25.326 (2000) and Decree 1558/2001; constitutional habeas data (article 43); EU adequacy since 2003, recognised by the UK |
|---|---|
| Authority | Agencia de Acceso a la Información Pública (AAIP); register of databases |
| Rights | Access (10 days), rectification, updating, deletion (5 days); express consent; sensitive data protected |
| Sanctions | Warning, suspension, modest fines updated by resolution; closure of databases |
| Intimate images | Digital violence under Law 26.485 (Law 27.736, 2023): removal measures ordered by a judge; no separate offence for adults; article 128 for minors |
| Right to be forgotten | Rejected by the Supreme Court for lawful information of public interest (Denegri, 2022) |
| Figures | About 500 complaints a year to the AAIP; thousands of calls about digital violence to the Línea 144 |
| British and Irish residents | Argentine rights against Argentine companies; UK GDPR or GDPR against companies in or targeting the UK or the EU (ICO, Data Protection Commission); sharing intimate images an offence in the UK and Ireland |
In practice
- Exercise your rights of access and deletion with the company (email or form), which must reply within 10 and 5 days; without a reply, complain free of charge to the AAIP or bring an action of habeas data before a judge (quick, and without a compulsory lawyer in some jurisdictions).
- Faced with an intimate image shared without consent: gather the evidence, report to the prosecutor or the UFECI, ask the civil or family judge for the removal measures of Law 26.485 (digital violence) and notify the platform; the Línea 144 gives guidance. From the UK, the Revenge Porn Helpline helps with removal from platforms.
- If the person sharing the images demands money (sextortion), it is extortion (article 168, 5 to 10 years): report it and do not pay.
- Ask a dating app for access to your data and for its deletion when you close the account; foreign apps are subject to the Argentine law if they process residents' data.
- Check in the AAIP's Registro Nacional de Bases de Datos (national register of databases) whether a company is registered; Defensa del Consumidor also receives complaints. Against a UK company, complain to the ICO; against one established in Ireland, as several large platforms are, to the Data Protection Commission.
Cost and coverage
Exercising your rights and complaining to the AAIP are free; habeas data with a reduced court fee; private lawyers for damages claims. Complaints to the ICO and to the Data Protection Commission are free.
Recent changes
Law 27.736 (2023) introduced digital violence; the 2023 bill for a new data law has not been debated; the AAIP issued resolutions on cookies and artificial intelligence in 2023-2024; the government cut the AAIP's budget in 2024; the EU's adequacy decision was reviewed in 2024 and kept.
Where to go
- AAIP — Agencia de Acceso a la Información Pública: complaints and register of databases (argentina.gob.ar/aaip).
- Línea 144: gender violence, including digital violence; UFECI: reports of image sharing and extortion.
- Asociación por los Derechos Civiles (ADC) and Vía Libre: digital rights.
- In the UK: the ICO (ico.org.uk) and the Revenge Porn Helpline; in Ireland: the Data Protection Commission; British Embassy in Buenos Aires: lists of lawyers; Irish citizens: Embassy of Ireland in Buenos Aires.
Worth knowing
Argentina has a 2000 law recognised by Europe, but with symbolic fines and no offence of sharing intimate images of adults: real protection runs through the courts (habeas data, interim measures for digital violence) more than through the regulator. The Supreme Court recognises no right to be forgotten for true facts of public interest. And a British or Irish victim of image-based abuse has stronger criminal protection at home than in Argentina: report in both countries.
Frequently asked questions
Can an Argentine company receive my data from the UK?
Yes, without special formalities: the EU recognised Argentina as adequate in 2003, and the UK kept that decision after leaving the EU, so transfers from the UK and Ireland are treated as safe without extra contractual clauses. The Argentine company remains bound by Law 25.326 and, if it targets the UK market, by the UK GDPR; the ICO remains competent for a complaint from a UK resident.
My ex, in Argentina, has shared intimate photos of me — what can I do?
From the UK or Ireland: report to the police, since sharing intimate images without consent is an offence throughout the UK and, in Ireland, under Coco's Law; in the UK, the Revenge Porn Helpline helps with the platforms. In Argentina: report to the UFECI and, if you are a woman, ask the judge for removal measures for digital violence (Law 27.736); in case of blackmail, report extortion. Both procedures can run in parallel; gather the evidence first and do not negotiate with the person sharing the images.
How do I get my data deleted from an Argentine dating app?
By a written request to the app (email or form), which must reply within five days under Law 25.326; failing that, a free complaint to the AAIP or an action of habeas data before a judge. An app that also offers its services in the UK or the EU is subject to the UK GDPR or the GDPR as well: the request can rely on the right to erasure (article 17) and, if refused, go to the ICO or the Data Protection Commission.
Official sources and links
- Law 25.326 — protection of personal data — official text
- Law 27.736 — digital violence (Ley Olimpia) — official text
- AAIP — Agencia de Acceso a la Información Pública — complaints and guides
- ICO — make a complaint — UK regulator
- argentina.gob.ar — official portal of the Argentine state: procedures, civil registry, migration, health, justice
- Normativa nacional (InfoLeg) — official texts of Argentine laws and decrees
- British Embassy Buenos Aires — gov.uk — consular help, notarial and documentary services for British nationals in Argentina
