Peruvian Personal Data Protection Law (LPDP)
View Law TextNeed Help with Peruvian Personal Data Protection Law (LPDP) Compliance?
Get expert guidance on implementing Peru's data protection requirements and ensuring ongoing compliance for your organization.
Get Expert HelpOverview
The Personal Data Protection Law (LPDP) establishes comprehensive requirements for the protection of personal data in Peru, enforced by the National Authority for Personal Data Protection.
Key Facts
- Enacted in 2011
- Enforced by National Authority for Personal Data Protection
- Requires registration of databases
Key Principles
Lawfulness and Consent
Personal data must be processed lawfully and with proper authorization.
Requirements
- Obtain valid consent
- Identify legal basis
- Document processing grounds
- Regular compliance reviews
- Maintain consent records
Examples
- Consent mechanisms
- Legal basis documentation
- Processing records
- Compliance reports
Transparency
Organizations must be transparent about their data processing activities.
Requirements
- Clear privacy notices
- Processing purpose disclosure
- Data sharing information
- Rights notification
- Regular updates
Examples
- Privacy policies
- Data processing notices
- Rights information
- Communication records
Data Security
Implementation of appropriate security measures to protect personal data.
Requirements
- Security risk assessments
- Technical safeguards
- Staff training
- Incident response
- Regular audits
Examples
- Security protocols
- Training programs
- Incident plans
- Audit reports
Compliance Requirements
Database Registration
Organizations must register their databases containing personal data with the National Authority for Personal Data Protection.
Implementation Steps
- Identify registrable databases
- Complete registration forms
- Submit to authority
- Maintain registration current
- Update when changes occur
Required Documentation
- Database inventory
- Registration certificates
- Processing records
- Update history
- Change notifications
Consent Management
Requirements for obtaining and managing valid consent for data processing.
Implementation Steps
- Implement consent mechanisms
- Document consent collection
- Enable withdrawal options
- Regular consent reviews
- Update consent records
Required Documentation
- Consent forms
- Collection records
- Withdrawal procedures
- Review logs
- Update history
Cross-Border Transfers
Requirements for transferring personal data outside Peru.
Implementation Steps
- Assess recipient country adequacy
- Implement transfer safeguards
- Obtain necessary approvals
- Document transfers
- Monitor compliance
Required Documentation
- Transfer assessments
- Safeguard documentation
- Approval records
- Transfer logs
- Monitoring reports
Enforcement & Penalties
Administrative Penalties
The National Authority for Personal Data Protection can impose administrative penalties for violations.
Penalty Categories
Example Cases
Additional Measures
The Authority can impose various corrective measures beyond monetary penalties.