With the advance of technology and the development of innovative products, platforms, and the unlimited transfer of information and personal data in an increasingly digital world, individuals are gradually losing control over their personal data and how it is used, especially when such use occurs without the explicit consent of the data subject.
Currently, Paraguay lacks a comprehensive and modern legal framework aligned with ongoing technological developments to ensure the proper collection, processing and use of personal data. All existing regulations that relate to the protection of personal data require constant review and, where appropriate, adjustment. This is essential to guarantee and protect individuals’ rights to intimacy and persona integrity, with the support of an independent authority capable of supervising companies and organizations involved in data processing. People have the fundamental right to know – and the State has the duty to ensure – how their personal data is processed and for what purposes. If these purposes are not fulfilled within the authorized timeframe, a competent authority should have the power to impose sanctions, without prejudice against any private legal action the individual may choose to pursue.
Current Legal Framework and its Background
In an attempt to establish a norm regarding personal data, Law No. 1682/2001 on the Protection of Private Information, which regulated the collection and processing of personal data strictly for private use was enacted. However, this law was replaced by Law No. 6534/2020 (hereinafter, the “Law”), which focuses specifically on the protection of credit-related personal data. Its stated purpose is to guarantee the protection of credit information of all individuals, regardless of nationality, race, or domicile, by regulating data collection and access while safeguarding fundamental rights.
This law defines “personal data” as any type of information related to an identified or identifiable natural or legal person. An identifiable person is someone who can be recognized through and identifier or by reference to one or more elements specific to their physical, physiological, genetic, psychological, economic, cultural, or social identity. The law extends data protection rights and guarantees to legal entities to the extent applicable and defines sensitive personal data as any information concerning a person’s intimate sphere or whose improper use could result in discrimination or significant risk. Sensitive data is understood to be personal data that may reveal racial or ethnic origin, religious, philosophical, or moral beliefs, trade union membership, political opinions, health information, sexual life or orientation, and genetic and biometric data used for uniquely identifying an individual.
The law further defines credit information as both positive and negative data concerning the credit history of individuals and entities, including commercial activity, indebtedness levels, compliance with financial obligations, and overall credit risk.
While the law introduces definitions of personal and sensitive data, its primary scope centers around credit data. As such, there is a notable gap in the regulation of non-credit personal data, including how such data is collected, processed, and safeguarded. This leaves individuals without clear legal tools to monitor the use and purpose of their non-financial personal information. As a result, key constitutional rights—such as the rights to privacy, health, and personal integrity – remain at risk. In fact, Article 1 of the law is clear by stating that the law aims to protect credit-related data to preserve fundamental rights, privacy, informational self-determination, freedom, security, and fair treatment.
In other words, the law does not explicitly cover personal data beyond the credit sphere. As previously noted, this highlights the limited scope of the current framework. A robust personal data protection regime would require both substantive rules and the establishment of a specialized authority to ensure proper oversight and enforcement.
Undoubtedly, credit information is a critical component of data protection, but it is not the only one. Other equally important aspects of individuals’ personal data —ranging from communications and health records to geolocation and biometric data— should also be protected. Stronger oversight would help reduce extortion, unsolicited marketing repeated calls and messages offering products and services that strongly affect individuals’ quality of life, and other cases that may even lead to economic losses. Moreover, improper handling of personal data may cause psychological harm, without appropriate controls or competent authority to address violations of fundamental rights.
Therefore, while there is no general data protection law currently in force in Paraguay, the growing volume of data transfers and technological developments underscore the need for a modern, dedicated framework for the protection of personal and sensitive data. Such a framework should enhance state control and provide individuals with reassurance that their data will only be used with informed consent or, where such consent is lacking, that they have a reliable institutional channel to seek support and redress through coherent and enforceable public policy.
The Draft of Personal Data Protection Law in Paraguay
In recent years, Paraguay has been working on a draft bill aimed to establish a legal framework for the protection of personal data. Its goal is to guarantee data subjects’ rights and regulate the circulation of personal information in line with the National Constitution and international treaties ratified by Paraguay.
Some key highlights of the draft include:
- Key Principles
- Accuracy: Data must be complete, accurate, and kept up to date.
- Lawfulness: Data processing must be carried out on a lawful basis.
- Purpose limitation: Data must be collected for specific, explicit, legitimate purposes, and only retained for as long as necessary.
- Proportionality: The amount and type of data must be appropriate and relevant to the purpose.
- Fairness: Data must not be obtained through deceptive, fraudulent, or unlawful means.
- Transparency: The data controller must inform the individual of the data processing activities.
- Storage limitation: Data must only be retained for as long as necessary to fulfill its intended purpose.
- Accountability: Data controllers must take technical and organizational measures to ensure compliance.
- Security: Appropriate safeguards must be adopted to protect personal data.
- Confidentiality: There is a continuing obligation of confidentiality, even after the relationship with the data subject has ended.
- The draft bill grants several rights, such as right to information; right to access; right to rectification; right to object; right to erasure; right to data portability; right not to be subject to automated or semi-automated decisions.
- The bill also establishes a Data Protection Officer who must be appointed under certain conditions by data controllers and processors.
- The bill proposes the creation of a dedicated “Data Protection Agency”, a fully independent public body responsible for enforcing the law and monitoring compliance.
Importantly, the draft bill does not repeal the existing law on credit data. Instead, it complements the current regime and refers to it for the specific treatment of credit-related personal information.
Comparison with European Regulation
Regarding the data protection bill currently under discussion in congress, below, we present a general comparison with the standards set forth by the European Union’s General Data Protection (GDPR), highlighting shared elements and key similarities:
| Paraguayan Draft Bill | European Union’s General Data Protection (GDPR) |
| Refers to the comprehensive protection of personal data of individuals, to ensure the full exercise of data subjects’ rights and the free circulation of such data, by the Constitution and international treaties to which Paraguay is a signatory. | Refers to the protection of individuals regarding the processing of personal data and the rules concerning the free movement of such data. |
| Defines personal data as any information that helps to identify a specific or identifiable individual. A person is considered identifiable when they can be identified by an identifier or by one or more elements specific to their physical, physiological, genetic, psychological, economic, cultural, or social identity. This also includes metadata and data fragments. | Defines personal data as any information relating to an identified or identifiable individual (“data subject”); an identifiable individual can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more elements specific to their physical, physiological, genetic, psychological, economic, cultural or social identity. |
| Sensitive personal data includes those related to racial or ethnic origin, political opinions, religious, philosophical or moral beliefs, membership or affiliation with trade unions or political organizations; health-related data, sexual preferences or orientation, biometric and genetic data linked to a natural person, and, in general, any data that may promote unlawful or arbitrary discrimination or prejudice. | (Equivalent provisions are included in the GDPR, identifying special categories of data that require enhanced protection.) |
| Defines data processing as any operation or set of operations, whether manual, automated, or partially automated, carried out on personal data. This includes, but is not limited to, collecting, accessing, recording, organizing, structuring, adapting, indexing, modifying, extracting, consulting, storing, retaining, blocking, transferring, sharing, disclosing, possessing, using, and any other form of handling or disposition of personal data. | Defines data processing as any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means. This includes collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. |
| Establishes core principles such as accuracy, lawfulness, purpose limitation, proportionality, fairness, transparency, storage limitation, security, and confidentiality. | Establishes principles such as lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. |
Based on the comparison above, the ongoing draft bill shares several important similarities with the GDPR, particularly in its emphasis on a modern and technology-driven regulatory framework.
Therefore, we can conclude that a comprehensive legal framework specifically regulating personal data, as already exists in other countries across the region, remains a pending matter in Paraguay.
For more information on personal data protection, please contact attorney Enzo Berino at eberino@altra.com.py.