ARCO rights
Access, rectification, cancellation and opposition are the regional vocabulary. They map onto GDPR rights but the procedural steps, forms and deadlines are national, and cancellation is often broader than erasure.
Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.
Open the guideWe scope against the laws that actually apply to you, then sequence the work by risk.
Start the assessmentWhat must be operational before the substantive obligations commence in 2027.
Read the briefingAnswer 18 questions and get a prioritised control roadmap instantly.
Start the assessmentTrack 01 assumes no prior knowledge of governance, risk and compliance.
Start Track 01Regional overview
Latin America is not a single market for privacy compliance, but it is more coherent than it first appears. Most regimes descend from the Ibero-American tradition, which means a habeas data constitutional right, a registration or notification culture, and an emphasis on the data subject’s ARCO rights. The region is also in motion: Chile and Ecuador have moved to GDPR-style frameworks with independent regulators, and Argentina has a long-running reform effort. Brazil has its own detailed guide.
At a glance
| Jurisdiction | Framework and regulator | What to watch |
|---|---|---|
| Brazil | LGPD, supervised by the ANPD. | The regional benchmark. Ten lawful bases and published standard contractual clauses. See our Brazil guide. |
| Mexico | Mexico’s new Federal Law for the Protection of Personal Data Held by Private Parties took effect on March 21, 2025. Following the dissolution of INAI, private-sector data-protection enforcement responsibilities were transferred to the Secretaría de Anticorrupción y Buen Gobierno (SABG) under the new institutional framework. | The privacy notice is a heavily prescribed document and the ARCO response clocks are short. Organizations should verify the latest guidance, procedures, and enforcement arrangements published by the SABG before relying on this summary. |
| Chile | Law 21.719, establishing a GDPR-style regime and a dedicated Data Protection Agency. | The most significant recent change in the region. Build to the new obligations now rather than to the superseded 1999 law. |
| Colombia | Law 1581 of 2012, supervised by the Superintendency of Industry and Commerce. | The National Database Registry is a real, enforced filing duty, and authorisation is close to a consent-first model. |
| Argentina | Law 25.326, supervised by the Agency for Access to Public Information. | Holds EU adequacy. Registration of databases applies, and a modernising reform has been under discussion for years. |
| Peru | Law 29733 with its regulation, supervised by the National Authority for Personal Data Protection. | Database registration duties and an active sanctioning authority. Consent formalities are strict. |
| Uruguay | Law 18.331, supervised by the URCDP. | Holds EU adequacy, requires database registration and a DPO for defined controllers. |
| Ecuador | Organic Law on Personal Data Protection, with sanctions in force since 2023. | Closely modelled on the GDPR, including DPO and impact assessment duties. |
Common ground
Access, rectification, cancellation and opposition are the regional vocabulary. They map onto GDPR rights but the procedural steps, forms and deadlines are national, and cancellation is often broader than erasure.
Colombia, Peru, Argentina and Uruguay each operate a register of databases. This is an administrative duty that European programmes routinely miss, and it is enforced.
Several regimes, Mexico most of all, specify what the privacy notice must contain and how it must be delivered. A generic global notice will not satisfy them.
Legitimate interests is not universally available. Where it is absent, consent or a statutory exception must carry the processing, which changes how you design marketing and analytics.
Routes vary from adequacy lists to contractual undertakings to consent. Brazil and Chile are converging on the clause-based model; others still rely on the data subject’s authorisation.
Notices, consents and rights channels need to be in Spanish or Portuguese as applicable. Regulators treat an English-only notice as a transparency failure.
Practical approach
The efficient design is a single regional baseline set at the strictest common denominator, with a thin national layer for the things that genuinely cannot be harmonised. In practice that means one record of processing, one security standard and one incident process, plus country-specific notices, registrations and rights forms.
Record of processing, retention schedule, security controls, vendor due diligence and incident response can all be regional. Build them to Brazil or Chile and the rest follow.
Notices, consent wording, registration filings, rights response letters and the DPO or contact designation are national. Keep a country matrix and owners for each.
Response deadlines are short and differ by country. A regional service level set at the shortest applicable period removes a recurring source of breach.
Chile, Argentina and Mexico are each in or near a reform cycle. Review the matrix on a fixed cadence rather than when something breaks.
Mexico: the new Federal Law for the Protection of Personal Data Held by Private Parties was published in the Diario Oficial de la Federación on 20 March 2025 and took effect on 21 March 2025. Official text: LFPDPPP, Cámara de Diputados. See also the Diario Oficial de la Federación, 20 March 2025. This summary states the position as at 22 September 2026. Mexico’s supervisory framework and implementing arrangements may continue to evolve, so confirm the current position against the official sources before relying on it.
Where to go next
Read the Brazil LGPD guide for the region’s anchor regime, the United States state laws page if your programme spans the Americas, and the jurisdiction index for everything else we track. For help building a regional matrix, talk to us.