Our Director of New Technologies and AI, Juan Pablo González, spoke with Diario Financiero, where he discussed the implications of the first set of regulations under the Personal Data Protection Act.
This week, the first set of regulations for the law governing the protection and processing of personal data—which establishes the Personal Data Protection Agency—was published in the Official Gazette. The law is set to take effect on December 1, unless Congress approves the postponement proposed by the government.
The regulations govern the requirements, methods, and procedures for the implementation, certification, registration, and oversight of infringement prevention models (MPI).
Specifically, they establish the rules for those who choose to adopt the MPI, a voluntary compliance program for data controllers—that is, natural or legal persons, whether public or private.
Among other measures, the regulation requires characterizing the data and processing activities; identifying the processes with the highest risk of violations and incorporating them into a risk matrix; establishing protocols, reporting channels, and complaint procedures; and detailing the guidelines for appointing a data protection officer.
It also regulates the certification, registration, and oversight of the model by the future agency, which may serve as a mitigating factor in the event of any sanctions imposed by the agency.
Data Protection Officer and Measures
Lizzy Seaman, director of the Data Protection practice at Prieto Abogados, noted that the regulation provides organizations with guidelines and “some certainty in implementing complex, time-consuming, and costly rules” before the law takes effect.
She highlighted, for example, that it specifies the requirements for appointing a data protection officer, who must have knowledge and experience in the field, independence within the organization, and “sufficient resources to perform their duties and avoid conflicts of interest.”
Juan Pablo González, Director of New Technologies and AI at az, noted that data controllers who opt for this model must, among other things, characterize their data processing activities—for example, through a record of processing activities (RPA)—and establish internal measures to prevent internal non-compliance with the model, such as procedures and sanctions.
“Furthermore, having a certified prevention model would act as a mitigating factor (for sanctions). Instead of reaching the highest penalty of 20,000 UTM, it could allow the agency to adjust within that range, obviously taking other criteria into account,” he said.
Source: Diario Financiero, September 11. [See here]



