What's Happening?
The Legislative Assembly of El Salvador has approved amendments to the Personal Data Protection Law, primarily altering how organizations manage their data protection obligations. A key change for the private sector is the elimination of the general requirement
to appoint a Data Protection Officer (DPO). Previously, Article 15 of the law mandated all obligated entities to appoint a DPO to handle requests related to ARCO-POL rights (Access, Rectification, Cancellation, Opposition, and Portability). While the general obligation for private companies to formally maintain a DPO is removed, their responsibilities towards data subjects and the need to establish internal mechanisms for addressing these rights remain. The reform transfers several responsibilities previously assigned to the DPO directly to the obligated entity, including providing assistance to departments and service providers, and establishing processes for managing ARCO-POL requests. Public institutions, however, are still required to appoint a DPO, who may also serve as the institution’s Information Officer.
Why It's Important?
These amendments have significant implications for businesses operating in El Salvador, particularly those with U.S. ties or international operations. The removal of the mandatory DPO role for the private sector could reduce administrative burdens and compliance costs for companies. However, it also places a greater direct responsibility on the obligated entities to ensure data protection compliance. U.S. companies with subsidiaries or data processing operations in El Salvador will need to review their internal structures and policies to align with the updated law. While the formal DPO requirement is lifted, the underlying obligations regarding data subjects' rights and privacy notices remain. Companies must ensure they have robust internal frameworks to receive, assess, and respond to ARCO-POL requests within the stipulated deadlines (20 business days, extendable). Failure to comply could lead to legal repercussions and reputational damage. This shift emphasizes a move towards a more flexible, yet still accountable, data protection landscape for the private sector.
What's Next?
Companies in El Salvador, especially those in the private sector, will need to reassess their data protection strategies in light of these amendments. Organizations that currently have a DPO must decide whether to retain this structure, modify it, or reassign data protection functions to another department or individual. The focus will be on ensuring an effective compliance framework is in place, even without a dedicated DPO. Companies are also required to update their privacy notices, as the obligation to include the DPO's contact information has been removed, replaced by a requirement to indicate the means for submitting ARCO-POL requests. For organizations still developing their data protection programs, these changes will influence the design of their compliance structures, internal policies, and channels for handling data subject requests. The Legislative Assembly's decision to maintain the DPO requirement for public institutions suggests a differentiated approach to data governance between the public and private sectors.
Beyond the Headlines
The amendments to El Salvador's Personal Data Protection Law, particularly the removal of the mandatory DPO for the private sector, reflect a broader global debate on regulatory burdens versus effective data governance. While seemingly reducing a formal requirement, the law explicitly transfers the DPO's responsibilities directly to the obligated entity, underscoring that the core duty of protecting personal data remains paramount. This could lead to a more integrated approach to data protection within companies, where compliance is embedded across various departments rather than centralized in a single role. However, it also places a greater onus on corporate leadership to understand and implement complex data protection requirements. The distinction between public and private sector obligations highlights the government's intent to maintain stricter oversight over public data handling while offering more flexibility to businesses. This legislative shift could influence how other nations in the region balance regulatory frameworks with economic competitiveness, potentially setting a precedent for data protection laws in Central America.













