#ElSalvador 🇸🇻 #BDS_LaborAlert: ACE Establishes New Data Protection and Administrative Enforcement Obligations
2:44

#ElSalvador 🇸🇻 #BDS_LaborAlert: ACE Establishes New Data Protection and Administrative Enforcement Obligations

On August 11, 2026, the State Cybersecurity Agency (ACE in Spanish) formally issued, through publication in the Official Gazette, two key instruments for the implementation of the Personal Data Protection Law (LPDP): the Guidelines for Data Protection Officers (DPOs) and the Regulations Governing Administrative Penalties Proceedings.

Both instruments entered into force on August 19, 2026. As of that date, ACE granted obligated entities a twenty (20) business-day period to adapt their processes to the new provisions and obtain accreditation for their Data Protection Officer. This process must be completed by email at dpdatos@ace.gob.sv. The deadline for complying with this obligation is September 16, 2026.

The Guidelines establish the requirements applicable to DPOs, including their technical qualifications, eligibility rules, and registration procedure. They also allow the DPO role to be performed internally or externally, either individually or through the appointment of a common DPO for corporate groups.

The DPO's main responsibilities include the independent management of ARCO-POL rights, oversight of privacy notices, and the development of personal data protection training programs.

The Regulations Governing Administrative Penalties Proceedings, in turn, establish the rules to be enforced by ACE's Data Protection Directorate when investigating and determining violations and imposing the corresponding penalties. The Regulations adopt the simplified procedure as the standard procedure, reserving the ordinary procedure for matters involving greater technical complexity. They also establish a maximum ninety (90) business-day period for preliminary investigation proceedings and authorize the adoption of interim measures where serious risks exist.

Notably, the Regulations establish criteria for determining the amount of fines, taking into account factors such as the offender's financial capacity, the degree of intent, and the nature or sensitivity of the personal data affected. These provisions operate within a framework that recognizes the guarantees of due process and presumption of innocence, while also providing for compulsory enforcement mechanisms in the event of noncompliance with the penalties imposed.

We recommend that organizations take these provisions into account and adapt their internal processes to ensure proper compliance before the upcoming deadline. Should you have any questions, we would be pleased to assist you.

The published instruments are provided below for download and reference:

I have a question

Otros artículos

#ElSalvador 🇸🇻 #BDS_LaborAlert: Government Enacts the “25th Fortnight Law”: Additional Income for Workers

The “25th Fortnight Law” was approved by the Legislative Assembly on January 14, 2026 with 59...

#Honduras 🇭🇳 #BDS_Informs: Labor Implications for Employers and Employees of the May 1st Holiday

Please note that Friday, May 1st, 2026, on which International Labor Day is observed, is a ...

#DominicanRepublic 🇩🇴 #BDS_LaborAlert: New Employer Obligations Regarding First Aid and Workplace Emergency Response

Companies should review their workplace emergency response measures following the entry into force...