BDS Publications

#ElSalvador 🇸🇻 #BDS_LaborAlert: ACE Establishes New Data Protection and Administrative Enforcement Obligations

Written by BDS Asesores | Sep 7, 2026, 5:50:59 PM

On August 11, 2026, the State Cybersecurity Agency (ACE in Spanish) formally issued, through publication in the Official Gazette, two key instruments for the implementation of the Personal Data Protection Law (LPDP): the Guidelines for Data Protection Officers (DPOs) and the Regulations Governing Administrative Penalties Proceedings.

Both instruments entered into force on August 19, 2026. As of that date, ACE granted obligated entities a twenty (20) business-day period to adapt their processes to the new provisions and obtain accreditation for their Data Protection Officer. This process must be completed by email at dpdatos@ace.gob.sv. The deadline for complying with this obligation is September 16, 2026.

The Guidelines establish the requirements applicable to DPOs, including their technical qualifications, eligibility rules, and registration procedure. They also allow the DPO role to be performed internally or externally, either individually or through the appointment of a common DPO for corporate groups.

The DPO's main responsibilities include the independent management of ARCO-POL rights, oversight of privacy notices, and the development of personal data protection training programs.

The Regulations Governing Administrative Penalties Proceedings, in turn, establish the rules to be enforced by ACE's Data Protection Directorate when investigating and determining violations and imposing the corresponding penalties. The Regulations adopt the simplified procedure as the standard procedure, reserving the ordinary procedure for matters involving greater technical complexity. They also establish a maximum ninety (90) business-day period for preliminary investigation proceedings and authorize the adoption of interim measures where serious risks exist.

Notably, the Regulations establish criteria for determining the amount of fines, taking into account factors such as the offender's financial capacity, the degree of intent, and the nature or sensitivity of the personal data affected. These provisions operate within a framework that recognizes the guarantees of due process and presumption of innocence, while also providing for compulsory enforcement mechanisms in the event of noncompliance with the penalties imposed.

We recommend that organizations take these provisions into account and adapt their internal processes to ensure proper compliance before the upcoming deadline. Should you have any questions, we would be pleased to assist you.

The published instruments are provided below for download and reference: