Patient data protection in Argentina: Law 25.326 and Law 26.529 compliance guide for dental imaging centers
An Argentine dental imaging center handles sensitive data every day. Law 25.326 on Personal Data Protection, enacted in 2000, was a pioneering rule in Latin America and earned Argentina an EU adequacy decision (2003/490/EC), a status shared by very few countries outside the EU. The supervisory authority is the Agency for Access to Public Information (AAIP).
This article explains what Law 25.326 requires, how it interlocks with Law 26.529 on Patient Rights and Law 26.742 on Dignified Death, what the EU adequacy means for international transfers, and how CBCTHub satisfies each technical safeguard for your imaging center.
Regulatory framework for an Argentine dental clinic
- Law 25.326 (2000) on Personal Data Protection (Habeas Data).
- Decree 1558/2001 regulating Law 25.326.
- Law 26.529 (2009) on Patient Rights, Clinical Record, and Informed Consent.
- Law 26.742 (2012) on dignified death, amending Law 26.529.
- AAIP Resolution 47/2018 recommended security measures.
- Decision 2003/490/EC from the European Commission: Argentina has adequacy for transfers from the EU.
- Pending reforms: GDPR-aligned modernization projects are under parliamentary review.
Law 25.326 in plain English
Law 25.326, known as the Habeas Data law for the constitutional action that protects personal data, was enacted on October 4, 2000 and regulated by Decree 1558/2001. It creates a general personal-data protection regime with principles, rights, and a supervisory authority. The AAIP, created by Law 27.275 in 2016, took over the functions of the previous DNPDP.
Sensitive data under Law 25.326
Article 2 defines sensitive data as data revealing racial and ethnic origin, political opinions, religious beliefs, philosophical or moral convictions, union membership, and information concerning health or sexual life. Article 7 establishes that no person may be obligated to provide sensitive data and that it may only be processed when there are general interest reasons authorized by law or express consent from the data subject. A CBCT scan is sensitive data.
What the law specifically requires about patient data
Express informed consent
Article 5 requires free, express, and informed consent to process personal data, which in the case of sensitive data must be in writing. Law 26.529 article 5 details the informed-consent requirements in healthcare.
Data subject rights
Access (art. 14), rectification, update or deletion (art. 16), opposition (art. 19). The controller must respond within 10 days for access and 5 days for rectification.
Law 25.326 principles
Lawfulness, quality, purpose, accuracy, conservation, security, confidentiality, and limited transfer.
Security measures
Article 9 requires controllers and users to adopt technical and organizational measures necessary to ensure security and confidentiality. AAIP Resolution 47/2018 details recommended measures across three levels.
Incident notification
AAIP Resolution 47/2018 recommends informing the AAIP of security incidents. Although Law 25.326 sets no strict legal clock, regulatory practice follows GDPR-style logic.
International transfers
Article 12 prohibits transfer to countries or international organizations that do not provide adequate levels of protection. There are exceptions: express consent, international bank transfers, international judicial cooperation, public health. Because Argentina has EU adequacy, transfers from Europe to Argentina are free.
Registration with the National Registry of Databases
Article 21 requires the controller of a personal data file with non-purely-personal purposes to register it with the National Registry of Databases, managed by AAIP. Registration is free and done online.
Retention (Law 26.529)
Law 26.529 article 18 establishes that the clinical record is the property of the patient and must be retained by the establishment for at least ten years from the last recorded action.
AAIP penalties
- Warning.
- Suspension.
- Fines from ARS 1,000 to ARS 100,000 (updated periodically; nominal values rise with inflation).
- Closure or cancellation of the data file.
Argentine fines are nominally lower than GDPR, but reform proposals would raise them substantially. Additionally, non-compliance may generate civil liability and, in serious cases, criminal liability for breach of professional secrecy (Penal Code art. 156).
The EU adequacy decision
European Commission Decision 2003/490/EC recognizes that Argentina offers an adequate level of personal-data protection. This means a European clinic may transfer data to Argentina without Standard Contractual Clauses or other additional safeguards. It is a meaningful distinction: only Argentina, Uruguay, the UK, Switzerland, Canada, Japan, Israel, Andorra, Faroes, Guernsey, Isle of Man, Jersey, and New Zealand enjoy adequacy.
Concrete risks for an Argentine dental imaging center
Not retaining the clinical record for 10 years, sending scans by WhatsApp without security measures, failing to register the database with AAIP, lacking current informed consent, exposing data through a misconfigured website. All have been sanctioned by AAIP. Penal Code article 156 additionally punishes breach of professional secrecy with a fine and possible disqualification.
How CBCTHub helps you comply with Law 25.326 and Law 26.529
Informed consent in Law 26.529 format
CBCTHub generates informed-consent templates adapted to Law 26.529 article 5 requirements (purpose, risks, alternatives, right to withdraw). The patient signs electronically and the signature is publicly verifiable.
End-to-end encryption
TLS 1.3 and AES-256 meet the technical measures recommended by AAIP Resolution 47/2018 at its critical level for sensitive data.
Exportable audit log
Every exam access is logged with timestamp, IP, and user_id. Meets the confidentiality principle of article 9 and lets you respond to AAIP requests or patient inquiries about who viewed their scan.
PIN and unique links with expiration
Each exam has a unique opaque URL with optional PIN. The clinic''s public page requires a mandatory PIN. Links expire automatically per policy, honoring the purpose principle.
Right to erasure
DELETE /api/v1/exams/{id} removes the exam and all DICOMs in R2 irreversibly. Meets the right of article 16 of Law 25.326.
Portability via export-data
The endpoint /api/account/export-data returns data in structured JSON. Although Law 25.326 does not formally include portability, the endpoint prepares you for future reforms.
Contract with the data user
CBCTHub signs a contract with every Argentine clinic per article 25 of Law 25.326. Available at /privacidad.
Multi-tenant RLS on Supabase
Strict isolation between clinics. Meets the security and confidentiality principles of articles 9 and 10 of Law 25.326.
Servers compatible with EU-Argentina adequacy
Cloudflare R2 and Supabase offer regions that meet the standards of the adequacy decision. Argentine clinic data may be hosted in the US under Data Privacy Framework or in SAm/EU regions per plan.
Law 25.326 compliance checklist for your center
- Register the database with AAIP''s National Registry of Databases.
- Designate a personal data controller or processor.
- Informed-consent template per Law 26.529.
- Documented procedure for handling data subject rights (10 days for access).
- Security system per AAIP Resolution 47/2018.
- Contract with CBCTHub and every processor.
- Retention policy of at least 10 years per Law 26.529.
- Annual staff training.
- Security incident log.
FAQ
Can I send scans via WhatsApp?
Not securely. WhatsApp does not meet the security and confidentiality principles of Law 25.326 article 9 for sensitive data. Use a secure CBCTHub link.
How long must I retain the clinical record?
Law 26.529 article 18 sets a minimum of ten years from the last recorded action.
What happens if I lose the backup with patient data?
You must notify AAIP per Resolution 47/2018. Fines today are nominally low but reform proposals would raise them significantly. There may also be civil and criminal liability.
Do I need to sign anything with CBCTHub?
Yes. Article 25 of Law 25.326 regulates service provision by processors. CBCTHub provides the contract at /privacidad.
Do I need to register my database with AAIP?
Yes, per article 21. The procedure is free and done through the AAIP website.
Official resources
- Agency for Access to Public Information (AAIP)
- Law 25.326 at InfoLEG
- Law 26.529 at InfoLEG
- Decision 2003/490/EC (EU-Argentina adequacy)
Download the CBCTHub processor contract | Solution for Argentine imaging centers | Plans and pricing
This article is informational and does not constitute legal advice. Consult with an Argentine data protection lawyer for your specific case.
Try CBCTHub for free
Upload, view, and share DICOM scans in the cloud. Nothing to install.
Create free accountRelated articles
Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers
How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.
Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers
How to comply with HIPAA (Public Law 104-191), Privacy Rule, Security Rule, and HITECH Act in a dental imaging clinic. PHI, BAA, OCR fines up to USD 1.5M per year.
Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers
Complete guide to Chile's current Law 19.628, the new Law 21.719 effective December 2026, and Law 20.584 on patient rights. How CBCTHub helps you comply today and tomorrow.