Guidelines for the Data Protection Officer in El Salvador: Key Points of the New Regulation

Article written by Roxana Romero de Gamero and Tatiana Beltranena

August 20, 2026, marks a new milestone in the implementation of the Personal Data Protection Act (LPDP) in El Salvador. The State Cybersecurity Agency (ACE) officially approved the Guidelines for the Personal Data Protection Officer (DPD), a key role in ensuring regulatory compliance and the effective protection of data subjects’ rights.

These guidelines apply to both individuals and legal entities, whether domestic or foreign, and cover public and private entities that engage in activities related to the processing of personal data.

Requirements to Become a Data Protection Officer

The regulations establish a set of minimum requirements that must be met to serve as a DPO. Among the most important are:

-A natural person or legal entity, regardless of nationality;

-A college degree, preferably in law;

-Minimum age of 21;

-Proven experience in areas such as data protection, legal administrative procedures, regulatory compliance, risk management, IT, information security, or cybersecurity;

-Approval of the mandatory certification program developed by the ACE;

-No conflict of interest with the position.

Main Responsibilities of the DPO

The Compliance Officer serves as the central hub for compliance within each organization. His or her responsibilities include:

-Submission of periodic reports to the ACE;

-Publication and updating of the Privacy Notice:

-Management of ARCOPOL requests (Access, Correction, Deletion, Objection, Portability, Right to be Forgotten, and Restriction).

-Strict confidentiality in the handling of information:

-Autonomy and functional independence in the performance of their duties.

Mandatory notification of the appointment to the ACE

Data controllers must notify the ACE of the appointment of the DPO via official letter, written notice, or institutional email addressed to the Personal Data Protection Directorate. The deadline for complying with this requirement is 20 business days from August 20, 2026. The ACE has announced that it will soon launch an online platform to facilitate this process.

The role of the Data Protection Officer (DPO) is becoming firmly established as a pillar of governance and compliance in the area of personal data. This role is not merely a formality: it involves ongoing oversight, risk management, addressing data subjects’ rights, and coordination with the regulatory authority.

At Novis Estudio Legal, we closely monitor every regulatory development in the area of personal data protection to ensure that our clients receive up-to-date, strategic guidance that is aligned with current regulations.

Tags:

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest Comments

No comments to show.

[:]