{"id":29573,"date":"2025-07-17T11:24:56","date_gmt":"2025-07-17T15:24:56","guid":{"rendered":"https:\/\/www.tedic.org\/?p=29573"},"modified":"2025-07-28T10:49:30","modified_gmt":"2025-07-28T14:49:30","slug":"paraguay-needs-a-robust-personal-data-protection-law-with-international-standards-and-real-safeguards","status":"publish","type":"post","link":"https:\/\/www.tedic.org\/en\/paraguay-needs-a-robust-personal-data-protection-law-with-international-standards-and-real-safeguards\/","title":{"rendered":"Paraguay needs a robust Personal Data Protection Law, with international standards and real safeguards"},"content":{"rendered":"\n<p>On Friday, July 4, 2025, TEDIC actively participated in the public hearing convened by the Senate\u2019s Commission on Science, Technology, Innovation, and Future, held in the context of analyzing the proposed law <a href=\"https:\/\/silpy.congreso.gov.py\/web\/expediente\/123459\">&#8220;Protection of Personal Data in Paraguay\u201d<\/a>. This project \u2014approved in both general and specific terms by the Chamber of Deputies in May of this year\u2014 represents a significant step forward in the legislative process initiated in 2021.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"648\" src=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Mari-AudienciaPublicaDP.png\" alt=\"\" class=\"wp-image-29565\" srcset=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Mari-AudienciaPublicaDP.png 1000w, https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Mari-AudienciaPublicaDP-300x194.png 300w, https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Mari-AudienciaPublicaDP-768x498.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p>From TEDIC, in collaboration with other organizations forming part of the <strong><a href=\"https:\/\/www.datospersonales.org.py\/\"><\/a><a href=\"https:\/\/www.datospersonales.org.py\/\">Personal Data Coalition<\/a><\/strong>, we\u2019ve supported this process from the outset by providing technical analysis, comparative normative proposals, and alerts about the risks posed by a weak or incomplete law.<\/p>\n\n\n\n<p>The bill, docket <a href=\"https:\/\/silpy.congreso.gov.py\/web\/expediente\/123459\"><u>D2162170<\/u><\/a> was introduced on <a href=\"https:\/\/www.tedic.org\/el-congreso-nacional-da-entrada-oficial-al-proyecto-de-ley-de-proteccion-de-datos-personales\/\">May 5, 2021<\/a>. Over that period, 13 sessions were conducted to analyze the bill\u2019s draft. On <a href=\"https:\/\/www.abc.com.py\/politica\/2024\/12\/18\/por-retraso-del-ejecutivo-diputados-aprueban-ley-de-datos-personales-a-medias\/\">December 17, 2024,  it was generally approved<\/a> during a plenary session and referred to committees for detailed, article-by-article review. In the following months, the responsible committees conducted exhaustive study and introduced various amendments. Finally, <a href=\"https:\/\/www.tedic.org\/primera-sancion-de-la-ley-de-datos-personales-en-paraguay\/\">on May 27, 2025, the bill was fully approved<\/a>, completing the first constitutional stage toward enactment.<\/p>\n\n\n\n<p>We firmly believe that Paraguay needs modern, comprehensive, and effective legislation on personal data protection. This law must recognize privacy as a fundamental human right and establish a normative framework that not only regulates data processing by the private sector, but also imposes limits and obligations on the State especially in activities involving sensitive data and surveillance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why is a personal data protection law necessary?<\/strong><\/h2>\n\n\n\n<p>In the digital age, our personal data is a strategic resource. Its indiscriminate use can have serious consequences\u2014from algorithmic discrimination and political persecution to identity theft, fraud, mass surveillance, restrictions on free expression, and violations of intimacy.<\/p>\n\n\n\n<p>At the international level, the trend is clear: data protection frameworks must align with human rights standards such as the EU General Data Protection Regulation (GDPR) or Council of Europe Convention 108+. These standards recognize fundamental principles that must govern any processing of personal data: legality, purpose limitation, proportionality, data minimization, security, transparency, and proactive accountability.<\/p>\n\n\n\n<p id=\"<iframe-width=&quot;560&quot;-height=&quot;315&quot;-src=&quot;https:\/\/www.youtube.com\/embed\/jmfXM8JC42Y?si=yFexVr4ALvGOwH98&quot;-title=&quot;YouTube-video-player&quot;-frameborder=&quot;0&quot;-allow=&quot;accelerometer;-autoplay;-clipboard-write;-encrypted-media;-gyroscope;-picture-in-picture;-web-share&quot;-referrerpolicy=&quot;strict-origin-when-cross-origin&quot;-allowfullscreen&gt;<\/iframe&gt;\">In Latin America, countries like Uruguay, Argentina, Brazil, Mexico, and Chile have advanced toward more modern and coherent legislation. Paraguay, on the other hand, still lacks comprehensive law and remains lagging in global rankings for personal data protection.<\/p>\n\n\n\n<p><strong>If you&#8217;d like to share this information with others, we recommend this short video that explains the topic clearly and concisely<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"En la era digital, nuestros los personales son un recurso estrat\u00e9gico\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/jmfXM8JC42Y?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The current bill: progress and challenges<\/strong><\/h2>\n\n\n\n<p>We recognize that the project approved by the Chamber of Deputies represents an important and necessary step. However, we have identified substantial weaknesses that could compromise the law\u2019s effectiveness and leave critical gaps.<\/p>\n\n\n\n<p><strong>1. Broad and unconstitutional exclusions from scope<\/strong><\/p>\n\n\n\n<p>Article 2 of the bill completely excludes data processing related to public security, national defense, immigration policy, and criminal prosecution. This absolute exclusion contradicts international standards such as Convention 108+ (which allows only proportionate and necessary restrictions) and weakens protections precisely where the most sensitive data are handled.<\/p>\n\n\n\n<p><strong>Proposal:<\/strong> Replace the absolute exclusion with a conditional exception that permits limitations of rights and obligations only when strictly necessary and proportionate\u2014without excluding general data protection principles.<\/p>\n\n\n\n<p><strong>2. Absence of a data retention principle<\/strong><\/p>\n\n\n\n<p>A key pillar of modern data protection law is temporal limitation: personal data cannot be stored indefinitely and must be deleted once its purpose is fulfilled. This basic rule prevents abuse and unnecessary accumulation of information. In the current bill, this principle is not included among the general principles and appears only marginally in relation to proportionality, weakening its force.<\/p>\n\n\n\n<p><strong>Proposal:<\/strong> Include a standalone data retention principle that sets clear limits, differentiates between data types (personal, sensitive, financial, surveillance data, etc.), and allows for sector-specific technical regulations.<\/p>\n\n\n\n<p><strong>3. Lack of a proactive accountability principle<\/strong><\/p>\n\n\n\n<p>Proactive accountability means that data controllers must not only comply with the law but demonstrate their compliance. This requires active measures: audits, record\u2011keeping, impact assessments, appointment of Data Protection Officers, internal training, etc. The current bill replaces this concept with a vague \u201cdue diligence,\u201d which lacks equivalent legal weight and institutional scope.<\/p>\n\n\n\n<p><strong>Proposal: <\/strong>Reinstate the principle of proactive accountability as articulated in the GDPR and Convention 108+, particularly for public sector obligations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Other critical concerns<\/strong><\/h2>\n\n\n\n<p><strong>4. Erosion of public access to information rights<\/strong><\/p>\n\n\n\n<p>Article 24 introduces a complex procedure for accessing public information containing personal data, requiring notification to the data subject and a non\u2011binding ruling. This could become a systematic barrier to transparency and weaken access to public information\u2014especially regarding contracts, officials, and use of public funds.<\/p>\n\n\n\n<p><strong>Proposal: <\/strong>Replace this procedure with a mechanism based on divisibility, harm test, and public interest test, following the model of Paraguay\u2019s Law No. 5282\/2014 on Access to Public Information.<\/p>\n\n\n\n<p><strong>5. Ambiguities in international data transfers<\/strong><\/p>\n\n\n\n<p>The bill states that in the absence of an adequate country, the controller must ensure legal compliance but fails to specify which mechanisms are acceptable (e.g., standard contractual clauses, binding corporate rules, codes of conduct), or who determines which countries offer adequate protection.<\/p>\n\n\n\n<p><strong>Proposal: <\/strong>Include a publicly available, up\u2011to\u2011date list of adequate countries (maintained by the supervisory authority) and specify acceptable safeguards for international transfers in line with international models.<\/p>\n\n\n\n<p><strong>6. Short mandate for leadership of the data protection authority<\/strong><\/p>\n\n\n\n<p>Article 40 sets a three-year term for the Director General of the future National Data Protection Agency. This duration is too short to ensure independence, strategic planning, or institutional continuity.<\/p>\n\n\n\n<p><strong>Proposal:<\/strong> Establish a five-year mandate with the possibility of a single reappointment, and a transparent, merit-based appointment process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Data protection as a human rights tool, not merely a technical norm<\/strong><\/h2>\n\n\n\n<p>At TEDIC, we view personal data processing not just as a technical or administrative matter but as deeply linked to democracy, accountability, access to justice, freedom of expression, and social equity.<\/p>\n\n\n\n<p>A strong law can empower citizens, safeguard vulnerable groups, prevent arbitrary use of surveillance technologies, and foster a digital ecosystem built on trust and respect for human dignity. Conversely, a weak law can normalize abusive practices like surveillance without judicial oversight, discriminatory use of artificial intelligence, unchecked data collection by companies, and opacity in public administration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The moment to strengthen is now<\/strong><\/h2>\n\n\n\n<p>The legislative process is not over. The Senate now has the opportunity \u2014and responsibility\u2014 to improve the text approved by the Deputies, incorporating these technical and legal adjustments.<\/p>\n\n\n\n<p>TEDIC, together with the Coalition for Personal Data Protection, reiterates our willingness to collaborate with the National Congress, offering inputs, comparative proposals, and technical arguments to help strengthen this law. We will continue working with civil society and all people interested in defending digital rights to ensure Paraguay enacts a Personal Data Protection Law that meets current challenges and citizens\u2019 expectations.<\/p>\n\n\n\n<p>Because protecting our data is also protecting our freedom, privacy, and democracy.<\/p>\n\n\n\n<p>Download the <a href=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Desafios-de-la-version-sancionada-en-Diputados_COALICIONDATOSPERSONALES_julio2025.pdf\" data-type=\"attachment\" data-id=\"29548\">legal opinion of the Personal Data Coalition submitted to the Senate\u2019s Science &amp; Technology Commission on July\u202f14.<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>References<\/strong><\/p>\n\n\n\n<p>Internet Bolivia (2025). Guia de Implementaci\u00f3n de Protecci\u00f3n de Datos y Uso Responsable de Inteligencia Artificial en Bolivia. En <a href=\"https:\/\/internetbolivia.org\/wp-content\/uploads\/2025\/05\/guia_proteccion_datos_web.pdf\"><u>https:\/\/internetbolivia.org\/wp-content\/uploads\/2025\/05\/guia_proteccion_datos_web.pdf<\/u><\/a><\/p>\n\n\n\n<p>Federico Legal (2025) Opini\u00f3n preliminar del experto en Acceso a la informaci\u00f3n p\u00fablica. En <a href=\"https:\/\/x.com\/federicolegal\/status\/1943048423302672822?s=48\"><u>https:\/\/x.com\/federicolegal\/status\/1943048423302672822?s=48<\/u><\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/Desafios-de-la-version-sancionada-en-Diputados_COALICIONDATOSPERSONALES_julio2025.pdf\"><img loading=\"lazy\" decoding=\"async\" width=\"697\" height=\"933\" src=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/ParecerCoalicion.png\" alt=\"\" class=\"wp-image-29545\" srcset=\"https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/ParecerCoalicion.png 697w, https:\/\/www.tedic.org\/wp-content\/uploads\/2025\/07\/ParecerCoalicion-224x300.png 224w\" sizes=\"auto, (max-width: 697px) 100vw, 697px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>On Friday, July 4, 2025, TEDIC actively participated in the public hearing convened by the Senate\u2019s Commission on Science, Technology, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29574,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1233],"tags":[1536,714,715],"class_list":["post-29573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","tag-data-protection","tag-personal-data-en","tag-privacy-en"],"_links":{"self":[{"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/posts\/29573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/comments?post=29573"}],"version-history":[{"count":16,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/posts\/29573\/revisions"}],"predecessor-version":[{"id":29670,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/posts\/29573\/revisions\/29670"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/media\/29574"}],"wp:attachment":[{"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/media?parent=29573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/categories?post=29573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tedic.org\/en\/wp-json\/wp\/v2\/tags?post=29573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}