Data protection and business compliance
Data protection in El Salvador: which companies must comply?
Which companies fall within scope, what the data protection officer deadline means, and what businesses should review under El Salvador’s data protection framework.
A company may sell exclusively to other businesses and still have data protection obligations. Consider its employee files, the job applications it receives, or information about the people with whom it negotiates. Personal information is part of operations far more routine than selling databases or running a digital platform.
Company size does not determine the obligation
The Law for the Protection of Personal Data applies to individuals and legal entities engaged in activities involving the processing of personal data, including on paper or through third parties. It does not provide a general exemption for microenterprises, companies with few employees, or businesses whose revenue falls below a particular threshold.LPDP, Article 2.
The rule is this: every company that processes personal data falls within the law’s scope, except for processing activities expressly excluded by law.
In practice, a store that retains names and addresses to deliver orders, a medical practice that manages patient files, or a distributor that maintains personnel records all have concrete reasons to review their compliance. ACE’s policies cover private entities that collect, store, process, or transfer personal information.Data handling policies, Article 2.
The exclusions are specific. For example, certain credit history processing activities are governed by special legislation; this does not exempt banks in relation to all the information they handle. Nor should a family business be confused with an exclusively domestic activity that has no commercial purpose.LPDP, Article 3.
What the September 16 deadline means
The law has been in force since November 23, 2024. It does not first become applicable in September 2026.LPDP, Article 64.
The State Cybersecurity Agency has announced September 16, 2026, as the deadline for submitting any outstanding notifications of data protection officer appointments. According to the official notice, those who have already notified the Agency of an appointment do not need to do so again.Official ACE notice.
The distinction matters: notifying the Agency of an appointment fulfills a specific requirement, but does not, by itself, demonstrate that the company has met its other obligations.
The data protection officer must be formally appointed, meet the required qualifications, and have the conditions needed to work independently. The obligation is not limited to large companies and may be fulfilled through an internal or external officer. Before assigning the role to a manager, the person responsible for IT, or a regular adviser, the company should therefore review that person’s other responsibilities and any potential conflicts of interest.Data protection officer guidelines, Articles 3, 5–6, 13 and 26–28.
What to review within the company
A useful starting point is to follow the information through the business: how it arrives, where it is stored, who can access it, and with whom it is shared. This review can reveal problems that cannot be resolved simply by publishing a document on the company’s website.
ACE’s policies include records of processing activities, privacy impact assessments, training, and audits. They also cover access controls, encryption, backups, and agreements with third parties that handle data. These matters require coordination among administration, human resources, technology, and legal advisers.Data handling policies, Articles 4–8.
The review should also cover privacy notices and the legal basis for using the information. Not all processing depends on consent, but having another legal basis does not remove the other obligations.LPDP, Articles 5 and 24.
The company also needs a procedure that works when someone requests to exercise their rights. The standard response period is 20 business days, with a justified extension of up to a further 20 business days. An unmonitored email address or a request passed between departments without anyone taking responsibility can become a compliance problem.Data protection officer guidelines, Articles 32–34.
The consequences of leaving compliance unresolved
Fines can reach 40 monthly minimum wages for the commerce sector for a very serious infringement. At the rate of US$408.80, that maximum is equivalent to US$16,352.LPDP, Article 57, Official minimum wage schedule.
The maximum fine is not imposed automatically. The rules require consideration of factors including the harm caused, the duration of the conduct, intent or negligence, and financial capacity. They also provide for provisional measures and the publication of public versions of enforcement decisions.Enforcement procedure rules, Articles 35–38, 43 and 46.
For a business, the consequences may also include time spent responding to official requests, correcting processes, and explaining to customers or employees what happened to their information.
Our recommendation is to begin with a clearly scoped review: identify existing processing activities, verify the data protection officer’s appointment, and organize outstanding measures by responsible person and deadline. This will help distinguish what has been addressed, what needs adjustment, and what requires immediate attention.
If your company needs to determine how this framework applies to its operations, you can contact Compass Abogados at juan.uceda@compassabogados.com.
Official sources consulted
- 1. Law for the Protection of Personal Data — Legislative Decree 144 ↗
- 2. Personal data handling policies — ACE ↗
- 3. Notice on notification of data protection officer appointments — ACE ↗
- 4. Data protection officer guidelines — ACE ↗
- 5. Administrative enforcement procedure rules — ACE ↗
- 6. Commerce and services minimum wage — Executive Decree 12 of 2025 ↗
General information reviewed as of September 2, 2026. Applying the rules requires consideration of each company’s circumstances.