
The Corporación de Exportadores de El Salvador (COEXPORT) has shared a guide outlining key aspects of the Personal Data Protection Law—established via Decree 144 of 2024—to help companies comply with the new regulations.
According to information released by COEXPORT, the regulations apply to any company with employees, clients, “obligated subjects,” or suppliers, regardless of size or revenue. A primary step for companies is the appointment of a Delegado de Protección de Datos (DPD), the deadline for this is september 16.
The DPD must hold a university degree and possess experience in data protection or information security; they must also be over 21 years of age and have a clean criminal record. The guide specifies that the legal representative, general or operations manager, head of Human Resources or IT, and in-house counsel are ineligible for this role.
The regulatory framework rests on four pillars: the Personal Data Protection Law itself, guidelines for the DPD, the sanctioning procedure, and policies regarding data handling and operations. Furthermore, individuals have the right to request access to, rectification of, cancellation of, objection to, portability of, erasure of (“right to be forgotten”), and limitation on the use of their personal information.

Companies have 20 business days to respond to such requests, with the possibility of a 20-day extension. COEXPORT also emphasizes the requirement to have procedures in place for handling security incidents, noting a 72-hour deadline to report a breach once the company becomes aware of the event.
Non-compliance with these provisions can result in fines. Penalties range from US$408 to US$4,088 for minor infractions, US$4,496 to US$10,220 for serious infractions, and US$10,628 to US$16,352 for very serious infractions. Fines may be cumulative for each infringing act.
Risks that companies must guard against include leaving data subject requests unanswered, failing to report security breaches, using customer data for unauthorized purposes, working with third parties without data processing agreements, and having a designated officer who is not registered with the Ciberseguridad del Estado (ACE).
To advance compliance, COEXPORT proposes a 90-day roadmap: the designated officer must be appointed, notified, and registered within the first 15 days; a diagnostic assessment, data inventory, and data flow map must be completed between days 16 and 45; and privacy notices and protocols must be prepared between days 46 and 90. Subsequently, compliance must be maintained through ongoing training and audits, conducted at least twice a year.
You may also read:
