CiberLATAMbywhalemate

Mendoza advances two cybersecurity laws

Mendoza added privacy by design, 72-hour breach notice and a repair fund backed by 50% of fines to its data protection bill.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Updated Aug. 20, 2026: Fuerza Patria expanded its data protection bill in Mendoza with privacy by design, 72-hour breach notice and a Repair Fund financed with 50% of fines. Senator Lucas Ilardo also stressed the duty to inform, repair and make transparent any compromised data.

The cybersecurity bill promoted by Mendoza’s executive branch remains under review in committees of the provincial Senate, while Fuerza Patria’s parallel data protection proposal has added definitions for privacy by design, damage repair and the use of fines. Both texts are still moving through the legislature and are aimed at strengthening the state’s response to computer incidents.

What does the executive proposal include?

The initiative was introduced by Governor Alfredo Cornejo in the provincial legislature and proposes creating a Provincial Cybersecurity System. That framework is meant to coordinate policies for prevention, detection, response and recovery after incidents affecting digital infrastructure or critical information. Sources in the provincial Security Ministry even describe it as a possible first law of its kind in the country.

Diario Judicial reported that the bill goes beyond a broad institutional framework. It also adds a data governance regime covering the full life cycle of information, from creation and storage to exchange and secure deletion. For the agencies covered, that means specific traceability, security and retention obligations.

The same analysis adds that the official text would apply to the executive, legislative and judicial branches, as well as third parties that provide technology services, infrastructure, connectivity, software or information custody to the state. It also extends to providers of essential critical services, in a scope that goes beyond the public administration alone.

How would the operating authority work?

According to Diario Judicial, the bill calls for an operational enforcement authority separate from the executive committee. That body would be responsible for carrying out the plan’s technical measures. The text also includes a tiered penalty regime for agencies that fail to meet mandatory standards, do not report incidents or hinder audits. Penalties range from warnings to restrictions on interconnection and the opening of administrative or contractual proceedings.

Clarín reported that Mendoza officials acknowledge the province faces cyberattacks every day and that the purpose of the initiative is to shield the administration from that level of activity. In that same vein, the provincial government said on social media that this is the country’s first Cybersecurity Law and emphasized its focus on protecting critical infrastructure and data handled by the public sector.

El Litoral also linked the attack on the Senate website to the legislative debate and said the initiative seeks to strengthen provincial technology infrastructure and establish response mechanisms for incidents.

What changed in Fuerza Patria’s proposal?

Fuerza Patria added a requirement to notify incidents within a maximum of 72 hours, privacy by design and a repair scheme funded by part of the fines to its data protection proposal. MDZ Online, citing lawmakers Lucas Ilardo and Félix González, said the bill seeks to formalize duties of transparency and assistance in cases of leaks or hacks.

Along with early notification, the text says any new state system or platform must build data protection and citizen security safeguards into its design from the outset. According to MDZ Online’s coverage, the goal is to align provincial rules with privacy by design principles used in international regulation.

The proposal also says 50% of fines collected for data protection violations would go to a Repair Fund. That fund would be used to finance free legal assistance and digital literacy programs for citizens, instead of sending those resources to general revenue without tracking.

In comments quoted by MDZ Online, Lucas Ilardo said that if a hack or improper access to personal data occurs, the state must inform affected people immediately, repair the damage and make transparent what information it holds on each citizen. Mendoza Today had already reported that the initiative also reinforces the state’s duty to repair the damage and recognizes a citizen’s right to know exactly what information the government has about them.

What happens if the state suffers a breach?

Fuerza Patria’s proposal requires notifying the incident within 72 hours and also informing citizens immediately if their data has been compromised. That system is paired with an obligation to repair the damage and with the right to access a detailed record of the information the state keeps on each person.

Mendoza Today added that 50% of fines for violations of personal data rules would go to a Repair Fund designed to finance free legal aid and digital literacy programs for citizens.

How was the debate shaped by the Senate hack?

The legislative debate was shaped by the cyberattack on the provincial Senate website that occurred after the executive bill was introduced. Local media reported that sources in the Security Ministry do not rule out a connection between the incident and the presentation of the initiative, although that link is being treated as a hypothesis rather than official confirmation.

Identidad Correntina and Diario San Rafael both said the hack happened after the anti cyberattack bill was introduced. In the case of the Senate website, reports also said the site was altered with a message against Argentina and an image of Chiqui Tapia, an episode that intensified the political urgency of the debate in Mendoza’s legislature.

Sources

View all