CiberLATAMbywhalemate

Mendoza Passes Cybersecurity Bill

Mendoza’s Senate gave initial approval to a bill creating a provincial system with a SOC, CSIRT and incident register.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Mendoza’s Senate overwhelmingly approved the provincial executive’s cybersecurity bill and sent it to the lower house for final approval. The measure passed 34 to 2.

Mendoza’s Senate approved the provincial executive branch’s cyber law bill by a wide margin and gave it initial approval, sending it to the Chamber of Deputies for final legislative action. The vote ended with 34 in favor and 2 against, according to provincial media that covered the session.

The measure was backed by Governor Alfredo Cornejo and seeks to protect personal data handled by the provincial government, as well as safeguard the information systems that support essential services. With that scope, the law turns cybersecurity into state policy and creates a dedicated provincial system to manage it.

How would the provincial system work?

The approved text sets out an institutional structure with an executive committee, an operational authority and a mandatory incident registry. It also explicitly includes a Security Operations Center, or SOC, for continuous monitoring of events, and a Computer Security Incident Response Team, or CSIRT, responsible for containing and mitigating attacks.

The law also establishes a specific vulnerability reporting program and a graduated sanctions regime for public agencies or vendors that fail to comply with alerts, obstruct audits or keep serious incidents confidential. The proposal therefore introduces active disclosure and cooperation obligations within the provincial system.

Who would have to comply?

The institutional scope was narrowed in committee. Compliance is mandatory only for the Executive Branch, while the Judiciary, the Legislature and the province’s 18 municipalities are invited to join or take part in the Strategic Cybersecurity Steering Committee, without being directly bound by the law.

What political criticism did the half-approval draw?

The initial approval also drew criticism from the opposition. Opposition sectors questioned the Executive Branch’s discretion to make direct purchases of cybersecurity-related technology and warned about possible risks from weak oversight in vendor contracting.

In that same debate, El Sol reported questions over direct purchases, while Mendoza Today compiled political objections to the text approved by the Senate. The discussion now moves to Deputies, where the bill will need final approval.

What regional context does the Mendoza move fit into?

Mendoza’s advance fits into a broader regional debate over regulation. An academic analysis from the University of the Andes on artificial intelligence regulation in Latin America cites bill proposals in Argentina that seek to amend Law 25,326 on Personal Data Protection to add principles of algorithmic transparency, as well as a comprehensive regulatory framework that repeals that law with an emphasis on proportionality, proactive responsibility and explicit AI regulation.

At the same time, Santa Fe moved ahead with a specific regulation on the use of artificial intelligence in the provincial state. The initiative requires transparency principles for AI systems used by the administration, obliges officials to explain how they work to the public and establishes controls to detect biases that could lead to discrimination in public decisions.

Sources

View all