CiberLATAMbywhalemate

Paraguay Applies Data Law to Businesses

Paraguay’s new data law now covers e-commerce, fintech, insurance and telecom, with rights, data minimization and habeas data.

Whalemate Labs · AI-assisted researchJul 21, 20262 min read

Paraguay’s Personal Data Protection Law No. 7593/2025 is already setting concrete obligations for sectors that handle customer information, including e-commerce, mobile apps, financial services, insurance and telecommunications. The law also adds rights of access, correction, deletion, portability and objection to commercial use of data.

Paraguay’s Personal Data Protection Law No. 7593/2025 is already reaching sectors that manage large volumes of customer information, including e-commerce, mobile apps, financial services, insurance and telecommunications, according to a specialized analysis cited by EMERiCs.

Scope for companies and public entities

Coverage in Paraguayan media says the law introduces rights of access, correction, deletion of records without justification, objection to the use of data for commercial or advertising purposes, portability between providers and the ability to challenge decisions made solely by algorithms or automated systems.

That same reporting also highlights the principle of data minimization. In practical terms, it requires companies to collect only the information needed to provide a service or carry out a specific activity.

Compliance and complaint channels

A report published by La Nación in Paraguay says the procedures to exercise these rights will be free of charge. If someone detects improper use of their data, they must first file a complaint with the company. If the response is not sufficient, they may go to the Data Protection Agency or use the constitutional guarantee of habeas data.

At the same time, the available material indicates that the law strengthens compliance obligations in industries that process customer data. The EMERiCs reference places that scope in both the private sector and areas tied to the administration of personal information.

Implementation and institutional framework

The available reporting also mentions implementation deadlines through 2027 and the creation of the National Personal Data Protection Agency, although the material provided does not detail interim dates or the full rollout schedule.

Against that backdrop, the law appears as a regulatory shift that does more than set out rights. It also adds concrete complaint mechanisms, data minimization duties and an institutional framework for handling complaints and reviewing automated decisions.

Sources

View all