Registering Databases of Personal Data according to Law 29733
The protection of personal data has become a priority in the current digital environment. In Peru, Law No. 29733, known as the Personal Data Protection Law, and its regulations, establish guidelines for the proper handling of personal information. One of the fundamental aspects of this regulation is the obligation to register databases containing personal data. In this article, we will analyze the importance of this registration, the relevant articles of the law and its regulations, applicable fines, and some examples of sanctions imposed by the Ministry of Justice (Minjus).
Importance of Registering Databases of Personal Data
Registering databases of personal data is crucial for several reasons:
- Transparency and Control: It allows authorities and data subjects to know who is collecting and processing personal information.
- Accountability: It fosters the responsibility of organizations by ensuring that they handle data in accordance with the law.
- Protection of Rights: It facilitates the protection of the rights of data subjects, ensuring that their data is processed appropriately.
- Prevention of Misuse: It helps prevent the unauthorized or improper use of personal data.
Obligations and Requirements under Law 29733 and its Regulations
Relevant Articles of Law 29733
- Article 25: Establishes the obligation to register databases containing personal data in the National Registry of Personal Data Protection.
- Article 27: Indicates that the registration must include detailed information about the data controller, the purpose of the data processing, and the security measures implemented.
Regulations of Law 29733
- Article 17: Details the registration procedure, which includes the submission of a specific form and the declaration of the security measures adopted.
- Article 18: Specifies the data that must be provided for registration, such as the identification of the data controller, the purpose of the database, and the description of data flows.
Registration Process
- Preparation of Documentation: Gather the required information, such as the identification of the data controller and the description of security measures.
- Form Submission: Complete and submit the registration form to the General Directorate of Personal Data Protection.
- Fee Payment: Pay the corresponding fee, which in 2024 is S/ 75.80.
- Review and Approval: The authority will review the submitted documentation and, if it meets the requirements, proceed to register the database.
Fines and Sanctions
Failure to comply with the obligation to register databases of personal data can result in significant sanctions. According to the law, violations can be minor, serious, or very serious, with fines varying according to the severity of the infraction.
- Minor Infractions: Fines ranging from 0.5 to 5 UIT (Tax Units).
- Serious Infractions: Fines ranging from 5 to 50 UIT.
- Very Serious Infractions: Fines ranging from 50 to 100 UIT.
Real Cases of Sanctions Imposed by Minjus
- Banco Internacional del Perú (Interbank) Case: In 2019, Interbank was sanctioned with a fine of 50 UIT for failing to register several of its databases containing personal data and for not having adequate security measures to protect customer information.
- Claro Perú Case: In 2017, the telecommunications company Claro was fined 80 UIT for not registering its databases containing personal data and for several infractions related to the improper handling of user information.
- Ripley Perú Case: In 2018, the department store Ripley was sanctioned with a fine of 70 UIT for not registering its databases containing personal data and for using customer information for unauthorized purposes without the proper consent.
Conclusion
The registration of databases containing personal data is not only a legal obligation under Law 29733 and its regulations but also an essential practice to ensure the protection of the rights of data subjects. Complying with this obligation helps organizations avoid significant sanctions and promotes an environment of transparency and accountability in handling personal information. Real cases of sanctions demonstrate the importance of adhering to the regulations to avoid legal and financial consequences.
It is crucial to have proper legal advice to comply with all legal obligations and avoid sanctions. At Trademark Law Firm, we offer specialized services for the registration of databases containing personal data, ensuring that your organization meets all necessary legal and security requirements.