Personal Data Protection: The State Cybersecurity Agency (ACE) Strengthens the Supervision and Compliance Framework

Personal Data Protection: The State Cybersecurity Agency (ACE) Strengthens the Supervision and Compliance Framework

August 2026Blog
  • Intellectual Property
By Paola LambertAssociate

Personal data protection in El Salvador is entering a phase of greater operational development and oversight. The Law protects all information that allows a natural person to be identified or identifiable, including information that, by its nature, requires a higher level of protection. With the publication of the new Guidelines for the Data Protection Officer and the Regulations for the Development of Administrative Sanctioning Proceedings, the State Cybersecurity Agency (ACE) establishes key aspects regarding who may serve as a Data Protection Officer, how their appointment must be formalized and registered, and how the Agency may investigate and sanction potential non-compliance. Both provisions were published in the Official Gazette on August 11, 2026, and entered into force on August 19, 2026.


One of the most relevant aspects is that the Data Protection Officer can no longer be a merely formal designation or simply be assigned to any person within the company or entity. The new Guidelines establish specific requirements regarding training, experience, independence, and the absence of conflicts of interest, with preference given to professionals with a degree in Legal Sciences. In addition, the Data Protection Officer must undergo the certification program implemented by the ACE and comply with ongoing training and reporting obligations, as well as obligations related to addressing ARCO-POL rights.

This is complemented by the fact that the ACE now has specific rules to investigate potential non-compliance, request information, conduct inspections, and administer administrative sanctioning proceedings, including through preventive compliance verifications. For regulated entities, this means reviewing not only whether they have a Data Protection Officer, but also whether their appointment, profile, documentation, and other compliance measures meet the new requirements and can be substantiated before the authority.
The entry into force of these provisions requires organizations to review their compliance framework and ensure that their implemented measures can be substantiated before the authority. To learn more about how these new provisions may affect your company or entity, you can contact our team

Next articles in this category

Torres Legal