On August 11, 2026, the “Guidelines for the Data Protection Officer” (the “Guidelines”), issued by the State Cybersecurity Agency (Agencia de Ciberseguridad del Estado or “ACE”), were published in the Official Gazette.
The obligation of regulated entities to appoint a Data Protection Officer (“DPO”) was already established under Article 15 of the Personal Data Protection Law. However, the new Guidelines introduce a specific framework governing the DPO’s profile, appointment, notification, registration, certification, operation, and oversight.
In particular, the Guidelines establish, for the first time, the obligation to notify and register the appointment of the DPO with the ACE through the DPO Registry to be implemented by the Agency.
Main obligations:
- Mandatory registration with the ACE
Each appointment of a DPO must be notified by the data controller to the Data Protection Directorate of the ACE through the electronic platform of the DPO Registry, within a maximum period of 15 business days counted from the day following the appointment.
The following documents, among others, must be submitted for registration:
- Certification of the agreement, minutes, item of minutes, or resolution through which the appointment was made;
- In the case of a DPO engaged through professional services, a notarized certified copy of the corresponding agreement; and
- For private-sector entities, documentation evidencing the legal existence of the legal entity and the authority of its legal representative, duly certified by a notary.
Likewise, any modification to the registered information must be updated within a maximum period of 10 business days.
- The appointment must comply with new formal requirements
The Guidelines establish the minimum information that must be included in the DPO appointment, including, among others:
- agreement, item of minutes, or resolution number;
- date of issuance;
- legal grounds;
- identification of the data controller;
- identification and institutional contact information of the DPO;
- start date of the DPO’s functions;
- term of the appointment or indication that it is for an indefinite term;
- powers and duties of the DPO; and
- corresponding signature.
In the private sector, when the appointment is documented through a document bearing a handwritten signature, such signature must be duly notarized.
- New requirements to serve as a DPO
The Guidelines establish minimum requirements for individuals serving as DPOs. Among other requirements, the DPO must:
- hold a university degree;
- be over 21 years of age;
- demonstrate experience in personal data protection, regulatory compliance, risk management, information technology, information security, cybersecurity, or related matters;
- have no applicable final convictions or sanctions; and
- take and pass the Data Protection Officer Certification Program once such program enters into force.
Certification will be free of charge for a duly appointed DPO. Once the program is implemented, passing the certification will be a condition for the validity of the appointment. The minimum passing grade will be 7 out of 10.
- Sworn declaration and conflicts of interest
Before accepting the position, the DPO must provide a simple sworn declaration stating whether or not he or she is in a situation that could give rise to an actual, potential, or apparent conflict of interest.
The Guidelines also expressly address situations that may constitute conflicts of interest. In the private sector, for example, certain executive, management, or highest-authority positions may be considered potentially incompatible when they involve determining the purposes and means of the processing of personal data.
- The DPO may be internal or external
The DPO may be appointed:
- internally, when the DPO is part of the data controller’s payroll; or
- externally, through a professional services agreement.
In addition, when a legal entity is engaged as the DPO, it must designate an individual who will be responsible for handling requests relating to ARCO-POL rights and who must meet the profile established in the Guidelines. The legal entity must also have demonstrable experience and a multidisciplinary team that includes, at a minimum, expertise in legal matters and cybersecurity, information systems, or risk management.
A single DPO may also be appointed for several entities belonging to the same corporate group or that are legally or economically related, provided that the DPO can effectively perform his or her duties and there is no conflict of interest.
- New monitoring and training obligations
The data controller must verify that the DPO meets the required profile before the appointment and must ensure that such requirements continue to be met throughout the performance of the DPO’s functions, conducting verifications at least every three years.
Additionally, the data controller must ensure that the DPO receives at least one annual training session on personal data protection and ARCO-POL rights. In turn, the DPO must prepare an annual training plan for the entity’s personnel, including onboarding for new employees whose duties are related to the processing of personal data.
- The DPO will have a broader role within the organization
The Guidelines establish that the DPO must perform his or her functions with autonomy and functional independence and participate in a timely manner in matters related to personal data protection, including from the early stages of designing new processing activities, products, or services.
Likewise, the DPO must be considered a key point of contact within the organization and report directly to the highest level of management.
What happens to DPOs who have already been appointed?
Appointments made before the Guidelines enter into force that do not comply with the new requirements will remain valid.
However, such DPOs must take and pass the certification program issued by the ACE.
Additionally, while the ACE has not yet enabled the electronic platform of the DPO Registry, notifications regarding appointments, modifications, or terminations must be submitted by means of an official letter, written communication, or institutional email addressed to the Data Protection Directorate of the ACE, within 20 business days following the entry into force of the Guidelines.
The Guidelines will enter into force eight days after the day following their publication in the Official Gazette.
In summary, although the obligation to appoint a DPO already existed, the new Guidelines make the appointment process substantially more formal and documented by introducing registration with the ACE, eligibility requirements, conflict-of-interest declarations, certification, registration updates, periodic training, and oversight mechanisms.
Organizations that already have a DPO should not assume that the existing appointment is sufficient. They should review their current arrangements against the new requirements and, as applicable, take the necessary steps to notify and register the DPO with the ACE.
