TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Guatemala TerraLex Guide to Data Protection Guide

Date posted:
23/04/2021
Last update:
09/04/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

In Guatemalan legislation, there is no specific regulation that governs the processing and protection of personal data.

Nevertheless, the Political Constitution of the Republic of Guatemala provides a general framework of rights related to information (habeas data). In Article 24 – inviolability of correspondence, documents, and books – establishes that “the correspondence of every person, their documents and books are inviolable… The secrecy of correspondence and telephone, radio, cable, and other products of modern technology is guaranteed.” The only way this information can be reviewed or seized is by a final ruling issued by a competent judge, in accordance with legal formalities. Likewise, Article 31 – access to state archives and records – establishes that “every person has the right to know what is registered about them in archives, files, or any other form of state records, and the purpose for which this information is used, as well as to request correction, rectification, and updating.”

Although not specific to data protection, the Law of Access to Public Information (LAPI) (Decree Number 57-2008), which regulates the use of public information, guarantees every individual the right to know and protect personal data contained in state archives, as well as updates to it (Art. 1, paragraph 2). It also contemplates important concepts such as personal data, sensitive data, or sensitive personal data, and habeas data as per its object.

These terms are defined as follows:

  • Personal data: that relating to any information concerning identified or identifiable natural persons.
  • Sensitive data or sensitive personal data: that which refers to the physical or moral characteristics of individuals or facts or circumstances of their private life or activity, such as personal habits, racial origin, ethnic origin, political ideologies and opinions, religious beliefs or convictions, physical or mental health status, sexual preference or life, moral and family status, or other similar intimate issues.
  • Habeas data: it is the guarantee that every person has to exercise the right to know what is registered about them in files, records, or any other form of public records, and the purpose for which this information is used, as well as its protection, correction, rectification, or updating. Impersonal data, such as demographic data collected for statistical purposes, are not subject to the regime of habeas data or personal data protection.

Furthermore, in Article 22 – confidential information – the LAPI establishes as confidential information, that which is expressly defined in Article 24 of the Political Constitution of the Republic of Guatemala, sensitive or personal sensitive data, which can only be known by the right holder, and private information received by the obligated party under confidentiality guarantee, among others.

Regarding the processing of personal information, Article 30 of the LAPI outlines specific procedures and obligations regarding personal data processing. It establishes that “the obligated parties will be responsible for personal data and, in relation to this, must: 1. Adopt appropriate procedures to receive and respond to requests for access and correction of data submitted by the data holders or their legal representatives, as well as train public servants and make their policies regarding data protection known; 2. Administer personal data only when it is adequate, relevant, and not excessive, in relation to the purposes for which it was obtained; 3. Make available to the individual, starting from the moment personal data is collected, the document in which the purposes of its processing are established; 4. Ensure that personal data is accurate and updated; 5. Adopt the necessary measures to guarantee the security, and where applicable confidentiality or reservation of personal data and prevent its alteration, loss, transmission, and unauthorized access. Active parties may not use the obtained information for commercial purposes, except with the express authorization of the data holder.”

Finally, obligated parties may not disseminate, distribute, or commercialize personal data contained in information systems developed in the exercise of their functions, unless the express written consent of the individuals referenced in the information has been given. The State will ensure that if express consent is granted, no undue influence will be exerted to the detriment of the governed individual, clearly explaining the consequences of their actions (Art. 31 LAPI).

Notwithstanding the absence of specific legislation on data protection, based on disputes from private parties, Guatemala’s Constitutional Court has issued resolutions on the matter, stating that: “According to this Court’s criterion, any commercialization of personal data must be subject to the condition that such information was voluntarily provided by the person, with the person’s authorization, whose data will be subject to commercialization; and that, at the time of obtaining such information, the person’s rights to update, rectify, maintain confidentiality, and delete, as mentioned above, have been guaranteed, as a way to safeguard the fundamental rights to personal privacy, privacy, and honor.” (Files 863-2011 and 3552-2014).

In addition to Constitutional standards, criminal law regulates crimes involving the breach of these obligations, such as Article 274 "D" of the Criminal Code, which regulates that imprisonment shall be imposed on anyone who creates a data bank or computerized registry with data that may affect the privacy of persons. Article 274 "E" regulates that imprisonment will be imposed on anyone who alters computer records or computer programs to hide or distort information required for a commercial activity, or for compliance with an obligation. Article 274 "F" regulates that imprisonment and a fine shall be imposed on anyone who, without authorization, uses the computer records of another, or enters, by any means, its data bank or electronic files.

To whom do the laws apply?

The Political Constitution of the Republic of Guatemala, being the supreme law of the country, applies to all individuals within the national territory, both nationals and foreigners.

Regarding the Law of Access to Public Information, Article 6 establishes that the obligated parties are “any individual or legal entity, public or private, national or international of any nature, institution or entity of the State, organization, body, entity, agency, institution, and any other that manages, administers, or executes public resources, state assets, or acts of public administration in general, that is required to provide the public information requested from them.” This means it applies to state organizations, centralized, decentralized, and autonomous entities, banks, financial agencies, superintendencies, and any public entity, business, organization, or entity receiving public funds or resources.

The Criminal Code provides for crimes related to misuse of data, cybersecurity, and related figures.

Scope of protection

What type of data is covered by the law?

The Law of Access to Public Information distinguishes between personal data, i.e. data relating to any information concerning identified or identifiable natural persons; and sensitive personal data, i.e. personal data referring to the physical or moral characteristics of persons or to facts or circumstances of their private life or activity, such as personal habits, racial origin, ethnic origin, political ideologies and opinions, religious beliefs or convictions, physical or mental health, sexual preference or life, moral and family situation, or other intimate matters of a similar nature.

What are the main exemptions (if any)?

Non-identifiable impersonal data, such as demographic data collected for statistical purposes, are not subject to the personal data protection regime.

What rights do the laws grant to the data owners?

Guatemalan legislation grants various rights to the owners of information; primarily, it grants and guarantees the right to inviolability of correspondence, documents, and books (Art. 24 Political Constitution of the Republic of Guatemala).

It also recognizes the right of access to information, meaning individuals can request and obtain information about their personal data held in archives or information systems of public entities. Likewise, it grants the right of rectification, which allows the data holders to request correction or updating of their personal data when it is inaccurate or outdated. Additionally, it protects the right to informed consent, meaning public entities cannot disseminate, distribute, or commercialize personal data.

The Constitutional Court of Guatemala has issued rulings within files 1356-2006 and 863-2011, defining the individual's right to informational self-determination, which gives him/her control over all data concerning them, and protection against improper use and for profit by a third party. Also, the Court's criteria is that any commercialization of a person’s information must be subject to the following conditions: a) In obtaining data: with purpose, legitimately, and voluntarily; b) In the use of data: with consent and purpose; and c) In the registration of the data: i) rights of updating, ii) rectification, iii) confidentiality, and iv) exclusion.

These rights aim to guarantee that individuals have control over their personal information and ensure their privacy and dignity.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

See answer regarding legislation and regulations – national laws.

Specifically, it is necessary to highlight what is established in Article 24 – inviolability of correspondence, documents, and books – of the Constitution of the Republic of Guatemala, which states that “the correspondence of every person, their documents and books are inviolable… The secrecy of correspondence and telephone, radio, cable, and other products of modern technology is guaranteed.”

What are the main obligations imposed by the law?

See answer regarding legislation and regulations – national laws.

However, it is important to emphasize what is stated in Article 30 of the LAPI, which outlines specific procedures and obligations regarding the processing of personal data: “Obligated parties will be responsible for personal data and, in relation to this, must: 1. Adopt appropriate procedures to receive and respond to requests for access and correction of data submitted by the data holders or their legal representatives, as well as train public servants and make their policies regarding data protection known; 2. Administer personal data only when it is adequate, relevant, and not excessive, in relation to the purposes for which it was obtained; 3. Make available to the individual, starting from the moment personal data is collected, the document in which the purposes of its processing are established; 4. Ensure that personal data is accurate and updated; 5. Adopt the necessary measures to guarantee security, and where applicable confidentiality or reservation of personal data and prevent its alteration, loss, transmission, and unauthorized access. Active parties may not use the obtained information for commercial purposes, except with the express authorization of the data holder.”

Do the laws establish a data retention period to be observed?

Yes, the Commercial Code (Decree Number 2-70) establishes an obligation regarding the conservation of books or records.

Article 376 of the Commercial Code – conservation of books or records – establishes that “merchants, their heirs or successors, shall keep the books or records of the general course of their business for the entire duration of the business and until the liquidation of all their operations and commercial dependencies.”

It also provides a general rule regarding the period for document destruction, stating that “documents related specifically to certain acts or negotiations may be destroyed once the statute of limitations for actions arising from them has passed. If there is any pending matter directly or indirectly related to them, they must be kept until it is resolved.” (Art. 383 Commercial Code)

For example, the Tax Code (Decree Number 6-91) establishes that it is the obligation of taxpayers and responsible parties to maintain, in an orderly manner, while the statute of limitations has not expired, books, documents, files, bank account statements, or the taxpayer's information systems, relating to their economic and financial activities, as well as documents showing compliance with their tax obligations.

Must the data processing activities be recorded under the law?

There are certain regulated sectors, such as banking, that have regulations related to maintaining information securely. The Banking and Financial Groups Law establishes the need for confidentiality regarding client information, and banking information can only be revealed in cases provided by law, such as a judicial order. Similarly, Resolution JM-102-2011 from the Monetary Board requires banking entities to adopt security measures to protect systems and information.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

No, Guatemala does not have a specific DPNA. However, according to the Law of Access to Public Information and as described in the applicability section of the law, obligated parties will be responsible for personal data and must adopt procedures to address access and correction requests, train their staff, and disclose their protection policies. They may only administer data that is adequate and relevant in accordance with its purpose, ensuring that it is accurate and up-to-date. They must also inform the holder of the purpose of the data processing, implement security measures to prevent its alteration, loss, or unauthorized access, and refrain from using it for commercial purposes without express authorization.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

The Information Units shall oversee: 1. Receiving and processing requests for access to public information; 2. Guiding interested parties in the formulation of requests for public information; 3. Providing consultation regarding the public information requested by the interested parties or notifying them of denial of access to the same as well as the reasoning for such denial; 4. Issuing a simple or certified copy of the public information requested, if it is in the files of the obligated subject; 5. Coordinating, organizing, administering, safeguarding, and systematizing the files containing the public information in its charge, always respecting the legislation on the matter.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

As of now, Guatemala does not have specific regulation regarding this issue.

Is it necessary to notify the National Authority prior to the international transfer?

N/A

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

In Guatemala, there are various regulations establishing security standards in information management, including the Commercial Code, the Tax Code, and the Criminal Code.

The Commercial Code, for example, obliges companies to maintain accounting and financial records with integrity and security, and this obligation for retention is at least five years, as established in Article 382.

In the case of the Tax Code, it establishes that taxpayers and responsible parties must keep, in an orderly manner, while the statute of limitations has not expired, books, documents, files, bank account statements, or the taxpayer's information systems related to their economic and financial activities, as well as documents that show compliance with their tax obligations.

Finally, the Criminal Code contemplates some crimes related to information security, such as the crime.

Do the laws establish any kind of mandatory notification duty?

N/A

What are the sanctions for noncompliance with data protection laws?

The Criminal Code, Decree nº 17-73 of the Congress of the Republic, sanctions with prison and a fine the creation of forbidden databases that may harm people’s privacy, among other acts.

Other comments

Other comments

The Constitutional Court of Guatemala in case number 1356-2006 on October 11, 2006, ruled with respect to data or files held by third parties for commercial use, establishing that there are four rights that must be observed with respect to the recording of personal data:

  1. The right to update data;
  2. The right to rectification of erroneous data;
  3. The right to confidentiality of personal information;
  4. The right to the exclusion of sensitive user information.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.