logo Lawwwing

Paraguay's New Data Protection Regulation: Law No. 7593/2025

After years of debate, Paraguay took a decisive step toward protecting digital privacy. Congress passed Law No. 7593/25 on the Protection of Personal Data, which creates a regulatory framework governing the processing of personal data of individuals in the country. Law 7593/2025 is clearly inspired by the standards set out in the European GDPR and […]
Legal Lawwwing
August 31, 2026

After years of debate, Paraguay took a decisive step toward protecting digital privacy. Congress passed Law No. 7593/25 on the Protection of Personal Data, which creates a regulatory framework governing the processing of personal data of individuals in the country.

Law 7593/2025 is clearly inspired by the standards set out in the European GDPR and by the data protection laws of other countries in the region. In this article, we will highlight the most relevant aspects of this new regulation, which will come into force in November 2027.

Who does the law apply to?

The law applies to any processing of personal data carried out by individuals or legal entities, regardless of the medium used or the country in which they are based, provided that:

  • They are established in Paraguay, even if the processing takes place abroad.
  • They process data of individuals located within Paraguayan territory, even without being established in the country.
  • They offer goods or services aimed at Paraguayan residents, or monitor their behavior within national territory.

Principles governing data processing

The law establishes a set of principles aligned with other personal data protection regulations such as the GDPR: accuracy, lawfulness, purpose limitation, data minimization, storage limitation, transparency, security, and confidentiality. Together, these principles seek to ensure that personal data is collected only for clear and legitimate purposes, and retained only for as long as necessary.

Accordingly, the processing of personal data will only be lawful if it is based on at least one of the following conditions:

  • the data subject's consent,
  • compliance with a legal obligation,
  • the performance of a contract,
  • the legitimate interest of the data controller,
  • the exercise of rights in judicial or administrative proceedings,
  • or the protection of the life and health of the data subject.

One notable point concerns the processing of data of children and adolescents. For minors under 16 years of age, the consent of whoever holds parental authority or guardianship is required; for those between 16 years of age and the age of majority, the processing of sensitive data requires the consent of both the adolescent and their legal representative.

Data subjects' rights

The law consolidates the following rights for personal data subjects:

  • Access: to know what personal data is being processed.
  • Rectification: to correct inaccurate or outdated data.
  • Erasure: to request the deletion of data in certain cases.
  • Objection: to object to processing on particular grounds.
  • Portability: to request that data be transferred between controllers.
  • Right to challenge automated decisions that produce legal effects or significantly affect the person.

Data controllers have a maximum period of 30 calendar days to respond to these requests, and the exercise of these rights must be free of charge.

A new supervisory authority: The National Personal Data Protection Agency

The law creates the National Personal Data Protection Agency, which will operate as a decentralized unit within the Ministry of Information and Communication Technologies, with functional autonomy to regulate, oversee, monitor, and sanction compliance with the law.

Among its functions are receiving complaints and claims, conducting audits, approving codes of conduct and self-regulatory mechanisms, assessing the adequacy of countries receiving data, and drafting standard data protection clauses, among others.

What does my website need to comply with Law 7593/25?

To comply with Law 7593/25, your website must incorporate technical and informational elements that guarantee transparency and user control over their information.

1. Consent management

If the legal basis for processing the data is consent, the website must ensure that it is:

  • Prior, freely given, informed, and unambiguous. It must be expressed through a clear statement or affirmative action. Therefore, implicit or default consent must be excluded.
  • Specific. Consent must be obtained for one or several specific purposes.
  • Revocable. The user must be able to withdraw their consent at any time through simple, free means. Furthermore, it must be possible to revoke it as easily as it was given.
  • Verifiable. The burden of proving that the data subject gave consent falls on the data controller.

2. Transparent privacy policy

Information about data processing must be presented in clear, simple language and be permanently accessible. Therefore, at the time of data collection, your website must inform users, at a minimum, of:

  • Identity and contact details: legal address, phone number, and email or equivalent channel of the data controller
  • Processing details: categories of data, purposes, and legal basis
  • Recipients: whether international communications or transfers of data are anticipated
  • Retention: how long the data will be kept, or the criteria used to determine this
  • User rights: existence of and mechanisms for exercising ARSOP rights (access, rectification, erasure, objection, and portability)
  • Automated decisions: if profiling is carried out, information about the logic applied must be provided
  • Right to lodge a complaint with the supervisory authority

3. Channels for exercising ARSOP rights

The website must have a simple, free procedure for users to exercise their ARSOP rights. These requests must be answered within a maximum of 30 calendar days.

If a piece of personal data is found to be incorrect, the controller must stop using it (blocking) or, if it continues to be used, must notify that it is being verified.

4. Security and privacy by design

Under the new legislation, both organizational and technical measures must be adopted to ensure security and prevent loss, alteration, or unauthorized access.

In addition, the website must be configured so that, by default, only the data strictly necessary for each specific purpose is processed.

If a security incident occurs, the company is obliged to notify the supervisory authority and the data subject within a maximum of 72 hours from the moment it became aware of it.

5. Minors

If your website is aimed at minors, in addition to adapting the language used, you must take into account that:

  • Minors under 16 years of age require the prior consent of their legal guardian
  • Minors between 16 and 18 years of age may give their own consent, but in the case of sensitive data they require the consent of their guardians as well

What are the penalties for non-compliance?

The law classifies violations as minor or serious:

  • Minor violations: failing to adequately inform the data subject, or failing to keep data protection policies available
  • Serious violations: processing minors' data without consent, failing to adopt adequate security measures, or failing to notify security breaches

Fines range from 20 to 2,500 minimum daily wages. However, they can reach up to 5,000 daily wages if sensitive data is affected, and up to 10,000 daily wages if the sensitive data belongs to children and adolescents.

How can Lawwwing help your e-commerce business?

The new regulation requires you to review how you process personal data, update your consent acceptance system, integrate security measures throughout your entire process, and safeguard the information of minors.

Making these changes is complex, especially if your e-commerce business processes large amounts of data or uses it in multiple ways. Complying with all the legal requirements and staying up to date with regulatory changes demands effort, resources, and constant vigilance.

That's why at Lawwwing we want to make it very easy for you. We provide the solution to adapt your e-commerce business to the new Law 7593/2025, and we automatically generate and update your data processing policy and a fully customizable cookie banner.

Adapt your e-commerce business to Law 7593/2025 today with Lawwwing.

How can we help you?
If you have any questions, our specialists are here to assist you whenever you need it.
Live Chat
Share this article
Blog

Related Articles

Businesses trust Lawwwing to ensure their legal compliance, keeping their documents up-to-date and avoiding penalties.
cross