ES EN
El Salvador’s Data Protection Officer Reform: What Changes for Businesses?

El Salvador’s Data Protection Officer Reform: What Changes for Businesses?

On September 17, 2026, El Salvador’s Legislative Assembly approved amendments to the Personal Data Protection Law, listed in its records as Legislative Decree No. 659. One of the main changes is the removal of the general requirement for private companies to appoint a personal data protection officer.

For businesses, this change provides an opportunity to review how they organize compliance. Their responsibilities toward the individuals whose data they use remain in place.

Scope of this update: This article examines the approved reform. As of the review date, September 22, 2026, its publication in the Official Gazette and its exact effective date could not be verified.

The reform shifts responsibility for handling requests to the entity subject to the law

According to published information about the reform’s approval, the general requirement set out in Article 15 is repealed. Data subjects’ requests will be directed to the entity subject to the law, and companies will be able to organize their internal response procedures without necessarily establishing a data protection officer position.

The Legislative Assembly explains that individuals will be able to submit requests directly to the institution, company, or organization that holds or uses their information. ARCO-POL rights—access, rectification, cancellation, objection, portability, the right to be forgotten, and restriction of processing—remain in place.

From a management perspective, this flexibility calls for clear decisions about who receives a request, who evaluates it, and who communicates the response. A company may distribute these tasks across departments, but it should ensure that doing so does not cause delays or leave requests without follow-up.

Public institutions must retain a data protection officer

The reform expressly maintains the requirement for public institutions to have a data protection officer. The role may be performed by the institution’s existing Information Officer. The State Cybersecurity Agency (ACE, by its Spanish initials) will retain its regulatory, supervisory, oversight, and inspection powers.

Procedures to review

The official announcement also states that a record must be kept indicating when information is undergoing rectification. If the data has been shared, the entity subject to the law must notify the recipients of its correction, update, or deletion within five business days after determining that the request is justified. It also provides five business days to address the withdrawal of consent.

These situations require separate tracking. As a practical measure, we recommend maintaining a request log that records the date of receipt, actions taken, communications with third parties, and completion of the process.

What do we recommend for businesses?

In light of the approved change, businesses should review their internal data protection arrangements and prepare any necessary adjustments once the reform’s effective date has been confirmed:

  1. Assign clear responsibilities. Identify the person or department that will coordinate responses to requests and the support they will need.
  2. Review contact channels. Ensure that customers, employees, and other data subjects can easily identify where to submit their requests.
  3. Update internal procedures. Establish controls for receiving, evaluating, and responding to requests, as well as tracking deadlines.
  4. Identify third parties that receive information. Maintain a map of service providers and recipients to facilitate any required communications.
  5. Keep records of how requests are handled. Document decisions and actions so the company can explain how each case was addressed.

These organizational recommendations should be tailored to each company’s information volume, activities, and risks.

What if the company already has a data protection officer?

The decision to retain a dedicated role deserves an operational assessment. In organizations with numerous databases or complex processing activities, keeping someone responsible for coordinating privacy matters can help with request handling and internal oversight.

Before changing an appointment or terminating a contract, we recommend reviewing its terms, the effective date of the legal change, and how assigned tasks will continue to be performed. The aim should be to maintain effective service for data subjects throughout the transition.

At Montano & Co., we can help your company assess its obligations and review its personal data protection policies, contracts, and procedures in line with its operations and needs.

Let’s talk about your next project.

montanoandco.net

Sources consulted (in Spanish):

  1. Legislative Assembly: Decrees issued in 2026, Decree No. 659.
  2. Diario El Mundo: Requirement for private companies to appoint personal data protection officers repealed, September 17, 2026.
  3. Legislative Assembly: Amendments to the Data Protection Law will streamline request handling, September 17, 2026.