Personal Data Protection Act for Psychologists: What You Have to Know About Law 25.326

Every time a patient gives you their name, their phone, their diagnosis or tells you something in session, you are handling personal data protected by law. and not any data: mental health data are the most sensitive category that exists in Argentine legislation.
The 25.326 Personal Data Protection Act regulates how these data are collected, stored, used and shared. It applies to any psychologist working in Argentina, whether you keep your records on paper, in an Excel spreadsheet or in a clinical software.
In this article we explain to you what the law says, what obligations you have and how to fulfill them without complicating you.
What is the 25.326 Law?
The 25.326 law, passed in the year 2000, is the norm that regulates the integral protection of personal data in Argentina. It is the Argentine equivalent to the European GDPR (although earlier and less strict in some respects).
Its objective is to guarantee the right to honour and privacy of persons, regulating the processing of personal data recorded in archives, records, data banks or other technical means.
The control body is the Agency for Access to Public Information (AAIP),, which replaced the former National Directorate for the Protection of Personal Data.
Note
The protection of personal data has constitutional rank in Argentina. Article 43 of the National Constitution enshrines the action of habeas data.
Key concepts you need to know
Personal data
Any information concerning a particular or identifiable natural person. In your clinical practice, this includes:
- First name, last name, DNI
- Telephone, email, address
- Date of birth
- Health insurance data
- Emergency contact
Sensitive Data
Personal data revealing racial and ethnic origin, political opinions, religious, philosophical or moral convictions, trade union membership and information concerning health or sexual life (Art. 2). They are the category with greater legal protection.
In your clinical practice, almost everything is sensitive:
| Data | Why is he sensitive? |
|---|---|
| Diagnosis | Health information |
| Reason for consultation | Health information |
| Contents of meetings | Health and privacy information |
| Medication | Health information |
| Sexual orientation | Sexual life |
| Religious beliefs | Religious convictions |
| History of substance use | Health information |
| Suicide ideation | Health information |
Data holder
The person to whom the data refer. In your case: the patient.
Responsible for archiving, recording, database or database
The natural person or person of ideal existence, public or private, who owns a file, register, database or database (Art. 2). In your case: you as a professional.
Data processing
Systematic operations and procedures, whether electronic or not, that allow the collection, preservation, management, storage, modification, relationation, evaluation, blocking, destruction and in general the processing of personal data, as well as their transfer to third parties (Art. 2).
Data dissociation
Any processing of personal data in such a way that the information obtained cannot be associated with a specific or identifiable person (Art. 2). This is relevant when you share clinical material in supervision or research.
What duties do you have as a psychologist?
1. Consent to data processing
The general rule (Art. 5.1) is that the processing of personal data is unlawful when the holder does not give his consent free, express and informed, which must be recorded in writing, or by other means permitting it to be equated..
However, Art. 5.2.d establishes a important exception for psychologists: consent is not necessary when the data " derive from a contractual, scientific or professional relationship of the data holder, and are necessary for its development or compliance."The therapeutic relationship is a professional relationship, so the data necessary for clinical care are covered by this exception.
In addition, Art. 8 specifically empowers health professionals to collect and process data relating to the health of their patients, respecting the principles of professional secrecy.
In practice: Although the law allows you to process data without additional consent for the professional relationship, it is a good practice to include a section on data handling in your informed consent. This fulfills the duty of information (Art. 6) and generates transparency.
Note
Art. 7 of the law states that, as a general rule, the formation of files that store sensitive data is prohibited. But Art. 8 creates the specific exception: health facilities and health professionals may collect and process data related to the health of their patients, provided that they respect professional secrecy.
2. Data quality (Art. 4)
The Act lays down strict principles on data quality:
- They should be certain, appropriate, relevant and not excessive in relation to the scope and purpose for which they were obtained (Art. 4.1)
- Collection cannot be done by unfair or fraudulent means (Art. 4.2)
- Can't be used for different purposes or incompatible with those that motivated their obtaining (Art. 4.3). If a patient gave you their email to coordinate appointments, you can't use it for newsletters (unless you consent separately)
- They should be exact and updated when necessary (Art. 4.4)
- Incorrect or incomplete data should be delete and replaced when the person responsible is aware (Art. 4.5)
- They should be destroyed when they are no longer necessary or relevant to the original purposes (Art. 4.7)
4. Security (Art. 9)
The controller must adopt the technical and organisational measures necessary to ensure the security and confidentiality of personal data so as to prevent their adulteration, loss, consultation or unauthorised processing, and to detect deviations, whether intentional or not (Art. 9.1).
The law also prohibits the recording of personal data in files that do not meet technical conditions of integrity and security (Art. 9.2). This includes:
- Access control (who can see the data?)
- Safe storage (where are the data?)
- Protection against loss or destruction (is there backup?)
- Protection against unauthorized access (is there a password, encryption?)
- Deviation detection (can you detect if someone accessed without permission?)
As you handle sensitive health data, the required safety standard is high.
5. Duty of confidentiality (Art. 10)
The controller and the persons involved in any stage of the data processing are bound by professional secrecy in relation to the data. This obligation subsists even after the end of the relationship with the data file holder (Art. 10.1).
This duty may only be relieved by a court decision or if there are substantial reasons relating to public security, national defence or public health (Art. 10.2).
If you have administrative staff, you need a confidentiality agreement.
6. Duty of information (Art. 6)
When you collect personal data, you must inform the patient expressly and clearly beforehand:
- The finality for which they will be treated and for whom they may be addressed (Art. 6.a)
- The existence of the file and the identity and address of the person responsible (Art. 6.b)
- The mandatory or optional nature of the replies (art. 6.c)
- The consequences of providing data, refusal or inaccuracy (Art. 6.d)
- The possibility of exercising rights of access, rectification and deletion (Art. 6.e)
7. Transfer of data to third parties (Art. 11)
The data may only be transferred for the performance of purposes directly related to the legitimate interest of the assignor and the assignee, and with the subject to the consent of the holder (Art. 11.1). Consent for the assignment is revocable (Art. 11.2).
Consent is not required for the assignment in the case of health data and is necessary for reasons of public health, emergency or epidemiological studies, provided that identity is preserved by appropriate dissociation (Art. 11.3.d).
Important: The assignee is subject to the same obligations as the assignor, and both respond solidary and jointly (Art. 11.4). This applies if you share data with a supervisor, colleague or software provider.
Patient's rights to their data
The law recognizes the following rights:
Right of information (Art. 13)
Any person may request from the control body information on the existence of personal files, records or databases, their purposes and the identity of their controllers. This record is for consultation public and free.
Right of access (Art. 14)
The patient, subject to accreditation of his identity, has the right to request and obtain information from his personal data. You have a period of 10 days to respond from the reliable intimation (Art. 14.2). If you do not respond or the answer is insufficient, the action of habeas data is enabled.
Access is free at intervals not less than 6 months, except for legitimate interest (Art. 14.3). In the case of deceased persons, the right corresponds to their universal successors (Art. 14.4).
The information should be provided in clear, uncodified form and in accessible language (Art. 15.1), and should address the totality of the record belonging to the holder (Art. 15.2).
Right to rectify, update or delete (Art. 16)
Everyone has the right to have their personal data rectified, updated and, where appropriate, deleted or subject to confidentiality (Art. 16.1). You have 5 working days to do so from receipt of the claim (Art. 16.2).
On deletion: It does not apply when it could cause damage to the legitimate rights or interests of third parties, or when there is a legal obligation to keep the data (Art. 16.5). This is key to medical records, since the 26.529 Act requires you to keep it for 10 years. In practice:
- Administrative data (telephone, email, health insurance): may be deleted
- medical records: is preserved for the legal term, but access may be blocked
- Data on digital systems: is anonymized or deleted for what is not a medical records
The data must be kept within the time limits provided for in the applicable provisions (Art. 16.7).
The rectification, update or deletion is free of charge for the person concerned (Art. 19).
Council
When a patient exercises any of these rights, he or she documents the order and your response in the medical records. This protects you from a possible claim. If you gave data to a third party, you must notify him or her of rectification or deletion within 5 business days (Art. 16.4).
What is habeas data?
Habeas data is the judicial action that anyone can initiate to:
- Know what your data is in a database
- Request the rectification, deletion or updating of incorrect data
- Require the confidentiality of sensitive data
In the context of your clinical practice, a patient could initiate a habeas data if:
- You deny him access to his medical records.
- You don't correct incorrect data after I ask you to
- You share your data without consent
Procedure: The patient first makes the claim to you (extrajudicial). If you do not respond or you do not satisfy it, he can initiate the legal action before a judge.
Database registration
Do you have to search your database?
Art. 21 states that any file, record, database or public data bank, and private to provide reports, must be registered in the Register. Art. 24 adds that individuals who form files other than for personal use only must register in accordance with Art. 21. In practice, this applies to:
- individual clinical practice: if you keep patient records (paper or digital), technically you should register the basis
- Institutions and centers: is mandatory without exception
- Clinical Software: the software provider must register its own database
Reality vs. theory: Many independent professionals do not register their database, and AAIP rarely controls individual clinical practices. However, registration is free and online, and protects you from complaints. It is advisable to do so.
How to register?
- Enter the AAIP website (www.argentina.gob.ar/aaip)
- Look for the "National Database Register"
- Complete the form with your database information (what data, for what purpose, what security measures, etc.)
- Registration is free and renewed annually
Penalties for non-compliance
Administrative sanctions (Art. 31)
The control body may apply: warning, suspension, fine from $1.000 to $100.000, closure or cancellation of the file, record or data bank (Art. 31.1). The penalties are graduated in relation to the gravity of the violation and the resulting damages (Art. 31.2).
The amounts are those of the original law (year 2000) and are updated by regulation.
Criminal sanctions (Art. 32)
The Act incorporated two articles into the Criminal Code:
- Art. 117 bis CP: Prison from 1 month to 2 years for anyone knowingly inserting false data into a personal data file. The penalty goes up to 6 months to 3 years if you provide false information to a third party. It is increased by half if damage is caused
- Art. 157 bis CP: Prison from 1 month to 2 years for anyone who unlawfully accesses a personal data bank, or discloses information whose secret he is obliged to preserve by law
In addition to criminal and administrative sanctions:
- Civil liability: The patient may sue for damages
- Ethical sanctions: of the professional college
Common situations in clinical practice
"A relative calls and asks for information"
You cannot give information without the patient’s consent. Not even confirm that that person is your patient. The exception is whether the relative is the legal representative of a minor or a person with restricted capacity.
"Health insurance calls for detailed diagnosis"
You are only required to report the diagnostic code (CIE/DSM), the session frequency and the general plan. Not the content of the sessions or detailed clinical information.
"I share cases with colleagues for supervision"
The law provides for dissociation of data (Art. 2): the processing of data in such a way that the information cannot be associated with a determined or determinable person. If you dissociate correctly, the data ceases to be personal. If the dissociation is not complete (because the case is identifiable), you need the consent of the patient for the assignment (Art. 11) and a confidentiality agreement with the supervisor.
"Use Google Drive to keep medical records"
Google Drive is a generic storage tool, not a clinical software. The main problem is not where the servers are, but that Google Drive does not offer a medical records structure, does not guarantee the unalterability required by Art. 13 of the 26.529 Law, and according to its terms of service, Google can access the stored content. You should check that your account has the corresponding security measures (two-step verification, encryption, restricted access).
"I accidentally erased a patient's medical records."
If you don’t have backup, you have a serious problem. The law obliges you to keep the data and the 26.529 law obliges you to keep the medical records for 10 years. Not having backup is not just a technical problem — is a legal breach.
"A patient asks me to erase everything"
You can delete the administrative data, but the medical records must be kept for the legal period (10 years). Explain this legal limitation to the patient and offer to block access if he or she is not going to continue treatment.
Compliance Checklist
Use this list to check if your clinical practice complies with the 25.326 law:
Consent and transparency
- Your informed consent includes a section on handling personal data
- The patient knows what data you collect, for what and where you keep them.
- Consent is in writing or otherwise comparable (Art. 5.1)
Security
- Paper records are locked
- Digital records have password and, ideally, encryption
- Your computer has access password
- You use two-step verification on your digital accounts
- You have backup of your clinical records
- Your WiFi network has a secure password (not "123456")
Access
- Only you (and authorized personnel) access patient data
- Administrative staff have a signed confidentiality agreement
- If you use clinical software, you checked its security measures.
Patient rights
- You know how to respond to an access request (10 days running)
- You know how to respond to a rectification request (5 business days)
- You have a procedure to deliver a copy of the medical records
Registration
- You registered your database to the AAIP (recommended)
- Renewed annual registration
How Brauni helps you comply with the 25.326 Law
Brauni was designed taking into account the 25.326 law from day one. You can see how that translates into practice in digital medical records; in short:
- End-to-end encryption: Sensitive data are encrypted at rest and in transit
- Grenular access control: Only you access the information of your patients
- Integrated consent: Informed consent includes the data protection section
- Auto-Backups: You will never lose a medical records
- Access Log: Full audit of who accesses what and when
- Patient rights provided: Exports, corrects or blocks patient data in seconds
- Data not training AI: Your clinical information is never used to train models
Free Brauni test for 30 days, no card
Automatic session notes, digital medical records and more.
Start for freeSummary
| Concept | Description |
|---|---|
| What does it regulate? | Collection, storage, use and sharing of personal data |
| Does it apply to psychologists? | Yes. Art. 8 empowers health professionals to process health data of their patients, respecting professional secrecy |
| Consent | Free, express and informed, in writing or equivalent means (Art. 5.1). It is not necessary when deriving from the professional relationship (Art. 5.2.d) |
| Patient's rights | Information (Art. 13), Access — 10 straight days (Art. 14), Rectification/Removal — 5 working days (Art. 16) |
| Habeas data | Action for non-compliance (Art. 33-43) |
| Sanctions | Administrative: warning of a fine of $1.000-$100.000 and closure (Art. 31). Penalties: imprisonment from 1 month to 3 years (Art. 32) |
| Key | Comply with the duty of information (Art. 6), adequate safety measures (Art. 9) and respond when the patient exercises his rights |
Related articles

Privacy and Security
Record therapy sessions: what the law says and how to do it right
Recording therapy sessions is legal only with prior informed consent. What Argentine law requires, how to write the clause and how to save the audio.

Privacy and Security
Cybersecurity for psychologists: how to protect your patients' data
Practical cybersecurity guide for psychological clinical practice. Passwords, WiFi, phishing, ransomware, backups and what to do if they steal your notebook with medical records.

Privacy and Security
WhatsApp with patients: limits, risks and good practices
How to use WhatsApp with patients without breaking the frame or confidentiality: clear boundaries, crisis protocol and good practices for psychologists.