
Recent amendments to El Salvador’s Personal Data Protection Law have significantly changed the obligations related to the Data Protection Officer (DPO), eliminating the general requirement for private companies to appoint one.
However, this does not eliminate organizations’ obligations toward data subjects.
Companies must continue to properly manage requests to exercise ARCO-POL rights, maintain internal mechanisms to handle such requests, and review their processes, policies, and privacy notices in accordance with the new provisions.
Against this backdrop, our Senior Associate Rodrigo Benítez Nassar analyzes in AmCham El Salvador’s Business Magazine how data protection should be understood as more than a formal compliance requirement and should instead become part of business management, governance, and decision-making.
Read the full article here (page 26)
Personal Data Protection: A Business Conversation