
The Legislative Assembly of El Salvador approved a series of amendments to the Personal Data Protection Law, focused on how organizations must manage compliance with their obligations in this area, particularly regarding the role of the Data Protection Officer (DPO) and the handling of requests to exercise ARCO-POL rights.
The main change for the private sector is the elimination of the general obligation to appoint a DPO. However, this does not eliminate companies’ obligations toward data subjects or their responsibility to establish internal mechanisms to address their rights.
General obligation for companies to appoint data protection officers is repealed
The reform repeals Article 15 of the Law, which provided that all obligated entities were required to appoint a DPO to manage and process requests related to ARCO-POL rights. Article 17, concerning the duty to assist the DPO, is also repealed.
This means that private companies will no longer be subject, under this provision, to a general obligation to formally maintain this role. The elimination of the DPO does not mean that compliance obligations are eliminated.
The reform expressly transfers to the obligated entity several responsibilities that were previously assigned to the DPO, including providing assistance and guidance to its departments or service providers and establishing internal mechanisms to manage requests to exercise ARCO-POL rights.
Therefore, companies must have clear processes in place to receive, assess, and respond to requests from data subjects, even if they decide not to maintain a formal DPO.
ARCO-POL rights and applicable deadlines remain in effect
The amendments maintain the obligations related to the exercise of data subjects’ rights. Among other aspects:
- Requests must be submitted to the corresponding obligated entity.
- The deadline to respond to ARCO-POL requests is 20 business days, extendable for an additional 20 business days when justified reasons exist.
- Incomplete requests may be subject to a single notice to cure, and the data subject has 10 business days to remedy the deficiencies.
- Decisions denying a request must be duly reasoned and communicated to the data subject within the deadlines established by the Law.
- Regarding withdrawal of consent, the obligated entity continues to have 5 business days to take action.
Privacy notice requirements are also modified
The amendment also modifies the requirements applicable to privacy notices. In particular, it no longer requires the name or contact information of the DPO to be included among the information specified for such notices.
The relevant provision now requires an indication of the means or mechanisms available for submitting requests to exercise ARCO-POL rights.
Companies that currently identify a DPO in their privacy notices, forms, websites, or other documents should review these materials to determine whether updates are required.
What about public institutions?
The reform establishes an important distinction for the public sector.
Although the general obligation previously established is eliminated, public institutions must appoint a DPO, who may also serve as the institution’s Information Officer. Likewise, the obligation to include the DPO’s contact information in notices provided to users is eliminated.
What comes next?
The amendments reduces a formal requirement for the private sector, but does not reduce the need for an effective compliance framework.
Companies that already have a DPO may use this change as an opportunity to review whether to maintain this structure, modify it, or assign data protection functions internally to another department or responsible individual. The key will be ensuring that the organization can comply with its obligations under the Law.
Organizations that are still implementing their data protection programs should consider these changes when defining their compliance structure, internal policies, and channels for handling data subjects’ requests.