Skip to content
All resources

Compliance

Law 7593: what your company must do (and by when)

Paraguay's first data protection law requires every company to strengthen its cybersecurity. What it demands, of whom, the fines, and how to prepare.

What Law 7593 is

Enacted in November 2025, it is Paraguay's first general personal data protection law, inspired by the European GDPR.

It changes the rules: protecting personal data is no longer an optional best practice — it's an enforceable legal obligation with concrete sanctions.

Who it applies to

Every company that processes data of natural persons, regardless of size or sector. If you have customers, employees, suppliers or users, it applies to you.

Micro, SMB or large enterprise — the law doesn't distinguish by size.

What “personal data” is

Any information that identifies or can identify a person: name, ID, email, phone, address, billing data, location.

There's a more protected category —sensitive data— like health, biometrics, religion or orientation. Leaking it carries higher penalties.

Legal basis: no processing without justification

The core rule is simple: you can't process personal data without a legitimate legal basis (e.g., the person's consent, performing a contract, or a legal obligation).

Keeping or using data “just because” is no longer valid.

The key obligations

Two have the biggest day-to-day impact:

  • Strengthen cybersecurity to protect the data you handle.
  • Notify the authority of leaks or incidents compromising personal data within 72 hours.

People's rights

People can request access to their data, its rectification, updating, deletion, and object to certain uses. Your company must be able to respond to those requests.

The fines

Sanctions range from 20 to 2,500 minimum daily wages for general infractions, up to 5,000 for sensitive data and up to 10,000 for minors' sensitive data.

In practice, that can exceed a billion guaraníes. The cost of not preparing is real.

The timeline

The law comes into full force in late November 2027 (a 24-month grace period). During 2026 the supervisory authority is set up within MITIC.

That window isn't for relaxing: it's the time to get in order before enforcement is full.

What you can do now

  • Map what personal data you process and under what legal basis.
  • Know what you expose to the internet, where most incidents begin.
  • Strengthen the security of your systems and access.
  • Have a response plan to meet the 72-hour notification.
  • Start with a free assessment of your surface with NEO.

See what your company exposes — free

Analyze your domain