Personal Data Protection Law in El Salvador: Everything You Need to Know About the CNAD’s New Provisions

Personal Data Protection Law in El Salvador: Everything You Need to Know About the CNAD’s New Provisions

August 2026Blog
By Torres Legal

Digital Asset Service Providers and Certifiers overseen by the National Digital Assets Commission (CNAD) must review the designation, profile, and registration of their Personal Data Protection Delegate, as well as establish an institutional communication channel with the State Cybersecurity Agency (ACE), in accordance with the new personal data protection provisions in El Salvador.

Personal data protection continues to take shape in El Salvador. With the publication of the Guidelines for Personal Data Protection Delegates by ACE, an obligation already contemplated in the legislation now has more concrete rules regarding the profile, designation, registration, and operation of this role.

In this context, CNAD issued Circular No. 008-2026, directed at the Digital Asset Service Providers and Certifiers under its supervision, through which it communicates the Guidelines and establishes a deadline of 20 business days for these entities to adjust their organizational and operational structure, in accordance with the new provisions.

From a general obligation to concrete rules

The Personal Data Protection Law, in its article 2, establishes a broad scope of application for natural and legal persons, public or private, engaging in activities related to personal data processing. Moreover, article 15 establishes the obligation to appoint a Personal Data Protection Delegate.

The new ACE Guidelines develop this obligation, establishing requirements for the profile, designation, documentation, registration, and communication of the Delegate. In simple terms: the obligation already existed; now there are more defined rules to fulfill it.

Who should pay attention to this new provision?

Circular No. 008-2026 is specifically directed at the Digital Asset Service Providers and Certifiers supervised by CNAD.

For these entities, the adaptation period began with the entry into force of the Guidelines, on August 19, 2026. Therefore, they should verify now whether they have a Personal Data Protection Delegate and whether this Delegate meets the requirements established in the new Guidelines.

What should an entity review?

1. The Delegate's profile The Guidelines establish a minimum profile to perform this role, related to academic training, professional experience, and suitability. Among other aspects, they consider knowledge or experience in areas such as personal data protection, regulatory compliance, risk management, information security, or cybersecurity.

The first review should, therefore, focus on determining whether the proposed or currently designated person meets the required profile.

2. The manner of designation

The appointment must be formally documented, in accordance with the rules applicable to the organization and the type of Delegate designated.

It's not enough to identify the responsible person: the entity should be able to formally accredit their designation.

3. The registration and communication with ACE

Obliged entities must carry out the corresponding procedure to register and communicate the appointment of their Delegate with the Personal Data Protection Directorate of ACE. Additionally, they should consider the established deadlines for communicating modifications related to this role.

As part of this adaptation, each entity should establish an institutional email address that will function as the official communication channel with the Personal Data Protection Directorate of ACE and should be reported to the authority.

Reference:

What happens to those who already had a Delegate?

The Delegates appointed before the entry into force of the Guidelines retain the validity of their designation. However, they must undergo and pass the certification program implemented by ACE.

Therefore, organizations that already have this role should also review if their designation and profile are aligned with the new provisions.

What should an entity supervised by CNAD do now?

Why is it relevant?

The publication of these Guidelines represents a new step in the implementation of the personal data protection regime in El Salvador and poses new considerations for entities supervised by CNAD.

Compliance is not limited to the appointment of a Delegate, but to ensuring that the organization is aligned with the new requirements. The time to review the level of compliance and take the necessary measures is now.

At Torres Legal, we assist entities in reviewing the Guidelines, evaluating applicable requirements, designating and documenting the Delegate, as well as the corresponding regulatory adaptation process.

Next articles in this category

Torres Legal