TL Insights
Back to TL Insights
Personal Data Protection Law in El Salvador: Everything You Need to Know About the CNAD’s New Provisions
Digital Asset Service Providers and Certifiers overseen by the National Digital Assets Commission (CNAD) must review the designation, profile, and registration of their Personal Data Protection Delegate, as well as establish an institutional communication channel with the State Cybersecurity Agency (ACE), in accordance with the new personal data protection provisions in El Salvador.
Personal data protection continues to take shape in El Salvador. With the publication of the Guidelines for Personal Data Protection Delegates by ACE, an obligation already contemplated in the legislation now has more concrete rules regarding the profile, designation, registration, and operation of this role.
In this context, CNAD issued Circular No. 008-2026, directed at the Digital Asset Service Providers and Certifiers under its supervision, through which it communicates the Guidelines and establishes a deadline of 20 business days for these entities to adjust their organizational and operational structure, in accordance with the new provisions.

From a general obligation to concrete rules
The Personal Data Protection Law, in its article 2, establishes a broad scope of application for natural and legal persons, public or private, engaging in activities related to personal data processing. Moreover, article 15 establishes the obligation to appoint a Personal Data Protection Delegate.
The new ACE Guidelines develop this obligation, establishing requirements for the profile, designation, documentation, registration, and communication of the Delegate. In simple terms: the obligation already existed; now there are more defined rules to fulfill it.
Who should pay attention to this new provision?
Circular No. 008-2026 is specifically directed at the Digital Asset Service Providers and Certifiers supervised by CNAD.
For these entities, the adaptation period began with the entry into force of the Guidelines, on August 19, 2026. Therefore, they should verify now whether they have a Personal Data Protection Delegate and whether this Delegate meets the requirements established in the new Guidelines.
What should an entity review?
1. The Delegate's profile The Guidelines establish a minimum profile to perform this role, related to academic training, professional experience, and suitability. Among other aspects, they consider knowledge or experience in areas such as personal data protection, regulatory compliance, risk management, information security, or cybersecurity.
The first review should, therefore, focus on determining whether the proposed or currently designated person meets the required profile.
2. The manner of designation
The appointment must be formally documented, in accordance with the rules applicable to the organization and the type of Delegate designated.
It's not enough to identify the responsible person: the entity should be able to formally accredit their designation.
3. The registration and communication with ACE
Obliged entities must carry out the corresponding procedure to register and communicate the appointment of their Delegate with the Personal Data Protection Directorate of ACE. Additionally, they should consider the established deadlines for communicating modifications related to this role.
As part of this adaptation, each entity should establish an institutional email address that will function as the official communication channel with the Personal Data Protection Directorate of ACE and should be reported to the authority.
Reference:
What happens to those who already had a Delegate?
The Delegates appointed before the entry into force of the Guidelines retain the validity of their designation. However, they must undergo and pass the certification program implemented by ACE.
Therefore, organizations that already have this role should also review if their designation and profile are aligned with the new provisions.
What should an entity supervised by CNAD do now?

Why is it relevant?
The publication of these Guidelines represents a new step in the implementation of the personal data protection regime in El Salvador and poses new considerations for entities supervised by CNAD.
Compliance is not limited to the appointment of a Delegate, but to ensuring that the organization is aligned with the new requirements. The time to review the level of compliance and take the necessary measures is now.
At Torres Legal, we assist entities in reviewing the Guidelines, evaluating applicable requirements, designating and documenting the Delegate, as well as the corresponding regulatory adaptation process.

Next articles in this category

August 2026
CNAD Circular No. 008-2026: New Data Protection Compliance Requirements
The National Commission of Digital Assets (CNAD) issued Circular No. 008-2026, addressed to Digital Asset Service Providers and Certifiers, through which it communicates the Guidelines for Personal Data Protection Delegates issued by the State Cybersecurity Agency (ACE).

August 2026
Personal Data Protection: The State Cybersecurity Agency (ACE) Strengthens the Supervision and Compliance Framework
Personal data protection in El Salvador is entering a phase of greater operational development and oversight. The Law protects all information that allows a natural person to be identified or identifiable, including information that, by its nature, requires a higher level of protection. With the publication of the new Guidelines for the Data Protection Officer and the Regulations for the Development of Administrative Sanctioning Proceedings, the State Cybersecurity Agency (ACE) establishes key aspects regarding who may serve as a Data Protection Officer, how their appointment must be formalized and registered, and how the Agency may investigate and sanction potential non-compliance. Both provisions were published in the Official Gazette on August 11, 2026, and entered into force on August 19, 2026.

July 2026
Eleven ideas with an owner: the (with lawyers) history of the world's biggest sport
This article was born at the precise moment when the fever for the biggest sporting event in the world began to take over everyone this year. It was born from a conversation between someone who loves soccer from the memory of their grandfather, a physical education teacher, and someone who loves intellectual property because they deeply believe that ideas also deserve history, care, and ownership. Coco sees soccer as one who recognizes a family heritage. I see it from another place, perhaps less evident but just as exciting: from the brands, patents, contracts, image rights, and all those invisible creations that make the world's greatest sport also one of the most powerful industries on the planet.

June 2026
Torres Legal contributes to the Blockchain & Crypto-Assets Global Practice Guide 2026 by Chambers and Partners
The 2026 edition of the Blockchain & Crypto-Assets Global Practice Guide by Chambers and Partners includes the contribution of Torres Legal as the author of the El Salvador chapter.
