Are cookies personal data in Peru?

Yes. Supreme Decree 016-2024-JUS, the regulation of Peru's Ley 29733 in force since March 2025, names location data and online identifiers in its definition of personal data. A cookie ID that recognises a returning browser, an advertising ID, an IP address logged with a session: each one is personal data, so a site that runs analytics or advertising tags processes personal data whether or not it ever asks for a name.
What the definition now says
Peru's definition of personal data was always broad: any information about a natural person that identifies them or makes them identifiable. The 2024 regulation keeps that test and adds, by name, information about location and online identifiers to the kinds of data it covers. A person counts as identifiable when they can be identified directly or by combining data through means that could reasonably be used.
That removes the argument that a pseudonymous cookie is not about anyone. The cookie exists to recognise the same browser on the next visit, and that is exactly the combination the test describes. For a website, the practical reading is simple: measurement and advertising cookies are personal data processing, and the consent rules apply to them.
What consent has to look like
Ley 29733 asks for consent that is free, prior, express, unequivocal and informed. Each word rules something out on a banner.
Five words in the law. Five things a banner cannot do.
What the law asks
- Free: refusing is a real option
- Prior: before any optional tag
- Express: an active choice
- Unequivocal: no room for doubt
- Informed: each purpose named
What it rules out on a banner
- Refusing is harder than accepting
- Tags fire before the banner appears
- Boxes ticked in advance
- Scrolling or browsing on taken as a yes
- A purpose the notice never named
Our reading of the five words, not an official checklist.
What changes on the site
Optional tags wait. Cookies the site needs in order to work are generally treated differently. Measurement, advertising and session recording cookies are the ones that need the visitor's choice first, which means they cannot fire on page load and be cleaned up afterwards.
The notice names them. Informed consent means the visitor can see each purpose and each third party that sets cookies before they choose. A notice written once and never updated drifts from what the site actually loads, so the cookie list has to come from a scan of the real pages.
The proof is yours. You have to be able to show when and how a visitor consented, which takes a stored record per decision rather than an accept rate. The fields are in how to prove a visitor gave consent.
Google will not flag this for you. Its EU user consent policy covers visitors in the European Economic Area, the UK and Switzerland, so nothing in Google Ads or GA4 warns you about Peru. The denied default for visitors in Peru has to come from your own setup.
How to check your own site from Peru
Load the site from a connection in Peru
Use a private window so no earlier choice is remembered, and a connection that exits in Peru, so you see what a Peruvian visitor sees. Testing from another country only tells you how the site behaves for that country.
Before you click anything, read what is already there
Open the browser's developer tools and look at the cookies and the network requests. Anything set for measurement or advertising before the banner has been answered is the first thing to fix.
Reject, then reload
Choose reject, reload the page and check again. No optional cookie should appear, and the consent state on Google requests should read denied. How to check the Consent Mode v2 signal shows where to read it.
Accept, then change your mind
Accept, reopen your preferences from the page and withdraw. The change should take effect straight away, without contacting anyone, and it should be saved as a new record next to the first one.
Where Velo fits
Velo reads the visitor's country at the edge and treats Peru as opt in: every Consent Mode v2 signal starts denied until the visitor chooses, the banner asks in Spanish per category with nothing ticked in advance, and each decision is stored with a receipt id, the region and the banner version. A site owner cannot switch Peru to opt out in the console. The Ley 29733 page has the details.
The notice, the registration of personal data banks and the legal reading of your own processing stay with you. If your company also has to appoint a data protection officer, their questions start with the website, and what Peru's data protection officer checks lists them. This is general information, not legal advice.
Common questions
What people ask about this topic.
Are cookies personal data in Peru?
Yes. Supreme Decree 016-2024-JUS, the regulation of Ley 29733 in force since March 2025, names online identifiers and location data in its definition of personal data. Cookie IDs, advertising IDs and IP addresses tied to a session count, even on a site that never collects a name.
Do I need a cookie banner for visitors in Peru?
If your site sets measurement or advertising cookies, you need a way to ask for consent before they are set and to record the answer, because Ley 29733 requires consent that is free, prior, express, unequivocal and informed. A banner is the usual way to do that. Cookies the site needs in order to work are generally treated differently.
Is continuing to browse valid consent in Peru?
We would not rely on it. The law asks for consent that is express and unequivocal, and carrying on scrolling is neither an express act nor an unambiguous one, so treating it as acceptance is hard to defend. An active choice on the banner is the safer reading.
Does Peru's data protection law apply to a website based outside Peru?
It can. The 2024 regulation widened the territorial scope, including to some controllers outside Peru whose processing is aimed at people in Peru. Whether it reaches your site depends on your processing, so check it with legal advice.
What are the fines under Ley 29733?
Up to 100 UIT for the most serious infractions, and never more than 10% of the company's gross annual income. The UIT is set every year; for 2026 it is S/ 5,500.
Website privacy, in one place.
Scan your site →

