Free scan About Support Contact
Get Velo

Already have an account? Log in

What Peru's data protection officer checks on your site

Compliance 5 October 2026· 6 min read
The Velo mascot holds a clipboard with three big checkmarks

All posts

Peru's data protection regulation, Supreme Decree 016-2024-JUS, requires some companies to appoint a data protection officer, with start dates set by annual sales: above 2,300 UIT from 30 November 2025, 1,700 to 2,300 UIT from 30 November 2026, and smaller companies in 2027 and 2028. The officer's questions start with the website, because cookies and other online identifiers now count as personal data.

Who has to appoint one

Not every company. The regulation ties the duty to what you process: public bodies, organisations whose processing involves large volumes of personal data or affects a large number of people, and those whose main activity involves sensitive data. Company size then decides when the duty starts, counted from the regulation's publication on 30 November 2024.

Whether your own processing meets those criteria is a question for your lawyers, and this note does not answer it. It covers what lands on the marketing and web teams once the answer is yes. The officer's job is to show that the company complies, and the website is the one part of that anyone can check from outside.

One date per company size. The website questions are the same.

When the duty starts, by annual sales

  • Above 2,300 UIT: 30 November 2025
  • 1,700 to 2,300 UIT: 30 November 2026
  • 150 to 1,700 UIT: 30 November 2027
  • Up to 150 UIT: 30 November 2028

What the officer asks of the website

  • Which cookies are set, and by whom
  • Whether anything loads before a choice
  • Whether one visitor's consent can be shown
  • Whether a visitor can change their mind
  • Whether the data bank is registered

The dates apply where the regulation's criteria are met.

The appointment date depends on company size. The questions about the website do not, and none of them can be answered by pointing at the banner.

Why the website comes first

The regulation's definition of personal data now names location data and online identifiers explicitly. A cookie ID that recognises a returning browser, an advertising ID, an IP address logged with a session: each of those is personal data, even on a site that never asks for a name. We cover what that definition changed in the note on cookies under the new regulation.

Ley 29733 asks for consent that is free, prior, express, unequivocal and informed. On a website, that means the visitor chooses before any analytics or advertising tag runs, and you keep a record you can show later. An officer can check the first part in an afternoon with a browser, which is why the website is usually the first thing they look at.

The five questions, and how to answer each

  1. Which cookies and scripts does the site set, and who sets them?

    The answer is an inventory taken from the real pages, not from memory: every cookie, every third party script, and the company behind each one, named in your privacy or cookie notice. It goes stale every time someone adds a tag, so the officer will want to know who reviews new scripts and how often the inventory is refreshed.

  2. Does anything optional load before the visitor chooses?

    Open the site from a connection in Peru, in a private window, and look at the cookies and network requests before touching the banner. Measurement and advertising tags should be waiting. The full routine is in how to test a cookie banner before going live.

  3. Can we show one visitor's consent, for one date?

    Prior and express consent has to be demonstrable, so the answer is a stored record: when the choice was made, which categories were granted and refused, how it was given and which banner version was on screen. An accept rate on a dashboard does not answer it. The fields are set out in how to prove a visitor gave consent.

  4. Can a visitor change their mind, and does the site respect it?

    The visitor needs a way back to their choices from every page, and a change has to take effect, not just be noted. A withdrawal should be saved as a new record next to the first one, not as an edit of it. We walk through this in what happens when someone withdraws consent.

  5. Is the personal data bank registered?

    Peru keeps a national register of personal data banks. If the data your site collects sits in a bank that has to be registered, the officer will ask whether it is. That is a company question rather than a website one, but the inventory from the first step is where the answer starts.

Where agencies come in

For an agency, the officer is a new person in client meetings, and a useful one: their job is to ask for exactly the evidence an agency can provide. The consent record should name the client as the controller, be stored where the client can reach it, and go with the client if the relationship ends. We cover whose name belongs on it in the note on white label consent for agencies.

If you run sites for clients with visitors from Peru, do this before 30 November: go through the five questions for each site and export the consent log. Your first meeting with a new officer then starts from evidence, not promises.

What a consent tool covers, and what stays with you

Velo reads the visitor's country at the edge and treats Peru as opt in: every Consent Mode v2 signal starts denied until the visitor chooses, the banner asks in Spanish per category with nothing ticked in advance, and each decision is stored with a receipt id, the region and the banner version. That answers questions two to four. The Ley 29733 page has the details.

The appointment itself, the privacy notice, the data bank registration and a plan for security incidents stay with the company. The regulation asks for incidents to be reported to the authority within 48 hours, and no banner answers that. This note is general information, not legal advice.

Common questions

What people ask about this topic.

When does a mid-sized company in Peru need a data protection officer?

From 30 November 2026, for companies with annual sales above 1,700 and up to 2,300 UIT whose processing falls under the regulation's criteria. Larger companies have been covered since 30 November 2025, and smaller ones follow in November 2027 and November 2028. The dates count from the publication of Supreme Decree 016-2024-JUS on 30 November 2024.

Does every company in Peru need a data protection officer?

No. The regulation ties the duty to the processing: public bodies, processing that involves large volumes of personal data or affects many people, and organisations whose main activity involves sensitive data. Size decides when the duty starts, not whether it applies. Check your own case with legal advice.

What will a data protection officer check on a website?

In practice, five things: which cookies and scripts the site sets and who sets them, whether anything optional loads before the visitor chooses, whether one visitor's consent can be shown for one date, whether a visitor can change their mind, and whether the data bank behind the site is registered.

Are cookies personal data under Peru's new regulation?

Yes. Supreme Decree 016-2024-JUS names online identifiers and location data in its definition of personal data, so cookie IDs, advertising IDs and IP addresses tied to a session count, even on a site that never collects a name.

Does a cookie banner make a company compliant with Ley 29733?

No. A banner handles one part of the law: asking for consent before optional cookies are set and recording the answer. The officer, the privacy notice, the registration of data banks, security measures and incident reporting are separate duties the company still has to meet.