Privacy Policies
There is a rule in Panama’s data protection law that few people know about: when you collect information over the Internet, the way you satisfy your duty to inform is by **presenting the data subject with an accessible privacy policy**. This is not a best-practice recommendation or a trust badge. It is the mechanism the law itself provides.
And yet most of the privacy policies circulating in Panama are translated foreign templates. They speak of «data controllers», «processors» and «special categories of data» — the vocabulary of the European regulation, which is not ours. They serve a decorative function. What they do not do is contain what Panamanian law requires them to contain.
What your policy has to say
Where data is collected directly from the data subject, Panamanian law requires you to disclose nine things:
1. Who the controller is and how to reach them.
2. What the data will be used for.
3. What legal condition makes that processing lawful — and, where it rests on consent, that consent may be withdrawn at any time.
4. Who the data is disclosed to.
5. Whether the data will leave the country, and under which legal condition.
6. How long the data is kept, or the criteria used to determine that period.
7. How to exercise the rights of access, rectification, cancellation, objection and portability.
8. And more…
Take your current policy and check it against this list. If three or more are missing, the document does not comply.
What the service covers
**Privacy policies** for websites, online stores and mobile applications, drafted in the vocabulary of Panamanian law — *titular de los datos*, *responsable del tratamiento*, *custodio de la base de datos* — rather than in translated European terminology.
**Cookie notices and demonstrable consent.** The law is not satisfied by the fact that the data subject consented; it requires that you be able to prove it afterwards. That changes how the form is built in the first place.
**Layered notices for mobile.** Panamanian law allows the information to be split, with a short first layer — who you are, what you use the data for, and how to exercise rights — linking through to the rest. It is the right answer for small screens, and almost nobody in Panama is using it.
**Terms and conditions of use** that are consistent with the privacy policy rather than in quiet contradiction with it.
**Consent clauses** presented so that they are clearly distinguishable from the surrounding text, as the law requires when consent sits inside a longer document.
**Spanish and English versions.** As a sworn public translator authorised in Panama, I produce both, and the English is not machine output.
Why a template will not do
A privacy policy is a statement about specific facts: what data you collect, on what legal basis, for how long, and who you share it with. A template states facts that are not yours.
If your payment gateway stores data outside Panama and your policy does not say so, the document does not protect you — it exposes you, because it puts in writing that you claimed something other than what you do. And under Panamanian law, failing in the duty to inform the data subject is a serious infringement.
There is a further layer that is easy to miss. The law provides that the minimum content of privacy policies is set by **each sector’s own regulator**. If your activity is regulated — banking, insurance, health, telecommunications — the general law is the floor, not the ceiling.
Who this is for
Online stores, SaaS platforms, fintech companies, mobile applications, digital marketing agencies, and in particular anyone processing children’s data, where Panamanian law requires prior authorisation from the parent or guardian and reasonable efforts to verify it.
Foreign companies are a large part of this work. If you sell into Panama, host data here, or operate through a Panamanian entity, Panamanian law reaches you regardless of where your head office sits — and a GDPR-compliant policy is not automatically a compliant one here.
Data Privacy
Panama’s Law 81 of 2019 has been in force since March 2021, and its implementing regulation followed two months later. Five years on, a great many companies processing personal data in Panama could not demonstrate to ANTAI — the national data protection authority — how they process it or on what authority.
That gap between the rule and the practice is where I work.
Does the law apply to you?
Only one of these needs to be true:
– Your database sits in Panamanian territory and holds data on nationals or foreigners.
– You, as controller, are domiciled in Panama.
– The processing originates or is stored in Panamanian territory.
– The processing is part of commercial activity conducted over the Internet and directed at the Panamanian market.
That last one is the one most companies overlook, and it is what brings foreign businesses within scope. It also ties the data protection regime to Panama’s electronic documents and signatures law, Law 51 of 2008. The two frameworks operate together, not separately.
What the service covers
**Compliance assessment.** What data you hold, where it came from, where it is hosted, who has access to it, and what legal ground supports it. The output is a report with the gaps ranked by urgency.
**Database register.** The law requires a written register with roughly a dozen entries per database — purpose, retention period, recipients, security measures, and even a record of everyone who has accessed the data. It needs to exist before ANTAI asks for it, not after.
**How to do handling of data subject rights.** Access, rectification, cancellation, objection and portability, on the real deadlines, to answer an access request and to rectify. The burden of proving it falls on you. That is why the procedure is documented from day one.
**Vendor contracts.** Your cloud provider, CRM, billing platform and call centre are all *custodios de la base de datos* — Panama’s closest equivalent to a processor. The law sets out eight conditions those contracts must contain. If yours do not, the exposure is yours, not theirs.
**Cross-border transfers.** A review of what leaves Panama and under what safeguard: contractual clauses, model clauses validated by the authority, approved binding self-regulation schemes, or intra-group corporate rules. AI use and exposure of personal data.
**Security breach protocol.** When a security breach occurs, you have 72hrs from the moment you become aware of it to notify ANTAI **and the affected data subjects**, with a defined minimum content. That protocol gets written before the incident. During the incident there is no time left.
What is actually at stake
Fines run from **one thousand to ten thousand balboas ($)**. I will be straight with you: for many companies that figure is not frightening, and presenting it as a threat would be treating you as if you could not do arithmetic.
What should concern you sits further along in the same law. For very serious infringements it provides for **closure of the database records** and **suspension or disqualification of the data processing activity**, whether temporary or permanent. A company whose operation depends on its customer database does not survive that, and at that point the fine is the least of it.
Processing without proper consent, obstructing the exercise of data subject rights, or storing data without adequate security are serious infringements. Transferring data abroad in breach of the law, or disregarding the rules on sensitive data, are very serious ones.
Why work with me
I have spent more than twenty years in digital law in Panama, and I was the drafter and legal lead of Law 82 of 2012, the electronic signature law in force in this country. I do not come to this field from the outside: I worked from within the construction of Panama’s digital regulatory framework — the same framework the data protection regulation points back to when it defines its own scope.
I also work in both languages as a sworn public translator authorised in Panama, which matters more than it sounds. Compliance documents that a foreign parent company has to review, and Panamanian filings that have to be produced in Spanish, do not have to travel through a third party.
For more info write to me at tradslegal@outlook.com or on WhatsApp.
