Laws and regulations
We operate across 14 Latin American jurisdictions. These are the rules that govern each one — personal data protection and anti-money-laundering — and how we handle the data of anyone visiting this site.
Last reviewed: 2026-08-09
Your data
How we handle the data of anyone visiting this site
We designed our data handling against the strictest standard between Latin American regulation and the European GDPR. Meeting the strictest one means meeting the rest.
Stated purpose
We use your data solely to handle your sales or support enquiry. We will not use it for anything else without asking you again.
Only what is needed
We ask only for what it takes to answer you. No advertising profiles, and no selling data to third parties — ever.
Limited retention
We keep conversations for 18 months, then they are deleted automatically. It does not depend on someone remembering to delete them.
Provable consent
We record which version of the notice you accepted, with date and time, and email you the receipt. Noting that you accepted is not enough — we must be able to show what you accepted.
Enforceable rights
You can request a copy, a correction or the deletion of your data at any time, without giving a reason and at no cost.
By jurisdiction
Applicable regulation by country
Two distinct axes that are often confused: data protection governs how people's personal data is handled; anti-money-laundering governs the duty to know and monitor customers and counterparties.
Swipe to see all columns
| Country | Personal data protection | Supervisory authority | AML / CFT |
|---|---|---|---|
| AR Argentina | Ley 25.326 | AAIP | Ley 25.246 · UIF |
| CL Chile | Ley 21.719 | Agencia de Protección de Datos Personales | Ley 19.913 · Ley 21.595 · UAF |
| CO Colombia | Ley 1581 de 2012 | SIC | SAGRILAFT · SARLAFT 4.0 |
| CR Costa Rica | Ley 8968 | PRODHAB | Ley 8204 · SUGEF 13-19 |
| EC Ecuador | Ley Orgánica de Protección de Datos Personales | Superintendencia de Protección de Datos Personales | UAFE |
| SV El Salvador | Ley de Protección de Datos Personales | No dedicated authority | UIF |
| GT Guatemala | No comprehensive general law | No dedicated authority | IVE |
| HN Honduras | No comprehensive general law | No dedicated authority | CNBS · UAF |
| MX Mexico | LFPDPPP | No dedicated authority | Ley Fintech · PLD/FT CNBV |
| NI Nicaragua | Ley 787 | No dedicated authority | Ley 977 · UAF |
| PA Panama | Ley 81 de 2019 | ANTAI | Ley 23 de 2015 · Acuerdos SBP |
| PE Peru | Ley 29733 | ANPD | SPLAFT · SBS / UIF |
| DO Dominican Republic | Ley 172-13 | No dedicated authority | Ley 155-17 · Norma IDECOOP |
| VE Venezuela | No comprehensive general law | No dedicated authority | SIRO · Sudeban |
| EU European Union | GDPR — Reglamento (UE) 2016/679 | EDPB | — |
European Union
Why the GDPR applies to us too
The General Data Protection Regulation reaches any organisation handling the data of people in the European Union, regardless of where it is established. Our site receives visits from Europe, so it applies to us.
Explicit lawful basis
Every processing activity rests on a specific basis: consent, legitimate interest or performance of a contract. Never on silence.
Privacy by design
Protection is not bolted on at the end: it shapes the data model from day one. What is never captured cannot leak.
Controlled transfers
Our processors are documented, with the corresponding safeguards for international transfers.
Algorithmic transparency
When a virtual assistant helps you, we say so. We never present an automated system as if it were a person.
Your rights
What you can demand from us
These rights exist in every regulation listed above, under different names and with local nuances. We honour them the same way, wherever you are from.
Access
Find out what data of yours we hold, where it came from and what we use it for.
Rectification
Correct any inaccurate or incomplete data we hold about you.
Erasure
Ask us to delete your data, unless a legal obligation requires us to keep it.
Objection and portability
Object to a specific processing activity, or receive your data in a format you can take with you.
How to exercise them
Write to us and we will reply within the deadlines set by the regulation of your country. You do not need to give a reason, and there is no charge.
Data controller
info@snap-compliance.comAbout this information
This summary is informational and does not constitute legal advice. Regulation changes, and every specific case has its own particulars. For an assessment of your situation, consult your legal adviser or write to us.
Do you need to comply with any of these?
Our platform parameterises the regulation of each jurisdiction, so the compliance team works against the framework that actually applies to them, not a generic one.
Talk to the team