Skip to content
RESETEnterprise architecture ES Initial assessment

Home / Legal Reset / Data protection and Law 81 in Panama

Law 81 · Legal Reset

Privacy cannot be solved by copying a policy.

We translate Law 81 and its obligations into owners, workflows, and evidence so personal data is managed inside the operation.

Initial assessment

The problem

The policy says one thing. Data moves through a different company.

Marketing, sales, HR, vendors, and technology collect data through different paths, with retention and access that are rarely documented.

A public policy without an inventory, owners, or an incident procedure does not show how information is protected.

Law 81 of 2019 does not require a perfect document, but evidence of management: who authorizes a new data-processing activity, how the organization responds when a data subject exercises their rights, and what happens in the first hours after an incident.

How we solve it

Legal architecture built as a working system.

Inventory

Data, purposes, sources, systems, and owners.

  • Databases and systems
  • Processing purposes
  • Retention periods
  • Access and owners

Legal basis

Consent, notices, and processing criteria.

  • Consent records
  • Privacy notices
  • Lawful basis for processing
  • Minors and sensitive data

Operations

Data-subject rights, retention, access, and incidents.

  • Data-subject rights requests
  • Incident procedure
  • Processing records
  • Internal training

Third parties

Processors, transfers, and protection clauses.

  • Data processors
  • International transfers
  • Contractual clauses
  • Vendor audits

Execution

From legal exposure to a system that controls it.

Frequently asked questions

Before defining the scope.

Which companies should assess compliance?

Every organization processing personal data should understand the obligations applying to its operation and the information it handles.

Is a privacy notice enough?

No. A notice communicates; compliance also requires internal practice to match what was communicated.

Does this include cybersecurity?

Legal protection and technical security must coordinate, but they are not the same. The scope defines which technical controls need integration.

What is delivered?

Depending on the diagnosis: inventory, processing matrix, policies, clauses, procedures, records, and an implementation plan.

What if we already have a published privacy policy?

We audit it against real operations: if it matches, we formalize and document it; if not, we adjust the policy, the process, or both.

Does this apply to companies that don’t sell directly to consumers?

Yes. Any organization processing employee, vendor, or B2B customer data has obligations, though volume or risk changes the scope.

Next step

Can you explain where each personal-data set lives and who uses it?

Tell us which decision, structure, or filing you need to resolve. The legal team will review the context and guide you toward the right path.

Initial assessment