What Peruvian Law Requires When Companies Collect Data for Promotions
Flip through social media or walk into a shopping centre in Peru and you will almost certainly see a sweepstake promising a car, a trip or the latest smartphone. To enter, consumers hand over their name, ID number, email, phone and sometimes even their address. Yet that exchange does not give the organising company a free pass to use the data however it likes. Under Peru’s Personal Data Protection Law (LPDP) and its regulations, the moment a business collects personal information for a promotion it takes on a strict set of obligations.
Carol Quiroz, a partner in the data protection and information security practice at Estudio Olaechea, and Bruno Mejía, who leads the competition and markets team at EY Law, both emphasise that simply ticking a box to enter a draw does not amount to consent for any subsequent use of the data. Companies must inform participants who will handle their information, for what exact purpose, how long it will be kept, and — where required — obtain prior, informed consent. The law also obliges them to spell out whether the data will be shared with third parties or transferred abroad, and to provide straightforward ways for people to exercise their rights later.
That means the information gathered to run a promotion cannot automatically be repurposed for marketing, customer profiling or advertising. If a brand wants to use the list for future campaigns, it must have told participants so from the start and secured a separate, clear agreement. Even then, the individual retains the right to withdraw consent or object to commercial use, and the company must provide a simple, free mechanism to do so.
Where Marketing Campaigns Typically Stumble and the Penalties That Follow
Consent Is the First Hurdle — and Many Campaigns Fail It
The experts point to a string of practical failures that trip up businesses, most of them not malicious but the result of cramped campaign timelines and legal oversights. A common mistake, Quiroz notes, is focusing entirely on the terms and conditions of the draw while forgetting to include a privacy notice altogether. Equally damaging are pre-ticked boxes that supposedly authorise advertising or data sharing with commercial partners: under the LPDP these do not constitute valid consent.
Mejía adds that ambiguous consent clauses, requests for excessive personal data beyond what the sweepstake genuinely needs, and a failure to separate the main purpose from secondary commercial uses all land companies in regulatory trouble. He also points out that many firms keep the databases long after the promotion ends, or lack adequate security measures to protect the information they hold. While asking for a date of birth or national ID number might seem intrusive, Mejía explains that these can be justified when they are necessary to verify the winner’s age or identity, prevent duplicate entries, or meet tax obligations tied to the prize.
The rise of joint promotions between banks, shopping centres and sponsoring brands adds another layer of complexity. Quiroz stresses that these projects must be structured from the outset with a privacy policy that clearly discloses whether data will be shared among organisers and that obtains fully informed consent. Mejía underscores that sharing information with third parties is only legal if it is compatible with the purpose the participant was told about and complies with all LPDP requirements, including consent when the law demands it.
The Price of Getting It Wrong
Mistakes carry a financial sting. Quiroz says the most frequent fines imposed by the National Authority for Personal Data Protection range from 5 to 50 UIT — between roughly S/27,500 and S/275,000. Mejía notes that the law itself sets a wider bracket, from 0.5 UIT (about S/2,750) to 100 UIT (S/550,000), depending on the gravity of the infraction. On top of fines, the authority can order corrective steps such as halting data processing, deleting data obtained without proper consent, or cancelling entire databases.
Why This Shifts the Compliance Conversation
Both lawyers agree that data protection is no longer a box-ticking formality but a fundamental design element of any commercial campaign. A poorly drafted form or a consent clause that a regulator later deems invalid can transform a marketing initiative into a significant legal contingency. For companies accustomed to treating sweepstakes as simple lead-generation tools, the message is clear: the law now demands that privacy be built in, not bolted on.
Practical Steps for Running a Sweepstakes Without Triggering a Data Breach
For marketing, legal and compliance teams designing promotions in Peru, several concrete measures emerge directly from the law and the specialists’ experience:
- Embed a full privacy notice from day one. Do not launch a sweepstake landing page or physical entry form without a clearly visible privacy policy that states who controls the data, the specific purpose(s), storage periods, and whether data will be shared or transferred abroad — backed by a separate, unforced consent mechanism for any secondary marketing use.
- Audit the data fields you request. Strip out every piece of personal information that isn’t strictly necessary for the draw’s administration, winner verification or tax compliance. If you plan to keep data for future prospecting, obtain explicit, informed consent for that purpose in a separate, unambiguous step.
- Set a deletion schedule. Once the promotion ends and the prize is delivered, destroy, block or anonymise the collected data unless the law or a previously accepted additional purpose justifies keeping it. Inform participants of that timeline upfront.
- Strengthen inter-company agreements. In joint promotions, draft a binding agreement among all co-organisers that prescribes how data is handled, who bears responsibility, and how participants can exercise their rights — and reflect that agreement in the privacy disclosures shown to consumers.
- Train campaign teams on the LPDP. Because many violations stem from operational oversight rather than deliberate abuse, brief the marketing, digital and events staff on consent requirements, the ban on pre-ticked boxes, and the technical steps needed to accept and record withdrawals of consent.
Risk & Opportunity Assessment
| Commercial Risk | Medium | Fines of up to S/550,000 and orders to delete entire databases can erase the commercial value of a campaign, while also creating unexpected budget overruns. |
| Competitive Risk | Low | Rivals complying visibly with LPDP may build stronger consumer trust, but the immediate competitive harm remains limited unless a breach triggers public enforcement. |
| Regulatory Risk | High | The National Authority for Personal Data Protection actively imposes sanctions from 0.5 to 100 UIT and can mandate corrective measures that disrupt ongoing marketing activities. |
| Reputation Risk | Medium | A publicised penalty or data misuse scandal linked to a consumer promotion can erode brand credibility, especially when the public perceives their personal information was used without permission. |
| Technology Disruption | Low | No radical technological shift is at play; the core challenge is process design rather than tech obsolescence. |
| Commercial Opportunity | High | Companies that implement transparent, well-documented consent and data retention practices can differentiate themselves, turning regulatory compliance into a trust-building asset for future promotions. |
Comments 0