Regulatory
Personal data: security is also an organizational duty
Law 25,326 and the AAIP require purpose, access, confidentiality, security and incident response to be managed as one system.
Data protection does not end with a privacy policy. Whoever manages a database should be able to explain what data is collected, why it is used, who has access, how long it is retained and what measures prevent loss or unauthorized access.
The AAIP identifies security and confidentiality duties as well as rules for disclosures and international transfers. In practice, this calls for coordination across contracts, technical permissions, vendor inventories and internal procedures.
A contact form also processes personal data. It should request only what is needed, explain the purpose and avoid promising uses the system cannot support. Where email, hosting or analytics providers are involved, their roles should be identified.
When an incident occurs, documenting decisions and corrective steps makes it possible to reconstruct events and reduce harm. Response does not begin with the incident; it begins with an up-to-date map of data and accountable people.