Envíos Masivos Panamá.

Law 81 and bulk messaging: how to send email, SMS and WhatsApp legally in Panama

What Panama's Law 81 of 2019 requires for your bulk campaigns: consent, ARCOP rights, ANTAI penalties and a practical checklist to send without fines.

If you run email, SMS or WhatsApp campaigns in Panama, Law 81 of 2019 on personal-data protection applies to you. This isn’t theory: it’s in force, the ANTAI enforces it, and it even reaches companies based abroad when they direct their commercial activity at Panamanian customers. The good news is that complying isn’t complicated — and, as a bonus, it improves the deliverability of your sends. This guide explains, in practical terms, what it requires so you can send by the book.

This is general information, not legal advice. For your specific case, consult a professional.

What Law 81 is and since when it applies

Law 81 of 26 March 2019 sets out the principles, rights and obligations for processing personal data in Panama. It took effect on 29 March 2021 and was regulated by Executive Decree 285 of 28 May 2021, which added the procedures, the requirements for collecting information and the criteria for penalties.

The supervisory authority is the ANTAI (National Authority for Transparency and Access to Information), through its Directorate for the Protection of Personal Data. It is the body that audits, handles complaints and imposes penalties.

In spirit, the law resembles the European GDPR: it returns control over the use of personal information to the individual, and requires whoever processes it to do so with permission, transparency and security.

Who it applies to

It applies to any party — natural or legal, public or private — that processes the personal data of people in Panama. For your campaigns, that means it applies if you handle emails, phone numbers or any data that identifies a contact.

A point many overlook: it also applies to foreign companies when their online commercial activity targets Panamanian customers. Selling from abroad does not exempt you.

Excluded, for example, are data processed by an individual for purely personal or household activities, and those governed by special laws.

The heart of the law for marketing is this: to process a piece of data and send commercial communications you need the data subject’s consent, and that consent must be:

  • Prior: before you send to them, not after.
  • Informed: the person knows who you are and what you’ll use their data for.
  • Unambiguous: a clear affirmative action, not a pre-ticked box or silence.
  • Traceable: you must be able to prove when and how you obtained it.

The data subject can also withdraw consent at any time (without retroactive effect), and you must make that easy.

In practice, this comes down to two very concrete things:

  1. Real opt-in, ideally double. The person asks to receive your messages and, better still, confirms with a second step. That gives you the traceability the law requires.
  2. Don’t buy or scrape lists. A purchased list has no traceable consent: sending to it is a breach and, on top of that, destroys your sending reputation. (For the technical side, see our guide to email deliverability.)

The rights you must be able to handle (ARCOP)

Informed consent goes hand in hand with a set of rights the data subject can exercise and that you must be able to handle. They are known as ARCOP:

  • Access: to know what data of theirs you hold.
  • Rectification: to correct inaccurate data.
  • Cancellation: to ask you to delete their data.
  • Opposition: to refuse a processing activity, such as receiving advertising.
  • Portability: to take their data to another controller.

For a messaging operation, the minimum is a clear channel to unsubscribe and to handle deletion requests, and to honour them within a reasonable time.

What it means on each channel

ChannelWhat Law 81 asks of you in practice
EmailInformed opt-in, a visible and working unsubscribe link, a record of consent
SMSPrior consent, an opt-out option (e.g. reply STOP), no purchased lists
WhatsAppConsent to write on that channel, respect for WhatsApp’s policies and for opt-outs

In all three cases, the common denominator is the same: permission, transparency and an easy way out.

Each channel also has its own technical rules, which we develop in their pages: email deliverability (SPF, DKIM, DMARC and one-click unsubscribe), bulk WhatsApp (mandatory opt-in, templates and the 24-hour window) and bulk SMS (sender registration and consent).

The penalties: what you’re risking

Law 81’s penalty regime (article 36) provides for fines of US$1,000 to US$10,000, depending on severity and recurrence. But the fine isn’t the only thing:

Penalty regime · ANTAI

Beyond the US$1,000 to US$10,000 fine, the ANTAI can impose a written warning, a summons, closure of the database registration and suspension or disqualification of the processing activity. The controller must also compensate any material or moral damage caused.

Infractions are classified as minor, serious and very serious. Processing data without consent or restricting the ARCO rights is treated as a serious offence. The very serious ones, moreover, are not subject to a statute of limitations.

For an SME, a database closure or a public sanction weighs more than the fine itself: it means losing your contact tool and your customers’ trust overnight.

Do I need a Data Protection Officer?

Decree 285 created the figure of the Data Protection Officer (DPO). It is mandatory for public entities and recommended, but not mandatory, for the private sector. Even without formally appointing one, it’s wise for someone in your company to be responsible for how data is collected, stored and used.

Compliance checklist for bulk messaging

  • Collect prior, informed and unambiguous consent (opt-in, preferably double).
  • Keep evidence of each consent (date, source, accepted text).
  • State clearly who you are and what you’ll use the data for.
  • Include an easy unsubscribe in every message and process it quickly.
  • Have a channel to handle access, rectification, cancellation, opposition and portability.
  • Don’t buy or scrape databases.
  • Keep data secure and up to date.
  • Assign someone responsibility for compliance.

Controller and processor: where we fit in

A point that reassures many companies: outsourcing the sending doesn’t take you out of the law, it organises you within it. Law 81 distinguishes two roles. You, the business owner, are the controller: you decide what the data is used for. Whoever sends on your behalf is the processor or custodian, who processes that data following your instructions.

The law explicitly contemplates that relationship: Decree 285 provides that the registration of databases transferred to third parties be recorded in writing, including by electronic means. Done well, working with a processor isn’t an outsourcing risk: it’s a documented compliance structure, with clear responsibilities and traceability of who processed what.

A nuance for regulated sectors: if you’re in banking, insurance or healthcare, your special law governs first and Law 81 applies on a supplementary basis. It’s not “Law 81 only”: it’s your sector framework plus Law 81 for whatever the former doesn’t cover.

Complying without it becoming your headache

Complying with Law 81 is, above all, about organising how you ask for permission and how you respect the way out. It’s perfectly achievable — but it’s ongoing work, and it overlaps with the technical side of deliverability.

That’s why we run it for you as your processor: compliant opt-in, double confirmation, traceable opt-outs and records ready in case the ANTAI asks. You send with peace of mind; we keep compliance up to date.

Is your operation in line with Law 81?

We run a free Law 81 + deliverability check: we review your consent base, your domain and your list, and hand back a clear traffic light with 3 actions. It's what others charge $450 for.

Get your free check