Peru - AI License Plate Regulation (PL 07651/2023)

Project 7651/2023 — Bill to regulate use of AI algorithms for license-plate recognition

Proyecto 7651/2023 — Proyecto de ley para regular el uso de algoritmos de IA para el reconocimiento de placas vehiculares

Peru

RAI-PE-NA-P7RUAXX-2024
Under Review(Under Review)
BillConformity Assessment and RegistrationData Protection and PrivacyGovernance and Oversight
Export PDF

Project 7651/2023 proposes a legal framework to regulate the use of algorithms and artificial intelligence techniques for real-time recognition of vehicle license plates, with the stated goal of preventing crimes such as vehicle theft and circulation of altered plates. The bill requires registration, privacy safeguards, transparency measures, human oversight, and sanctions for misuse, and places oversight responsibilities on national authorities.

Overview

Project 7651/2023 (registered as PL 07651/2023-CR) is a draft law presented to the Peruvian Congress on 22 April 2024 that aims to regulate the deployment and use of algorithms and artificial intelligence techniques for the recognition of vehicle license plates ("reconocimiento de placas de rodaje"). The draft frames the intervention as a public-safety measure to prevent and investigate crimes involving stolen vehicles and altered plates by enabling real-time detection using video surveillance systems with AI modules. The bill text and parliamentary listing can be consulted on the official legislative portal of the Congress (Congress of the Republic of Peru) and the specific expediente entry (Expediente PL 07651), while additional copies of the proposed text are available in the congressional archive (Bill PDF (archivo MTc4NTA5)). The project has attracted commentary from legal and technology observers and is summarized in public repositories such as the University of the Andes' IA/regulation database and practitioner notes (Uniandes IA repository, CMS Legal bytes).

Definitions

The bill defines core terms to delimit scope: "algorithm and AI techniques" refers to software and models used to detect, read and match license-plate characters (including optical character recognition and computer-vision models); "recognition in real time" denotes automated processing of live video streams or near-real-time processing of recently captured images; "authorized registry" describes a national or inter-agency register containing plates authorized to circulate and plates reported as stolen or altered; "operator" includes any public agency, municipal body, or private entity that deploys or operates plate-recognition systems; "match event" refers to an automated positive identification requiring follow-up. These definitions delimit obligations such as registration, logging, and human verification requirements to avoid purely automated enforcement outcomes.

Governance and Institutional Framework

The draft assigns regulatory, oversight and coordination roles to a set of public bodies. It contemplates technical rules and operational coordination by the Ministry of Transport and Communications (MTC) for deployments related to transport infrastructure, while data protection obligations and supervisory authority fall under the Autoridad Nacional de Protección de Datos Personales (ANPD). Operational access and law-enforcement follow-up are expected to involve the Policía Nacional del Perú (PNP) and the Ministry of the Interior. The Congress remains the legislative and oversight authority and the bill contemplates inter-institutional memoranda of understanding for data sharing. The draft requires that any public or private operator obtain prior registration/authorization and submit technical documentation, privacy impact assessments, and security plans to the designated authorities for approval.

Key Focus Areas

The bill concentrates on several intersecting policy pillars: (1) Risk management and necessity: deployments must demonstrate a specific public-safety purpose, documented risk assessment, and proportionality analysis; (2) Data protection and privacy: mandatory data protection impact assessments (DPIAs), minimum retention periods, anonymization/pseudonymization where feasible, and strict access controls; (3) Transparency and accountability: public disclosure of authorized deployments, registries of systems and operators, mandatory logging and tamper-evident audit trails; (4) Human oversight: requirement that automated matches be subject to human review before administrative or criminal measures are taken; (5) Cybersecurity and model security: technical standards for encryption, secure model update procedures, and vulnerability management; (6) Conformity and registration: compulsory system registration and periodic conformity assessments by accredited evaluators; and (7) Remedies and redress: complaint mechanisms and obligations to rectify incorrect matches and delete improperly retained images. The draft therefore intersects privacy, fundamental rights, and surveillance regulation.

Implementation Framework

Implementation is organized into pre-deployment, operational and post-deployment phases. Pre-deployment requires operators to: register systems; provide system architecture, datasets descriptions, model provenance, training/validation metrics, and DPIAs; obtain authorization from the designated regulator(s); and run third-party audits or conformity assessments. Operational requirements include secure logging, role-based access controls, encryption of stored media and model artifacts, predefined retention schedules, and procedures for human verification and escalation. Post-deployment mandates periodic reporting to regulators, incident notification procedures for breaches or misuse, and scheduled audits. The bill contemplates technical regulations and secondary norms to be issued by the MTC in coordination with the ANPD and relevant security bodies to define technical standards for cameras, model accuracy, false-positive thresholds, and interoperability with vehicle registries.

Monitoring and Evaluation

Monitoring mechanisms include mandatory operational reports to the ANPD and the coordinating ministry, independent audits by accredited entities, and public transparency reports summarizing deployments, incidents, and enforcement actions. The draft requires impact evaluations at specified intervals (for example, 12 and 36 months after authorization) to measure accuracy, social impact on rights (freedom of movement, privacy), and effectiveness in crime reduction. The bill also contemplates an independent oversight committee or ombudsperson function to review complaints and advise on policy adjustments. Metrics to be tracked include detection accuracy, false positive/false negative rates, number of matches leading to actions, complaints received, and incidents of data breaches.

Penalties, Liability, and Appeals

Proposed enforcement measures range from administrative sanctions (warnings, fines graduated by severity and repeat violations), suspension or revocation of system registrations, mandatory corrective measures, and referral to prosecutorial authorities for criminal misuse. The bill envisages civil liability for damages caused by negligent or unlawful operation, and allows affected individuals to seek correction, deletion, and compensation through administrative and judicial channels. Operators are required to maintain documentary evidence to defend decisions and are subject to inspection. Appeals procedures are to be defined in implementing regulations and require timely administrative review and access to evidentiary material for affected persons while balancing confidentiality of investigatory data.

Relationship to Other Instruments

The draft explicitly interfaces with existing Peruvian legal instruments: the Law on Personal Data Protection (Law No. 29733 and its regulatory framework) and rules governing vehicle registries and transport regulation. It calls for coordination with the Autoridad Nacional de Protección de Datos Personales for compliance with data-protection principles and with transport and interior ministries for operational rules. The proposal does not supersede general criminal or traffic laws but creates a specialized compliance layer for automated plate-recognition systems. Observers recommend alignment with administrative procedure laws to ensure due process in enforcement actions.

International Alignment

Project 7651/2023 draws on international debates about automated surveillance and AI governance, sharing policy elements present in other jurisdictions such as mandatory DPIAs, transparency registers, human-in-the-loop requirements, and conformity assessments. It references comparative practices and the need to align with international human-rights standards. The bill's measures can be compared to EU regulatory trends (e.g., rules in the AI Act proposals) and Latin American initiatives on algorithmic control and data protection. Observers urge that Peru consider international standards and best practices, and build interoperability and data-protection reciprocity where cross-border data flows are involved.

Implementation Timeline

PhaseMilestoneTarget Date
IntroductionProject presented to Congress (PL 07651/2023-CR)2024-04-22
Committee reviewReferral to Commission(s) for study, hearings2024 Q2 (ongoing)
Regulatory designMTC & ANPD draft implementing regs after approvalPost-approval + 6-12 months
Registration & auditsOperators register systems; initial conformity assessmentsImplementation year + 0-6 months
MonitoringFirst mandatory impact evaluation12 months after major deployments

Compliance Checklist

RequirementOperator action
RegistrationSubmit application, system architecture, DPIA
AuthorizationObtain prior approval from designated authority
DPIAConduct and publish non-sensitive summary of DPIA
Human reviewEnsure human-in-the-loop for match validation
Retention limitsApply anonymization and delete raw images per schedule
AuditabilityMaintain tamper-evident logs; permit audits
SecurityImplement encryption and model-security measures

Sources and References

SourceType
Congress of the Republic of Peru — legislative agenda listing (includes PL 07651/2023-CR)Primary Source
Expediente PL 07651 — Congress legislative portalPrimary Source
Bill PDF (congress archive file)Primary Source
University of the Andes — IA regulation repository summarySecondary Source
CMS Peru — legal bulletin (analysis)Secondary Source
Plain English

Peru's proposed Project 7651/2023 aims to regulate how public agencies, municipal bodies, and private companies use artificial intelligence to recognize vehicle license plates in real-time, primarily to combat vehicle theft and altered plates.

This bill applies to any entity, whether public or private, that deploys or operates systems for real-time license plate recognition using algorithms and AI techniques. This includes software and models for detecting, reading, and matching license plate characters from live video streams or recently captured images.

If passed, operators would face several key requirements. They must first register their systems and obtain authorization from designated authorities, submitting detailed technical documentation, privacy impact assessments, and security plans. The bill mandates strong data protection, including minimum data retention periods, anonymization where possible, and strict access controls. Transparency is also crucial, requiring public disclosure of authorized deployments and maintaining tamper-evident audit trails. Critically, any automated match identifying a vehicle must undergo human review before any administrative or criminal action can be taken, ensuring a "human-in-the-loop" approach.

As a bill currently under review by the Peruvian Congress, it is not yet law, and its effective date remains unknown. It is still in the committee review phase, with further regulatory design and implementation expected to take many months after potential approval.

Non-compliance could lead to significant consequences, including administrative sanctions like warnings and fines, suspension or revocation of system registrations, and mandatory corrective actions. Operators could also face civil liability for damages resulting from negligent or unlawful operations, and individuals would have rights to seek correction, deletion, and compensation for incorrect matches.

A key practical implication for companies is the extensive upfront work required: not only must systems be registered and authorized, but operators must also conduct thorough Privacy Impact Assessments and submit comprehensive security plans *before* deployment. This means a significant regulatory hurdle and documentation burden from the outset.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 15 marked complete

Plain-English obligations under Peru - AI License Plate Regulation (PL 07651/2023). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Operators of plate-recognition systems.

    obtain prior registration/authorization and submit technical documentation, privacy impact assessments, and security plans to the designated authorities for approval.
  2. #2CriticalBefore placing on market

    Applies to: Operators of plate-recognition systems.

    provide system architecture, datasets descriptions, model provenance, training/validation metrics, and DPIAs
  3. #3CriticalBefore placing on market

    Applies to: Operators of plate-recognition systems.

    mandatory data protection impact assessments (DPIAs)
  4. #4CriticalBefore placing on market

    Applies to: Operators of plate-recognition systems.

    submit technical documentation, privacy impact assessments, and security plans to the designated authorities for approval.
  5. #5CriticalBefore placing on market

    Applies to: Operators of plate-recognition systems.

    run third-party audits or conformity assessments.
  6. #6Critical

    Applies to: Operators of plate-recognition systems.

    requirement that automated matches be subject to human review before administrative or criminal measures are taken
  7. #7Critical

    Applies to: Operators of plate-recognition systems.

    minimum retention periods, anonymization/pseudonymization where feasible, and strict access controls
  8. #8Critical

    Applies to: Operators of plate-recognition systems.

    mandatory logging and tamper-evident audit trails
  9. #9Critical

    Applies to: Operators of plate-recognition systems.

    technical standards for encryption, secure model update procedures, and vulnerability management
  10. #10Critical

    Applies to: Operators of plate-recognition systems.

    incident notification procedures for breaches or misuse
  11. #11Important

    Applies to: Operators of plate-recognition systems.

    compulsory system registration and periodic conformity assessments by accredited evaluators
  12. #12Important

    Applies to: Operators of plate-recognition systems.

    public disclosure of authorized deployments
  13. #13Important

    Applies to: Operators of plate-recognition systems.

    complaint mechanisms and obligations to rectify incorrect matches and delete improperly retained images.
  14. #14Important

    Applies to: Operators of plate-recognition systems.

    Post-deployment mandates periodic reporting to regulators
  15. #15Important12 months after major deployments

    Applies to: Operators of plate-recognition systems.

    The draft requires impact evaluations at specified intervals (for example, 12 and 36 months after authorization)

© Regulations.AI — created on 13-Jun-2026