Data Protection in the Dominican Republic

Data Protection in the Dominican Republic: What Law 172-13 Covers and the Reform Waiting in Congress


Every business that holds customer data in the Dominican Republic operates under a statute written in 2013, largely with credit bureaus in mind. That gap between what companies actually do with data and what the law was built to regulate is precisely why the regime matters, and why its replacement has been debated for years.

The foundation is constitutional. Article 44 of the Dominican Constitution protects honor and personal intimacy, and Article 70 establishes the habeas data action: every person’s right to access the data recorded about them in public or private registries, and to know how that information is used. Law 172-13, enacted December 13, 2013, sets the parameters and procedures for exercising it, a legislative response to the routine disclosure, use and trade of personal data that fuels identity theft and violations of fundamental rights.

Principles and rights

The law’s guiding principles include the legality and legitimate purpose of personal data files, the quality of the data held, the data subject’s right of access, the owner’s consent, data security, the duty of secrecy of the person responsible for the file, and fair, lawful means of collection. “Personal data” is defined broadly, any numeric, alphabetic, graphic, photographic, acoustic or other information concerning identified or identifiable individuals.

On that base sit the operative rights: consultation of what public and private data banks hold; access, rectification, cancellation and opposition; indemnity; and the judicial habeas data action itself. Under Article 17, that action lies to learn of and access personal data stored by an entity with which the person had a commercial, labor or contractual relationship, or data merely presumed to exist, and to demand rectification, deletion or updating where information is inaccurate, outdated or legally prohibited from being recorded.

Credit data, prohibitions and exceptions

The credit system gets its own architecture. Article 29 designates the Superintendency of Banks as the control body for credit-related personal data, empowered to advise individuals on their rights and impose administrative sanctions. Credit information bureaus (SICs) require prior authorization from the Monetary Board and registration under the Superintendency’s supervision, with ownership restrictions between SICs and financial intermediaries. SICs are expressly prohibited from collecting or storing details of savings and checking account movements, bank certificates of deposit, religious information, behavioral data and other private, intimate information. Files held by the armed forces, security, police and intelligence bodies for administrative purposes sit outside the law’s reach.

What comes next

The candid assessment shared by practitioners: Law 172-13 regulates credit reporting well and everything else thinly. There is no independent data protection authority, and a comprehensive replacement bill, drafted with Council of Europe support, has been pending before Congress for years without enactment. Companies handling Dominican personal data should track that reform closely: a modern, GDPR-style regime would bring consent standards, accountability duties and cross-border transfer rules that today exist only as best practice.

If your business collects, processes or transfers personal data touching the Dominican Republic, we can audit your exposure under the current law, and position you for the one that is coming.


Do you need advisory services in connection with Data Protection  in Dominican Republic? Contact Us.


ABOUT THE AUTHOR: Felipe Castillo is a Partner leading the Foreign Investment, Real Estate & Tourism areas at Arthur & Castillo Advisers and Consultants in the Dominican Republic. He specializes in foreign investment, real estate and international business (Master in International Business, Entrepreneurship and Finance Studies from Georgetown University in Washington, D.C. & Masters in International E- Business in Universitat Pompeu Fabra in Barcelona) with more than 20 years of experience in Foreign Investment, Free Trade Zones, International Business and Cross Border Real Estate practice. He is a Certified Business Bankruptcy Expert and English and Spanish Interpreter.

Email: fcastillo@aclaw.com

Disclaimer: This publication is not intended to provide advice or suggest a guaranteed outcome as individual situations will differ and the situation may have changed since publication. For specific advice on the information provided and related topics, please contact the author.

© Arthur & Castillo ®. All Rights Reserved.