I. Data Privacy Law Overview
Personal data privacy in the Dominican Republic (DR) is governed by the Comprehensive Protection of Personal Data Law 172-13 of December 13, 2013, which develops the constitutional guarantee of habeas data (Art. 70 of the Constitution) and the right to privacy and personal data protection (Art. 44).
The law responds to the recognition that every person has the right to access the data recorded about them in public or private registries and to know the use made of it, in an environment where the disclosure, use and trading of personal data can lead to identity theft and violations of fundamental rights.
The purpose of Law 172-13 is the comprehensive protection of personal data stored in files and public and private registries, guaranteeing the rights to honor and privacy and facilitating access to the information recorded about each person.
Unlike GDPR-style regimes, Law 172-13 does not create a general data protection authority, registration duty or breach-notification regime for most sectors; enforcement runs through the courts (habeas data) and, for credit data, the Superintendence of Banks. Companies should nonetheless build consent and security practices to the statute’s principles.
II. Principles
The fundamental principles of Law 172-13 include: the lawfulness and legitimate purpose of personal data files; data quality; the data subject’s right of access; the consent of the data subject; data security and the duty of confidentiality of the person responsible for the file; and loyalty and lawfulness of the means used in collecting personal data.
Article 6(9) of Law 172-13 defines personal data as any numeric, alphabetic, graphic, photographic, acoustic or other information concerning identified or identifiable individuals.
III. Personal Data Privacy Rights
The rights guaranteed by the law include: the right of consultation of data recorded in public and private data banks; the rights of access, rectification, cancellation and opposition; the right to indemnification; and the judicial action of habeas data, all subject to the general conditions and the administrative and judicial procedures established by law.
Under Article 17 of Law 172-13, the habeas data action lies to learn of the existence of personal data stored in files, registries or public or private data banks, whether resulting from a commercial, labor or contractual relationship with a public or private entity, or simply presumed to exist, and to demand the rectification, deletion or updating of information that is inaccurate, outdated or whose registration is prohibited by law.
IV. Personal Credit Information
For credit-related personal data, Article 29 of Law 172-13 designates the Superintendence of Banks (SB) as the supervisory body, empowered to assist and advise individuals on the scope of their rights and the legal remedies available, and to impose administrative sanctions for violations.
The law further empowers the Monetary Board to grant prior authorization for credit information bureaus (Sociedades de Información Crediticia, SICs) to operate in the DR, after which they must enroll in the public SIC registry under SB supervision. The law also establishes prohibitions on cross-ownership and investments between SICs and financial intermediation entities.
V. Prohibitions
SICs are prohibited from collecting, storing, copying, updating, recording, selecting or systematizing information on the details and movements of savings and checking accounts and bank certificates of deposit, religious information, behavioral information, and any other private and intimate information of a person.
VI. Exceptions to Law 172-13
The files and data of the Armed Forces, security, police and intelligence bodies are excluded: personal data collected by those entities for administrative purposes, which must be permanently stored, are not subject to the Data Protection Law.
Cross-border data transfers are not comprehensively regulated under Law 172-13; multinational groups typically cover DR operations through contractual safeguards. A modernization of the data protection framework has been under legislative discussion for several years and should be monitored before structuring long-term data operations.
This publication is provided for informational purposes only and not as legal advice. Any transaction related to any of the described aspects shall require advice and be specifically consulted with the Firm in advance. © Arthur & Castillo. All Rights Reserved. Next
