Personal Data Protection in the Dominican Republic
Your Personal Data in the Dominican Republic: What Law 172-13 Protects and What It Lacks
A person requests their credit history and discovers outdated, or outright wrong, information in a Dominican credit bureau. The question that follows, what can I do about it?, has had a concrete legal answer since 2013: Law 172-13 on the Protection of Personal Data, and a specific judicial action known as habeas data.
The law is born of article 44 of the Dominican Constitution and seeks two things at once: to protect the honor and privacy of persons against the use of their information, and to guarantee them access to the data that others, public or private, have on record about them. From this derive the so-called ARCO rights: access, rectification, cancellation, and objection, plus the right to compensation where applicable.
The judicial mechanism to enforce them is the habeas data action: it allows one to ascertain what information exists about a person in public and private files or databases, even when its existence is only presumed, and to demand its correction, updating, or deletion when it is inaccurate, outdated, or its recording is prohibited by law.
The particular case of credit
For credit information specifically, the law places the Superintendency of Banks as the oversight body, with the power to advise data subjects and to sanction violations. Credit information companies (SIC) need prior authorization from the Monetary Board to operate, and are prohibited from collecting certain especially sensitive information: detailed movements of bank accounts, religious information, or any intimate data about a person that does not lend itself directly to credit assessment.
Outside the scope of the law are the files of the Armed Forces, the Police, and the intelligence agencies, when the information was collected for administrative purposes and must be kept permanently.
What the original 2013 text did not anticipate is the current volume of data circulating through digital platforms and artificial intelligence tools. That is why there is public discussion, still without an approved law, about reforming the Dominican framework to bring it closer to more recent international standards.
If your company collects, stores, or processes personal data in the Dominican Republic of clients, employees, or users, it is worth mapping your compliance with Law 172-13 now, before an eventual reform raises the required standard. We can help you assess your exposure and prepare a privacy policy compliant with the law in force.
Do you want more information about our services for Personal Data Protection in the Dominican Republic? Contact Us.
Disclaimer: This publication is not intended to provide advice or suggest a guaranteed outcome as individual situations will differ and the situation may have changed since publication. For specific advice on the information provided and related topics, please contact the author.
© Arthur & Castillo ®. All Rights Reserved.