Skip to the content
Global Data RulesData governance rules, country by country

Costa Rica

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Costa Rica — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Waking up

Costa Rica does not force anyone to keep data inside the country. We found no rule in any industry that says data must stay there. Instead the law controls sharing. You may only hand personal data to another organisation if the person agreed. That applies in Costa Rica and abroad. There is also a firm rule that most personal data must be deleted or made anonymous after ten years. Fines are small. But the regulator can shut a database down for up to six months.

Data governance in Costa Rica

The eight things that decide how you handle data about people in Costa Rica. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. What matters is where your handling has effects, not where your office is. If your use of personal data has effects inside Costa Rica, the law applies. That holds even if you have no company, staff or server there. There is no size, revenue or staff limit that gets you out. We found no general requirement to appoint a local representative. If you have to register a database, you must name a contact person who answers to the regulator and to the public.

What you have to do here:
Publish a complaints contact

Where the data is allowed to live

Yes, and nothing has to stay behind. We looked for rules requiring data to stay in the country in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling, mapping and defence. We found none, checked on 19 August 2026. The catch is not geography. It is consent. Handing personal data to another organisation, at home or abroad, needs the person's clear permission. Moving data to your own cloud provider or your own group company does not count as handing it over. So it needs no consent.

Ways to send data out:
Explicit consent

What to do: Get the paperwork for one of the routes below signed before any data leaves Costa Rica.

Sending data out of the country

There is no list of approved or banned countries. Costa Rica does not use lists at all. The permission you need comes from the person, not from the government. Before data goes to another organisation, you need three things. The person's clear and informed yes. A contract with the receiving organisation that puts it under the same duties you have. And, if you had to register your database, a written handling protocol filed with the regulator. If someone complains, you have to prove all of this. The regulator does not have to disprove it.

What you have to do here:
Written vendor contract · Put a transfer safeguard in place
Ways to send data out:
Explicit consent

The regulator, and whether it actually acts

The Agency for the Protection of Inhabitants' Data, known as PRODHAB, sits inside the Ministry of Justice and Peace. It is real and it is staffed. It has a national director, David Rodriguez Suarez. He signed its mid-year 2026 performance report on 16 July 2026. Its website was updated in August 2026. But the last decisions on its own transparency page are from 2023. Its maximum fine is small. It made news in 2025 by ordering the central bank to stop collecting data that had not been made anonymous. Our verdict: it is willing and starting to act, but it does not hit hard yet.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Costa Rica is unusual. It sets a firm delete date. Personal data that could harm the person must not be kept more than ten years. The ten years run from the date of the events recorded. A specific law can say otherwise. If you need the data longer, you must strip out anything that identifies the person. Separately, you must delete data as soon as it stops being relevant for the purpose you collected it for. Where a specific legal duty to keep records clashes with the ten-year limit, the specific duty wins.

What you have to do here:
Delete data after a period · Let people delete their data

What to do: Set an automatic deletion job so data does not sit past its deadline.

If something goes wrong

The main deadline is five working days. If personal data is lost, destroyed, mislaid or otherwise compromised, you must tell the affected people. You have five working days from the incident. In the same window you must start a full review of how bad it is. You must also tell the regulator. Say what happened, which data was hit, what you fixed straight away, and where people can find out more. Telecoms companies have a second deadline to the telecoms regulator. Government bodies report to the national cyber team.

What you have to do here:
Tell affected people · Report breaches to the regulator · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things catch people out. One: 'transfer' has a narrow legal meaning. Sending data to your own cloud or your own group needs no consent. Selling a list to an unrelated Costa Rican company does. Two: the ten-year delete limit has no equal in most countries, and it is absolute. Three: sending Costa Ricans' data abroad without consent is the most serious class of offence. It can shut your database for up to six months. Four: if you run a database to sell or share data, you must register it. You pay 200 US dollars a year and say where the data physically sits. Five: the fines are small, but the Act still allows criminal prosecution on top.

What you have to do here:
Register or notify · Delete data after a period
What it costs if you get it wrong:
Criminal liability · Order to stop

What's changing next

Nothing is confirmed to arrive in the next twelve months. A full replacement law modelled on European rules has been in parliament since 2022, as file number 23.097. It had not passed as of 19 August 2026. Costa Rica seated a new parliament on 1 May 2026. Treat the bill as a proposal, not a plan. The thing to watch is quieter. The detailed rules that make the current law workable sit in a decree the president can rewrite alone. That decree has already been rewritten twice.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: Acuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion · Acuerdo CONASSIF 5-24 (version of 5 August 2024), successor to Acuerdo CONASSIF 5-17 / SUGEF 14-17. Commencement date not verified. · Directly binding regulation

In forceYes — store it anywhere

Banking's rule is about disclosure, not about where data sits. Supervised financial firms may host abroad. But each year they must tell the banking supervisor which country, region and zone their cloud services sit in. They must also say where their backups are held. Financial firms supervised by the banking supervisor do not have to register their databases with the privacy regulator. That regulator still keeps full power over them.

Enforced by General Superintendency of Financial Entities

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Ley General de Telecomunicaciones N.° 8642, articulo 42, y Decreto Ejecutivo N.° 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones) · Ley 8642 (Ley General de Telecomunicaciones), article 42; Decreto Ejecutivo 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones). Exact commencement dates not verified. · Directly binding regulation

In forceYes — store it anywhere

Telecoms operators face confidentiality and deletion duties. They face no rules about where data must sit. Call and connection records and location data must be erased or made anonymous once they are no longer needed. Using traffic data for marketing needs explicit consent. Network security risks must be reported to the telecoms regulator. We found no requirement for telecoms data to be held in Costa Rica.

Enforced by Telecommunications Superintendency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Government

Cyber security rules

Official name: Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales · Decreto Ejecutivo N.° 45061-MICITT, replacing Decreto 37052. A non-binding public consultation on the draft opened on 30 April 2025; the adoption date was not verified. · Directly binding regulation

In forceNot yet established

Costa Rica rebuilt its government cybersecurity rules after the 2022 ransomware emergency. A draft regulation on cybersecurity governance for government institutions went to public consultation on 30 April 2025. The ministry now calls it decree 45061. We could not read the decree text. So we have not confirmed its duties, its deadlines, or any cloud or data-location conditions on government suppliers.

Enforced by Ministry of Science, Innovation, Technology and Telecommunications

How this country controls where data goes: No restriction

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley de Proteccion de la Persona frente al tratamiento de sus datos personales · Ley N.° 8968 of 7 July 2011, published in La Gaceta N.° 170 of 5 September 2011 · Act of parliament

In forceYes, with paperwork

The general privacy law. It does not require data to stay in Costa Rica. Instead it bans handing personal data to another organisation without the person's express permission. That applies at home and abroad. It sets a firm ten-year deletion limit. It makes databases run for sale or distribution register and pay an annual fee. The top fine is about 27,000 US dollars. The regulator can also suspend a database for up to six months.

In force since 5 September 2011Enforced from 5 March 2013

Enforced by Agency for the Protection of Inhabitants' Data

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent

Breach reporting rules

Official name: Reglamento a la Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales · Decreto Ejecutivo N.° 37554-JP of 30 October 2012, amended by Decreto Ejecutivo N.° 40008-JP of 19 July 2016 and Decreto Ejecutivo N.° 41582 of 21 February 2019 · Directly binding regulation

In forceYes, with paperwork

The decree that makes the Act workable. It is the document that actually decides most questions. It applies the rules to anyone whose use of data has effects in Costa Rica. It sets a five-working-day breach notice to both the person and the regulator. It requires a matching contract on transfers. And it leaves suppliers, service providers, technology intermediaries and same-group companies out of the definition of a 'transfer'.

In force since 5 March 2013

Enforced by Agency for the Protection of Inhabitants' Data

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent

Who you would hear from

  • Agencia de Proteccion de Datos de los Habitantes (Prodhab)

    General personal data protection: register of databases, complaints, orders to delete or correct, fines, referral of possible crimes to the public prosecutor

    Staffed and running. National director David Rodriguez Suarez digitally signed the Agency's mid-year 2026 performance report on 16 July 2026. The 2026 operating and financial plans are filed. A 2025 to 2030 strategic plan is published. The portal was last modified on 14 August 2026. But the Agency's own published decisions stop at 2023. The transparency page offers year tabs for 2018 through 2023 and nothing later. The top fine is about 27,000 US dollars. Its most visible recent action was a 2025 precautionary measure against the central bank over data that had not been made anonymous. That is documented by professional and press sources, not on the Agency's own site.

  • Superintendencia General de Entidades Financieras (SUGEF)

    Banks and supervised financial entities: technology governance, annual technology profile including cloud country and backup location

    Fully operational. It collects the annual technology profile through the SICVECA reporting system. It ran training for firms on the 2026 profile in July 2025. Several regulation PDFs on its site were unreachable on 19 August 2026. Parts of the normativa section returned a maintenance page.

  • Superintendencia de Telecomunicaciones (SUTEL)

    Telecoms operators: secrecy of communications, traffic and location data, network security risk reporting, end-user protection

    Active. It publishes technical opinions on legislation, including a formal opinion on the personal data protection bill. It also issues binding end-user protection measures against operators.

  • Ministerio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)

    National cybersecurity policy, the national computer security incident response team, government institution cybersecurity governance, telecoms network cybersecurity

    Operational. It runs a national security operations centre around the clock, with a dedicated incident reporting mailbox. It issued the 2023 to 2027 national cybersecurity strategy. It consulted on the government cybersecurity governance regulation in April 2025. It publishes the resulting decree 45061.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The full text of Acuerdo CONASSIF 5-24, the banking technology governance regulation

    We could not confirm the banking technology rules against the regulation text. The PDF on the banking supervisor's own site returned a 404 on 19 August 2026. Our evidence for the cloud country, region and backup-location reporting fields comes from the supervisor's July 2025 training deck for the 2026 technology profile. So we cannot rule out an unread condition on offshore outsourcing, such as a storage-location or prior-approval rule. We also cannot state the incident reporting deadline for banks. Ask the banking supervisor if this affects you.

  • The full text, exact date and obligations of Decreto 45061-MICITT on government cybersecurity governance

    We could not confirm what this decree says. The ministry's own pages name it but link only to the national legal database, which blocks automated access. We know a draft went to non-binding public consultation on 30 April 2025. We know the ministry now refers to the decree as existing. We could not confirm its start date, whether it puts cloud or data-location conditions on government suppliers, or any incident reporting deadline. Check with the ministry if you supply government bodies.

  • The current parliamentary stage of bill 23.097, the proposed replacement data protection law

    We could not confirm how far this bill has got. Parliament's own case-tracking system blocks automated access. We can show the bill exists and was formally consulted on, from the telecoms regulator's published technical opinion. We can show the 2011 Act has still not been reformed, from the data protection regulator's own site. We cannot say which committee stage it is at. We cannot say whether it survived the change of parliament on 1 May 2026.

  • Whether PRODHAB has issued any decision, fine or precautionary measure since 2023

    We could not confirm how active the regulator has been since 2023. Its own transparency page publishes 'depersonalised resolutions' for 2018 to 2023 only. Professional and press sources report a 2025 precautionary measure against the central bank. That suggests the Agency is still deciding cases and simply not publishing them. On that basis we rate enforcement 'waking' rather than 'dormant'.

  • Costa Rica's general tax, accounting and anti-money-laundering record retention floors

    We could not confirm Costa Rica's general tax and commercial record-keeping periods against a government source. The national legal database that hosts the Tax Procedure Code and the Commercial Code blocks automated access. We ran out of search budget before finding a government-hosted copy. These periods matter, because the ten-year deletion limit in the data protection Act gives way to any special legal rule. Check the current periods with a Costa Rican adviser.

  • That no sectoral where data has to be stored rule exists in health, insurance, securities, education, gambling, mapping or defence

    We found no rule requiring data to stay in the country in these industries. We could not confirm that against every government source. We searched each of them and found nothing as at 19 August 2026. The health sector rules, the digital health record Act and its regulation, sit on the blocked national legal database and were not read in full. If you work in health, check before you rely on this.

  • The US dollar values given for the fine ceilings

    We could not confirm the exchange rate used here. The base salary of 462,200 colones for 2026 is confirmed from the judiciary's own announcement. But the conversion to dollars uses a rough rate of about 505 colones to the dollar. We did not check that against the central bank on the day. Treat the dollar figures as rough.

  • Whether the annual 200 US dollar registration fee and the per-query fee are actually being collected today

    We could not confirm that these fees are current. Both figures come from the Act itself, and the regulator's registration page describes the process. But we found no fee schedule or collection notice dated 2025 or 2026 on the regulator's site. Ask PRODHAB for the current fee before you budget for it.

  • Exact commencement dates for the implementing decree, the banking technology regulation and the telecoms privacy regulation

    We could not confirm some start dates. The 2011 Act was published in the official gazette on 5 September 2011. Its implementing decree was signed on 30 October 2012. We could not open the gazette to confirm the decree's publication date, which is when it started. We have used 5 March 2013 as the date the Act became workable. That is the date commonly given for the decree's publication, and we could not confirm it from a government source. We did not check the start dates for Acuerdo CONASSIF 5-24 or Decreto 35205-MINAET at all, and have left them blank rather than guess.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.