Costa Rica
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Costa Rica — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Costa Rica does not force anyone to keep data inside the country. We found no rule in any industry that says data must stay there. Instead the law controls sharing. You may only hand personal data to another organisation if the person agreed. That applies in Costa Rica and abroad. There is also a firm rule that most personal data must be deleted or made anonymous after ten years. Fines are small. But the regulator can shut a database down for up to six months.
Data governance in Costa Rica
The eight things that decide how you handle data about people in Costa Rica. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. What matters is where your handling has effects, not where your office is. If your use of personal data has effects inside Costa Rica, the law applies. That holds even if you have no company, staff or server there. There is no size, revenue or staff limit that gets you out. We found no general requirement to appoint a local representative. If you have to register a database, you must name a contact person who answers to the regulator and to the public.
- What you have to do here:
- Publish a complaints contact
The Act's scope article covers personal data held in automated or manual databases of public or private bodies. It also covers all later use of that data. The effects test comes from the regulation that implements the Act. Its scope article extends the rules to such data where the data produces effects inside the country. It also applies where Costa Rican law covers the data under a contract or under international law. Databases kept purely for internal, personal or household purposes fall outside. That only lasts while they are not sold, distributed or otherwise sold on. A 2016 amendment also removed data about people in their professional role, where the use serves the profession or meets a legal duty. Where registration applies, you must name a 'responsable', the person answerable to the Agency and to the public. You give a contact address and the physical location of each database. The regulation does not say that person must live in Costa Rica.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 2 (scope of application)
micitt.go.cr
“Esta ley sera de aplicacion a los datos personales que figuren en bases de datos automatizadas o manuales, de organismos publicos o privados, y a toda modalidad de uso posterior de estos datos.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), article 3 (scope of application), as amended by Decreto 40008-JP
iafa.go.cr
“Este Reglamento sera de aplicacion a los datos personales que figuren en las bases de datos automatizadas o manuales, de organismos publicos o privados, y a toda modalidad de uso posterior de estos datos, en tanto surtan efectos dentro del territorio nacional, o les resulte aplicable la legislacion costarricense derivada de la celebracion de un contrato o en los terminos del derecho internacional.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
Where the data is allowed to live
Yes, and nothing has to stay behind. We looked for rules requiring data to stay in the country in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling, mapping and defence. We found none, checked on 19 August 2026. The catch is not geography. It is consent. Handing personal data to another organisation, at home or abroad, needs the person's clear permission. Moving data to your own cloud provider or your own group company does not count as handing it over. So it needs no consent.
- Ways to send data out:
- Explicit consent
We rate this conditional rather than open, because the general rule is a consent gate rather than free movement. The Act's transfer chapter has a single article. Whoever runs a public or private database may only pass on data from it if the person has expressly and validly authorised that. The regulation then defines the word narrowly. A 'transfer' means a handover from one organisation that decides how data is used to another such organisation. It expressly does not cover moving data to a supplier, a service provider, a technology intermediary, or to companies in the same economic-interest group. The definitions article backs this up. A database shared inside one economic-interest group stays an 'internal database', whether the group is local or international. That holds as long as nothing is spread, distributed or sold to outsiders. So hosting Costa Rican customer data in a foreign cloud region sits outside the consent rule. So does copying it to a parent company overseas. Selling a marketing list to an unrelated company sits inside the rule, even if that company is down the street in San Jose. Industry rules add duties rather than walls. Banking and finance: no rule that data must stay in the country. But under the technology governance regulation, supervised firms must file an annual technology profile. For each cloud service it reports the country code and the cloud region and zone. It also reports the service and deployment model, and where cloud and offline backups sit. Telecoms: no rule that data must stay in the country. But traffic and location data must be deleted or made anonymous once no longer needed to carry the communication or provide the service. Identified network security risks must be reported to the telecoms regulator. Government: we found no rule that data must stay in the country. A cybersecurity governance decree for government institutions exists, but we could not read its text. Health, insurance, securities, education, gambling, mapping and defence: we found no rule on storage location or on transfers, checked 19 August 2026, medium confidence. Costa Rica does not license online gambling at all, so there is no gambling data regulator to impose one.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 14 (transfer of personal data, general rule)
micitt.go.cr
“Los responsables de las bases de datos, publicas o privadas, solo podran transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y validamente tal transferencia y se haga sin vulnerar los principios y derechos reconocidos en esta ley.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), article 40 (conditions for transfer), as amended by Decreto 40008-JP
iafa.go.cr
“No se considera trasferencia el traslado de datos personales del responsable de una base de datos a un encargado, proveedor de servicios o intermediario tecnologico o las empresas del mismo grupo de interes economico.”
Link checked 19 August 2026
- Official sourceSuperintendencia General de Entidades Financieras (SUGEF)SUGEF - Perfil Tecnologico 2026 under Acuerdo CONASSIF 5-24: reporting fields include CodPais, RegionNube, ZonaNube and UbicacionRespaldosNube
sugef.fi.cr
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Secondary sourceDLA PiperData protection laws in Costa Rica
dlapiperdataprotection.com
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Costa Rica.
Sending data out of the country
There is no list of approved or banned countries. Costa Rica does not use lists at all. The permission you need comes from the person, not from the government. Before data goes to another organisation, you need three things. The person's clear and informed yes. A contract with the receiving organisation that puts it under the same duties you have. And, if you had to register your database, a written handling protocol filed with the regulator. If someone complains, you have to prove all of this. The regulator does not have to disprove it.
- What you have to do here:
- Written vendor contract · Put a transfer safeguard in place
- Ways to send data out:
- Explicit consent
Costa Rica decides case by case, and the person decides, not an official. There is no list of countries judged safe enough. There is no list of banned countries and no list of approved ones. The government publishes no standard contract clauses. Because there are no lists, there is no question of whether a list has been filled in. The Act contains no unused list power that could be switched on by notice. The regulation adds three practical requirements around the consent. Article 43 requires the sending organisation to sign a contract with the receiving organisation. That contract must impose at least the same duties the sender is under. Article 41 makes transfers conditional on faithfully following the minimum handling protocols registered with the Agency. Article 42 puts the burden of proof on the sender to show the transfer met the Act and the regulation. Under the Act, a registered handling protocol creates a presumption that you complied, which can be rebutted. That is the closest thing Costa Rica has to a safe harbour. Remember the exception in question two. None of this applies where the recipient is your supplier, service provider, technology intermediary or a company in your own economic-interest group.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 40 to 43 (conditions, protocols, burden of proof, transfer contract)
iafa.go.cr
“Articulo 43. Contrato para la transferencia de datos. El responsable de la transferencia de datos personales debera establecer un contrato con el responsable receptor, en el que se prevean, al menos las mismas obligaciones a las que se encuentra sujeto el responsable de la transferencia de dichos datos.”
Link checked 19 August 2026
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 12 and 14 (handling protocols and the transfer rule)
micitt.go.cr
“La manipulacion de datos con base en un protocolo de actuacion inscrito ante la Prodhab hara presumir, 'iuris tantum', el cumplimiento de las disposiciones contenidas en esta ley, para los efectos de autorizar la cesion de los datos contenidos en una base.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
The regulator, and whether it actually acts
The Agency for the Protection of Inhabitants' Data, known as PRODHAB, sits inside the Ministry of Justice and Peace. It is real and it is staffed. It has a national director, David Rodriguez Suarez. He signed its mid-year 2026 performance report on 16 July 2026. Its website was updated in August 2026. But the last decisions on its own transparency page are from 2023. Its maximum fine is small. It made news in 2025 by ordering the central bank to stop collecting data that had not been made anonymous. Our verdict: it is willing and starting to act, but it does not hit hard yet.
The Act created PRODHAB as a body with maximum administrative autonomy attached to the Ministry of Justice and Peace. It has its own legal personality for managing its budget and contracts. It also has independence of judgement. Its powers cover several things. Keeping the register of databases. Demanding information and protocols. Getting access to regulated databases. Deciding complaints. Ordering data to be deleted, corrected or restricted. Imposing the Act's fines. And referring anything that might be a crime to the public prosecutor. Signs it is working. A named director signed 2026 planning documents. The 2026 operating and financial plans are filed with the budget authority. A strategic plan runs 2025 to 2030. The site was last modified 14 August 2026. Signs it is not yet aggressive: the 'depersonalised resolutions' tabs on its own transparency page cover 2018 to 2023 and stop there. No decision from 2024, 2025 or 2026 is publicly available from the Agency itself. The top fine is roughly 27,000 US dollars. The one visible 2025 action was a precautionary measure stopping the Banco Central de Costa Rica from requiring data that had not been made anonymous. That is reported by professional and press sources, not published by the Agency. Industry regulators are clearly active. The banking supervisor collects annual technology profiles. The telecoms regulator issues binding consumer protection measures. We rate the Agency waking rather than active, because its own public record of decisions has not moved for over two years.
Sources
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Informe de Seguimiento Semestral, Plan Operativo Institucional 2026, signed by director David Rodriguez Suarez on 16 July 2026
prodhab.go.cr
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Resoluciones Despersonalizadas (year tabs run 2018 to 2023 only)
prodhab.go.cr
Link checked 19 August 2026
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 15 to 17 (creation, powers and direction of PRODHAB)
micitt.go.cr
“Son atribuciones de la Prodhab ... g) Imponer las sanciones establecidas, en el articulo 28 de esta ley, a las personas fisicas o juridicas, publicas o privadas, que infrinjan las normas sobre proteccion de los datos personales, y dar traslado al Ministerio Publico de las que puedan configurar delito.”
Link checked 19 August 2026
- Secondary sourceInternational Association of Privacy ProfessionalsMedida cautelar: un precedente importante establecido por la Agencia de Proteccion de Datos en Costa Rica
iapp.org
Link checked 19 August 2026
How long you must keep it — and when to delete it
Costa Rica is unusual. It sets a firm delete date. Personal data that could harm the person must not be kept more than ten years. The ten years run from the date of the events recorded. A specific law can say otherwise. If you need the data longer, you must strip out anything that identifies the person. Separately, you must delete data as soon as it stops being relevant for the purpose you collected it for. Where a specific legal duty to keep records clashes with the ten-year limit, the specific duty wins.
- What you have to do here:
- Delete data after a period · Let people delete their data
The ten-year limit sits in the Act's data-quality article, under the heading about keeping data current. Two duties run in parallel. One is general: erase data that has stopped being relevant or necessary for the purpose you collected it for. The other is the absolute ten-year cut-off for data that could affect the person. That is counted from the date the recorded events happened. The clash rule sits in the same sentence. The ten-year limit applies unless a special legal rule says otherwise. So a tax, accounting, anti-money-laundering or health record-keeping duty with its own period beats the ten-year rule for the records it covers. The safe approach is to keep only what the specific duty requires. Strip the identifying details from the rest, or delete it. Telecoms goes the other way. The sector rules require operators to erase traffic and location data, or make it anonymous, once it is no longer needed. That means once it is no longer needed to carry the communication or to provide and bill the service. We did not check Costa Rica's general tax and commercial record-keeping minimums against a government source. See the unconfirmed list.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 6.1 (currency of data - the ten-year ceiling)
micitt.go.cr
“En ningun caso, seran conservados los datos personales que puedan afectar, de cualquier modo, a su titular, una vez transcurridos diez anos desde la fecha de ocurrencia de los hechos registrados, salvo disposicion normativa especial que disponga otra cosa. En caso de que sea necesaria su conservacion, mas alla del plazo estipulado, deberan ser desasociados de su titular.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
What to do: Set an automatic deletion job so data does not sit past its deadline.
If something goes wrong
The main deadline is five working days. If personal data is lost, destroyed, mislaid or otherwise compromised, you must tell the affected people. You have five working days from the incident. In the same window you must start a full review of how bad it is. You must also tell the regulator. Say what happened, which data was hit, what you fixed straight away, and where people can find out more. Telecoms companies have a second deadline to the telecoms regulator. Government bodies report to the national cyber team.
- What you have to do here:
- Tell affected people · Report breaches to the regulator · Report cyber incidents
Deadline one, for everyone. Article 38 of the regulation gives five working days from the moment the breach happened. In that time you must tell the person about any problem in the handling or storage of their data. That covers loss, destruction or misplacement caused by a security failure. The point is to let affected people protect themselves. The same five-day window starts a duty to begin a full review of the scale of the damage. You must also work out the corrective and preventive measures needed. Article 39 sets the minimum content of the notice. That content must go to the person and to the Agency. Note that the clock starts when the breach happened, not when you found out. That is stricter than the discovery-based deadlines used in Europe and much of Asia. Deadline two, telecoms. Operators of public networks and publicly available services must tell the telecoms regulator and their users. This applies where the operator learns of an identifiable risk to network security. The statute gives no fixed number of hours. Deadline three, government. MICITT runs a national security operations centre around the clock. It also runs a national computer security incident response team for central government institutions. There is a dedicated incident reporting mailbox and a cybersecurity governance decree for government institutions. We could not read that decree, so any deadline in it is unconfirmed. Deadline four, banks. Supervised financial firms report operational and technology incidents to the banking supervisor under the technology governance regulation. We could not read that text either, so we have not confirmed a deadline. The painful overlap is deadline one against deadline four. A payments outage at a bank is a supervisory incident. If customer data moved, it is also a five-working-day notice to customers and to PRODHAB.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 38 and 39 (security breach and minimum information)
iafa.go.cr
“El responsable debera informar al titular sobre cualquier irregularidad en el tratamiento o almacenamiento de sus datos, tales como perdida, destruccion, extravio, entre otras, como consecuencia de una vulnerabilidad de la seguridad o que tuviere conocimiento del hecho, para lo cual tendra cinco dias habiles a partir del momento en que ocurrio la vulnerabilidad.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)Ley General de Telecomunicaciones 8642, article 42 (privacy of communications and personal data protection)
sutel.go.cr
“En caso de que el operador conozca un riesgo identificable en la seguridad de la red, debera informar a la Sutel y a”
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad services: CSIRT-CR / national security operations centre, 24/7 incident reporting to soc-cr@micitt.go.cr
micitt.go.cr
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things catch people out. One: 'transfer' has a narrow legal meaning. Sending data to your own cloud or your own group needs no consent. Selling a list to an unrelated Costa Rican company does. Two: the ten-year delete limit has no equal in most countries, and it is absolute. Three: sending Costa Ricans' data abroad without consent is the most serious class of offence. It can shut your database for up to six months. Four: if you run a database to sell or share data, you must register it. You pay 200 US dollars a year and say where the data physically sits. Five: the fines are small, but the Act still allows criminal prosecution on top.
- What you have to do here:
- Register or notify · Delete data after a period
- What it costs if you get it wrong:
- Criminal liability · Order to stop
1. THE TRANSFER EXCEPTION CUTS BOTH WAYS. Suppliers, service providers, technology intermediaries and same-group companies are left out of the definition of transfer. So international cloud hosting is easy. But the Act's general rule makes no difference between domestic and cross-border. A purely domestic handover to an unrelated organisation needs the same express consent as an export. Teams that build their consent flow around 'international transfer' wording miss the domestic half. 2. TEN YEARS IS A HARD STOP. Data that could affect the person must be gone ten years after the recorded events. Or it must be stripped of anything linking it to the person. A specific legal rule can say keep it. Keeping schedules copied from Europe or the United States will break this rule. 3. EXPORT WITHOUT CONSENT IS A 'FALTA GRAVISIMA'. Article 31 lists this as the most serious class of offence. It covers sending the personal data of Costa Ricans, or of foreigners living in the country, to databases in another country without the holders' consent. The penalty for that class is 15 to 30 base salaries. It also suspends the file's operation for one to six months. The suspension, not the fine, is the commercial threat. 4. REGISTRATION, THE FEE AND THE LOCATION DISCLOSURE. Any database, public or private, run to distribute, spread or sell data must go on PRODHAB's register. The registration form asks for the names of the databases and their physical location. It also asks for the categories of data, the collection procedures and a technical description of your security measures. There is a flat annual fee of 200 US dollars. There is also a per-query fee of 25 US cents to 1 US dollar on commercial sales of individual records. That fee is capped at ten per cent of the contract price. Running a database unregistered when you should have registered is itself a most serious offence. Financial firms supervised by the banking supervisor do not have to register. PRODHAB still keeps full power over them. People routinely get that pair the wrong way round. 5. SMALL FINES, REAL CRIMINAL TAIL. The top administrative fine is 30 base salaries. The base salary for 2026 was fixed at 462,200 colones. So the top fine is about 13.9 million colones, roughly 27,000 US dollars. But the sanctions article opens by saying it applies without prejudice to the matching criminal penalties. PRODHAB must refer anything that might be a crime to the public prosecutor. 6. ONE MORE TRAP. The breach clock runs from when the breach happened, not from when you discovered it.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 21, 28, 31 and 33 (registration, sanctions, most serious offences, annual fee)
micitt.go.cr
“f) Transferir, a las bases de datos de terceros paises, informacion de caracter personal de los costarricenses o de los extranjeros radicados en el pais, sin el consentimiento de sus titulares.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 3, 40 and 44 (SUGEF exemption from registration, transfer carve-out, registration content)
iafa.go.cr
“Las bases de datos de entidades financieras que se encuentren sujetas al control y regulacion por parte de la Superintendencia General de Entidades Financieras (SUGEF), no requeriran inscribirse ante la Agencia de Proteccion de Datos de los Habitantes.”
Link checked 19 August 2026
- Official sourcePoder Judicial de Costa RicaPoder Judicial fixes the 'salario base' at 462,200 colones for fines and penalties from 1 January 2026 (Consejo Superior, session 113-2025 of 16 December 2025)
pj.poder-judicial.go.cr
“A partir del 1° de enero del 2026, el salario base que se debe aplicar para definir las penas por la comision de figuras delictivas ... es de ¢462.200,00.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
What's changing next
Nothing is confirmed to arrive in the next twelve months. A full replacement law modelled on European rules has been in parliament since 2022, as file number 23.097. It had not passed as of 19 August 2026. Costa Rica seated a new parliament on 1 May 2026. Treat the bill as a proposal, not a plan. The thing to watch is quieter. The detailed rules that make the current law workable sit in a decree the president can rewrite alone. That decree has already been rewritten twice.
PENDING LEGISLATION. Legislative file 23.097, 'Ley de Proteccion de Datos Personales', would replace the 2011 Act with European-style rules. It would allow legal bases other than consent. It would require data protection officers. It would add formal routes for sending data abroad. And it would give the regulator more power. The telecoms regulator filed a formal technical opinion on it. That is our government evidence that the file exists and was consulted on. As of today PRODHAB's own website still says the Act has never been reformed. So the bill has not become law. We could not read parliament's own case-tracking system, which blocks automated access. So we cannot confirm which committee stage the bill is at. Do not plan around it. RULES THAT CAN CHANGE WITHOUT WARNING. These matter more. First, and most important: almost everything that makes Costa Rica permissive sits in the decree that implements the Act, not in the Act itself. Suppliers, service providers, technology intermediaries and same-group companies were left out of the definition of 'transfer' by executive decree in 2016. So was the treatment of internationally shared group databases as merely 'internal'. So was the exemption of bank databases from registration. A president and a minister can narrow any of these by signing another decree. There is no parliamentary vote and no duty to consult. If that exception went, every foreign cloud deployment in the country would suddenly need consent from each person. Second, the Act lets PRODHAB issue binding directives in the official gazette. These tell public institutions how to handle personal data. Third, a cybersecurity governance decree for government institutions was consulted on in April 2025. MICITT now calls it decree 45061. Its duties on public bodies and their suppliers are in force, but we have not read them. Fourth, a 2023 decree already imposes cybersecurity measures on 5G and higher telecommunications networks.
Sources
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad: 'Se fortalece y se crea el Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales', Decreto N. 45061-MICITT
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - non-binding public consultation on the draft Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales, opened 30 April 2025
micitt.go.cr
Link checked 19 August 2026
- Secondary sourceDelfino.crLegislative file 23.097 - Ley de Proteccion de Datos Personales (bill tracker)
delfino.cr
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Acuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion · Acuerdo CONASSIF 5-24 (version of 5 August 2024), successor to Acuerdo CONASSIF 5-17 / SUGEF 14-17. Commencement date not verified. · Directly binding regulation
Banking's rule is about disclosure, not about where data sits. Supervised financial firms may host abroad. But each year they must tell the banking supervisor which country, region and zone their cloud services sit in. They must also say where their backups are held. Financial firms supervised by the banking supervisor do not have to register their databases with the privacy regulator. That regulator still keeps full power over them.
Enforced by General Superintendency of Financial Entities
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep records of how you use dataFile an annual 'perfil tecnologico', or technology profile, with the banking supervisor through the SICVECA reporting system. The cloud fields cover the country code, the cloud region and zone, the service model and the deployment model. The database fields cover whether backups are in the cloud, and where those backups and any offline backups sit.
- Written vendor contractList your information technology providers. Give each one an importance rating that matches how important the business process it supports is.
- Secure the data
- Independent audit
Sources
- Official sourceSuperintendencia General de Entidades Financieras (SUGEF)SUGEF - Perfil Tecnologico 2026 under Acuerdo CONASSIF 5-24: reporting fields include CodPais, RegionNube, ZonaNube and UbicacionRespaldosNube
sugef.fi.cr
Link checked 19 August 2026
- Official sourceLink may be brokenConsejo Nacional de Supervision del Sistema Financiero (CONASSIF) / SUGEFAcuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion
sugef.fi.cr
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento a la Ley 8968, article 3 (SUGEF-supervised entities exempt from registration with PRODHAB)
iafa.go.cr
“Las bases de datos de entidades financieras que se encuentren sujetas al control y regulacion por parte de la Superintendencia General de Entidades Financieras (SUGEF), no requeriran inscribirse ante la Agencia de Proteccion de Datos de los Habitantes. Sin perjuicio de lo anterior, la Agencia tendra plena competencia para regular y fiscalizar la proteccion de los derechos y garantias cubiertos bajo la Ley N.° 8968.”
Link checked 19 August 2026
Telecoms rules
Official name: Ley General de Telecomunicaciones N.° 8642, articulo 42, y Decreto Ejecutivo N.° 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones) · Ley 8642 (Ley General de Telecomunicaciones), article 42; Decreto Ejecutivo 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones). Exact commencement dates not verified. · Directly binding regulation
Telecoms operators face confidentiality and deletion duties. They face no rules about where data must sit. Call and connection records and location data must be erased or made anonymous once they are no longer needed. Using traffic data for marketing needs explicit consent. Network security risks must be reported to the telecoms regulator. We found no requirement for telecoms data to be held in Costa Rica.
Enforced by Telecommunications Superintendency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataOperators of public networks and publicly available services must keep communications secret. They must protect subscribers' personal data using the technical and administrative measures the executive sets.
- Report cyber incidentsIf the operator learns of an identifiable risk to network security, it must tell the telecoms regulator and its users. The statute gives no fixed number of hours.
- Delete data after a periodTraffic and location data must be erased or made anonymous once no longer needed to carry the communication or to provide and bill the service.
- Get consentYou need the user's explicit consent before using traffic data for marketing. Users can stay out of public directories and can block caller line identification.
Sources
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)Ley General de Telecomunicaciones 8642, article 42
sutel.go.cr
“Los operadores de redes publicas y proveedores de servicios de telecomunicaciones disponibles al publico, deberan garantizar el secreto de las comunicaciones, el derecho a la intimidad y la proteccion de los datos de caracter personal de los abonados y usuarios finales, mediante la implementacion de los sistemas y las medidas tecnicas y administrativas necesarias.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - Government issues regulation on cybersecurity measures for 5G and higher telecommunications networks, signed 28 August 2023
micitt.go.cr
Link checked 19 August 2026
Cyber security rules
Official name: Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales · Decreto Ejecutivo N.° 45061-MICITT, replacing Decreto 37052. A non-binding public consultation on the draft opened on 30 April 2025; the adoption date was not verified. · Directly binding regulation
Costa Rica rebuilt its government cybersecurity rules after the 2022 ransomware emergency. A draft regulation on cybersecurity governance for government institutions went to public consultation on 30 April 2025. The ministry now calls it decree 45061. We could not read the decree text. So we have not confirmed its duties, its deadlines, or any cloud or data-location conditions on government suppliers.
Enforced by Ministry of Science, Innovation, Technology and Telecommunications
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidentsGovernment institutions report cyber incidents to MICITT. It runs a national security operations centre around the clock, plus a national computer security incident response team. We have not confirmed the deadline.
- Secure the data
Sources
- Official sourceMICITTMICITT - Ciberseguridad: 'Se fortalece y se crea el Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales', Decreto N. 45061-MICITT
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - non-binding public consultation on the draft Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales, opened 30 April 2025
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad services: CSIRT-CR / national security operations centre, 24/7 incident reporting to soc-cr@micitt.go.cr
micitt.go.cr
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley de Proteccion de la Persona frente al tratamiento de sus datos personales · Ley N.° 8968 of 7 July 2011, published in La Gaceta N.° 170 of 5 September 2011 · Act of parliament
The general privacy law. It does not require data to stay in Costa Rica. Instead it bans handing personal data to another organisation without the person's express permission. That applies at home and abroad. It sets a firm ten-year deletion limit. It makes databases run for sale or distribution register and pay an annual fee. The top fine is about 27,000 US dollars. The regulator can also suspend a database for up to six months.
Enforced by Agency for the Protection of Inhabitants' Data
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Get consentInformed, express consent is the main basis for using data. The Act has no broad legitimate-interest basis.
- Tell people what you do
- Let people see their dataFree of charge, answered within five working days.
- Let people correct their data
- Let people delete their data
- Secure the data
- Delete data after a period — 10 yearsThis is an absolute limit for data that could affect the person. Count it from the date of the recorded events. A special legal rule can override it. After that, the data must be stripped of anything linking it to the person.
- Put a transfer safeguard in placeThe person must give express, valid permission before you hand data to another organisation. That applies at home and abroad.
- Register or notify — applies at: Databases administered for the purposes of distribution, dissemination or commercialisationRegistration with PRODHAB plus a flat annual fee of 200 US dollars.
- Keep records of how you use dataYou can file handling protocols with PRODHAB. A registered protocol is taken as proof you complied, unless someone shows otherwise.
- Independent auditPRODHAB may inspect and get access to regulated databases. It does this in specific cases, and rarely, where there is evidence of widespread mismanagement.
What it costs if you get it wrong
- Fixed maximum fine: 5 salarios base (about 2.31 million colones) — about $5 thousandMinor offences: collecting data without giving the person adequate information, or handling data through insecure mechanisms
- Fixed maximum fine: 20 salarios base (about 9.24 million colones) — about $18 thousandSerious offences: processing without informed express consent, transferring in breach of the transfer chapter, purpose creep, refusing access, refusing erasure or correction
- Fixed maximum fine: 30 salarios base (about 13.87 million colones) — about $28 thousandMost serious offences: private handling of sensitive data, obtaining data by deception or threat, breaching a secrecy duty, operating an unregistered database that should be registered, or transferring Costa Ricans' or resident foreigners' data to third-country databases without consent
- Order to stop: Suspension of the file's operation for one to six monthsMost serious offences, imposed in addition to the fine
- Criminal liabilitySanctions apply 'without prejudice to the corresponding criminal sanctions'; PRODHAB must refer possible crimes to the public prosecutor
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, full consolidated text
micitt.go.cr
“Los responsables de las bases de datos, publicas o privadas, solo podran transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y validamente tal transferencia.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceProcuraduria General de la RepublicaSistema Costarricense de Informacion Juridica - consolidated text of Ley 8968
pgrweb.go.cr
Link checked 19 August 2026
- Official sourcePoder Judicial de Costa RicaPoder Judicial fixes the 'salario base' at 462,200 colones for fines and penalties from 1 January 2026 (Consejo Superior, session 113-2025 of 16 December 2025)
pj.poder-judicial.go.cr
“A partir del 1° de enero del 2026, el salario base que se debe aplicar para definir las penas por la comision de figuras delictivas ... es de ¢462.200,00.”
Link checked 19 August 2026
Breach reporting rules
Official name: Reglamento a la Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales · Decreto Ejecutivo N.° 37554-JP of 30 October 2012, amended by Decreto Ejecutivo N.° 40008-JP of 19 July 2016 and Decreto Ejecutivo N.° 41582 of 21 February 2019 · Directly binding regulation
The decree that makes the Act workable. It is the document that actually decides most questions. It applies the rules to anyone whose use of data has effects in Costa Rica. It sets a five-working-day breach notice to both the person and the regulator. It requires a matching contract on transfers. And it leaves suppliers, service providers, technology intermediaries and same-group companies out of the definition of a 'transfer'.
Enforced by Agency for the Protection of Inhabitants' Data
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Tell affected people — within 120 hoursFive WORKING days, counted from the moment the breach occurred, not from discovery.
- Report breaches to the regulator — within 120 hoursThe same minimum information must go to PRODHAB. That is what happened, which data was hit, what you fixed straight away, and where to get more information.
- Written vendor contractThe sending organisation must sign a contract with the receiving organisation. It must impose at least the same duties the sender is under.
- Secure the dataYou need a risk analysis, a calculation of leftover risk and a plan to fix problems. You must tell PRODHAB your minimum security protocols for the register. Review security measures for sensitive data at least once a year.
- Register or notify — applies at: Owners of personal databases within scopeRegistration must give the names of the databases and their PHYSICAL LOCATION. Name the person responsible and any suppliers, with contact details and letters of acceptance. Give the purposes, the data categories, the collection procedures and a technical description of your security measures. Report changes within five working days.
- Assess high-risk projectsWrite down a risk analysis. It must identify hazards and estimate the risks to personal data.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento a la Ley 8968 (Decreto 37554-JP), consolidated text with the 2016 and 2019 amendments
iafa.go.cr
“La transferencia requerira siempre el consentimiento inequivoco del titular. ... No se considera trasferencia el traslado de datos personales del responsable de una base de datos a un encargado, proveedor de servicios o intermediario tecnologico o las empresas del mismo grupo de interes economico.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The full text of Acuerdo CONASSIF 5-24, the banking technology governance regulation
We could not confirm the banking technology rules against the regulation text. The PDF on the banking supervisor's own site returned a 404 on 19 August 2026. Our evidence for the cloud country, region and backup-location reporting fields comes from the supervisor's July 2025 training deck for the 2026 technology profile. So we cannot rule out an unread condition on offshore outsourcing, such as a storage-location or prior-approval rule. We also cannot state the incident reporting deadline for banks. Ask the banking supervisor if this affects you.
The full text, exact date and obligations of Decreto 45061-MICITT on government cybersecurity governance
We could not confirm what this decree says. The ministry's own pages name it but link only to the national legal database, which blocks automated access. We know a draft went to non-binding public consultation on 30 April 2025. We know the ministry now refers to the decree as existing. We could not confirm its start date, whether it puts cloud or data-location conditions on government suppliers, or any incident reporting deadline. Check with the ministry if you supply government bodies.
The current parliamentary stage of bill 23.097, the proposed replacement data protection law
We could not confirm how far this bill has got. Parliament's own case-tracking system blocks automated access. We can show the bill exists and was formally consulted on, from the telecoms regulator's published technical opinion. We can show the 2011 Act has still not been reformed, from the data protection regulator's own site. We cannot say which committee stage it is at. We cannot say whether it survived the change of parliament on 1 May 2026.
Whether PRODHAB has issued any decision, fine or precautionary measure since 2023
We could not confirm how active the regulator has been since 2023. Its own transparency page publishes 'depersonalised resolutions' for 2018 to 2023 only. Professional and press sources report a 2025 precautionary measure against the central bank. That suggests the Agency is still deciding cases and simply not publishing them. On that basis we rate enforcement 'waking' rather than 'dormant'.
Costa Rica's general tax, accounting and anti-money-laundering record retention floors
We could not confirm Costa Rica's general tax and commercial record-keeping periods against a government source. The national legal database that hosts the Tax Procedure Code and the Commercial Code blocks automated access. We ran out of search budget before finding a government-hosted copy. These periods matter, because the ten-year deletion limit in the data protection Act gives way to any special legal rule. Check the current periods with a Costa Rican adviser.
That no sectoral where data has to be stored rule exists in health, insurance, securities, education, gambling, mapping or defence
We found no rule requiring data to stay in the country in these industries. We could not confirm that against every government source. We searched each of them and found nothing as at 19 August 2026. The health sector rules, the digital health record Act and its regulation, sit on the blocked national legal database and were not read in full. If you work in health, check before you rely on this.
The US dollar values given for the fine ceilings
We could not confirm the exchange rate used here. The base salary of 462,200 colones for 2026 is confirmed from the judiciary's own announcement. But the conversion to dollars uses a rough rate of about 505 colones to the dollar. We did not check that against the central bank on the day. Treat the dollar figures as rough.
Whether the annual 200 US dollar registration fee and the per-query fee are actually being collected today
We could not confirm that these fees are current. Both figures come from the Act itself, and the regulator's registration page describes the process. But we found no fee schedule or collection notice dated 2025 or 2026 on the regulator's site. Ask PRODHAB for the current fee before you budget for it.
Exact commencement dates for the implementing decree, the banking technology regulation and the telecoms privacy regulation
We could not confirm some start dates. The 2011 Act was published in the official gazette on 5 September 2011. Its implementing decree was signed on 30 October 2012. We could not open the gazette to confirm the decree's publication date, which is when it started. We have used 5 March 2013 as the date the Act became workable. That is the date commonly given for the decree's publication, and we could not confirm it from a government source. We did not check the start dates for Acuerdo CONASSIF 5-24 or Decreto 35205-MINAET at all, and have left them blank rather than guess.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.