Skip to the content
Global Data RulesData governance rules, country by country

Costa Rica

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Waking up

Costa Rica does not force anyone to keep data inside the country. We found no storage-in-country rule in any industry. What it does instead is gate sharing: you may only hand personal data to another organisation if the person said yes, in Costa Rica or abroad. There is also a hard rule that most personal data must be deleted or anonymised after ten years. Fines are small, but the regulator can shut a database down for up to six months.

Data governance in Costa Rica

The eight things that decide how you handle data about people in Costa Rica. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules follow the effect, not the office. If your handling of personal data has effects inside Costa Rica, the law applies even if you have no company, staff or server there. There is no size, revenue or headcount threshold to fall under. We found no general requirement to appoint a local representative, although if you have to register a database you must name a contact person who answers to the regulator and to the public.

High confidenceNational rulesPublish a complaints contact

Where the data is allowed to live

Yes, and nothing has to stay behind. We searched for storage-in-country rules in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling, mapping and defence, and found none, checked on 19 August 2026. The catch is not geography, it is consent: handing personal data to another organisation, at home or abroad, needs the person's clear permission. Moving data to your own cloud provider or your own group company is not treated as handing it over, so it does not need consent.

High confidenceYes, with paperworkApproval each timeExplicit consent

Sending data out of the country

There is no list of approved or banned countries, because Costa Rica does not use lists at all. The permission you need comes from the person, not from the government. Before data goes to another organisation you need three things: the person's clear and informed yes, a contract with the receiving organisation that puts it under the same duties you are under, and, if you had to register your database, a written handling protocol lodged with the regulator. If a complaint is made, you have to prove all of this, not the regulator.

High confidenceApproval each timeExplicit consentWritten vendor contractPut a transfer safeguard in place

The regulator, and whether it actually acts

The Agency for the Protection of Inhabitants' Data, known as PRODHAB, sits inside the Ministry of Justice and Peace. It is real and it is staffed: it has a national director, David Rodriguez Suarez, who signed its mid-year 2026 performance report on 16 July 2026, and its website was updated in August 2026. But the last decisions it published on its own transparency page are from 2023, and its maximum fine is small. It made news in 2025 by ordering the central bank to stop collecting data that had not been anonymised. Verdict: awake and willing, not yet a heavy hitter.

Medium confidenceWaking up

How long you must keep it — and when to delete it

Costa Rica is unusual: it sets a hard delete date. Personal data that could harm the person in any way must not be kept more than ten years from the date of the events recorded, unless a specific law says otherwise. If you genuinely need it longer, you must strip it of anything that identifies the person. Separately, data must be deleted as soon as it stops being relevant for the purpose you collected it for. When a specific legal duty to keep records clashes with the ten-year ceiling, the specific duty wins.

High confidenceDelete data after a periodLet people delete their data

If something goes wrong

The main clock is five working days. If personal data is lost, destroyed, mislaid or otherwise compromised, you must tell the affected people within five working days of the incident, and within the same window start a full review of how bad it is. You must also tell the regulator, giving what happened, which data was hit, what you fixed straight away, and where people can find out more. Telecoms companies have a second clock to the telecoms regulator, and government bodies report to the national cyber team.

Medium confidenceTell affected peopleReport breaches to the regulatorReport cyber incidents

What catches people out

Five things bite. One: 'transfer' has a narrow legal meaning, so sending data to your own cloud or your own group needs no consent, but selling a list to an unrelated Costa Rican company does. Two: the ten-year delete ceiling has no equivalent in most countries and it is absolute. Three: sending Costa Ricans' data abroad without consent is the most serious class of offence and can shut your database for up to six months. Four: if you run a database to sell or share data, you must register it, pay 200 US dollars a year, and disclose where the data physically sits. Five: the fines are small, but the Act keeps criminal prosecution open on top.

High confidenceRegister or notifyKeep the data in the countryDelete data after a periodCriminal liabilityOrder to stop

What's changing next

Nothing is confirmed to land in the next twelve months. A full replacement law, modelled on European rules, has been in parliament since 2022 under file number 23.097, but it had not passed as of 19 August 2026 and Costa Rica seated a new parliament on 1 May 2026. Treat it as a proposal, not a plan. The thing to actually watch is quieter: the detailed rules that make the current law workable sit in a decree the president can rewrite alone, and that decree has already been rewritten twice.

Medium confidenceProposedDraft law

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Acuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion

Directly binding regulation · Acuerdo CONASSIF 5-24 (version of 5 August 2024), successor to Acuerdo CONASSIF 5-17 / SUGEF 14-17. Commencement date not verified.

In forceYes — store it anywhere

Banking's rule is disclosure, not residency. Supervised financial entities may host abroad, but must tell the banking supervisor every year which country, region and zone their cloud services sit in and where their backups are held. Separately, financial entities supervised by the banking supervisor do not have to register their databases with the privacy regulator, though that regulator keeps full competence over them.

Enforced by General Superintendency of Financial Entities

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence
Telecoms

Ley General de Telecomunicaciones N.° 8642, articulo 42, y Decreto Ejecutivo N.° 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones)

Directly binding regulation · Ley 8642 (Ley General de Telecomunicaciones), article 42; Decreto Ejecutivo 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones). Exact commencement dates not verified.

In forceYes — store it anywhere

Telecoms operators face confidentiality and deletion duties, not storage-location duties. Call and connection records and location data must be erased or anonymised once they are no longer needed, marketing use of traffic data needs explicit consent, and network security risks must be reported to the telecoms regulator. No requirement was found for telecoms data to be held in Costa Rica.

Enforced by Telecommunications Superintendency

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence
Government

Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales

Directly binding regulation · Decreto Ejecutivo N.° 45061-MICITT, replacing Decreto 37052. A non-binding public consultation on the draft opened on 30 April 2025; the adoption date was not verified.

In forceNot yet established

Costa Rica rebuilt its government cybersecurity rules after the 2022 ransomware emergency. A draft regulation on cybersecurity governance for government institutions went to public consultation on 30 April 2025 and the ministry now refers to it as decree 45061. We could not open the decree text, so its obligations, deadlines and any cloud or data-location conditions on government suppliers are unverified.

Enforced by Ministry of Science, Innovation, Technology and Telecommunications

Transfer model: No restriction

Low confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley de Proteccion de la Persona frente al tratamiento de sus datos personales

Act of parliament · Ley N.° 8968 of 7 July 2011, published in La Gaceta N.° 170 of 5 September 2011

In forceYes, with paperwork

The general privacy law. It does not require data to stay in Costa Rica. Instead it bans handing personal data to another organisation, at home or abroad, without the person's express permission, sets a ten-year hard deletion ceiling, and makes databases run for sale or distribution register and pay an annual fee. Maximum fine about 27,000 US dollars, plus the power to suspend a database for up to six months.

In force since 5 September 2011But only enforceable from 5 March 2013

Enforced by Agency for the Protection of Inhabitants' Data

Transfer model: Approval each time · Accepted routes: Explicit consent

High confidence

Reglamento a la Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales

Directly binding regulation · Decreto Ejecutivo N.° 37554-JP of 30 October 2012, amended by Decreto Ejecutivo N.° 40008-JP of 19 July 2016 and Decreto Ejecutivo N.° 41582 of 21 February 2019

In forceYes, with paperwork

The decree that makes the Act workable, and the instrument that actually decides most questions. It applies the regime to anyone whose processing has effects in Costa Rica, sets a five-working-day breach notification to both the person and the regulator, requires a back-to-back contract on transfers, and, critically, excludes processors, service providers, technology intermediaries and same-group companies from the definition of a 'transfer'.

In force since 5 March 2013

Enforced by Agency for the Protection of Inhabitants' Data

Transfer model: Approval each time · Accepted routes: Explicit consent

High confidence

Who you would hear from

  • Agencia de Proteccion de Datos de los Habitantes (Prodhab)

    General personal data protection: register of databases, complaints, orders to delete or correct, fines, referral of possible crimes to the public prosecutor

    Staffed and running. National director David Rodriguez Suarez digitally signed the Agency's mid-year 2026 performance report on 16 July 2026; 2026 operating and financial plans are filed and a 2025-2030 strategic plan is published; the portal was last modified on 14 August 2026. However, the Agency's own published decisions stop at 2023 - the transparency page offers year tabs for 2018 through 2023 and nothing later - and the maximum fine is about 27,000 US dollars. Its most visible recent action, a 2025 precautionary measure against the central bank over non-anonymised data, is documented by professional and press sources rather than on the Agency's own site.

  • Superintendencia General de Entidades Financieras (SUGEF)

    Banks and supervised financial entities: technology governance, annual technology profile including cloud country and backup location

    Fully operational. Collects the annual technology profile through the SICVECA reporting system and ran entity training on the 2026 profile in July 2025. Note that several regulation PDFs on its site were unreachable on 19 August 2026 and parts of the normativa section returned a maintenance page.

  • Superintendencia de Telecomunicaciones (SUTEL)

    Telecoms operators: secrecy of communications, traffic and location data, network security risk reporting, end-user protection

    Active. Publishes technical opinions on legislation, including a formal opinion on the personal data protection bill, and issues binding end-user protection measures against operators.

  • Ministerio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)

    National cybersecurity policy, the national computer security incident response team, government institution cybersecurity governance, telecoms network cybersecurity

    Operational. Runs a 24/7 national security operations centre with a dedicated incident reporting mailbox, issued the 2023-2027 national cybersecurity strategy, consulted on the government cybersecurity governance regulation in April 2025 and publishes the resulting decree 45061.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The full text of Acuerdo CONASSIF 5-24, the banking technology governance regulation

    The regulation PDF on the banking supervisor's own site returned a 404 on 19 August 2026 and the normativa index renders only with JavaScript. The cloud country, region and backup-location reporting fields are evidenced from the supervisor's own July 2025 training deck for the 2026 technology profile, not from the regulation text. We therefore cannot rule out an unread residency or prior-authorisation condition on offshore outsourcing, and we cannot state the incident reporting deadline for banks.

  • The full text, exact date and obligations of Decreto 45061-MICITT on government cybersecurity governance

    The ministry's own pages name the decree but link only to the national legal database, which blocks automated fetching. We know a draft went to non-binding public consultation on 30 April 2025 and that the ministry now refers to the decree as in existence. We could not verify its commencement date, whether it imposes cloud or data-location conditions on government suppliers, or any incident reporting deadline.

  • The current parliamentary stage of bill 23.097, the proposed replacement data protection law

    Parliament's own case-tracking system is behind an anti-bot gate and could not be read. We can evidence that the bill exists and was formally consulted on, from the telecoms regulator's published technical opinion, and that the 2011 Act has still not been reformed, from the data protection regulator's own site. We cannot say which committee stage it is at, nor whether it survived the change of legislature on 1 May 2026.

  • Whether PRODHAB has issued any decision, fine or precautionary measure since 2023

    The Agency's own transparency page publishes 'depersonalised resolutions' for 2018 to 2023 only. Professional and press sources report a 2025 precautionary measure against the central bank, which suggests the Agency is still deciding cases and simply not publishing them. We cannot prove a negative and have rated enforcement 'waking' rather than 'dormant' on that basis.

  • Costa Rica's general tax, accounting and anti-money-laundering record retention floors

    The national legal database that hosts the Tax Procedure Code and the Commercial Code blocks automated fetching, and we exhausted the search budget before locating a government-hosted mirror. The ten-year deletion ceiling in the data protection Act expressly yields to any 'special legal provision', so these floors matter, but we have not verified their length against a government source.

  • That no sectoral data residency rule exists in health, insurance, securities, education, gambling, mapping or defence

    This is a searched negative, not a proven one. We searched for storage-in-country rules in each of these sectors and found none as at 19 August 2026, but the health sector rules (the digital health record Act and its regulation) sit on the blocked national legal database and were not read in full.

  • The US dollar values given for the fine ceilings

    The base salary of 462,200 colones for 2026 is confirmed from the judiciary's own announcement, but the colon-to-dollar conversion uses an approximate rate of about 505 colones to the dollar that we did not verify against the central bank on the day. Treat the dollar figures as indicative.

  • Whether the annual 200 US dollar registration fee and the per-query fee are actually being collected today

    Both figures are in the Act itself and the regulator's registration page describes the process, but we found no current fee schedule or collection notice dated 2025 or 2026 on the regulator's site.

  • Exact commencement dates for the implementing decree, the banking technology regulation and the telecoms privacy regulation

    The 2011 Act was published in the official gazette on 5 September 2011 and its implementing decree was signed on 30 October 2012, but we could not open the gazette to confirm the decree's publication date, which is when it commenced. We have used 5 March 2013 as the date the Act became operable in practice, which is the date commonly given for the decree's publication and which we could not verify from a government source. Commencement dates for Acuerdo CONASSIF 5-24 and for Decreto 35205-MINAET were not verified at all and have been left blank rather than guessed.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Costa Rica versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.