Costa Rica
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Costa Rica does not force anyone to keep data inside the country. We found no storage-in-country rule in any industry. What it does instead is gate sharing: you may only hand personal data to another organisation if the person said yes, in Costa Rica or abroad. There is also a hard rule that most personal data must be deleted or anonymised after ten years. Fines are small, but the regulator can shut a database down for up to six months.
Data governance in Costa Rica
The eight things that decide how you handle data about people in Costa Rica. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules follow the effect, not the office. If your handling of personal data has effects inside Costa Rica, the law applies even if you have no company, staff or server there. There is no size, revenue or headcount threshold to fall under. We found no general requirement to appoint a local representative, although if you have to register a database you must name a contact person who answers to the regulator and to the public.
The Act itself, at its scope article, simply covers personal data held in automated or manual databases of public or private bodies and all later use of that data. The effects test comes from the implementing regulation, whose scope article extends the regime to such data 'insofar as they produce effects within the national territory, or Costa Rican law applies to them by virtue of a contract or under international law'. Databases kept purely for internal, personal or household purposes fall outside, but only for as long as they are not sold, distributed or otherwise commercialised. A 2016 amendment also carved out data about individuals in their professional capacity where the processing serves the profession or complies with a legal duty. Registration, where required, asks for a named 'responsable' before the Agency and before third parties, with a contact address, plus the physical location of each database; the regulation does not say that person must live in Costa Rica.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 2 (scope of application)
micitt.go.cr
“Esta ley sera de aplicacion a los datos personales que figuren en bases de datos automatizadas o manuales, de organismos publicos o privados, y a toda modalidad de uso posterior de estos datos.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), article 3 (scope of application), as amended by Decreto 40008-JP
iafa.go.cr
“Este Reglamento sera de aplicacion a los datos personales que figuren en las bases de datos automatizadas o manuales, de organismos publicos o privados, y a toda modalidad de uso posterior de estos datos, en tanto surtan efectos dentro del territorio nacional, o les resulte aplicable la legislacion costarricense derivada de la celebracion de un contrato o en los terminos del derecho internacional.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
Where the data is allowed to live
Yes, and nothing has to stay behind. We searched for storage-in-country rules in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling, mapping and defence, and found none, checked on 19 August 2026. The catch is not geography, it is consent: handing personal data to another organisation, at home or abroad, needs the person's clear permission. Moving data to your own cloud provider or your own group company is not treated as handing it over, so it does not need consent.
Rated conditional, not open, because the general rule is a consent gate rather than a free flow. The Act's transfer chapter has a single article: controllers of public or private databases 'may only transfer data contained in them where the holder of the right has expressly and validly authorised that transfer'. The implementing regulation then defines the word narrowly. A 'transfer' is a handover from one controller to a receiving controller. It expressly does not cover moving data from a controller to a processor, a service provider, a technology intermediary, or to companies in the same economic-interest group. The definitions article reinforces this: a database shared inside one economic-interest group, 'local or with an international presence', stays an 'internal database' as long as nothing is disseminated, distributed or sold to third parties. In practice that means hosting Costa Rican customer data in a foreign cloud region, or replicating it to a parent company overseas, sits outside the consent gate; selling a marketing list to an unrelated company, even one down the street in San Jose, sits inside it. SECTOR OVERRIDES, all of which add duties rather than walls. Banking and finance: no residency rule, but under the technology governance regulation supervised entities must file an annual technology profile that reports, for each cloud service, the country code, cloud region and zone, the service and deployment model, and the location of cloud and offline backups. Telecoms: no residency rule, but traffic and location data must be deleted or made anonymous once they are no longer needed to carry the communication or provide the service, and identified network security risks must be reported to the telecoms regulator. Government: no residency rule found; a cybersecurity governance decree for government institutions exists but we could not open its text. Health, insurance, securities, education, gambling, mapping and defence: no residency or transfer-specific rule found, checked 19 August 2026, medium confidence. Costa Rica notably does not license online gambling at all, so there is no gambling data regulator to impose one.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 14 (transfer of personal data, general rule)
micitt.go.cr
“Los responsables de las bases de datos, publicas o privadas, solo podran transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y validamente tal transferencia y se haga sin vulnerar los principios y derechos reconocidos en esta ley.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), article 40 (conditions for transfer), as amended by Decreto 40008-JP
iafa.go.cr
“No se considera trasferencia el traslado de datos personales del responsable de una base de datos a un encargado, proveedor de servicios o intermediario tecnologico o las empresas del mismo grupo de interes economico.”
Link checked 19 August 2026
- Official sourceSuperintendencia General de Entidades Financieras (SUGEF)SUGEF - Perfil Tecnologico 2026 under Acuerdo CONASSIF 5-24: reporting fields include CodPais, RegionNube, ZonaNube and UbicacionRespaldosNube
sugef.fi.cr
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Secondary sourceDLA PiperData protection laws in Costa Rica
dlapiperdataprotection.com
Link checked 19 August 2026
Sending data out of the country
There is no list of approved or banned countries, because Costa Rica does not use lists at all. The permission you need comes from the person, not from the government. Before data goes to another organisation you need three things: the person's clear and informed yes, a contract with the receiving organisation that puts it under the same duties you are under, and, if you had to register your database, a written handling protocol lodged with the regulator. If a complaint is made, you have to prove all of this, not the regulator.
The model is case-by-case, but the case is decided by the data subject rather than by an official. There is no adequacy list, no blocklist, no allowlist and no government-published standard contractual clauses. Because there are no lists, the question of whether a list is populated does not arise, and there is no dormant list power in the Act that could be switched on by notification. The regulation adds three operational requirements around the consent. Its article 43 requires the exporting controller to conclude a contract with the receiving controller providing for at least the same obligations the exporter is subject to. Its article 41 makes transfers conditional on faithful compliance with the minimum handling protocols registered with the Agency. Its article 42 places the burden of proof squarely on the controller to show the transfer complied with the Act and the regulation. Under the Act, a registered handling protocol creates a rebuttable presumption of compliance, which is the closest thing Costa Rica has to a safe harbour. Remember the carve-out in question two: none of this bites where the recipient is your processor, service provider, technology intermediary or a company in your own economic-interest group.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 40 to 43 (conditions, protocols, burden of proof, transfer contract)
iafa.go.cr
“Articulo 43. Contrato para la transferencia de datos. El responsable de la transferencia de datos personales debera establecer un contrato con el responsable receptor, en el que se prevean, al menos las mismas obligaciones a las que se encuentra sujeto el responsable de la transferencia de dichos datos.”
Link checked 19 August 2026
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 12 and 14 (handling protocols and the transfer rule)
micitt.go.cr
“La manipulacion de datos con base en un protocolo de actuacion inscrito ante la Prodhab hara presumir, 'iuris tantum', el cumplimiento de las disposiciones contenidas en esta ley, para los efectos de autorizar la cesion de los datos contenidos en una base.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
The regulator, and whether it actually acts
The Agency for the Protection of Inhabitants' Data, known as PRODHAB, sits inside the Ministry of Justice and Peace. It is real and it is staffed: it has a national director, David Rodriguez Suarez, who signed its mid-year 2026 performance report on 16 July 2026, and its website was updated in August 2026. But the last decisions it published on its own transparency page are from 2023, and its maximum fine is small. It made news in 2025 by ordering the central bank to stop collecting data that had not been anonymised. Verdict: awake and willing, not yet a heavy hitter.
PRODHAB was created by the Act as a body with maximum administrative autonomy attached to the Ministry of Justice and Peace, with its own legal personality for managing its budget and contracts, and independence of judgement. Its powers include keeping the register of databases, demanding information and protocols, accessing regulated databases, deciding complaints, ordering deletion, correction or restriction of data, imposing the Act's fines, and referring anything that might be a crime to the public prosecutor. Evidence it is operational: a named director signing 2026 planning documents; 2026 operating and financial plans filed with the budget authority; a strategic plan running 2025 to 2030; site last modified 14 August 2026. Evidence it is not yet aggressive: the published 'depersonalised resolutions' tabs on its own transparency page run 2018, 2019, 2020, 2021, 2022 and 2023 and stop there, so no decision from 2024, 2025 or 2026 is publicly available from the Agency itself; and the fine ceiling is roughly 27,000 US dollars. The one visible 2025 action, a precautionary measure restraining the Banco Central de Costa Rica from requiring non-anonymised data, is reported by professional and press sources rather than published by the Agency. Sector regulators are separately and clearly active: the banking supervisor collects annual technology profiles, and the telecoms regulator issues binding consumer-protection measures. Rated waking rather than active because the Agency's own public record of decisions has not moved for over two years.
Sources
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Informe de Seguimiento Semestral, Plan Operativo Institucional 2026, signed by director David Rodriguez Suarez on 16 July 2026
prodhab.go.cr
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Resoluciones Despersonalizadas (year tabs run 2018 to 2023 only)
prodhab.go.cr
Link checked 19 August 2026
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 15 to 17 (creation, powers and direction of PRODHAB)
micitt.go.cr
“Son atribuciones de la Prodhab ... g) Imponer las sanciones establecidas, en el articulo 28 de esta ley, a las personas fisicas o juridicas, publicas o privadas, que infrinjan las normas sobre proteccion de los datos personales, y dar traslado al Ministerio Publico de las que puedan configurar delito.”
Link checked 19 August 2026
- Secondary sourceInternational Association of Privacy ProfessionalsMedida cautelar: un precedente importante establecido por la Agencia de Proteccion de Datos en Costa Rica
iapp.org
Link checked 19 August 2026
How long you must keep it — and when to delete it
Costa Rica is unusual: it sets a hard delete date. Personal data that could harm the person in any way must not be kept more than ten years from the date of the events recorded, unless a specific law says otherwise. If you genuinely need it longer, you must strip it of anything that identifies the person. Separately, data must be deleted as soon as it stops being relevant for the purpose you collected it for. When a specific legal duty to keep records clashes with the ten-year ceiling, the specific duty wins.
The ceiling sits in the data-quality article of the Act, under the heading of keeping data current. Two duties run in parallel: a general one to erase data that has stopped being relevant or necessary for the purpose it was collected for, and the absolute ten-year cut-off for data capable of affecting the person, counted from the date the recorded events occurred. The conflict rule is written into the same sentence: the ceiling applies 'unless a special legal provision provides otherwise'. So a tax, accounting, anti-money-laundering or health record-keeping duty with its own period displaces the ten-year rule for the records it covers, and the safe reading is to keep only what the specific duty requires and dissociate or delete the rest. In telecoms the direction is the opposite of a floor: the sector rules require operators to erase or anonymise traffic and location data once they are no longer needed to carry the communication or to provide and bill the service. We did not verify Costa Rica's general tax and commercial record-keeping floors against a government source in this pass; see the unconfirmed list.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, article 6.1 (currency of data - the ten-year ceiling)
micitt.go.cr
“En ningun caso, seran conservados los datos personales que puedan afectar, de cualquier modo, a su titular, una vez transcurridos diez anos desde la fecha de ocurrencia de los hechos registrados, salvo disposicion normativa especial que disponga otra cosa. En caso de que sea necesaria su conservacion, mas alla del plazo estipulado, deberan ser desasociados de su titular.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
If something goes wrong
The main clock is five working days. If personal data is lost, destroyed, mislaid or otherwise compromised, you must tell the affected people within five working days of the incident, and within the same window start a full review of how bad it is. You must also tell the regulator, giving what happened, which data was hit, what you fixed straight away, and where people can find out more. Telecoms companies have a second clock to the telecoms regulator, and government bodies report to the national cyber team.
Clock one, everyone: the regulation's article 38 gives five working days from the moment the breach occurred to inform the data subject about any irregularity in the handling or storage of their data, such as loss, destruction or misplacement, resulting from a security failure, so that affected people can protect themselves. The same five-day window triggers a duty to begin an exhaustive review of the scale of the damage and the corrective and preventive measures needed. Article 39 sets the minimum content and, importantly, requires that content to go to the data subject AND to the Agency. Note the clock starts when the breach happened, not when you found out, which is stricter than the discovery-based clocks used in Europe and much of Asia. Clock two, telecoms: operators of public networks and publicly available services must inform the telecoms regulator and users where the operator becomes aware of an identifiable risk to network security. No fixed hour count is given in the statute. Clock three, government: MICITT runs a 24/7 national security operations centre and a national computer security incident response team for central government institutions, with a dedicated incident reporting mailbox, and a cybersecurity governance decree for government institutions. We could not open that decree's text, so any deadline in it is unverified. Clock four, banks: supervised financial entities report operational and technology incidents to the banking supervisor under the technology governance regulation; we could not open that text either and have not verified a deadline. The overlap that hurts is clock one against clock four: a payments outage at a bank is simultaneously a supervisory incident and, if customer data moved, a five-working-day notification to customers and to PRODHAB.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 38 and 39 (security breach and minimum information)
iafa.go.cr
“El responsable debera informar al titular sobre cualquier irregularidad en el tratamiento o almacenamiento de sus datos, tales como perdida, destruccion, extravio, entre otras, como consecuencia de una vulnerabilidad de la seguridad o que tuviere conocimiento del hecho, para lo cual tendra cinco dias habiles a partir del momento en que ocurrio la vulnerabilidad.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)Ley General de Telecomunicaciones 8642, article 42 (privacy of communications and personal data protection)
sutel.go.cr
“En caso de que el operador conozca un riesgo identificable en la seguridad de la red, debera informar a la Sutel y a”
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad services: CSIRT-CR / national security operations centre, 24/7 incident reporting to soc-cr@micitt.go.cr
micitt.go.cr
Link checked 19 August 2026
What catches people out
Five things bite. One: 'transfer' has a narrow legal meaning, so sending data to your own cloud or your own group needs no consent, but selling a list to an unrelated Costa Rican company does. Two: the ten-year delete ceiling has no equivalent in most countries and it is absolute. Three: sending Costa Ricans' data abroad without consent is the most serious class of offence and can shut your database for up to six months. Four: if you run a database to sell or share data, you must register it, pay 200 US dollars a year, and disclose where the data physically sits. Five: the fines are small, but the Act keeps criminal prosecution open on top.
1. THE TRANSFER CARVE-OUT CUTS BOTH WAYS. Because processors, service providers, technology intermediaries and same-group companies are excluded from the definition of transfer, international cloud hosting is easy. But the Act does not distinguish domestic from cross-border in its general rule, so a purely domestic handover to an unrelated controller needs the same express consent as an export. Teams that build their consent flow around 'international transfer' language miss the domestic half. 2. TEN YEARS IS A HARD STOP. Data capable of affecting the person must be gone, or dissociated from the person, ten years after the recorded events, unless a specific legal rule says keep it. Retention schedules imported from Europe or the United States will breach this. 3. EXPORT WITHOUT CONSENT IS A 'FALTA GRAVISIMA'. Article 31 lists, as the most serious class of offence, transferring to third-country databases the personal data of Costa Ricans or of foreigners resident in the country without their holders' consent. The sanction for that class is 15 to 30 base salaries plus suspension of the file's operation for one to six months. The suspension, not the fine, is the commercial threat. 4. REGISTRATION, THE FEE AND THE LOCATION DISCLOSURE. Any database, public or private, run for the purposes of distribution, dissemination or commercialisation must be entered on PRODHAB's register, and the registration form asks for the names of the databases and their physical location, the categories of data, the collection procedures and a technical description of the security measures. There is a flat annual fee of 200 US dollars, plus a per-query fee of between 25 US cents and 1 US dollar on commercial sales of individualised records, capped at ten per cent of the contract price. Processing without being registered when you should be is itself a most serious offence. Financial entities supervised by the banking supervisor are exempt from registering, but PRODHAB keeps full competence over them, which is a distinction people routinely get backwards. 5. SMALL FINES, REAL CRIMINAL TAIL. The maximum administrative fine is 30 base salaries. The base salary for 2026 was fixed at 462,200 colones, so the ceiling is about 13.9 million colones, roughly 27,000 US dollars. But the sanctions article opens with the words 'without prejudice to the corresponding criminal sanctions', and PRODHAB is required to refer anything that might be a crime to the public prosecutor. 6. BONUS TRAP: the breach clock runs from when the breach happened, not from when you discovered it.
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, articles 21, 28, 31 and 33 (registration, sanctions, most serious offences, annual fee)
micitt.go.cr
“f) Transferir, a las bases de datos de terceros paises, informacion de caracter personal de los costarricenses o de los extranjeros radicados en el pais, sin el consentimiento de sus titulares.”
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento (Decreto 37554-JP), articles 3, 40 and 44 (SUGEF exemption from registration, transfer carve-out, registration content)
iafa.go.cr
“Las bases de datos de entidades financieras que se encuentren sujetas al control y regulacion por parte de la Superintendencia General de Entidades Financieras (SUGEF), no requeriran inscribirse ante la Agencia de Proteccion de Datos de los Habitantes.”
Link checked 19 August 2026
- Official sourcePoder Judicial de Costa RicaPoder Judicial fixes the 'salario base' at 462,200 colones for fines and penalties from 1 January 2026 (Consejo Superior, session 113-2025 of 16 December 2025)
pj.poder-judicial.go.cr
“A partir del 1° de enero del 2026, el salario base que se debe aplicar para definir las penas por la comision de figuras delictivas ... es de ¢462.200,00.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
What's changing next
Nothing is confirmed to land in the next twelve months. A full replacement law, modelled on European rules, has been in parliament since 2022 under file number 23.097, but it had not passed as of 19 August 2026 and Costa Rica seated a new parliament on 1 May 2026. Treat it as a proposal, not a plan. The thing to actually watch is quieter: the detailed rules that make the current law workable sit in a decree the president can rewrite alone, and that decree has already been rewritten twice.
PENDING LEGISLATION. Legislative file 23.097, 'Ley de Proteccion de Datos Personales', would replace the 2011 Act with a European-style regime: lawful bases beyond consent, data protection officers, formal international transfer mechanisms, and a stronger regulator. The telecoms regulator filed a formal technical opinion on it, which is our government evidence that the file exists and was consulted on. As of today PRODHAB's own website still states that the Act has never been reformed, so the bill has not become law. We could not read the parliament's own case-tracking system, which blocks automated access, so the bill's current committee stage is unverified. Do not plan around it. DORMANT SWITCHES, which matter more. First and most important: almost everything that makes Costa Rica permissive lives in the implementing decree, not the Act. The exclusion of processors, service providers, technology intermediaries and same-group companies from the definition of 'transfer', the treatment of internationally shared group databases as merely 'internal', and the exemption of bank databases from registration were all inserted by executive decree in 2016. A president and a minister can narrow any of them by signing another decree, with no parliamentary vote and no consultation requirement. If that carve-out were removed, every foreign cloud deployment in the country would suddenly need per-person consent. Second: the Act empowers PRODHAB to issue binding directives, published in the official gazette, telling public institutions how to handle personal data. Third: a cybersecurity governance decree for government institutions was consulted on in April 2025 and MICITT now refers to it as decree 45061; its obligations on public bodies and their suppliers are in force but we have not read them. Fourth: a 2023 decree already imposes cybersecurity measures on 5G and higher telecommunications networks.
Sources
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad: 'Se fortalece y se crea el Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales', Decreto N. 45061-MICITT
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - non-binding public consultation on the draft Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales, opened 30 April 2025
micitt.go.cr
Link checked 19 August 2026
- Secondary sourceDelfino.crLegislative file 23.097 - Ley de Proteccion de Datos Personales (bill tracker)
delfino.cr
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Acuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion
Directly binding regulation · Acuerdo CONASSIF 5-24 (version of 5 August 2024), successor to Acuerdo CONASSIF 5-17 / SUGEF 14-17. Commencement date not verified.
Banking's rule is disclosure, not residency. Supervised financial entities may host abroad, but must tell the banking supervisor every year which country, region and zone their cloud services sit in and where their backups are held. Separately, financial entities supervised by the banking supervisor do not have to register their databases with the privacy regulator, though that regulator keeps full competence over them.
Enforced by General Superintendency of Financial Entities
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep records of processingAnnual 'perfil tecnologico' filed with the banking supervisor through the SICVECA reporting system. Cloud reporting fields include the country code, cloud region and zone, service model and deployment model; database fields include whether backups are in the cloud and where those backups and offline backups are located.
- Written vendor contractInformation technology providers must be listed with a criticality rating tied to the criticality of the business process they support.
- Secure the data
- Independent audit
Sources
- Official sourceSuperintendencia General de Entidades Financieras (SUGEF)SUGEF - Perfil Tecnologico 2026 under Acuerdo CONASSIF 5-24: reporting fields include CodPais, RegionNube, ZonaNube and UbicacionRespaldosNube
sugef.fi.cr
Link checked 19 August 2026
- Official sourceLink may be brokenConsejo Nacional de Supervision del Sistema Financiero (CONASSIF) / SUGEFAcuerdo CONASSIF 5-24, Reglamento General de Gobierno y Gestion de la Tecnologia de Informacion
sugef.fi.cr
Link checked 19 August 2026
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento a la Ley 8968, article 3 (SUGEF-supervised entities exempt from registration with PRODHAB)
iafa.go.cr
“Las bases de datos de entidades financieras que se encuentren sujetas al control y regulacion por parte de la Superintendencia General de Entidades Financieras (SUGEF), no requeriran inscribirse ante la Agencia de Proteccion de Datos de los Habitantes. Sin perjuicio de lo anterior, la Agencia tendra plena competencia para regular y fiscalizar la proteccion de los derechos y garantias cubiertos bajo la Ley N.° 8968.”
Link checked 19 August 2026
Ley General de Telecomunicaciones N.° 8642, articulo 42, y Decreto Ejecutivo N.° 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones)
Directly binding regulation · Ley 8642 (Ley General de Telecomunicaciones), article 42; Decreto Ejecutivo 35205-MINAET (Reglamento sobre medidas de proteccion de la privacidad de las comunicaciones). Exact commencement dates not verified.
Telecoms operators face confidentiality and deletion duties, not storage-location duties. Call and connection records and location data must be erased or anonymised once they are no longer needed, marketing use of traffic data needs explicit consent, and network security risks must be reported to the telecoms regulator. No requirement was found for telecoms data to be held in Costa Rica.
Enforced by Telecommunications Superintendency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataOperators of public networks and publicly available services must guarantee the secrecy of communications and protect subscribers' personal data through technical and administrative measures set by the executive.
- Report cyber incidentsWhere the operator becomes aware of an identifiable risk to network security it must inform the telecoms regulator and users. No fixed hour count in the statute.
- Delete data after a periodTraffic and location data must be erased or made anonymous once no longer needed to carry the communication or to provide and bill the service.
- Get consentExplicit user consent required before traffic data is used for marketing. Users may be excluded from public directories and may block caller line identification.
Sources
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)Ley General de Telecomunicaciones 8642, article 42
sutel.go.cr
“Los operadores de redes publicas y proveedores de servicios de telecomunicaciones disponibles al publico, deberan garantizar el secreto de las comunicaciones, el derecho a la intimidad y la proteccion de los datos de caracter personal de los abonados y usuarios finales, mediante la implementacion de los sistemas y las medidas tecnicas y administrativas necesarias.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Telecomunicaciones (SUTEL)SUTEL technical opinion 07296-SUTEL-ACS-2022 on the personal data protection bill (file 23.097), describing operators' duties under Decreto 35205-MINAET
sutel.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - Government issues regulation on cybersecurity measures for 5G and higher telecommunications networks, signed 28 August 2023
micitt.go.cr
Link checked 19 August 2026
Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales
Directly binding regulation · Decreto Ejecutivo N.° 45061-MICITT, replacing Decreto 37052. A non-binding public consultation on the draft opened on 30 April 2025; the adoption date was not verified.
Costa Rica rebuilt its government cybersecurity rules after the 2022 ransomware emergency. A draft regulation on cybersecurity governance for government institutions went to public consultation on 30 April 2025 and the ministry now refers to it as decree 45061. We could not open the decree text, so its obligations, deadlines and any cloud or data-location conditions on government suppliers are unverified.
Enforced by Ministry of Science, Innovation, Technology and Telecommunications
Transfer model: No restriction
What it makes you do
- Report cyber incidentsGovernment institutions report cyber incidents to MICITT's 24/7 national security operations centre and national computer security incident response team. Deadline not verified.
- Secure the data
Sources
- Official sourceMICITTMICITT - Ciberseguridad: 'Se fortalece y se crea el Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales', Decreto N. 45061-MICITT
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - non-binding public consultation on the draft Reglamento para la Gobernanza en Ciberseguridad y la Resiliencia Cibernetica de las Instituciones Gubernamentales, opened 30 April 2025
micitt.go.cr
Link checked 19 August 2026
- Official sourceMICITTMICITT - Ciberseguridad services: CSIRT-CR / national security operations centre, 24/7 incident reporting to soc-cr@micitt.go.cr
micitt.go.cr
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley de Proteccion de la Persona frente al tratamiento de sus datos personales
Act of parliament · Ley N.° 8968 of 7 July 2011, published in La Gaceta N.° 170 of 5 September 2011
The general privacy law. It does not require data to stay in Costa Rica. Instead it bans handing personal data to another organisation, at home or abroad, without the person's express permission, sets a ten-year hard deletion ceiling, and makes databases run for sale or distribution register and pay an annual fee. Maximum fine about 27,000 US dollars, plus the power to suspend a database for up to six months.
Enforced by Agency for the Protection of Inhabitants' Data
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Get consentInformed, express consent is the backbone of the regime; the Act has no broad legitimate-interest basis.
- Tell people what you do
- Let people see their dataFree of charge, answered within five working days.
- Let people correct their data
- Let people delete their data
- Secure the data
- Delete data after a period — 10 yearsAbsolute ceiling for data capable of affecting the person, counted from the date of the recorded events, unless a special legal rule provides otherwise. Beyond that the data must be dissociated from the person.
- Put a transfer safeguard in placeExpress and valid authorisation by the data subject before any handover to another controller, domestic or foreign.
- Register or notify — applies at: Databases administered for the purposes of distribution, dissemination or commercialisationRegistration with PRODHAB plus a flat annual fee of 200 US dollars.
- Keep records of processingHandling protocols may be lodged with PRODHAB; a registered protocol creates a rebuttable presumption of compliance.
- Independent auditPRODHAB may inspect and access regulated databases, in specific cases and exceptionally where there is evidence of widespread mismanagement.
What it costs if you get it wrong
- Fixed maximum fine: 5 salarios base (about 2.31 million colones) — about $5 thousandMinor offences: collecting data without giving the person adequate information, or handling data through insecure mechanisms
- Fixed maximum fine: 20 salarios base (about 9.24 million colones) — about $18 thousandSerious offences: processing without informed express consent, transferring in breach of the transfer chapter, purpose creep, refusing access, refusing erasure or correction
- Fixed maximum fine: 30 salarios base (about 13.87 million colones) — about $28 thousandMost serious offences: private handling of sensitive data, obtaining data by deception or threat, breaching a secrecy duty, operating an unregistered database that should be registered, or transferring Costa Ricans' or resident foreigners' data to third-country databases without consent
- Order to stop: Suspension of the file's operation for one to six monthsMost serious offences, imposed in addition to the fine
- Criminal liabilitySanctions apply 'without prejudice to the corresponding criminal sanctions'; PRODHAB must refer possible crimes to the public prosecutor
Sources
- Official sourceMinisterio de Ciencia, Innovacion, Tecnologia y Telecomunicaciones (MICITT)Ley 8968, full consolidated text
micitt.go.cr
“Los responsables de las bases de datos, publicas o privadas, solo podran transferir datos contenidos en ellas cuando el titular del derecho haya autorizado expresa y validamente tal transferencia.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceProcuraduria General de la RepublicaSistema Costarricense de Informacion Juridica - consolidated text of Ley 8968
pgrweb.go.cr
Link checked 19 August 2026
- Official sourcePoder Judicial de Costa RicaPoder Judicial fixes the 'salario base' at 462,200 colones for fines and penalties from 1 January 2026 (Consejo Superior, session 113-2025 of 16 December 2025)
pj.poder-judicial.go.cr
“A partir del 1° de enero del 2026, el salario base que se debe aplicar para definir las penas por la comision de figuras delictivas ... es de ¢462.200,00.”
Link checked 19 August 2026
Reglamento a la Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales
Directly binding regulation · Decreto Ejecutivo N.° 37554-JP of 30 October 2012, amended by Decreto Ejecutivo N.° 40008-JP of 19 July 2016 and Decreto Ejecutivo N.° 41582 of 21 February 2019
The decree that makes the Act workable, and the instrument that actually decides most questions. It applies the regime to anyone whose processing has effects in Costa Rica, sets a five-working-day breach notification to both the person and the regulator, requires a back-to-back contract on transfers, and, critically, excludes processors, service providers, technology intermediaries and same-group companies from the definition of a 'transfer'.
Enforced by Agency for the Protection of Inhabitants' Data
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Tell affected people — within 120 hoursFive WORKING days, counted from the moment the breach occurred, not from discovery.
- Report breaches to the regulator — within 120 hoursThe same minimum information must go to PRODHAB: nature of the incident, data compromised, immediate corrective action, and where to get more information.
- Written vendor contractThe exporting controller must sign a contract with the receiving controller imposing at least the same obligations the exporter is under.
- Secure the dataRisk analysis, residual-risk calculation and a remediation work plan; minimum security protocols must be notified to PRODHAB for the register. Security measures for sensitive data must be reviewed at least annually.
- Register or notify — applies at: Owners of personal databases within scopeRegistration must state the names of the databases and their PHYSICAL LOCATION, the responsible person and processors with contact details and letters of acceptance, purposes, data categories, collection procedures and a technical description of security measures. Changes must be notified within five working days.
- Assess high-risk projectsA documented risk analysis identifying hazards and estimating risks to personal data.
Sources
- Official sourceInstituto sobre Alcoholismo y Farmacodependencia (official copy of Decreto Ejecutivo 37554-JP as amended)Reglamento a la Ley 8968 (Decreto 37554-JP), consolidated text with the 2016 and 2019 amendments
iafa.go.cr
“La transferencia requerira siempre el consentimiento inequivoco del titular. ... No se considera trasferencia el traslado de datos personales del responsable de una base de datos a un encargado, proveedor de servicios o intermediario tecnologico o las empresas del mismo grupo de interes economico.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Normativa: 'Al dia de hoy, la Ley no ha sufrido ninguna reforma'
prodhab.go.cr
“Al dia de hoy, la Ley no ha sufrido ninguna reforma, mientras que los decretos ejecutivos N.° 40008-JP, en 2016 y N.° 41582 en 2019, modificaron algunos articulos del Reglamento.”
Link checked 19 August 2026
- Official sourceAgencia de Proteccion de Datos de los HabitantesPRODHAB - Tramites y Servicios: how to register a database, including the physical location of the database
prodhab.go.cr
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The full text of Acuerdo CONASSIF 5-24, the banking technology governance regulation
The regulation PDF on the banking supervisor's own site returned a 404 on 19 August 2026 and the normativa index renders only with JavaScript. The cloud country, region and backup-location reporting fields are evidenced from the supervisor's own July 2025 training deck for the 2026 technology profile, not from the regulation text. We therefore cannot rule out an unread residency or prior-authorisation condition on offshore outsourcing, and we cannot state the incident reporting deadline for banks.
The full text, exact date and obligations of Decreto 45061-MICITT on government cybersecurity governance
The ministry's own pages name the decree but link only to the national legal database, which blocks automated fetching. We know a draft went to non-binding public consultation on 30 April 2025 and that the ministry now refers to the decree as in existence. We could not verify its commencement date, whether it imposes cloud or data-location conditions on government suppliers, or any incident reporting deadline.
The current parliamentary stage of bill 23.097, the proposed replacement data protection law
Parliament's own case-tracking system is behind an anti-bot gate and could not be read. We can evidence that the bill exists and was formally consulted on, from the telecoms regulator's published technical opinion, and that the 2011 Act has still not been reformed, from the data protection regulator's own site. We cannot say which committee stage it is at, nor whether it survived the change of legislature on 1 May 2026.
Whether PRODHAB has issued any decision, fine or precautionary measure since 2023
The Agency's own transparency page publishes 'depersonalised resolutions' for 2018 to 2023 only. Professional and press sources report a 2025 precautionary measure against the central bank, which suggests the Agency is still deciding cases and simply not publishing them. We cannot prove a negative and have rated enforcement 'waking' rather than 'dormant' on that basis.
Costa Rica's general tax, accounting and anti-money-laundering record retention floors
The national legal database that hosts the Tax Procedure Code and the Commercial Code blocks automated fetching, and we exhausted the search budget before locating a government-hosted mirror. The ten-year deletion ceiling in the data protection Act expressly yields to any 'special legal provision', so these floors matter, but we have not verified their length against a government source.
That no sectoral data residency rule exists in health, insurance, securities, education, gambling, mapping or defence
This is a searched negative, not a proven one. We searched for storage-in-country rules in each of these sectors and found none as at 19 August 2026, but the health sector rules (the digital health record Act and its regulation) sit on the blocked national legal database and were not read in full.
The US dollar values given for the fine ceilings
The base salary of 462,200 colones for 2026 is confirmed from the judiciary's own announcement, but the colon-to-dollar conversion uses an approximate rate of about 505 colones to the dollar that we did not verify against the central bank on the day. Treat the dollar figures as indicative.
Whether the annual 200 US dollar registration fee and the per-query fee are actually being collected today
Both figures are in the Act itself and the regulator's registration page describes the process, but we found no current fee schedule or collection notice dated 2025 or 2026 on the regulator's site.
Exact commencement dates for the implementing decree, the banking technology regulation and the telecoms privacy regulation
The 2011 Act was published in the official gazette on 5 September 2011 and its implementing decree was signed on 30 October 2012, but we could not open the gazette to confirm the decree's publication date, which is when it commenced. We have used 5 March 2013 as the date the Act became operable in practice, which is the date commonly given for the decree's publication and which we could not verify from a government source. Commencement dates for Acuerdo CONASSIF 5-24 and for Decreto 35205-MINAET were not verified at all and have been left blank rather than guessed.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Costa Rica versus
Compare