Skip to the content
Global Data RulesData governance rules, country by country

Dominican Republic

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Dormant

The Dominican Republic has had a personal data law since December 2013, and it never got a regulator. Data may leave the country whenever one of nine reasons in the law applies, and consent is the easy one. There is no list of banned countries, no filing, no registration and no breach report to send. But breaking the law is a crime, not a paperwork slip, and the money-laundering and tax rules make you keep records for ten years.

Data governance in Dominican Republic

The eight things that decide how you handle data about people in Dominican Republic. Same eight on every country page, so you can compare.

Who has to follow these rules

The law says it applies throughout the national territory. It does not say it follows Dominicans' data abroad, and it does not ask a foreign company to appoint anyone locally. There is no size or revenue threshold, and no register to join. If you have no office, no staff and no equipment in the country, there is no authority with power to fine you, but a Dominican judge can still hear a claim from a person here and a prosecutor can still act if the conduct is a crime.

High confidenceNational rules

Where the data is allowed to live

Yes, but only for one of nine reasons written into the law. The first is that the person freely decided to allow it, which is how almost everyone does it. The others cover medical care and epidemics, bank and stock market transactions, treaties and free trade agreements, crime-fighting cooperation, performing a contract with the person, legal claims and tax or customs demands, international judicial assistance, and requests from an international body drawing on a public register. There is no list of banned countries and no list of approved ones. We searched banking, payments, insurance, securities, health, telecommunications, government cloud, education, gambling and mapping and found no rule ordering personal data to stay in the country. The one storage rule we did find is narrow: records showing who really owns a company must be kept inside the Dominican Republic.

High confidenceYes, with paperworkNo restrictionExplicit consentNeeded for a contractLegal claimsImportant public interest

Sending data out of the country

There is nothing to sign with the government and nobody to ask. No approval, no standard contract, no registration, no adequacy list. You only need to be able to show that one of the nine reasons in the law applied when the data moved, and in ordinary business that means a consent that was free, informed and unambiguous. Because no authority polices this, the person who checks your homework is a judge, and only after someone complains.

High confidenceNo restrictionExplicit consentPut a transfer safeguard in placeExtra vendor secrecy terms

The regulator, and whether it actually acts

Nobody, in the way most countries mean it. The Dominican Republic has no data protection authority. The only body the law gives fining power to is the Superintendency of Banks, and only over credit reference companies. Everyone else is policed by criminal prosecutors, by the high-technology crime police unit, and by ordinary judges hearing claims brought by individuals. The Constitutional Court was issuing rulings as recently as the seventeenth of August 2026, so the court route is real. The sector regulators are genuinely working: the Superintendency of Banks published circulars throughout 2026, and the National Cybersecurity Centre was signing cooperation agreements in July 2026.

High confidenceDormant

How long you must keep it — and when to delete it

The floors are much stronger than the ceilings. Businesses covered by the money-laundering rules must keep transaction records, customer checks, account files and business correspondence for at least ten years after the relationship ends. Tax and accounting records also run ten years. Internet and telephone providers must keep traffic, connection and access records for at least ninety days. Anyone who runs a credit check must keep the customer's written permission for six months. Going the other way, the only real deletion rule is that a credit history may not report events older than forty-eight months, and that inaccurate or incomplete data must be corrected or removed. If a keep-it rule and a delete-it rule collide, the keep-it rule wins, because the law says the right to have data erased does not apply where another law requires it to be kept.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsKeep records of processing

If something goes wrong

There is no general duty to report a data breach. The 2013 law does not contain one, so a private company that loses customer data owes no report to any authority and no notice to the people affected. Two narrower clocks do exist. Government bodies must report a cybersecurity incident immediately, and the report must reach the national cyber team or the sector team within twenty-four hours of detection. Banks and payment system participants must run a documented incident process and answer to the financial sector's own incident response team, but the regulation sets no fixed number of hours. Everyone can also report voluntarily to the National Cybersecurity Centre, which runs a public reporting page.

High confidenceReport cyber incidentsSecure the data

What catches people out

Five things that are not in the summary. First, breaking this law is a crime: any person or company that violates it faces six months to two years in prison plus a fine of one hundred to one hundred and fifty times the monthly minimum wage, which runs to tens of thousands of US dollars. Second, selling or offering a list of email addresses without the owners' express consent is a separate crime under the anti-spam law, carrying six months to five years, and it is the public prosecutor who brings it. Third, the absence of a breach report duty is not protection, because the person harmed can sue and a prosecutor can charge. Fourth, records of who really owns a company must be held inside the country, which quietly breaks a fully offshore corporate-records setup. Fifth, there is no authority to give you a ruling, a licence or a comfort letter, so there is no way to buy certainty in advance.

High confidenceCriminal liabilityKeep the data in the countryRegister or notifyKeep logs

What's changing next

Three things are moving. A cybersecurity bill of sixty-four articles, covering public administration and critical infrastructure, went to a Senate committee in September 2025 and was still being studied there; it is a bill, so it binds nobody yet. The telecommunications institute has put forward a proposal for a new telecommunications law to replace the 1998 statute. And the operational risk rules for banks, approved in November 2025, have parts that only start to bite on the first of April 2027. We found no bill in either chamber to replace the 2013 data protection law or to create a data protection authority.

Medium confidenceProposedPartly in force

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Ley No. 155-17 contra el Lavado de Activos y el Financiamiento del Terrorismo

Act of parliament · Ley núm. 155-17, Gaceta Oficial núm. 10886 de 1 de junio de 2017, articles 43, 104 and 105

Partly in forceA copy must stay

The anti-money-laundering law sets the country's real retention floor at ten years, for both regulated businesses and ordinary taxpayers. It also rewrote the Tax Code so that records of who really owns a company must be held at a place inside Dominican territory, which is the only genuine data residency requirement we found anywhere in Dominican law.

In force since 1 June 2017

Enforced by Directorate General of Internal Taxes

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence
Banking

Reglamento de Seguridad Cibernética y de la Información

Directly binding regulation · Junta Monetaria, Segunda Resolución de 1 de noviembre de 2018 (JM 181101-02), read with the Reglamento sobre Riesgo Operacional, Cuarta Resolución de 27 de noviembre de 2025 (JM 251127-04)

In forceYes, with paperwork

The banking cybersecurity rulebook. It expressly allows cloud and outsourced processing, including abroad, on condition that the bank documents a policy, runs a risk analysis, and writes an inspection right for the Superintendency of Banks into the contract. There is no requirement to keep banking data in the country, but the supervisor can object to an arrangement it does not like.

In force since 1 November 2018

Enforced by Superintendency of Banks

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Government

Decreto núm. 685-22 que establece los principios y lineamientos generales para la adopción de controles, políticas y estándares de madurez cibernética en el sector público

Directly binding regulation · Decreto núm. 685-22, Gaceta Oficial núm. 11088 de 18 de noviembre de 2022

In forceYes, with paperwork

Government bodies under the executive branch must report cybersecurity incidents within twenty-four hours of detection to the National Cybersecurity Centre or their sector incident response team. The duty does not reach private companies, and the other branches of the state may opt in but are not bound.

In force since 18 November 2022

Enforced by National Cybersecurity Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley No. 172-13 que tiene por objeto la protección integral de los datos personales asentados en archivos, registros públicos, bancos de datos u otros medios técnicos de tratamiento de datos

Act of parliament · Ley núm. 172-13, Gaceta Oficial núm. 10737 de 15 de diciembre de 2013

In forceYes, with paperwork

The general personal data law. It grants access, correction, erasure and a court-based habeas data claim, and lets data leave the country on any of nine listed grounds with consent first among them. It creates no data protection authority, no register of controllers and no breach reporting duty, and it hands administrative fining power to the banking regulator over credit reference companies alone. Its real teeth are criminal.

In force since 15 December 2013

Enforced by Superintendency of Banks

Transfer model: No restriction · Accepted routes: Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence
Telecoms

Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología

Act of parliament · Ley núm. 53-07, Gaceta Oficial núm. 10416 de 23 de abril de 2007

In forceYes, with paperwork

Service providers, including internet providers, must keep traffic, connection and access records for at least ninety days so that they can be produced in a criminal investigation. Prosecutors can order preservation, real-time collection and interception through the courts. The law told the telecommunications institute to write implementing rules within six months of 2007.

In force since 23 April 2007

Enforced by Dominican Telecommunications Institute

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Superintendencia de Bancos de la República Dominicana

    Banks and financial intermediation; the only body with administrative fining power under the data protection law, and only over credit reference companies

    Fully staffed and issuing circulars and letter-circulars continuously through 2026. Its register of normative acts shows fifteen circulars and ten letter-circulars issued in 2026 alone by 19 August 2026. Its powers under the data protection law, however, reach only credit reference companies; we found no published decision applying that law to an ordinary business.

  • Banco Central de la República Dominicana / Junta Monetaria

    Issues the banking cybersecurity, operational risk and payment system regulations, and hosts the financial sector incident response team

    The Monetary Board approved a full rewrite of the operational risk regulation on 27 November 2025.

  • Centro Nacional de Ciberseguridad (CNCS)

    National cyber incident response, public sector cyber maturity, critical infrastructure coordination. Sits within the National Intelligence Directorate.

    Running an incident reporting channel and a coordinated vulnerability disclosure policy, and signing institutional agreements as recently as 29 July 2026.

  • Instituto Dominicano de las Telecomunicaciones (INDOTEL)

    Telecommunications, internet service providers, digital signatures and electronic commerce; lists the data protection law among the laws affecting its functions

    Active regulator with a sitting board, a public complaints service and a published proposal for a new telecommunications law.

  • Ministerio de Administración Pública (MAP)

    Governing body for the June 2026 national interoperability and data governance framework for public administration

    Given open-ended power by the 2026 decree to issue binding standards and guides; none published at the time of checking.

  • Dirección General de Impuestos Internos (DGII)

    Tax record keeping and the beneficial ownership information duty inserted into the Tax Code

    Operational as a tax administration. We could not verify on its own site whether the regulation fixing where beneficial ownership records must be kept has been issued.

  • Procuraduría General de la República / Departamento de Investigación de Crímenes y Delitos de Alta Tecnología (DICAT)

    Criminal enforcement of the data protection law, the high-technology crimes law and the anti-spam law

    The practical enforcement route in the absence of a data protection authority. We did not locate published statistics on prosecutions brought specifically under the data protection law.

  • Tribunal Constitucional de la República Dominicana

    Constitutional protection of privacy and the habeas data right

    Publishing decisions dated 17 August 2026.

  • No existe

    Would supervise the general data protection law

    None exists. The 2013 law creates no supervisory authority, no register of controllers and no complaints procedure outside the courts. Searching the official national law repository on 19 August 2026 for laws and decrees with 'datos personales' or 'protección de datos' in the title returned only the 2013 law itself.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the regulation fixing the place inside Dominican territory where beneficial ownership records must be kept has actually been issued

    The statute says the location will be set by regulation. No decree with that subject appears in the official national law repository, and the tax authority's own regulations index returned a not-found error on 19 August 2026. It may exist as a General Norm of the tax authority that we could not open. The residency duty is therefore recorded as partially in force.

  • Whether the securities regulator imposes any technology, outsourcing or data localisation rules on market participants

    The Superintendency of the Securities Market's website returned an access-denied error to every automated request on 19 August 2026, so its norms could not be read. This is the largest unchecked gap in the sectoral layer.

  • Whether the insurance supervisor imposes any data or cloud rules

    The insurance supervisor's site redirects to a different host and its normative index was not read. No insurance data instrument appears in the national law repository.

  • The current peso value of the minimum monthly wage used to calculate fines

    Fines in the data protection law, the anti-spam law and the high-technology crimes law are all expressed as multiples of the minimum wage. The labour ministry's minimum wage page could not be located on 19 August 2026, so the US dollar approximations given here are indicative only.

  • Whether the Superintendency of Banks has ever imposed a sanction under the data protection law on a credit reference company

    The Superintendency's sanctions page requires JavaScript and returned no readable content. We can evidence the power but not its use.

  • The current stage of the 2025 cybersecurity bill

    The Senate's own news page evidences it was in committee in September 2025 and that hearings were being held. We found no later official record, so we cannot say whether it has advanced, stalled or lapsed. It is recorded as a bill with no legal effect.

  • Whether the telecommunications institute ever issued the implementing regulation on preservation of provider data that the 2007 law ordered within six months

    Not located on the regulator's own site. The ninety-day statutory floor stands regardless.

  • Whether any court has ruled on the ambiguity in the international transfer article, which by its own words governs only transfers that require the data subject's consent

    No decision on this point was located on the Constitutional Court's site, which does not expose a full-text search to automated access.

60-day cadence. Three dormant switches justify the shorter interval: the regulation that would fix where beneficial ownership records must be kept, the open-ended standard-setting power the June 2026 decree hands the Ministry of Public Administration, and a cybersecurity bill sitting in a Senate committee that would give the country its first cross-sector incident regime. Add to that two unread regulators, securities and insurance, which should be revisited whenever their sites become reachable.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Dominican Republic versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.