Dominican Republic
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Dominican Republic — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
The Dominican Republic has had a personal data law since December 2013. It never got a regulator. Data can leave the country whenever one of nine reasons in the law applies. Consent is the easy one. There is no list of banned countries. There is no filing, no registration and no breach report to send. But breaking the law is a crime, not just a paperwork slip. And the money-laundering and tax rules make you keep records for ten years.
Data governance in Dominican Republic
The eight things that decide how you handle data about people in Dominican Republic. Same eight on every country page, so you can compare.
Who has to follow these rules
The law says it applies throughout the national territory. It does not say it follows Dominicans' data abroad. It does not ask a foreign company to appoint anyone locally. There is no size or revenue threshold, and no register to join. Say you have no office, no staff and no equipment in the country. Then no authority has the power to fine you. But a Dominican judge can still hear a claim from a person here. And a prosecutor can still act if what you did is a crime.
Law 172-13 says its rules are of public order and apply in all the national territory. It does not reach out to companies abroad the way Brazil's or Europe's laws do. It has no duty to appoint a local representative, and no threshold test. The law leaves four things out. Purely personal or household files. Files held by the intelligence and criminal investigation bodies. Files about people who have died. And data about companies, including the name, job title, work address, work phone and work email of the people who work for them. So if you are a foreign business with no local presence, your real exposure is criminal law and private lawsuits, not a regulator.
Sources
- Official sourceConsultoría Jurídica del Poder Ejecutivo — official law repositoryLey No. 172-13 de protección integral de los datos personales, articles 1 to 4 (scope, territory, exclusions)
consultoria.gov.do
“Artículo 3.- Ámbito de aplicación. Las normas de la presente ley son de orden público y de aplicación en todo el territorio nacional.”
Link checked 19 August 2026
- Official sourceCámara de Diputados de la República DominicanaLey No. 172-13 sobre protección de datos personales, 13 December 2013 — copy published by the Chamber of Deputies
camaradediputados.gob.do
Link checked 19 August 2026
Where the data is allowed to live
Yes, but only for one of nine reasons written into the law. The first is that the person freely decided to allow it. That is how almost everyone does it. The others cover medical care and epidemics, bank and stock market transactions, treaties and free trade agreements, and crime-fighting cooperation. They also cover performing a contract with the person, legal claims, and tax or customs demands. The last two are international judicial help, and requests from an international body using a public register. There is no list of banned countries and no list of approved ones. We searched banking, payments, insurance, securities, health, telecommunications, government cloud, education, gambling and mapping. We found no rule ordering personal data to stay in the country. The one storage rule we did find is narrow. Records showing who really owns a company must be kept inside the Dominican Republic.
- Ways to send data out:
- Explicit consent · Needed for a contract · Legal claims · Important public interest
Industry by industry, checked on 19 August 2026. BANKING AND PAYMENTS: the Monetary Board's Cybersecurity and Information Security Regulation of 1 November 2018 expressly allows cloud services. It asks only for a written policy and a risk analysis. It sets no location requirement. The Operational Risk Regulation approved on 27 November 2025 lets a bank outsource all or part of its data handling. But the contract must let the Superintendency of Banks inspect the supplier, and the Superintendency may object to the arrangement. That is supervision, not a rule about where data sits. SECURITIES: the securities regulator's website blocked automated access on 19 August 2026, so we could not read its technology rules. It is listed in the unconfirmed section. INSURANCE, HEALTH, EDUCATION, GAMBLING, MAPPING: we found no rule about keeping data in the country in the official national law repository. Health adds a duty to keep patient records confidential, but says nothing about where they sit. TELECOMMUNICATIONS: internet and telecom providers must keep traffic, connection and access data for at least ninety days. The law does not say where. GOVERNMENT: the June 2026 interoperability decree tightly controls who may touch public-sector data. It forbids private contractors from keeping or reusing it once their purpose ends. Again, it does not fix a location. WHO REALLY OWNS A COMPANY: the anti-money-laundering law rewrote the Tax Code. Every Dominican company, and some foreign ones, must hold up-to-date information on the real human owners. The law says a regulation will set where it must be kept, 'within Dominican territory'. That is the country's only true rule about data staying put. We could not confirm that the regulation putting it into effect has been issued.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, article 80 — international transfer of data
consultoria.gov.do
“Artículo 80.- Transferencia internacional de datos. La transferencia de datos personales de cualquier tipo con países u organismos internacionales o supra nacionales, que requieran del consentimiento del titular de los datos, solamente se efectuará cuando: 1. La persona física, libre y conscientemente, decidiera autorizar por voluntad propia la transferencia de datos, o cuando las leyes lo permitan.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17 contra el Lavado de Activos, article 104 — amends article 50(c) of the Tax Code on beneficial ownership records
consultoria.gov.do
“Reglamentariamente se determinará la información de los beneficiarios finales que es necesario obtener, el lugar donde deba conservarse dentro del territorio dominicano y la periodicidad de actualización.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, Junta Monetaria, Segunda Resolución of 1 November 2018 — cloud services clause
sb.gob.do
“Contratación de Servicios de Computación en la Nube: Se debe documentar una política para el uso y contratación de servicios de computación en la nube, incluyendo el hospedaje de servicios web, que contemple el desarrollo de un análisis de riesgos.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional, Junta Monetaria, Cuarta Resolución of 27 November 2025 — outsourcing of data processing
sb.gob.do
“La entidad que subcontrate una parte o la totalidad de su procesamiento de datos y otros servicios deberá incluir en los contratos que suscriba, una cláusula que permita a la Superintendencia de Bancos la revisión de los procesos tercerizados en el proveedor del servicio.”
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Dominican Republic.
Sending data out of the country
There is nothing to sign with the government and nobody to ask. No approval, no standard contract, no registration, no approved-country list. You only need to show that one of the nine reasons in the law applied when the data moved. In ordinary business that means consent that was free, informed and unambiguous. No authority polices this. The person who checks your homework is a judge, and only after someone complains.
- What you have to do here:
- Put a transfer safeguard in place · Extra vendor secrecy terms
- Ways to send data out:
- Explicit consent
The law controls your reason for the transfer, not the destination. No country has ever been named as banned or as approved. The law contains no power to name one. There is no equivalent of Europe's approved-country decisions, or of India's banned list. The file to keep is evidence of consent. On top of that, anyone who touches personal data at any stage owes a duty of secrecy. That duty lasts after the relationship ends. One drafting quirk is worth knowing. The transfer article opens by talking about transfers 'that require the consent of the person the data is about'. So transfers resting on another legal reason sit in a dark corner of the text. Nobody has the authority to settle that question today.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 5 (principles, including the duty of secrecy) and 80 (international transfer)
consultoria.gov.do
“Deber de secreto. El responsable del archivo de datos personales y quienes intervengan en cualquier fase del tratamiento de los datos de carácter personal están obligados al secreto profesional respecto de los mismos.”
Link checked 19 August 2026
The regulator, and whether it actually acts
Nobody, in the way most countries mean it. The Dominican Republic has no data protection authority. The only body the law gives fining power to is the Superintendency of Banks. That power covers credit reference companies only. Everyone else is policed by criminal prosecutors, by the high-technology crime police unit, and by ordinary judges hearing claims from individuals. The Constitutional Court was issuing rulings as recently as 17 August 2026. So the court route is real. The industry regulators are working. The Superintendency of Banks published circulars throughout 2026. The National Cybersecurity Centre was signing cooperation agreements in July 2026.
Law 172-13 names the Superintendency of Banks as the body that can punish credit information companies. Fines run from ten to one hundred minimum monthly wages. It can also withdraw an operating permit. The law gives that power to nobody else, and over nobody else. There is no register of companies that hold data. There is no complaint desk for general privacy matters. There are no published enforcement decisions applying the general parts of the law, and no guidance from a supervisor. Three routes do work. First, a habeas data claim in the courts, which the law itself creates. Second, a criminal complaint, because the law makes several kinds of misuse a crime. Third, for regulated firms, ordinary supervision by the Superintendency of Banks or the telecommunications institute. Calling enforcement dormant here is a statement about the general law. It is not about the financial regulator, which is active.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 17 to 19 (habeas data action) and 81 to 88 (sanctions)
consultoria.gov.do
“Artículo 81.- Sanciones administrativas. El órgano competente para sancionar las infracciones administrativas cometidas por las Sociedades de Información Crediticia (SIC) será la Superintendencia de Bancos.”
Link checked 19 August 2026
- Official sourceSuperintendencia de BancosNormativas SB — the Superintendency of Banks' circular register, showing circulars issued through 2026
sb.gob.do
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadCentro Nacional de Ciberseguridad — institutional site and incident reporting service, with activity dated July 2026
cncs.gob.do
Link checked 19 August 2026
- Official sourceTribunal Constitucional de la República DominicanaTribunal Constitucional — decisions published up to 17 August 2026
tribunalconstitucional.gob.do
Link checked 19 August 2026
How long you must keep it — and when to delete it
The rules on keeping data are much stronger than the rules on deleting it. Businesses covered by the money-laundering rules must keep transaction records, customer checks, account files and business correspondence. That runs for at least ten years after the relationship ends. Tax and accounting records also run ten years. Internet and telephone providers must keep traffic, connection and access records for at least ninety days. Anyone who runs a credit check must keep the customer's written permission for six months. Going the other way, there is only one real deletion rule. A credit history may not report events older than forty-eight months. Wrong or incomplete data must also be corrected or removed. If a keep-it rule and a delete-it rule clash, the keep-it rule wins. The law says the right to have data erased does not apply where another law requires it to be kept.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
The ten-year minimums come from the anti-money-laundering law for regulated businesses. That same law rewrote the Tax Code to add a ten-year minimum for taxpayers. It covers accounting books, special registers, receipts and any document about the taxpayer's operations, on paper or electronic. The ninety-day minimum comes from the high-technology crimes law. It binds service providers, including internet providers. A prosecutor can extend it with a preservation order of up to ninety days, which can be renewed. The six-month minimum covers the written permission to run a credit check. During that time the person cannot deny having authorised it. The forty-eight-month limit is the credit reporting window. The general law's erasure right is switched off where a contract or a law requires you to keep the data. That is how the conflict is resolved.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, article 43 (ten-year record keeping) and article 105 (ten-year tax record keeping)
consultoria.gov.do
“Los Sujetos Obligados deben conservar todos los registros necesarios sobre transacciones, medidas de debida diligencia, archivos de cuentas, correspondencia comercial, y los resultados de los análisis realizados, durante al menos 10 años después de finalizada la relación comercial.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 53-07 sobre Crímenes y Delitos de Alta Tecnología, article 56 — ninety-day minimum retention by service providers
consultoria.gov.do
“los proveedores de servicio deberan conservar los datos de trafico, conexion, acceso o cualquier otra informacion que pueda ser de utilidad a la investigacion, por un periodo minimo de noventa (90) dias.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 5 and 14 (erasure yields to legal retention duties) and the forty-eight-month credit reporting window
consultoria.gov.do
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no general duty to report a data breach. The 2013 law does not contain one. So a private company that loses customer data owes no report to any authority. It owes no notice to the people affected either. Two narrower clocks do exist. Government bodies must report a cybersecurity incident immediately. The report must reach the national cyber team or the industry team within twenty-four hours of detection. Banks and payment system participants must run a written incident process. They answer to the financial sector's own incident response team. The rules set no fixed number of hours. Anyone can also report voluntarily to the National Cybersecurity Centre, which runs a public reporting page.
- What you have to do here:
- Report cyber incidents · Secure the data
The lack of a private-sector breach duty is the most surprising feature here. No regulator has filled the gap with guidance, because there is no regulator. That does not make silence safe. The general duties of security and secrecy still apply. Someone affected can sue you for damages. Knowingly revealing data you were legally bound to keep secret is a crime. Deliberately or dishonestly getting into a personal database without permission is a separate crime. The twenty-four hour public sector clock comes from the November 2022 decree on cyber maturity in public administration. That decree also requires follow-up reports as soon as new information appears. It warns that steps to contain an incident must not destroy evidence.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 685-22, article 12 — mandatory incident reporting by public bodies within twenty-four hours
consultoria.gov.do
“Los entes y órganos de la Administración Pública, inmediatamente y sin demora, deberán reportar los incidentes de ciberseguridad que les afecten... Estos comunicarán el incidente dentro de las primeras 24 horas de haber sido detectado.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, articles 31 and 49 to 58 — incident management and the financial sector incident response team
sb.gob.do
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadReportar incidentes — the National Cybersecurity Centre's incident reporting channel
cncs.gob.do
What catches people out
Five things are not in the summary. First, breaking this law is a crime. Any person or company that breaks it faces six months to two years in prison. There is also a fine of one hundred to one hundred and fifty times the monthly minimum wage. That runs to tens of thousands of US dollars. Second, selling or offering a list of email addresses without the owners' express consent is a separate crime under the anti-spam law. It carries six months to five years, and the public prosecutor brings the case. Third, having no breach report duty is not protection. The person harmed can sue you, and a prosecutor can charge you. Fourth, records of who really owns a company must be held inside the country. That quietly breaks a fully offshore setup for company records. Fifth, there is no authority to give you a ruling, a licence or a comfort letter. So there is no way to buy certainty in advance.
- What you have to do here:
- Keep the data in the country · Register or notify · Keep logs
- What it costs if you get it wrong:
- Criminal liability
A sixth trap. Your internet or hosting provider must be able to produce ninety days of traffic and access records on demand. That sits badly with systems that delete logs after thirty days. A seventh trap. This law sets no special age for children at all. It simply points to the children's code, the penal code and other special laws. So there is no clear digital age of consent to design for. An eighth trap. Credit reference companies are fenced off. They must be authorised by the Monetary Board. They must be listed in a public register held by the Superintendency of Banks. No bank or other deposit-taking institution may own shares in one. Anyone misusing a credit report faces prison.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 84 to 88 — exceptional, civil and criminal sanctions
consultoria.gov.do
“Artículo 88.- El suscriptor o afiliado, el cliente o consumidor, los representantes de las entidades públicas, o cualquier persona física o jurídica que viole las disposiciones contenidas en la presente ley, será sancionada con prisión correccional de seis meses a dos años, y una multa de cien (100) a ciento cincuenta (150) salarios mínimos vigentes.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 310-14 que regula el envío de correos electrónicos comerciales no solicitados, articles 12 and 13
consultoria.gov.do
“Ofrecer la venta de bases de datos con direcciones de correos electrónicos sin el consentimiento expreso de los propietarios de los mismos, con el objetivo de generar comunicaciones comerciales no solicitadas.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, article 104 — beneficial ownership information to be kept within Dominican territory
consultoria.gov.do
Link checked 19 August 2026
What's changing next
Three things are moving. A cybersecurity bill of sixty-four articles went to a Senate committee in September 2025. It covers public administration and critical infrastructure. It was still being studied there. It is a bill, so it binds nobody yet. The telecommunications institute has proposed a new telecommunications law to replace the 1998 one. And the operational risk rules for banks, approved in November 2025, have parts that only start on 1 April 2027. We found no bill in either chamber to replace the 2013 data protection law, or to create a data protection authority.
Three switches that could be flipped matter more than the pending bills. First, the anti-money-laundering law already says a regulation will fix where inside Dominican territory records of company owners must be kept. Issuing that regulation would turn a quiet phrase in the law into a real storage requirement overnight. Second, the June 2026 interoperability and data governance decree gives the Ministry of Public Administration open-ended power. It can issue binding standards, guides and minimum controls for public sector data. That covers private contractors who touch it. The text sets no consultation step. Third, the same decree makes the Comptroller General the auditor of compliance. That creates a way to enforce rules on public sector data that did not exist before. Watch the National Cybersecurity Centre too. It sits inside the national intelligence directorate. It widened its remit through decrees in 2022 and 2024.
Sources
- Official sourceSenado de la República DominicanaComisión de Transporte y Telecomunicaciones avanza en la evaluación del proyecto de ley de Ciberseguridad, 3 September 2025
senadord.gob.do
Link checked 19 August 2026
- Official sourceInstituto Dominicano de las TelecomunicacionesIndotel presenta propuesta de nueva Ley de Telecomunicaciones para modernizar el sector
indotel.gob.do
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 403-26 — Marco Nacional de Interoperabilidad y Gobernanza de Datos, articles 37 and 48
consultoria.gov.do
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional — provisions commencing 1 April 2027
sb.gob.do
“establecidos en este Reglamento entrarán en vigencia a partir del 1º de abril del 2027.”
Link checked 19 August 2026
What to do: Diarise 1 April 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Finance data needs a copy kept in the country
Official name: Ley No. 155-17 contra el Lavado de Activos y el Financiamiento del Terrorismo · Ley núm. 155-17, Gaceta Oficial núm. 10886 de 1 de junio de 2017, articles 43, 104 and 105 · Act of parliament
The anti-money-laundering law sets the country's real record-keeping minimum at ten years. That covers both regulated businesses and ordinary taxpayers. It also rewrote the Tax Code so records of who really owns a company must be held somewhere inside Dominican territory. That is the only true rule about data staying in the country that we found anywhere in Dominican law.
Enforced by Directorate General of Internal Taxes
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryInformation about the real human owners of a company must be kept somewhere within Dominican territory. A regulation will set the place. We could not confirm that regulation has been issued. So we treat this storage duty as not yet in force.
- Keep records of how you use dataBeneficial ownership information must be updated no later than six months after any change.
- Keep data for a minimum period — 10 yearsTen years for transaction records, customer checks, account files, business correspondence and analysis results. Count from the end of the relationship, or the date of a one-off transaction.
- Keep data for a minimum period — applies at: All taxpayers, 10 yearsTen years for accounting books, special registers, receipts and any document, physical or electronic, relating to the taxpayer's operations.
- Appoint a data protection officerThis is not a privacy officer. Regulated businesses must appoint a senior compliance officer. That person is the link to the Financial Analysis Unit and the supervisor.
What it costs if you get it wrong
- Criminal liabilityMoney laundering offences under the same law
- Fixed maximum fineAdministrative breaches by regulated businesses; serious breaches prescribe after five years
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, articles 43, 104 and 105
consultoria.gov.do
“Reglamentariamente se determinará la información de los beneficiarios finales que es necesario obtener, el lugar donde deba conservarse dentro del territorio dominicano y la periodicidad de actualización, que en ningún caso será superior a los 6 meses posteriores a los cambios ocurridos en el beneficiario final.”
Link checked 19 August 2026
Cyber security rules
Official name: Reglamento de Seguridad Cibernética y de la Información · Junta Monetaria, Segunda Resolución de 1 de noviembre de 2018 (JM 181101-02), read with the Reglamento sobre Riesgo Operacional, Cuarta Resolución de 27 de noviembre de 2025 (JM 251127-04) · Directly binding regulation
The banking cyber security rulebook. It expressly allows cloud and outsourced data handling, including abroad. The bank must write down a policy, run a risk analysis, and put an inspection right for the Superintendency of Banks into the contract. There is no requirement to keep banking data in the country. But the supervisor can object to an arrangement it does not like.
Enforced by Superintendency of Banks
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataBoard-approved cybersecurity programme, a cybersecurity and information security officer, and a functional committee.
- Written vendor contractCloud services are allowed, but you need a written policy and a risk analysis. Outsourcing contracts must let the Superintendency of Banks inspect the supplier. The Superintendency may also object to the arrangement.
- Report cyber incidentsYou need written incident management, forensic capability, and membership of the financial sector's incident response team. The rules set no fixed reporting deadline in hours.
- Independent auditInternal audit of the cybersecurity programme, plus continuity stress tests at least once a year.
- Assess high-risk projectsRisk analysis required before contracting cloud services and before outsourcing.
What it costs if you get it wrong
- Fixed maximum fineBreach by a financial intermediation entity, under the sanctions regulation of the monetary and financial system
- Order to stopPrecautionary measures available to the supervisor
Sources
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, Junta Monetaria, 1 November 2018
sb.gob.do
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional, Junta Monetaria, 27 November 2025, articles 51, 52 and 89
sb.gob.do
Link checked 19 August 2026
- Official sourceSuperintendencia de BancosReglamento de Seguridad Cibernética y de la Información — regulator's own page
sb.gob.do
Link checked 19 August 2026
Cyber security rules (Government)
Official name: Decreto núm. 685-22 que establece los principios y lineamientos generales para la adopción de controles, políticas y estándares de madurez cibernética en el sector público · Decreto núm. 685-22, Gaceta Oficial núm. 11088 de 18 de noviembre de 2022 · Directly binding regulation
Government bodies in the executive branch must report cybersecurity incidents within twenty-four hours of detection. The report goes to the National Cybersecurity Centre or to their industry incident response team. The duty does not reach private companies. Other branches of the state may opt in, but are not bound.
Enforced by National Cybersecurity Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursPublic bodies must report immediately and without delay. The report must reach the national or industry incident response team within twenty-four hours of detection.
- Secure the dataIncident classification into low, medium, high and critical levels; a service interruption of more than eight hours counts towards critical.
- Keep records of how you use dataContainment measures must not destroy evidence, and follow-up reports are required as soon as new information appears.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 685-22, articles 1 to 14
consultoria.gov.do
“Estos comunicarán el incidente dentro de las primeras 24 horas de haber sido detectado, acompañando toda la información necesaria para valorar su impacto.”
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadCSIRT-RD — the national incident response team
cncs.gob.do
Link checked 19 August 2026
State and security data rules
Official name: Decreto núm. 403-26 que aprueba el Reglamento que establece el Marco Nacional de Interoperabilidad y Gobernanza de Datos de la Administración Pública · Decreto núm. 403-26, Gaceta Oficial núm. 11247 de 19 de junio de 2026 · Directly binding regulation
A brand new set of rules for how the Dominican state governs and shares its own data. Data must be classified before it is shared. Audit logs must be traceable. Where personal data is involved, you need a legal reason. It puts hard limits on private contractors who touch public data. It sets no location requirement. It repealed the earlier interoperability decrees.
Enforced by Ministry of Public Administration
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep records of how you use dataEvery act of data sharing between public bodies must be traceable, auditable and recordable, with audit logs kept for as long as the law requires.
- Allowed because the law requires itWhere the exchange involves personal or sensitive data, you must identify a legal reason before the exchange. The data protection rules apply on top.
- Written vendor contractPrivate contractors, concessionaires and technology partners may only reach public data in exceptional cases, with express authorisation. They may not reuse, transfer, keep or exploit it beyond the purpose that justified access.
- Let people delete their dataOnce the purpose ends, the third party must stop using the data immediately. It must return, block, delete or restrict it.
- Independent auditThe Comptroller General audits compliance across public administration.
What it costs if you get it wrong
- Claims by individualsCivil, administrative, criminal or contractual liability for authorised third parties who breach the access conditions
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 403-26, articles 17, 23, 36, 37, 49 and 50
consultoria.gov.do
“Los terceros autorizados no podrán reutilizar, ceder, transferir, conservar, explotar o tratar la información obtenida por interoperabilidad fuera de la finalidad que justificó su acceso.”
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Banking rules
Official name: Ley No. 172-13 que tiene por objeto la protección integral de los datos personales asentados en archivos, registros públicos, bancos de datos u otros medios técnicos de tratamiento de datos · Ley núm. 172-13, Gaceta Oficial núm. 10737 de 15 de diciembre de 2013 · Act of parliament
The general personal data law. It gives you access, correction and erasure rights, plus a court claim called habeas data. It lets data leave the country on any of nine listed grounds, with consent first among them. It creates no data protection authority, no register of companies holding data, and no breach reporting duty. It gives fining power to the banking regulator over credit reference companies alone. Its real teeth are criminal.
Enforced by Superintendency of Banks
How this country controls where data goes: No restriction · Accepted routes: Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Get consent
- Tell people what you do
- Let people see their dataFree of charge four times a year for credit information, at intervals of not less than three months.
- Let people correct their data
- Let people delete their dataThis does not apply where a contract or a law requires you to keep the data.
- Secure the data
- Extra vendor secrecy termsThe duty of professional secrecy binds everyone involved at any stage. It lasts after the relationship ends.
- Delete data after a period — applies at: Credit history reporting window, 4 yearsCredit reference companies may not report credit events older than forty-eight months.
- Keep data for a minimum period — applies at: Users of credit reports, 6 monthsThe written permission to run a credit check must be kept for six months.
- Register or notify — applies at: Credit reference companies onlyYou need authorisation from the Monetary Board, plus entry in a public register held by the Superintendency of Banks. There is no register for ordinary businesses.
- Put a transfer safeguard in placeOne of nine statutory grounds must apply. No paperwork is filed with any authority.
What it costs if you get it wrong
- Criminal liability: Prisión correccional de 6 meses a 2 años y multa de 100 a 150 salarios mínimosAny person or company that breaches the law
- Criminal liability: Multa de 10 a 50 salarios mínimosKnowingly inserting false data, passing on false data, unlawfully accessing a personal database, or revealing data you were legally bound to keep secret
- Fixed maximum fine: Multa de 10 a 100 salarios mínimosAdministrative breach by a credit reference company, imposed by the Superintendency of Banks
- Loss of your licenceA credit reference company that does not start operating within six months of authorisation
- Claims by individualsDamage suffered by an individual as a result of a breach of the law
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, full text, Gaceta Oficial núm. 10737
consultoria.gov.do
Link checked 19 August 2026
- Official sourceCámara de DiputadosLey No. 172-13 sobre protección de datos personales, 13 December 2013
camaradediputados.gob.do
Link checked 19 August 2026
Telecoms rules
Official name: Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología · Ley núm. 53-07, Gaceta Oficial núm. 10416 de 23 de abril de 2007 · Act of parliament
Service providers, including internet providers, must keep traffic, connection and access records for at least ninety days. The point is that they can be produced in a criminal investigation. Prosecutors can order preservation, real-time collection and interception through the courts. The law told the telecommunications institute to write the detailed rules within six months of 2007.
Enforced by Dominican Telecommunications Institute
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 3 monthsAt least ninety days of traffic, connection and access data, or anything else useful to an investigation. The law does not say where it must be stored.
- Keep data for a minimum period — 3 monthsA prosecutor may separately order preservation of a system or its data for up to ninety days, renewable for further periods.
What it costs if you get it wrong
- Criminal liabilityTrading in data obtained during an investigation, or disclosing personal data of an accused person beyond the scope of the investigation
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 53-07, articles 53 to 59
consultoria.gov.do
“los proveedores de servicio deberan conservar los datos de trafico, conexion, acceso o cualquier otra informacion que pueda ser de utilidad a la investigacion, por un periodo minimo de noventa (90) dias.”
Link checked 19 August 2026
- Official sourceInstituto Dominicano de las TelecomunicacionesMarco Legal — Indotel lists Ley 53-07, Ley 310-14 and Ley 172-13 among the laws affecting its functions
indotel.gob.do
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the regulation fixing the place inside Dominican territory where beneficial ownership records must be kept has actually been issued
The law says the location will be set by a regulation. No decree on that subject appears in the official national law repository. We could not open the tax authority's own regulations index on 19 August 2026. The rule may exist as a General Norm of the tax authority. Until it is confirmed, treat this storage duty as only partly in force.
Whether the securities regulator imposes any technology, outsourcing or keeping data in the country rules on market participants
We could not read the Superintendency of the Securities Market's rules. Its website refused every automated request on 19 August 2026. This is the biggest unchecked gap by industry. If you work in securities, check with the regulator before you rely on this.
Whether the insurance supervisor imposes any data or cloud rules
We could not read the insurance supervisor's rules. Its site redirects to a different host. No insurance data rule appears in the national law repository. If you are an insurer, check with the supervisor before you rely on this.
The current peso value of the minimum monthly wage used to calculate fines
Fines in the data protection law, the anti-spam law and the high-technology crimes law are all multiples of the minimum wage. We could not find the labour ministry's minimum wage page on 19 August 2026. So the US dollar figures here are rough guides only.
Whether the Superintendency of Banks has ever imposed a sanction under the data protection law on a credit reference company
We could not read the Superintendency's sanctions page. We can show the power exists, but not that it has ever been used.
The current stage of the 2025 cybersecurity bill
The Senate's own news page shows the bill was in committee in September 2025, and that hearings were being held. We found no later official record. So we cannot say whether it has advanced, stalled or lapsed. Treat it as a bill with no legal effect.
Whether the telecommunications institute ever issued the implementing regulation on preservation of provider data that the 2007 law ordered within six months
We could not find this regulation on the regulator's own site. The ninety-day minimum in the law applies either way.
Whether any court has ruled on the ambiguity in the international transfer article, which by its own words governs only transfers that require the the people the data is about's consent
We found no court decision on this point. The Constitutional Court's site does not allow automated full-text search. If this ambiguity matters to your transfers, take local legal advice.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.