Skip to the content
Global Data RulesData governance rules, country by country

Dominican Republic

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Dominican Republic — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Dormant

The Dominican Republic has had a personal data law since December 2013. It never got a regulator. Data can leave the country whenever one of nine reasons in the law applies. Consent is the easy one. There is no list of banned countries. There is no filing, no registration and no breach report to send. But breaking the law is a crime, not just a paperwork slip. And the money-laundering and tax rules make you keep records for ten years.

Data governance in Dominican Republic

The eight things that decide how you handle data about people in Dominican Republic. Same eight on every country page, so you can compare.

Who has to follow these rules

The law says it applies throughout the national territory. It does not say it follows Dominicans' data abroad. It does not ask a foreign company to appoint anyone locally. There is no size or revenue threshold, and no register to join. Say you have no office, no staff and no equipment in the country. Then no authority has the power to fine you. But a Dominican judge can still hear a claim from a person here. And a prosecutor can still act if what you did is a crime.

Where the data is allowed to live

Yes, but only for one of nine reasons written into the law. The first is that the person freely decided to allow it. That is how almost everyone does it. The others cover medical care and epidemics, bank and stock market transactions, treaties and free trade agreements, and crime-fighting cooperation. They also cover performing a contract with the person, legal claims, and tax or customs demands. The last two are international judicial help, and requests from an international body using a public register. There is no list of banned countries and no list of approved ones. We searched banking, payments, insurance, securities, health, telecommunications, government cloud, education, gambling and mapping. We found no rule ordering personal data to stay in the country. The one storage rule we did find is narrow. Records showing who really owns a company must be kept inside the Dominican Republic.

Ways to send data out:
Explicit consent · Needed for a contract · Legal claims · Important public interest

What to do: Get the paperwork for one of the routes below signed before any data leaves Dominican Republic.

Sending data out of the country

There is nothing to sign with the government and nobody to ask. No approval, no standard contract, no registration, no approved-country list. You only need to show that one of the nine reasons in the law applied when the data moved. In ordinary business that means consent that was free, informed and unambiguous. No authority polices this. The person who checks your homework is a judge, and only after someone complains.

What you have to do here:
Put a transfer safeguard in place · Extra vendor secrecy terms
Ways to send data out:
Explicit consent

The regulator, and whether it actually acts

Nobody, in the way most countries mean it. The Dominican Republic has no data protection authority. The only body the law gives fining power to is the Superintendency of Banks. That power covers credit reference companies only. Everyone else is policed by criminal prosecutors, by the high-technology crime police unit, and by ordinary judges hearing claims from individuals. The Constitutional Court was issuing rulings as recently as 17 August 2026. So the court route is real. The industry regulators are working. The Superintendency of Banks published circulars throughout 2026. The National Cybersecurity Centre was signing cooperation agreements in July 2026.

How long you must keep it — and when to delete it

The rules on keeping data are much stronger than the rules on deleting it. Businesses covered by the money-laundering rules must keep transaction records, customer checks, account files and business correspondence. That runs for at least ten years after the relationship ends. Tax and accounting records also run ten years. Internet and telephone providers must keep traffic, connection and access records for at least ninety days. Anyone who runs a credit check must keep the customer's written permission for six months. Going the other way, there is only one real deletion rule. A credit history may not report events older than forty-eight months. Wrong or incomplete data must also be corrected or removed. If a keep-it rule and a delete-it rule clash, the keep-it rule wins. The law says the right to have data erased does not apply where another law requires it to be kept.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no general duty to report a data breach. The 2013 law does not contain one. So a private company that loses customer data owes no report to any authority. It owes no notice to the people affected either. Two narrower clocks do exist. Government bodies must report a cybersecurity incident immediately. The report must reach the national cyber team or the industry team within twenty-four hours of detection. Banks and payment system participants must run a written incident process. They answer to the financial sector's own incident response team. The rules set no fixed number of hours. Anyone can also report voluntarily to the National Cybersecurity Centre, which runs a public reporting page.

What you have to do here:
Report cyber incidents · Secure the data

What catches people out

Five things are not in the summary. First, breaking this law is a crime. Any person or company that breaks it faces six months to two years in prison. There is also a fine of one hundred to one hundred and fifty times the monthly minimum wage. That runs to tens of thousands of US dollars. Second, selling or offering a list of email addresses without the owners' express consent is a separate crime under the anti-spam law. It carries six months to five years, and the public prosecutor brings the case. Third, having no breach report duty is not protection. The person harmed can sue you, and a prosecutor can charge you. Fourth, records of who really owns a company must be held inside the country. That quietly breaks a fully offshore setup for company records. Fifth, there is no authority to give you a ruling, a licence or a comfort letter. So there is no way to buy certainty in advance.

What you have to do here:
Keep the data in the country · Register or notify · Keep logs
What it costs if you get it wrong:
Criminal liability

What's changing next

Three things are moving. A cybersecurity bill of sixty-four articles went to a Senate committee in September 2025. It covers public administration and critical infrastructure. It was still being studied there. It is a bill, so it binds nobody yet. The telecommunications institute has proposed a new telecommunications law to replace the 1998 one. And the operational risk rules for banks, approved in November 2025, have parts that only start on 1 April 2027. We found no bill in either chamber to replace the 2013 data protection law, or to create a data protection authority.

What to do: Diarise 1 April 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Finance data needs a copy kept in the country

Official name: Ley No. 155-17 contra el Lavado de Activos y el Financiamiento del Terrorismo · Ley núm. 155-17, Gaceta Oficial núm. 10886 de 1 de junio de 2017, articles 43, 104 and 105 · Act of parliament

Partly in forceA copy must stay

The anti-money-laundering law sets the country's real record-keeping minimum at ten years. That covers both regulated businesses and ordinary taxpayers. It also rewrote the Tax Code so records of who really owns a company must be held somewhere inside Dominican territory. That is the only true rule about data staying in the country that we found anywhere in Dominican law.

In force since 1 June 2017

Enforced by Directorate General of Internal Taxes

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Banking

Cyber security rules

Official name: Reglamento de Seguridad Cibernética y de la Información · Junta Monetaria, Segunda Resolución de 1 de noviembre de 2018 (JM 181101-02), read with the Reglamento sobre Riesgo Operacional, Cuarta Resolución de 27 de noviembre de 2025 (JM 251127-04) · Directly binding regulation

In forceYes, with paperwork

The banking cyber security rulebook. It expressly allows cloud and outsourced data handling, including abroad. The bank must write down a policy, run a risk analysis, and put an inspection right for the Superintendency of Banks into the contract. There is no requirement to keep banking data in the country. But the supervisor can object to an arrangement it does not like.

In force since 1 November 2018

Enforced by Superintendency of Banks

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Cyber security rules (Government)

Official name: Decreto núm. 685-22 que establece los principios y lineamientos generales para la adopción de controles, políticas y estándares de madurez cibernética en el sector público · Decreto núm. 685-22, Gaceta Oficial núm. 11088 de 18 de noviembre de 2022 · Directly binding regulation

In forceYes, with paperwork

Government bodies in the executive branch must report cybersecurity incidents within twenty-four hours of detection. The report goes to the National Cybersecurity Centre or to their industry incident response team. The duty does not reach private companies. Other branches of the state may opt in, but are not bound.

In force since 18 November 2022

Enforced by National Cybersecurity Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Banking rules

Official name: Ley No. 172-13 que tiene por objeto la protección integral de los datos personales asentados en archivos, registros públicos, bancos de datos u otros medios técnicos de tratamiento de datos · Ley núm. 172-13, Gaceta Oficial núm. 10737 de 15 de diciembre de 2013 · Act of parliament

In forceYes, with paperwork

The general personal data law. It gives you access, correction and erasure rights, plus a court claim called habeas data. It lets data leave the country on any of nine listed grounds, with consent first among them. It creates no data protection authority, no register of companies holding data, and no breach reporting duty. It gives fining power to the banking regulator over credit reference companies alone. Its real teeth are criminal.

In force since 15 December 2013

Enforced by Superintendency of Banks

How this country controls where data goes: No restriction · Accepted routes: Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

Telecoms

Telecoms rules

Official name: Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología · Ley núm. 53-07, Gaceta Oficial núm. 10416 de 23 de abril de 2007 · Act of parliament

In forceYes, with paperwork

Service providers, including internet providers, must keep traffic, connection and access records for at least ninety days. The point is that they can be produced in a criminal investigation. Prosecutors can order preservation, real-time collection and interception through the courts. The law told the telecommunications institute to write the detailed rules within six months of 2007.

In force since 23 April 2007

Enforced by Dominican Telecommunications Institute

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Superintendencia de Bancos de la República Dominicana

    Banks and financial intermediation; the only body with administrative fining power under the data protection law, and only over credit reference companies

    Fully staffed. It issued circulars and letter-circulars continuously through 2026. Its register of rules shows fifteen circulars and ten letter-circulars issued in 2026 alone, by 19 August 2026. But its powers under the data protection law reach only credit reference companies. We found no published decision applying that law to an ordinary business.

  • Banco Central de la República Dominicana / Junta Monetaria

    Issues the banking cybersecurity, operational risk and payment system regulations, and hosts the financial sector incident response team

    The Monetary Board approved a full rewrite of the operational risk regulation on 27 November 2025.

  • Centro Nacional de Ciberseguridad (CNCS)

    National cyber incident response, public sector cyber maturity, critical infrastructure coordination. Sits within the National Intelligence Directorate.

    Running an incident reporting channel and a coordinated vulnerability disclosure policy, and signing institutional agreements as recently as 29 July 2026.

  • Instituto Dominicano de las Telecomunicaciones (INDOTEL)

    Telecommunications, internet service providers, digital signatures and electronic commerce; lists the data protection law among the laws affecting its functions

    Active regulator with a sitting board, a public complaints service and a published proposal for a new telecommunications law.

  • Ministerio de Administración Pública (MAP)

    Governing body for the June 2026 national interoperability and data governance framework for public administration

    The 2026 decree gives it open-ended power to issue binding standards and guides. None had been published when we checked.

  • Dirección General de Impuestos Internos (DGII)

    Tax record keeping and the beneficial ownership information duty inserted into the Tax Code

    Operational as a tax administration. We could not verify on its own site whether the regulation fixing where beneficial ownership records must be kept has been issued.

  • Procuraduría General de la República / Departamento de Investigación de Crímenes y Delitos de Alta Tecnología (DICAT)

    Criminal enforcement of the data protection law, the high-technology crimes law and the anti-spam law

    The practical enforcement route in the absence of a data protection authority. We did not locate published statistics on prosecutions brought specifically under the data protection law.

  • Tribunal Constitucional de la República Dominicana

    Constitutional protection of privacy and the habeas data right

    Publishing decisions dated 17 August 2026.

  • No existe

    Would supervise the general data protection law

    None exists. The 2013 law creates no supervisory authority, no register of companies holding data, and no complaints procedure outside the courts. We searched the official national law repository on 19 August 2026 for laws and decrees with 'datos personales' or 'protección de datos' in the title. It returned only the 2013 law itself.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the regulation fixing the place inside Dominican territory where beneficial ownership records must be kept has actually been issued

    The law says the location will be set by a regulation. No decree on that subject appears in the official national law repository. We could not open the tax authority's own regulations index on 19 August 2026. The rule may exist as a General Norm of the tax authority. Until it is confirmed, treat this storage duty as only partly in force.

  • Whether the securities regulator imposes any technology, outsourcing or keeping data in the country rules on market participants

    We could not read the Superintendency of the Securities Market's rules. Its website refused every automated request on 19 August 2026. This is the biggest unchecked gap by industry. If you work in securities, check with the regulator before you rely on this.

  • Whether the insurance supervisor imposes any data or cloud rules

    We could not read the insurance supervisor's rules. Its site redirects to a different host. No insurance data rule appears in the national law repository. If you are an insurer, check with the supervisor before you rely on this.

  • The current peso value of the minimum monthly wage used to calculate fines

    Fines in the data protection law, the anti-spam law and the high-technology crimes law are all multiples of the minimum wage. We could not find the labour ministry's minimum wage page on 19 August 2026. So the US dollar figures here are rough guides only.

  • Whether the Superintendency of Banks has ever imposed a sanction under the data protection law on a credit reference company

    We could not read the Superintendency's sanctions page. We can show the power exists, but not that it has ever been used.

  • The current stage of the 2025 cybersecurity bill

    The Senate's own news page shows the bill was in committee in September 2025, and that hearings were being held. We found no later official record. So we cannot say whether it has advanced, stalled or lapsed. Treat it as a bill with no legal effect.

  • Whether the telecommunications institute ever issued the implementing regulation on preservation of provider data that the 2007 law ordered within six months

    We could not find this regulation on the regulator's own site. The ninety-day minimum in the law applies either way.

  • Whether any court has ruled on the ambiguity in the international transfer article, which by its own words governs only transfers that require the the people the data is about's consent

    We found no court decision on this point. The Constitutional Court's site does not allow automated full-text search. If this ambiguity matters to your transfers, take local legal advice.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.