Dominican Republic
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
The Dominican Republic has had a personal data law since December 2013, and it never got a regulator. Data may leave the country whenever one of nine reasons in the law applies, and consent is the easy one. There is no list of banned countries, no filing, no registration and no breach report to send. But breaking the law is a crime, not a paperwork slip, and the money-laundering and tax rules make you keep records for ten years.
Data governance in Dominican Republic
The eight things that decide how you handle data about people in Dominican Republic. Same eight on every country page, so you can compare.
Who has to follow these rules
The law says it applies throughout the national territory. It does not say it follows Dominicans' data abroad, and it does not ask a foreign company to appoint anyone locally. There is no size or revenue threshold, and no register to join. If you have no office, no staff and no equipment in the country, there is no authority with power to fine you, but a Dominican judge can still hear a claim from a person here and a prosecutor can still act if the conduct is a crime.
Law 172-13 states that its rules are of public order and apply in all the national territory. It contains no extraterritorial hook of the kind found in Brazil's or Europe's laws, no local-representative duty and no threshold test. The law excludes four things from its scope: purely personal or household files, files held by the intelligence and criminal investigation bodies, files about dead people, and data about companies (including the name, job title, work address, work phone and work email of the people who work for them). Practical consequence: for a foreign business with no local presence, the binding exposure comes from criminal law and from private lawsuits rather than from a regulator.
Sources
- Official sourceConsultoría Jurídica del Poder Ejecutivo — official law repositoryLey No. 172-13 de protección integral de los datos personales, articles 1 to 4 (scope, territory, exclusions)
consultoria.gov.do
“Artículo 3.- Ámbito de aplicación. Las normas de la presente ley son de orden público y de aplicación en todo el territorio nacional.”
Link checked 19 August 2026
- Official sourceCámara de Diputados de la República DominicanaLey No. 172-13 sobre protección de datos personales, 13 December 2013 — copy published by the Chamber of Deputies
camaradediputados.gob.do
Link checked 19 August 2026
Where the data is allowed to live
Yes, but only for one of nine reasons written into the law. The first is that the person freely decided to allow it, which is how almost everyone does it. The others cover medical care and epidemics, bank and stock market transactions, treaties and free trade agreements, crime-fighting cooperation, performing a contract with the person, legal claims and tax or customs demands, international judicial assistance, and requests from an international body drawing on a public register. There is no list of banned countries and no list of approved ones. We searched banking, payments, insurance, securities, health, telecommunications, government cloud, education, gambling and mapping and found no rule ordering personal data to stay in the country. The one storage rule we did find is narrow: records showing who really owns a company must be kept inside the Dominican Republic.
Sector by sector, checked on 19 August 2026. BANKING AND PAYMENTS: the Monetary Board's Cybersecurity and Information Security Regulation of 1 November 2018 expressly contemplates cloud services, requiring only a documented policy and a risk analysis; it contains no location requirement. The Operational Risk Regulation approved on 27 November 2025 allows a bank to outsource all or part of its data processing, but the contract must let the Superintendency of Banks inspect the provider, and the Superintendency may object to the arrangement. That is supervision, not localisation. SECURITIES: the securities regulator's website blocked automated access on 19 August 2026, so its technology rules were not read; listed in the unconfirmed section. INSURANCE, HEALTH, EDUCATION, GAMBLING, MAPPING: no localisation instrument found in the official national law repository. HEALTH adds a confidentiality duty over patient records but says nothing about where they sit. TELECOMMUNICATIONS: internet and telecom providers must keep traffic, connection and access data for at least ninety days, but the law does not say where. GOVERNMENT: the June 2026 interoperability decree tightly controls who may touch public-sector data and forbids private contractors from keeping or reusing it once their purpose ends, but again does not fix a location. BENEFICIAL OWNERSHIP: the anti-money-laundering law rewrote the Tax Code so that every Dominican company, and some foreign ones, must hold up-to-date information on the real human owners, and says a regulation will set the place where it must be kept 'within Dominican territory'. That is the country's only true residency rule, and we could not confirm the implementing regulation has been issued.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, article 80 — international transfer of data
consultoria.gov.do
“Artículo 80.- Transferencia internacional de datos. La transferencia de datos personales de cualquier tipo con países u organismos internacionales o supra nacionales, que requieran del consentimiento del titular de los datos, solamente se efectuará cuando: 1. La persona física, libre y conscientemente, decidiera autorizar por voluntad propia la transferencia de datos, o cuando las leyes lo permitan.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17 contra el Lavado de Activos, article 104 — amends article 50(c) of the Tax Code on beneficial ownership records
consultoria.gov.do
“Reglamentariamente se determinará la información de los beneficiarios finales que es necesario obtener, el lugar donde deba conservarse dentro del territorio dominicano y la periodicidad de actualización.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, Junta Monetaria, Segunda Resolución of 1 November 2018 — cloud services clause
sb.gob.do
“Contratación de Servicios de Computación en la Nube: Se debe documentar una política para el uso y contratación de servicios de computación en la nube, incluyendo el hospedaje de servicios web, que contemple el desarrollo de un análisis de riesgos.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional, Junta Monetaria, Cuarta Resolución of 27 November 2025 — outsourcing of data processing
sb.gob.do
“La entidad que subcontrate una parte o la totalidad de su procesamiento de datos y otros servicios deberá incluir en los contratos que suscriba, una cláusula que permita a la Superintendencia de Bancos la revisión de los procesos tercerizados en el proveedor del servicio.”
Link checked 19 August 2026
Sending data out of the country
There is nothing to sign with the government and nobody to ask. No approval, no standard contract, no registration, no adequacy list. You only need to be able to show that one of the nine reasons in the law applied when the data moved, and in ordinary business that means a consent that was free, informed and unambiguous. Because no authority polices this, the person who checks your homework is a judge, and only after someone complains.
The law controls the reason for the transfer, not the destination. No country has ever been named as banned or as approved, because the statute contains no power to name one — there is no equivalent of Europe's adequacy decisions or of India's blacklist. The practical file to keep is evidence of consent, plus the ordinary duty of secrecy that binds anyone who touches personal data at any stage and survives the end of the relationship. Note one drafting quirk: article 80 opens with transfers 'that require the consent of the data subject', so transfers resting on another lawful basis sit in an unlit corner of the text. Nobody has authoritative power to resolve that ambiguity today.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 5 (principles, including the duty of secrecy) and 80 (international transfer)
consultoria.gov.do
“Deber de secreto. El responsable del archivo de datos personales y quienes intervengan en cualquier fase del tratamiento de los datos de carácter personal están obligados al secreto profesional respecto de los mismos.”
Link checked 19 August 2026
The regulator, and whether it actually acts
Nobody, in the way most countries mean it. The Dominican Republic has no data protection authority. The only body the law gives fining power to is the Superintendency of Banks, and only over credit reference companies. Everyone else is policed by criminal prosecutors, by the high-technology crime police unit, and by ordinary judges hearing claims brought by individuals. The Constitutional Court was issuing rulings as recently as the seventeenth of August 2026, so the court route is real. The sector regulators are genuinely working: the Superintendency of Banks published circulars throughout 2026, and the National Cybersecurity Centre was signing cooperation agreements in July 2026.
Law 172-13 names the Superintendency of Banks as the body competent to sanction administrative breaches committed by credit information companies, with fines of ten to one hundred minimum monthly wages and the power to withdraw an operating permit. It gives that power to no one else and over no one else. There is no register of data controllers, no complaint desk for general privacy matters, no published enforcement decisions applying the general provisions of the law, and no supervisory guidance. The routes that do work are: a habeas data claim before the courts, which the law itself creates; a criminal complaint, since the law makes several kinds of misuse a crime; and, for regulated firms, ordinary supervision by the Superintendency of Banks or the telecommunications institute. Rating this regime dormant is a statement about the general law, not about the financial regulator, which is active.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 17 to 19 (habeas data action) and 81 to 88 (sanctions)
consultoria.gov.do
“Artículo 81.- Sanciones administrativas. El órgano competente para sancionar las infracciones administrativas cometidas por las Sociedades de Información Crediticia (SIC) será la Superintendencia de Bancos.”
Link checked 19 August 2026
- Official sourceSuperintendencia de BancosNormativas SB — the Superintendency of Banks' circular register, showing circulars issued through 2026
sb.gob.do
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadCentro Nacional de Ciberseguridad — institutional site and incident reporting service, with activity dated July 2026
cncs.gob.do
Link checked 19 August 2026
- Official sourceTribunal Constitucional de la República DominicanaTribunal Constitucional — decisions published up to 17 August 2026
tribunalconstitucional.gob.do
Link checked 19 August 2026
How long you must keep it — and when to delete it
The floors are much stronger than the ceilings. Businesses covered by the money-laundering rules must keep transaction records, customer checks, account files and business correspondence for at least ten years after the relationship ends. Tax and accounting records also run ten years. Internet and telephone providers must keep traffic, connection and access records for at least ninety days. Anyone who runs a credit check must keep the customer's written permission for six months. Going the other way, the only real deletion rule is that a credit history may not report events older than forty-eight months, and that inaccurate or incomplete data must be corrected or removed. If a keep-it rule and a delete-it rule collide, the keep-it rule wins, because the law says the right to have data erased does not apply where another law requires it to be kept.
Ten-year floors: article 43 of the anti-money-laundering law for regulated businesses, and article 50(h) of the Tax Code as rewritten by article 105 of the same law, covering accounting books, special registers, receipts and any document, on paper or electronic, relating to the taxpayer's operations. Ninety-day floor: article 56 of the high-technology crimes law, which binds service providers including internet providers and can be extended by a prosecutor's preservation order of up to ninety days, renewable. Six-month floor: the credit-checking permission, during which the person cannot deny having authorised the check. Forty-eight-month ceiling: the credit reporting window. The general law's erasure right is expressly disapplied where a contractual or legal duty to retain exists, which is how the conflict resolves.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, article 43 (ten-year record keeping) and article 105 (ten-year tax record keeping)
consultoria.gov.do
“Los Sujetos Obligados deben conservar todos los registros necesarios sobre transacciones, medidas de debida diligencia, archivos de cuentas, correspondencia comercial, y los resultados de los análisis realizados, durante al menos 10 años después de finalizada la relación comercial.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 53-07 sobre Crímenes y Delitos de Alta Tecnología, article 56 — ninety-day minimum retention by service providers
consultoria.gov.do
“los proveedores de servicio deberan conservar los datos de trafico, conexion, acceso o cualquier otra informacion que pueda ser de utilidad a la investigacion, por un periodo minimo de noventa (90) dias.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 5 and 14 (erasure yields to legal retention duties) and the forty-eight-month credit reporting window
consultoria.gov.do
Link checked 19 August 2026
If something goes wrong
There is no general duty to report a data breach. The 2013 law does not contain one, so a private company that loses customer data owes no report to any authority and no notice to the people affected. Two narrower clocks do exist. Government bodies must report a cybersecurity incident immediately, and the report must reach the national cyber team or the sector team within twenty-four hours of detection. Banks and payment system participants must run a documented incident process and answer to the financial sector's own incident response team, but the regulation sets no fixed number of hours. Everyone can also report voluntarily to the National Cybersecurity Centre, which runs a public reporting page.
The absence of a private-sector breach duty is the single most surprising feature of this regime and the one most often misread. It is not a gap that a regulator has filled by guidance, because there is no regulator. It does not mean silence is safe: the general duties of security and secrecy still apply, an affected person can sue for damages, and knowingly revealing data you were legally bound to keep secret is a criminal offence. Deliberate or bad-faith unauthorised access to a personal database is separately criminal. The twenty-four hour public sector clock comes from the November 2022 decree on cyber maturity in public administration, which also requires follow-up reports as soon as new information emerges and warns that containment steps must not destroy evidence.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 685-22, article 12 — mandatory incident reporting by public bodies within twenty-four hours
consultoria.gov.do
“Los entes y órganos de la Administración Pública, inmediatamente y sin demora, deberán reportar los incidentes de ciberseguridad que les afecten... Estos comunicarán el incidente dentro de las primeras 24 horas de haber sido detectado.”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, articles 31 and 49 to 58 — incident management and the financial sector incident response team
sb.gob.do
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadReportar incidentes — the National Cybersecurity Centre's incident reporting channel
cncs.gob.do
What catches people out
Five things that are not in the summary. First, breaking this law is a crime: any person or company that violates it faces six months to two years in prison plus a fine of one hundred to one hundred and fifty times the monthly minimum wage, which runs to tens of thousands of US dollars. Second, selling or offering a list of email addresses without the owners' express consent is a separate crime under the anti-spam law, carrying six months to five years, and it is the public prosecutor who brings it. Third, the absence of a breach report duty is not protection, because the person harmed can sue and a prosecutor can charge. Fourth, records of who really owns a company must be held inside the country, which quietly breaks a fully offshore corporate-records setup. Fifth, there is no authority to give you a ruling, a licence or a comfort letter, so there is no way to buy certainty in advance.
A sixth trap worth knowing: your internet or hosting provider must be able to produce ninety days of traffic and access records on demand, which sits badly with architectures that expire logs in thirty days. A seventh: children are not given a special age threshold in this law at all — it simply defers to the children's code, the penal code and other special laws, so there is no clear digital age of consent to design to. An eighth: credit reference companies are ring-fenced. They must be authorised by the Monetary Board, listed in a public register held by the Superintendency of Banks, and no bank or other deposit-taking institution may own shares in one. Anyone misusing a credit report faces prison.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, articles 84 to 88 — exceptional, civil and criminal sanctions
consultoria.gov.do
“Artículo 88.- El suscriptor o afiliado, el cliente o consumidor, los representantes de las entidades públicas, o cualquier persona física o jurídica que viole las disposiciones contenidas en la presente ley, será sancionada con prisión correccional de seis meses a dos años, y una multa de cien (100) a ciento cincuenta (150) salarios mínimos vigentes.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 310-14 que regula el envío de correos electrónicos comerciales no solicitados, articles 12 and 13
consultoria.gov.do
“Ofrecer la venta de bases de datos con direcciones de correos electrónicos sin el consentimiento expreso de los propietarios de los mismos, con el objetivo de generar comunicaciones comerciales no solicitadas.”
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, article 104 — beneficial ownership information to be kept within Dominican territory
consultoria.gov.do
Link checked 19 August 2026
What's changing next
Three things are moving. A cybersecurity bill of sixty-four articles, covering public administration and critical infrastructure, went to a Senate committee in September 2025 and was still being studied there; it is a bill, so it binds nobody yet. The telecommunications institute has put forward a proposal for a new telecommunications law to replace the 1998 statute. And the operational risk rules for banks, approved in November 2025, have parts that only start to bite on the first of April 2027. We found no bill in either chamber to replace the 2013 data protection law or to create a data protection authority.
Three dormant switches matter more than the pending bills. First, the anti-money-laundering law already says a regulation will fix the place inside Dominican territory where beneficial ownership records must be kept; issuing that regulation would turn a quiet statutory phrase into an operational storage requirement overnight. Second, the June 2026 interoperability and data governance decree hands the Ministry of Public Administration open-ended power to issue binding standards, guides and minimum controls for public sector data and for private contractors touching it, with no consultation step in the text. Third, the same decree makes the Comptroller General the auditor of compliance, which creates an enforcement pathway for public sector data that did not exist before. Watch also the National Cybersecurity Centre, which sits inside the national intelligence directorate and expanded its remit through decrees in 2022 and 2024.
Sources
- Official sourceSenado de la República DominicanaComisión de Transporte y Telecomunicaciones avanza en la evaluación del proyecto de ley de Ciberseguridad, 3 September 2025
senadord.gob.do
Link checked 19 August 2026
- Official sourceInstituto Dominicano de las TelecomunicacionesIndotel presenta propuesta de nueva Ley de Telecomunicaciones para modernizar el sector
indotel.gob.do
Link checked 19 August 2026
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 403-26 — Marco Nacional de Interoperabilidad y Gobernanza de Datos, articles 37 and 48
consultoria.gov.do
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional — provisions commencing 1 April 2027
sb.gob.do
“establecidos en este Reglamento entrarán en vigencia a partir del 1º de abril del 2027.”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Ley No. 155-17 contra el Lavado de Activos y el Financiamiento del Terrorismo
Act of parliament · Ley núm. 155-17, Gaceta Oficial núm. 10886 de 1 de junio de 2017, articles 43, 104 and 105
The anti-money-laundering law sets the country's real retention floor at ten years, for both regulated businesses and ordinary taxpayers. It also rewrote the Tax Code so that records of who really owns a company must be held at a place inside Dominican territory, which is the only genuine data residency requirement we found anywhere in Dominican law.
Enforced by Directorate General of Internal Taxes
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryInformation about the real human owners of a company must be kept at a place within Dominican territory, to be set by regulation. We could not confirm that the implementing regulation has been issued, so the storage location duty is treated as not yet operative.
- Keep records of processingBeneficial ownership information must be updated no later than six months after any change.
- Keep data for a minimum period — 10 yearsTen years for transaction records, due diligence, account files, business correspondence and analysis results, counted from the end of the relationship or the date of an occasional transaction.
- Keep data for a minimum period — applies at: All taxpayers, 10 yearsTen years for accounting books, special registers, receipts and any document, physical or electronic, relating to the taxpayer's operations.
- Appoint a data protection officerNot a privacy officer: regulated businesses must appoint a senior compliance officer who acts as the link to the Financial Analysis Unit and the supervisor.
What it costs if you get it wrong
- Criminal liabilityMoney laundering offences under the same law
- Fixed maximum fineAdministrative breaches by regulated businesses; serious breaches prescribe after five years
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 155-17, articles 43, 104 and 105
consultoria.gov.do
“Reglamentariamente se determinará la información de los beneficiarios finales que es necesario obtener, el lugar donde deba conservarse dentro del territorio dominicano y la periodicidad de actualización, que en ningún caso será superior a los 6 meses posteriores a los cambios ocurridos en el beneficiario final.”
Link checked 19 August 2026
Reglamento de Seguridad Cibernética y de la Información
Directly binding regulation · Junta Monetaria, Segunda Resolución de 1 de noviembre de 2018 (JM 181101-02), read with the Reglamento sobre Riesgo Operacional, Cuarta Resolución de 27 de noviembre de 2025 (JM 251127-04)
The banking cybersecurity rulebook. It expressly allows cloud and outsourced processing, including abroad, on condition that the bank documents a policy, runs a risk analysis, and writes an inspection right for the Superintendency of Banks into the contract. There is no requirement to keep banking data in the country, but the supervisor can object to an arrangement it does not like.
Enforced by Superintendency of Banks
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataBoard-approved cybersecurity programme, a cybersecurity and information security officer, and a functional committee.
- Written vendor contractCloud services are permitted but need a documented policy and a risk analysis. Outsourcing contracts must let the Superintendency of Banks inspect the provider, and the Superintendency may object to the arrangement.
- Report cyber incidentsDocumented incident management, forensic capability and participation in the financial sector's incident response team. The regulation sets no fixed reporting deadline in hours.
- Independent auditInternal audit of the cybersecurity programme, plus continuity stress tests at least once a year.
- Assess high-risk projectsRisk analysis required before contracting cloud services and before outsourcing.
What it costs if you get it wrong
- Fixed maximum fineBreach by a financial intermediation entity, under the sanctions regulation of the monetary and financial system
- Order to stopPrecautionary measures available to the supervisor
Sources
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento de Seguridad Cibernética y de la Información, Junta Monetaria, 1 November 2018
sb.gob.do
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / Junta MonetariaReglamento sobre Riesgo Operacional, Junta Monetaria, 27 November 2025, articles 51, 52 and 89
sb.gob.do
Link checked 19 August 2026
- Official sourceSuperintendencia de BancosReglamento de Seguridad Cibernética y de la Información — regulator's own page
sb.gob.do
Link checked 19 August 2026
Decreto núm. 685-22 que establece los principios y lineamientos generales para la adopción de controles, políticas y estándares de madurez cibernética en el sector público
Directly binding regulation · Decreto núm. 685-22, Gaceta Oficial núm. 11088 de 18 de noviembre de 2022
Government bodies under the executive branch must report cybersecurity incidents within twenty-four hours of detection to the National Cybersecurity Centre or their sector incident response team. The duty does not reach private companies, and the other branches of the state may opt in but are not bound.
Enforced by National Cybersecurity Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursPublic bodies must report immediately and without delay; the report must reach the national or sectoral incident response team within twenty-four hours of detection.
- Secure the dataIncident classification into low, medium, high and critical levels; a service interruption of more than eight hours counts towards critical.
- Keep records of processingContainment measures must not destroy evidence, and follow-up reports are required as soon as new information appears.
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 685-22, articles 1 to 14
consultoria.gov.do
“Estos comunicarán el incidente dentro de las primeras 24 horas de haber sido detectado, acompañando toda la información necesaria para valorar su impacto.”
Link checked 19 August 2026
- Official sourceCentro Nacional de CiberseguridadCSIRT-RD — the national incident response team
cncs.gob.do
Link checked 19 August 2026
Decreto núm. 403-26 que aprueba el Reglamento que establece el Marco Nacional de Interoperabilidad y Gobernanza de Datos de la Administración Pública
Directly binding regulation · Decreto núm. 403-26, Gaceta Oficial núm. 11247 de 19 de junio de 2026
A brand new framework for how the Dominican state governs and shares its own data. It requires classification before sharing, traceable audit logs, a lawful basis where personal data is involved, and hard limits on private contractors who touch public data. It sets no location requirement, and it repealed the earlier interoperability decrees.
Enforced by Ministry of Public Administration
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep records of processingEvery act of data sharing between public bodies must be traceable, auditable and recordable, with audit logs kept for as long as the law requires.
- Allowed because the law requires itWhere the exchange involves personal or sensitive data, a lawful basis must be identified before the exchange, and the data protection framework applies on top.
- Written vendor contractPrivate contractors, concessionaires and technology partners may only reach public data exceptionally, with express authorisation, and may not reuse, transfer, keep or exploit it beyond the purpose that justified access.
- Let people delete their dataOnce the purpose ends, the third party must stop processing immediately and return, block, delete or restrict the data.
- Independent auditThe Comptroller General audits compliance across public administration.
What it costs if you get it wrong
- Claims by individualsCivil, administrative, criminal or contractual liability for authorised third parties who breach the access conditions
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoDecreto núm. 403-26, articles 17, 23, 36, 37, 49 and 50
consultoria.gov.do
“Los terceros autorizados no podrán reutilizar, ceder, transferir, conservar, explotar o tratar la información obtenida por interoperabilidad fuera de la finalidad que justificó su acceso.”
Link checked 19 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley No. 172-13 que tiene por objeto la protección integral de los datos personales asentados en archivos, registros públicos, bancos de datos u otros medios técnicos de tratamiento de datos
Act of parliament · Ley núm. 172-13, Gaceta Oficial núm. 10737 de 15 de diciembre de 2013
The general personal data law. It grants access, correction, erasure and a court-based habeas data claim, and lets data leave the country on any of nine listed grounds with consent first among them. It creates no data protection authority, no register of controllers and no breach reporting duty, and it hands administrative fining power to the banking regulator over credit reference companies alone. Its real teeth are criminal.
Enforced by Superintendency of Banks
Transfer model: No restriction · Accepted routes: Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Get consent
- Tell people what you do
- Let people see their dataFree of charge four times a year for credit information, at intervals of not less than three months.
- Let people correct their data
- Let people delete their dataDoes not apply where a contractual or legal duty to retain the data exists.
- Secure the data
- Extra vendor secrecy termsThe duty of professional secrecy binds everyone involved at any stage and survives the end of the relationship.
- Delete data after a period — applies at: Credit history reporting window, 4 yearsCredit reference companies may not report credit events older than forty-eight months.
- Keep data for a minimum period — applies at: Users of credit reports, 6 monthsThe written permission to run a credit check must be kept for six months.
- Register or notify — applies at: Credit reference companies onlyAuthorisation by the Monetary Board plus entry in a public register held by the Superintendency of Banks. There is no register for ordinary controllers.
- Put a transfer safeguard in placeOne of nine statutory grounds must apply. No paperwork is filed with any authority.
What it costs if you get it wrong
- Criminal liability: Prisión correccional de 6 meses a 2 años y multa de 100 a 150 salarios mínimosAny person or company that breaches the law
- Criminal liability: Multa de 10 a 50 salarios mínimosKnowingly inserting false data, passing on false data, unlawfully accessing a personal database, or revealing data you were legally bound to keep secret
- Fixed maximum fine: Multa de 10 a 100 salarios mínimosAdministrative breach by a credit reference company, imposed by the Superintendency of Banks
- Loss of your licenceA credit reference company that does not start operating within six months of authorisation
- Claims by individualsDamage suffered by an individual as a result of a breach of the law
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 172-13, full text, Gaceta Oficial núm. 10737
consultoria.gov.do
Link checked 19 August 2026
- Official sourceCámara de DiputadosLey No. 172-13 sobre protección de datos personales, 13 December 2013
camaradediputados.gob.do
Link checked 19 August 2026
Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología
Act of parliament · Ley núm. 53-07, Gaceta Oficial núm. 10416 de 23 de abril de 2007
Service providers, including internet providers, must keep traffic, connection and access records for at least ninety days so that they can be produced in a criminal investigation. Prosecutors can order preservation, real-time collection and interception through the courts. The law told the telecommunications institute to write implementing rules within six months of 2007.
Enforced by Dominican Telecommunications Institute
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 3 monthsAt least ninety days of traffic, connection and access data, or anything else useful to an investigation. The law does not say where it must be stored.
- Keep data for a minimum period — 3 monthsA prosecutor may separately order preservation of a system or its data for up to ninety days, renewable for further periods.
What it costs if you get it wrong
- Criminal liabilityTrading in data obtained during an investigation, or disclosing personal data of an accused person beyond the scope of the investigation
Sources
- Official sourceConsultoría Jurídica del Poder EjecutivoLey No. 53-07, articles 53 to 59
consultoria.gov.do
“los proveedores de servicio deberan conservar los datos de trafico, conexion, acceso o cualquier otra informacion que pueda ser de utilidad a la investigacion, por un periodo minimo de noventa (90) dias.”
Link checked 19 August 2026
- Official sourceInstituto Dominicano de las TelecomunicacionesMarco Legal — Indotel lists Ley 53-07, Ley 310-14 and Ley 172-13 among the laws affecting its functions
indotel.gob.do
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the regulation fixing the place inside Dominican territory where beneficial ownership records must be kept has actually been issued
The statute says the location will be set by regulation. No decree with that subject appears in the official national law repository, and the tax authority's own regulations index returned a not-found error on 19 August 2026. It may exist as a General Norm of the tax authority that we could not open. The residency duty is therefore recorded as partially in force.
Whether the securities regulator imposes any technology, outsourcing or data localisation rules on market participants
The Superintendency of the Securities Market's website returned an access-denied error to every automated request on 19 August 2026, so its norms could not be read. This is the largest unchecked gap in the sectoral layer.
Whether the insurance supervisor imposes any data or cloud rules
The insurance supervisor's site redirects to a different host and its normative index was not read. No insurance data instrument appears in the national law repository.
The current peso value of the minimum monthly wage used to calculate fines
Fines in the data protection law, the anti-spam law and the high-technology crimes law are all expressed as multiples of the minimum wage. The labour ministry's minimum wage page could not be located on 19 August 2026, so the US dollar approximations given here are indicative only.
Whether the Superintendency of Banks has ever imposed a sanction under the data protection law on a credit reference company
The Superintendency's sanctions page requires JavaScript and returned no readable content. We can evidence the power but not its use.
The current stage of the 2025 cybersecurity bill
The Senate's own news page evidences it was in committee in September 2025 and that hearings were being held. We found no later official record, so we cannot say whether it has advanced, stalled or lapsed. It is recorded as a bill with no legal effect.
Whether the telecommunications institute ever issued the implementing regulation on preservation of provider data that the 2007 law ordered within six months
Not located on the regulator's own site. The ninety-day statutory floor stands regardless.
Whether any court has ruled on the ambiguity in the international transfer article, which by its own words governs only transfers that require the data subject's consent
No decision on this point was located on the Constitutional Court's site, which does not expose a full-text search to automated access.
60-day cadence. Three dormant switches justify the shorter interval: the regulation that would fix where beneficial ownership records must be kept, the open-ended standard-setting power the June 2026 decree hands the Ministry of Public Administration, and a cybersecurity bill sitting in a Senate committee that would give the country its first cross-sector incident regime. Add to that two unread regulators, securities and insurance, which should be revisited whenever their sites become reachable.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Dominican Republic versus
Compare