Uruguay
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Uruguay — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Uruguay copies the European model. You can send personal data out of Uruguay, but you need a reason. Either the destination is on the regulator's approved list, or you have consent, protective contract clauses, or the regulator's permission. You must register every database before you use it. The regulator is small but real, and publishes decisions most months. Fines are capped low.
Data governance in Uruguay
The eight things that decide how you handle data about people in Uruguay. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law applies even if you have no office in Uruguay. It covers you if you offer goods or services to people in Uruguay. It also covers you if you study how they behave. And it covers you if you use equipment in Uruguay, such as a network, a server or a data centre. There is no size or revenue threshold to fall below. If your only link is data passing through Uruguay on its way elsewhere, you do not have to register your databases. But you must name a representative who lives in Uruguay.
- What you have to do here:
- Appoint a representative · Register or notify
Uruguay's reach beyond its borders was added by articles 37 to 40 of Law 19.670 of 15 October 2018. Article 2 of Decree 64/020 of 17 February 2020 spells it out. The regulator reads 'means situated in the country' very broadly. Its own guidance for foreign companies says the means can be technical, human, physical, logical or other. Any of them creates a link with Uruguayan territory. The transit-only exemption works only if you appoint a representative based in Uruguay and registered with the regulator. You also cannot contract out of the law. The guidance says the parties may never exclude Uruguayan law where it applies.
Sources
- Official sourceUnidad Reguladora y de Control de Datos Personales (URCDP)Guia para el cumplimiento de obligaciones de entidades extranjeras - ambito de aplicacion
gub.uy
Link checked 19 August 2026
- Official sourceDireccion Nacional de Impresiones y Publicaciones Oficiales (IMPO), official consolidated textDecreto 64/020, article 2 (scope; representative in national territory)
impo.com.uy
“siempre que ... el responsable del tratamiento designe un representante domiciliado en territorio nacional”
Link checked 19 August 2026
Where the data is allowed to live
In general yes, but with paperwork. You may not send personal data to a country that does not protect it well enough. Uruguay publishes a list of the countries and schemes that do. For anywhere else you need consent, protective contract clauses, or the regulator's permission. Two areas are much harder. They are financial firms supervised by the central bank, and central government bodies.
INDUSTRY BY INDUSTRY, checked 19 August 2026. BANKING and most other firms supervised by the central bank (a copy must stay in the country). Article 35.1.1 of the central bank's consolidated financial rulebook requires express prior authorisation from the Financial Services Superintendency. You need it for any outsourced service supplied from abroad. You also need it where the supplier sits in Uruguay but does the work wholly or partly from abroad. Article 35.3 then says that where data is handled abroad, one of the backup copies required by article 492 must be physically located in Uruguay. There is only one way to skip the in-country copy. You build a single physical access point inside Uruguay, at head office or a branch. It needs the infrastructure and the decryption keys to reach every offshore system continuously. You must test it at least once a year. Sometimes the offshore work counts as 'significant'. That means more than 15 per cent of gross income. Or more than 20 per cent of the cost of handling the data. Or no realistic alternative supplier. Then the host country must be rated BBB- or better. Or the supplier must be a bank rated BBB+ or better. Or it must be inside the same financial group. The same article applies to credit administrators, financial services companies, representative offices and crowdfunding platform operators, but without the 'significant' test. INSURANCE and REINSURANCE (a copy must stay in the country). Articles 16.1.1, 16.3 and 120.3 of the insurance rulebook were replaced by Circular 2422 of 30 December 2022. They carry word for word the same permission duty, the same in-Uruguay backup copy, and the same single access point alternative. SECURITIES and MARKETS (a copy must stay in the country). The securities rulebook is current to Circular 2508 of 7 August 2026. It repeats the identical wording for stock exchanges, intermediaries, fund managers and other supervised market firms. It cross-refers to its own article 255.2. CENTRAL GOVERNMENT (data must stay in the country). Article 3 of Decree 92/014 of 7 April 2014 requires Central Administration computer systems to sit in secure data centres inside the country. The only exception is systems that pose no risk. AGESIC, the digital government agency, polices this and may grant exceptions on properly reasoned grounds. EDUCATION. We found no rule about where data must be stored. Public education bodies still go through the regulator one transfer at a time. The national education technology plan Ceibal needed its own transfer permission in April 2026. HEALTH. We found no storage-location rule in the national electronic health record decree, checked 19 August 2026. Health data is sensitive data under the general law, so you need a transfer impact assessment. TELECOMS, GAMBLING, MAPPING, DEFENCE. We found no rule requiring data to stay in the country, checked 19 August 2026. Online gambling is not regulated at all yet.
Sources
- Official sourceIMPO, official consolidated textLaw 18.331, article 23 (international transfer of data)
impo.com.uy
“Se prohibe la transferencia de datos personales de cualquier tipo con paises u organismos internacionales que no proporcionen niveles de proteccion adecuados”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero, articles 35.1.1, 35.3 and 492 (text current to Circular 2506 of 23 June 2026)
bcu.gub.uy
“Con relacion al resguardo de la informacion en el exterior, una de las copias a que refiere el articulo 492 debera radicarse fisicamente en el Uruguay y permanecer accesible a los funcionarios de la Superintendencia de Servicios Financieros”
Link checked 19 August 2026
- Official sourceIMPO, official text of the decree as published in the Diario OficialDecree 92/014, article 3 (Central Administration systems in national data centres)
impo.com.uy
“Los sistemas informaticos ... de la Administracion Central deberan estar alojados en centros de datos seguros situados en territorio nacional, exceptuandose aquellos que no constituyan un riesgo para el organismo”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayCircular 2422 of 30 December 2022 - insurance and reinsurance rulebook, data safeguarding and outsourcing
bcu.gub.uy
Link checked 19 August 2026
What to do: Plan for a database inside Uruguay: this data is not allowed to leave.
Sending data out of the country
Uruguay uses a list of approved destinations, and the list is full, not empty. If your destination is on it, you send the data with no extra permission. You still register the database. If it is not on the list, you need three things, or any one of them. The person's clear consent. A contract with protective clauses. Or written permission from the regulator. Since June 2026 the regulator recommends the Council of Europe's model contract clauses as the safest wording.
- What you have to do here:
- Assess high-risk projects
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · To save someone’s life
Article 23 of Law 18.331 sets the ban and its exceptions. Resolution 23/021 of 8 June 2021 replaced the earlier 2019 list and removed the United States. Resolution 63/023 of 21 November 2023 set the current list. It covers the European Union and European Economic Area member states. It also covers Andorra, Argentina, Canada for the private sector, Guernsey, the Isle of Man and the Faroe Islands. And Israel, Japan, Jersey, New Zealand, the United Kingdom and Switzerland. It added two more. South Korea, for organisations under its Personal Information Protection Act. And the United States, but only for organisations on the Data Privacy Framework list published by the US Department of Commerce. Transfers still follow the limits and exceptions in the European decisions that approved those countries. Resolution 8/026 was adopted in 2026 and announced by the regulator on 1 June 2026. It recommends the Council of Europe model contract clauses under Convention 108+. You need a data protection impact assessment before transferring to a place without adequate protection. The regulator grants individual permissions case by case and publishes them. Examples during 2026 include Ceibal in April 2026 and McKinsey and Company in June 2026.
Sources
- Official sourceURCDPResolution 63/023 of 21 November 2023 - updated list of adequate jurisdictions
gub.uy
Link checked 19 August 2026
- Official sourceURCDPCambios en el regimen de transferencias internacionales de datos en Uruguay (Resolution 23/021 replacing 4/019; United States removed)
gub.uy
Link checked 19 August 2026
- Official sourceURCDPTransferencia - regulator's transfer hub, including Resolution 8/026 recommending Council of Europe model clauses and published individual transfer authorisations
gub.uy
Link checked 19 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Personal Data Regulation and Control Unit enforces the law. It sits inside the digital government agency. It is working. It is staffed and publishes numbered decisions most months. It rules on complaints against private companies and even against the state bank. It also approves transfers abroad one by one. Its biggest fine is capped at about three point three million Uruguayan pesos, roughly eighty thousand US dollars. Cyber incidents go to a separate team in the same agency. Financial firms answer to the central bank as well.
- What it costs if you get it wrong:
- Fixed maximum fine · Order to stop
Law 18.331 created the unit in 2008, with technical autonomy inside AGESIC. Here is the evidence of activity as at 19 August 2026. Over one thousand Executive Council resolutions are published. Resolution 42/025 of 19 December 2025 decided a complaint against Banco de la Republica Oriental del Uruguay. It was dismissed and no breach was found. Resolution 4/026 of 6 March 2026 dealt with a complaint against Alfa Plast. Resolution 9/026A of 24 April 2026 dealt with a complaint against G4S Secure Solutions Uruguay. Resolution 12/026 of 18 June 2026 authorised a transfer for McKinsey and Company. Database registration approvals continued steadily into August 2026. Article 35 of Law 18.331 sets the penalty ladder. It runs from observation, to warning, to a fine of up to 500,000 indexed units. Then a five-day suspension of the database, and finally its closure. One indexed unit was worth 6.6353 pesos on 19 August 2026, so the ceiling is about 3.3 million pesos. Money fines look rare in the published record. The unit's ordinary output is complaint rulings, opinions and registrations. That is why we rate enforcement as active rather than aggressive.
Sources
- Official sourceURCDPConsejo Ejecutivo - published resolutions, including complaint decisions and transfer authorisations 2025-2026
gub.uy
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textLaw 18.331, article 35 (sanctioning powers)
impo.com.uy
“Multa de hasta 500.000 UI (quinientas mil unidades indexadas)”
Link checked 19 August 2026
- Official sourceInstituto Nacional de EstadisticaUnidad Indexada, August 2026 daily values (6.6353 pesos on 19 August 2026)
www5.ine.gub.uy
Link checked 19 August 2026
How long you must keep it — and when to delete it
Two rules pull in opposite directions. You must keep company account books for twenty years and financial paperwork for ten. Anti-money-laundering customer records run for five years after the relationship ends. Security logs run for at least twelve months. Pulling the other way, records of unpaid commercial debts about a person must come off a database after five years. That can be extended once by another five years. A debt that has been paid off may stay for at most five years, and that cannot be renewed.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUMS. Article 497 of the central bank rulebook keeps company books for the twenty years set by the Commercial Code, counted from the last entry. It keeps documents, forms, correspondence and every other operational record for at least ten years. Article 297.2 requires anti-money-laundering customer files to be kept for at least five years after the relationship ends. Article 654 requires money transfer and cash-in-transit firms to keep transaction records for at least ten years. Article 10 of Decree 66/025 requires audit logs to be kept for at least twelve months. MAXIMUMS. Article 22 of Law 18.331 is the firm stop for credit and commercial debt data about individuals. It allows five years from the debt arising. One five-year renewal is available, but only if you ask in the thirty days before it expires. Debts already settled get a maximum of five years, which cannot be renewed, and must be marked as settled. The general principles of the law also require you to delete data once you no longer need it for the purpose you collected it for. CONFLICT. Uruguay publishes no single tie-breaker. Usually the industry minimum wins for that industry's records, because the law requires you to keep them. That does not let you reuse the data for anything else.
Sources
- Official sourceIMPO, official consolidated textLaw 18.331, article 22 (retention ceiling for commercial and credit data)
impo.com.uy
“Los datos personales relativos a obligaciones de caracter comercial de personas fisicas solo podran estar registrados por un plazo de cinco anos”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero, articles 297.2, 497 and 654 (retention floors)
bcu.gub.uy
“Los libros sociales originales o los soportes de informacion que contengan su reproduccion deberan conservarse hasta el cumplimiento del plazo de 20 (veinte) anos”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 66/025, article 10 (audit logs kept at least twelve months)
impo.com.uy
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count two deadlines. If personal data is exposed, you have seventy-two hours from finding out to tell the privacy regulator. You must also tell the people affected if the harm to them is serious. Separately, public bodies and private operators of critical services have twenty-four hours from finding out. They report a cyber incident to the national cyber team. A bank hit by ransomware is running both deadlines at once. It also owes its own report to the central bank.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE ONE, seventy-two hours. Decree 64/020 covers the company that decides how the data is used. It must tell the regulator within a maximum of 72 hours of learning about the breach. It must also tell affected people, in clear language, where they are significantly affected. DEADLINE TWO, twenty-four hours. Article 80 of Law 20.212 of 6 November 2023 covers public bodies, and private bodies linked to critical services or industries. They must report cybersecurity incidents to AGESIC within twenty-four hours of learning about them. Article 10 of Decree 66/025 repeats the twenty-four hour duty to CERTuy. That decree was signed on 20 February 2025 and published on 14 March 2025. Its article 12 adds a duty to report a possible incident fully and immediately. The decree also requires each covered body to name an information security officer with technical independence. DEADLINE THREE. Firms supervised by the central bank owe separate incident reporting to the Financial Services Superintendency, covering operations and outsourcing. We did not confirm a specific deadline in hours, and we have flagged that gap.
Sources
- Official sourceIMPO, official consolidated textDecree 64/020 (breach notification within 72 hours; DPO; impact assessments)
impo.com.uy
“plazo maximo de 72 horas de conocida la vulneracion”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textLaw 20.212, article 80 (national cyber incident registry; 24-hour reporting)
impo.com.uy
“entidades publicas y las entidades privadas vinculadas a servicios o sectores criticos del pais, deberan comunicar la ocurrencia de incidentes de ciberseguridad a AGESIC en un plazo de veinticuatro horas de conocido”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 66/025 of 20 February 2025 (duties of AGESIC's information security directorate; CERTuy reporting)
impo.com.uy
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things cost people their weekend in Uruguay. You must register every database with the regulator. That filing is the single most common thing foreign companies miss. Financial firms need two separate permissions to handle data abroad, not one. The threshold for appointing a data protection officer is low. Being a United States company is not enough to be on the approved list. And selling software to a government ministry can drag you into a hosting rule you never priced in.
- What you have to do here:
- Register or notify · Appoint a data protection officer · Put a transfer safeguard in place
1. REGISTRATION IS REAL AND IT IS THE MAIN EVENT. You must register each database with the regulator, and keep doing so. The regulator's published output is dominated by these approvals. Numbered registration resolutions ran into the 240s by 7 August 2026. There is no minimum size, so a small customer list counts. 2. TWO PERMISSIONS, NOT ONE. Circular 2422 says the central bank's outsourcing permission does not replace anything you owe the Personal Data Regulation and Control Unit. You may still need database registrations and international transfer permissions from that unit. Getting the banking approval does not get you the privacy approval. The reverse is also true. 3. THE DATA PROTECTION OFFICER THRESHOLD IS LOW. Decree 64/020 requires one for all public bodies. It also requires one for private bodies whose core business involves sensitive data. And for any private body handling the personal data of more than thirty-five thousand people. That last number catches mid-size retailers and employers that would be well below a threshold elsewhere. 4. THE UNITED STATES IS ONLY PARTLY APPROVED. The United States sits on the approved list only for organisations on the Data Privacy Framework list kept by the US Department of Commerce. A US supplier that is not on that list counts as an unapproved destination. You then need clauses, consent or a specific permission. Uruguay removed the United States from the list entirely in 2021, so this has already flipped once. 5. GOVERNMENT CUSTOMERS BRING A HOSTING RULE. Decree 92/014 requires Central Administration systems to sit in secure data centres on Uruguayan soil. AGESIC can grant a reasoned exception. A cloud vendor bidding to a ministry may need local hosting, or an exception it does not control.
Sources
- Official sourceURCDPURCDP Normativa - stream of database registration resolutions to August 2026
gub.uy
Link checked 19 August 2026
- Official sourceBanco Central del UruguayCircular 2422, article 16.1.1 - central bank authorisation is without prejudice to URCDP registration and transfer authorisation
bcu.gub.uy
“sin perjuicio de las inscripciones de las bases de datos y autorizaciones de transferencia internacional de datos personales que puedan corresponder ante la Unidad Reguladora y de Control de Datos Personales”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 64/020 (data protection officer required above 35,000 data subjects)
impo.com.uy
Link checked 19 August 2026
- Official sourceAGESICRequisitos de uso de la Nube para las entidades publicas
gub.uy
Link checked 19 August 2026
What's changing next
Nothing binding is due in the next twelve months. Artificial intelligence rules are being built step by step. The government agency was ordered to write a national data and artificial intelligence strategy. It must report to parliament with recommendations for a law. A governance decree followed in December 2025. Controlled testing spaces opened in May 2026, with the privacy regulator involved. A bill to regulate online betting was promised for 2026 but is not law. The bigger risk is the powers the government already holds.
COMING. Article 74 of Law 20.212 told AGESIC to design a national data and artificial intelligence strategy with the privacy regulator. It must also give parliament recommendations for regulating artificial intelligence in law. Decree 276/025 of 2 December 2025 put the governance in place. On 26 May 2026 five state bodies launched controlled testing environments for data and artificial intelligence use. They include AGESIC, the industry ministry, the innovation agency and the privacy regulator. None of this is binding regulation yet. A government bill to regulate online gambling was trailed for the first half of 2026. We found no official text, and it is not law. POWERS THE GOVERNMENT ALREADY HOLDS, which matter more. 1. The privacy regulator can rewrite the list of approved destinations by its own resolution. No consultation and no notice are needed. It has done exactly that twice. It removed the United States in June 2021 and partly restored it in November 2023. Any approval you rely on can be withdrawn by a single resolution. 2. The Financial Services Superintendency decides for itself whether an offshore arrangement is 'significant'. That decision switches on host-country credit-rating conditions, and it can apply to arrangements already running. 3. The same Superintendency can order a supervised firm to stop using a named outsourcer. Every outsourcing contract must contain that termination ground. 4. AGESIC controls exceptions to the government hosting rule and may simply decline to renew one. 5. Uruguay ratified the updated Council of Europe data protection convention, known as Convention 108+, through Law 19.948. Work to line up with it is the most likely driver of the next round of domestic change.
Sources
- Official sourceIMPO, official consolidated textLaw 20.212, article 74 (national data and artificial intelligence strategy; report to parliament)
impo.com.uy
Link checked 19 August 2026
- Official sourceMinisterio de Industria, Energia y MineriaOrganismos del Estado lanzaron instrumento de Entornos Controlados de Prueba (26 May 2026; Decree 276/025)
gub.uy
Link checked 19 August 2026
- Official sourceURCDPEvidence the adequacy list can be rewritten by resolution alone (United States removed in 2021)
gub.uy
Link checked 19 August 2026
- Secondary sourceYogonetGovernment to present an online gambling bill in the first half of 2026
yogonet.com
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Finance data needs a copy kept in the country
Official name: Recopilacion de Normas de Regulacion y Control del Sistema Financiero, articulos 35.1.1, 35.3, 492 y 497 · Circular 2419 (resolution of 27 December 2022, in force from Diario Oficial 13 January 2023); consolidated text current to Circular 2506 of 23 June 2026 · Directly binding regulation
Banks and most other firms supervised by the central bank need express permission before any data is handled abroad. They must also keep one backup copy inside Uruguay. The alternative is to build a controlled access point in the country. Big offshore arrangements also face country and supplier rating tests.
Enforced by Financial Services Superintendency, Central Bank of Uruguay
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Keep the data in the countryOne of the required backup copies must be physically in Uruguay and reachable by supervisors. The alternative is a single physical access point inside Uruguay, at head office or a branch. It must give total continuous control of all offshore data, backups and decryption keys. Test it at least once a year.
- Register or notifyExpress prior authorisation from the Financial Services Superintendency for any outsourcing done from abroad. You supply the draft contract and a risk assessment.
- Written vendor contractYour contract must say where the data is handled. It must give supervisors unrestricted audit access. It must also cover return and deletion of data at the end, continuity during intervention or liquidation, and termination on the supervisor's instruction.
- Hold a security certificateWhere offshore work counts as significant, one of three things must be true. The host country is rated BBB- or better. Or the supplier is a bank rated BBB+ or better. Or it is inside the same financial group, with recognised independent security, continuity and quality certifications.
- Keep data for a minimum period — 20 yearsCompany books twenty years; operational documents and safeguarded information at least ten years.
- Independent auditAnnual documented tests of the access point, of backup recovery and of the continuity plan.
What it costs if you get it wrong
- Order to stopThe Superintendency may revoke the outsourcing authorisation and order the firm to stop using the provider.
- Loss of your licencePersistent non-compliance with supervisory instructions.
Sources
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero (consolidated, current to Circular 2506 of 23 June 2026)
bcu.gub.uy
“Se admitira que no se radique una copia en Uruguay cuando las instituciones implementen y disponibilicen un espacio fisico con la infraestructura tecnologica necesaria para permitir el acceso y control total, continuo y permanente de todos los datos procesados en el exterior del pais”
Link checked 19 August 2026
Insurance data needs a copy kept in the country
Official name: Recopilacion de Normas de Seguros y Reaseguros, articulos 16.1.1, 16.1.2, 16.3, 120.1 y 120.3 · Circular 2422 of 30 December 2022 (Superintendency resolution of 27 December 2022) · Regulator directive
Insurers and reinsurers face the same rules as banks. They need permission before handling data abroad. They keep a backup copy inside Uruguay, or a local access point instead. Supervisors get access to everything, wherever it sits. The regulator applies matching wording to securities market firms.
Enforced by Financial Services Superintendency, Central Bank of Uruguay
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryOne backup copy physically in Uruguay, or a unified access point located in the country.
- Register or notifyExpress Superintendency authorisation for outsourcing done from abroad. Changes to what it covers need a fresh application.
- Extra vendor secrecy termsThe risk report must specifically assess the legal risk to information covered by secrecy duties under Uruguayan law.
- Secure the dataDaily backups, at least two copies, one stored a reasonable distance away in a different building, plus safeguarding of decryption keys.
What it costs if you get it wrong
- Order to stopAuthorisation may be revoked where the arrangement deviates from what was approved.
Sources
- Official sourceBanco Central del UruguayCircular N. 2422 - Recopilacion de Normas de Seguros y Reaseguros, modificaciones en lo relativo a resguardo de datos y tercerizaciones
bcu.gub.uy
“Con relacion al resguardo de la informacion en el exterior, una de las copias a que refiere el articulo 120.3 debera radicarse fisicamente en el Uruguay”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas del Mercado de Valores (consolidated, current to Circular 2508 of 7 August 2026) - identical wording for securities market participants
bcu.gub.uy
Link checked 19 August 2026
Government data must stay in the country
Official name: Decreto N. 92/014, articulo 3 (centros de datos seguros) y articulo 5 (fiscalizacion y excepciones) · Decreto 92/014 of 7 April 2014, published in the Diario Oficial on 24 April 2014 · Directly binding regulation
Uruguayan central government bodies must keep their computer systems in secure data centres inside Uruguay. There are two ways out. The system carries no risk, or the digital government agency grants a specific exception. This reaches any cloud vendor selling to a ministry.
Enforced by Agency for Electronic Government and the Information and Knowledge Society
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryCentral Administration computer systems must sit in secure data centres inside the country. The exception is systems that pose no risk to the body under the attached guidelines.
- Assess high-risk projectsA prior information risk analysis is required, and the digital government agency may grant exceptions on duly reasoned grounds.
Sources
- Official sourceIMPO, official text as published in the Diario OficialDecreto N. 92/014, articulo 3
impo.com.uy
“Los sistemas informaticos (art. 3 del Decreto N 451/009 de 28 de setiembre de 2009) de la Administracion Central deberan estar alojados en centros de datos seguros situados en territorio nacional”
Link checked 19 August 2026
- Official sourceAGESICRequisitos de uso de la Nube para las entidades publicas
gub.uy
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley N. 18.331 de Proteccion de Datos Personales y Accion de Habeas Data, as amended by articles 37 to 40 of Ley N. 19.670 · Ley 18.331 (11 August 2008); Ley 19.670 (15 October 2018), arts. 37-40; Decreto 414/009; Decreto 64/020 (17 February 2020) · Act of parliament
Uruguay's general privacy law applies to foreign companies that target people in Uruguay or use equipment there. Data may only go to an approved destination. Otherwise you need consent, protective clauses or the regulator's permission. You must register every database first.
Enforced by Personal Data Regulation and Control Unit
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life
What you have to do
- Register or notifyEvery database must be registered with the regulator before use. There is no small-business exemption.
- Appoint a data protection officer — applies at: All public bodies; private bodies whose core business is sensitive data; private bodies processing data on more than 35,000 people., from 17 February 2020
- Appoint a representativeRequired where your only link to Uruguay is data passing through. In exchange, you do not have to register your databases.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleRequired in clear language where the person is significantly affected.
- Assess high-risk projectsRequired before starting, including for any transfer to a destination without adequate protection.
- Put a transfer safeguard in place
- Delete data after a period — 5 yearsCommercial and credit debt data about individuals: five years, one renewal of five years, and five years non-renewable once the debt is settled.
What it costs if you get it wrong
- Fixed maximum fine: 500,000 Unidades Indexadas (about 3.3 million Uruguayan pesos on 19 August 2026) — about $80 thousandBreach of the data protection law by a database controller or processor.
- Order to stop: Five-day suspension of the database, then closure of the databaseRepeated or serious breach.
Sources
- Official sourceIMPO, official consolidated textLey N. 18.331 - Proteccion de Datos Personales y Accion de Habeas Data
impo.com.uy
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecreto 64/020 - regulation of articles 37 to 40 of Ley 19.670
impo.com.uy
“plazo maximo de 72 horas de conocida la vulneracion”
Link checked 19 August 2026
General data protection law (2023)
Official name: Resolucion N. 63/023, ampliacion de jurisdicciones adecuadas, building on Resolucion N. 23/021 and complemented by Resolucion N. 8/026 on model contractual clauses · URCDP Resolucion 23/021 (8 June 2021); Resolucion 63/023 (21 November 2023); Resolucion 8/026 (2026) · Official “this country is safe” decision
The regulator publishes the list of destinations it considers safe enough to receive personal data without extra permission. The list is full, not empty. The regulator can rewrite it by its own resolution at any time.
Enforced by Personal Data Regulation and Control Unit
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed
What you have to do
- Put a transfer safeguard in placeApproved destinations are the European Union and European Economic Area states. Also Andorra, Argentina, Canada (private sector), Guernsey, Isle of Man and the Faroe Islands. Also Israel, Japan, Jersey, New Zealand, the United Kingdom and Switzerland. South Korea counts for organisations under its privacy law. The United States counts only for organisations on the Data Privacy Framework list.
- Assess high-risk projectsRequired for transfers to any destination not on the list.
Sources
- Official sourceURCDPTransferencia internacional - regulator hub including Resolucion 8/026 recommending Council of Europe model contractual clauses
gub.uy
Link checked 19 August 2026
Breach reporting rules
Official name: Decreto N. 66/025, cometidos y atribuciones de la Direccion de Seguridad de la Informacion de AGESIC, reglamentando el articulo 80 de la Ley N. 20.212 · Ley 20.212 of 6 November 2023, art. 80; Decreto 66/025 promulgated 20 February 2025, published 14 March 2025 · Directly binding regulation
Public bodies and private operators of critical services must report cyber incidents to the national cyber team within twenty-four hours. They must keep audit logs for at least a year and name an information security officer. This deadline runs alongside the seventy-two hour privacy breach deadline, not instead of it.
Enforced by National Computer Security Incident Response Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — applies at: Public entities and private entities linked to critical services or sectors., within 24 hours
- Keep logs — 1 year
- Appoint a data protection officerYou need an information security officer with technical independence. That is a separate role from the data protection officer under the privacy law.
- Secure the dataAdopt the government's national cybersecurity standard, plus effective measures for critical information assets.
What it costs if you get it wrong
- Order to stopThe information security directorate issues warnings and reports non-compliance to the General Assembly twice a year; there is no cash fine attached.
Sources
- Official sourceIMPO, official consolidated textLey N. 20.212, articulo 80 (Registro Nacional de Incidentes de Ciberseguridad)
impo.com.uy
“deberan comunicar la ocurrencia de incidentes de ciberseguridad a AGESIC en un plazo de veinticuatro horas de conocido”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecreto N. 66/025
impo.com.uy
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That Uruguayan telecoms law imposes no rule forcing data to stay in the country or traffic-data retention duty on operators
The regulator's site serves the decree text through a third-party link we could not read. So we found no such rule, but we could not confirm it against the full text. Treat this as medium confidence, checked 19 August 2026.
That health data has no storage-location rule in Uruguay
The 2017 national electronic health record decree contains no rule about where data must be stored. We did not obtain the Ministry of Public Health orders issued under it. If you are a regulated healthcare provider, check before you rely on this.
The exact adoption date of URCDP Resolution 8/026 on Council of Europe model contractual clauses
The regulator's resolution index dates it 17 April 2026. The regulator's own news item announces approval on 1 June 2026. Both are on the regulator's site and they disagree. Plan to the earlier date.
A specific incident-reporting deadline in hours owed by financial firms to the Central Bank
The consolidated rulebook requires continuous availability and supervisor access. We could not find a numbered incident-reporting deadline. If you are supervised, assume the 24-hour and 72-hour national deadlines apply. Ask your supervisor whether there is a third.
The US dollar value of the maximum fine
We confirmed the indexed unit at 6.6353 pesos on 19 August 2026 from the national statistics institute. We did not confirm the peso-to-dollar rate on that date. The eighty thousand dollar figure is an approximation, not a checked conversion.
Whether any online gambling bill has actually been introduced in Parliament during 2026
Only trade press reported the government's intention to present one in the first half of 2026. We found no official parliamentary text. So we record this as an intention, not as a bill in progress.
Whether the URCDP has issued any monetary fine in 2025 or 2026
The complaint decisions we read ended without a fine. We could not read all of the more than one thousand published resolutions. So the absence of fines comes from a sample, and is not proven.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 90 days. Next check due 17 November 2026.