Skip to the content
Global Data RulesData governance rules, country by country

Uruguay

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Uruguay — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Uruguay copies the European model. You can send personal data out of Uruguay, but you need a reason. Either the destination is on the regulator's approved list, or you have consent, protective contract clauses, or the regulator's permission. You must register every database before you use it. The regulator is small but real, and publishes decisions most months. Fines are capped low.

Data governance in Uruguay

The eight things that decide how you handle data about people in Uruguay. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law applies even if you have no office in Uruguay. It covers you if you offer goods or services to people in Uruguay. It also covers you if you study how they behave. And it covers you if you use equipment in Uruguay, such as a network, a server or a data centre. There is no size or revenue threshold to fall below. If your only link is data passing through Uruguay on its way elsewhere, you do not have to register your databases. But you must name a representative who lives in Uruguay.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

In general yes, but with paperwork. You may not send personal data to a country that does not protect it well enough. Uruguay publishes a list of the countries and schemes that do. For anywhere else you need consent, protective contract clauses, or the regulator's permission. Two areas are much harder. They are financial firms supervised by the central bank, and central government bodies.

What to do: Plan for a database inside Uruguay: this data is not allowed to leave.

Sending data out of the country

Uruguay uses a list of approved destinations, and the list is full, not empty. If your destination is on it, you send the data with no extra permission. You still register the database. If it is not on the list, you need three things, or any one of them. The person's clear consent. A contract with protective clauses. Or written permission from the regulator. Since June 2026 the regulator recommends the Council of Europe's model contract clauses as the safest wording.

What you have to do here:
Assess high-risk projects
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Personal Data Regulation and Control Unit enforces the law. It sits inside the digital government agency. It is working. It is staffed and publishes numbered decisions most months. It rules on complaints against private companies and even against the state bank. It also approves transfers abroad one by one. Its biggest fine is capped at about three point three million Uruguayan pesos, roughly eighty thousand US dollars. Cyber incidents go to a separate team in the same agency. Financial firms answer to the central bank as well.

What it costs if you get it wrong:
Fixed maximum fine · Order to stop

How long you must keep it — and when to delete it

Two rules pull in opposite directions. You must keep company account books for twenty years and financial paperwork for ten. Anti-money-laundering customer records run for five years after the relationship ends. Security logs run for at least twelve months. Pulling the other way, records of unpaid commercial debts about a person must come off a database after five years. That can be extended once by another five years. A debt that has been paid off may stay for at most five years, and that cannot be renewed.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count two deadlines. If personal data is exposed, you have seventy-two hours from finding out to tell the privacy regulator. You must also tell the people affected if the harm to them is serious. Separately, public bodies and private operators of critical services have twenty-four hours from finding out. They report a cyber incident to the national cyber team. A bank hit by ransomware is running both deadlines at once. It also owes its own report to the central bank.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things cost people their weekend in Uruguay. You must register every database with the regulator. That filing is the single most common thing foreign companies miss. Financial firms need two separate permissions to handle data abroad, not one. The threshold for appointing a data protection officer is low. Being a United States company is not enough to be on the approved list. And selling software to a government ministry can drag you into a hosting rule you never priced in.

What you have to do here:
Register or notify · Appoint a data protection officer · Put a transfer safeguard in place

What's changing next

Nothing binding is due in the next twelve months. Artificial intelligence rules are being built step by step. The government agency was ordered to write a national data and artificial intelligence strategy. It must report to parliament with recommendations for a law. A governance decree followed in December 2025. Controlled testing spaces opened in May 2026, with the privacy regulator involved. A bill to regulate online betting was promised for 2026 but is not law. The bigger risk is the powers the government already holds.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Finance data needs a copy kept in the country

Official name: Recopilacion de Normas de Regulacion y Control del Sistema Financiero, articulos 35.1.1, 35.3, 492 y 497 · Circular 2419 (resolution of 27 December 2022, in force from Diario Oficial 13 January 2023); consolidated text current to Circular 2506 of 23 June 2026 · Directly binding regulation

In forceA copy must stay

Banks and most other firms supervised by the central bank need express permission before any data is handled abroad. They must also keep one backup copy inside Uruguay. The alternative is to build a controlled access point in the country. Big offshore arrangements also face country and supplier rating tests.

In force since 13 January 2023

Enforced by Financial Services Superintendency, Central Bank of Uruguay

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Insurance

Insurance data needs a copy kept in the country

Official name: Recopilacion de Normas de Seguros y Reaseguros, articulos 16.1.1, 16.1.2, 16.3, 120.1 y 120.3 · Circular 2422 of 30 December 2022 (Superintendency resolution of 27 December 2022) · Regulator directive

In forceA copy must stay

Insurers and reinsurers face the same rules as banks. They need permission before handling data abroad. They keep a backup copy inside Uruguay, or a local access point instead. Supervisors get access to everything, wherever it sits. The regulator applies matching wording to securities market firms.

In force since 30 December 2022

Enforced by Financial Services Superintendency, Central Bank of Uruguay

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Government data must stay in the country

Official name: Decreto N. 92/014, articulo 3 (centros de datos seguros) y articulo 5 (fiscalizacion y excepciones) · Decreto 92/014 of 7 April 2014, published in the Diario Oficial on 24 April 2014 · Directly binding regulation

In forceNo — it stays put

Uruguayan central government bodies must keep their computer systems in secure data centres inside Uruguay. There are two ways out. The system carries no risk, or the digital government agency grants a specific exception. This reaches any cloud vendor selling to a ministry.

In force since 24 April 2014

Enforced by Agency for Electronic Government and the Information and Knowledge Society

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley N. 18.331 de Proteccion de Datos Personales y Accion de Habeas Data, as amended by articles 37 to 40 of Ley N. 19.670 · Ley 18.331 (11 August 2008); Ley 19.670 (15 October 2018), arts. 37-40; Decreto 414/009; Decreto 64/020 (17 February 2020) · Act of parliament

In forceYes, with paperwork

Uruguay's general privacy law applies to foreign companies that target people in Uruguay or use equipment there. Data may only go to an approved destination. Otherwise you need consent, protective clauses or the regulator's permission. You must register every database first.

In force since 18 August 2008Enforced from 17 February 2020

Enforced by Personal Data Regulation and Control Unit

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life

General data protection law (2023)

Official name: Resolucion N. 63/023, ampliacion de jurisdicciones adecuadas, building on Resolucion N. 23/021 and complemented by Resolucion N. 8/026 on model contractual clauses · URCDP Resolucion 23/021 (8 June 2021); Resolucion 63/023 (21 November 2023); Resolucion 8/026 (2026) · Official “this country is safe” decision

In forceYes, with paperwork

The regulator publishes the list of destinations it considers safe enough to receive personal data without extra permission. The list is full, not empty. The regulator can rewrite it by its own resolution at any time.

In force since 21 November 2023

Enforced by Personal Data Regulation and Control Unit

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed

Breach reporting rules

Official name: Decreto N. 66/025, cometidos y atribuciones de la Direccion de Seguridad de la Informacion de AGESIC, reglamentando el articulo 80 de la Ley N. 20.212 · Ley 20.212 of 6 November 2023, art. 80; Decreto 66/025 promulgated 20 February 2025, published 14 March 2025 · Directly binding regulation

In forceYes — store it anywhere

Public bodies and private operators of critical services must report cyber incidents to the national cyber team within twenty-four hours. They must keep audit logs for at least a year and name an information security officer. This deadline runs alongside the seventy-two hour privacy breach deadline, not instead of it.

In force since 14 March 2025

Enforced by National Computer Security Incident Response Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Unidad Reguladora y de Control de Datos Personales (URCDP)

    General privacy law: database registration, complaints, international transfer authorisations, adequacy list.

    Staffed and working. Publishes numbered Executive Council resolutions most months, and over one thousand are on the public register. Recent examples follow. A complaint against the state bank BROU was decided on 19 December 2025. A complaint against Alfa Plast was decided on 6 March 2026. A complaint against G4S Secure Solutions Uruguay was decided on 24 April 2026. A transfer permission for McKinsey and Company was granted on 18 June 2026. Database registration resolutions ran to number 240 by 7 August 2026. Cash fines are rare in the published record and capped at 500,000 indexed units, roughly eighty thousand US dollars.

  • Agencia de Gobierno Electronico y Sociedad de la Informacion y del Conocimiento (AGESIC)

    Government cloud and data centre rules, national cybersecurity framework, national data and artificial intelligence strategy. Hosts the privacy regulator.

    Actively issuing policy. It made the national cybersecurity standard mandatory under Decree 66/025 in 2025. It issued artificial intelligence governance decree 276/025 in December 2025. It launched regulatory testing spaces in May 2026.

  • Superintendencia de Servicios Financieros, Banco Central del Uruguay

    Banks, credit administrators, financial services companies, payment and crowdfunding platforms, insurers, reinsurers and securities market participants. Authorises offshore data processing and enforces the in-country copy rule.

    Highly active rule-maker. The financial rulebook was current to Circular 2506 of 23 June 2026 and the securities rulebook to Circular 2508 of 7 August 2026 when checked.

  • CERTuy, Direccion de Seguridad de la Informacion de AGESIC

    Cyber incident reporting for public bodies and private operators of critical services.

    Given legal footing by article 80 of Law 20.212 and Decree 66/025. A state cybersecurity coordination group was publicised in December 2025. It involves CERTuy, the Interior Ministry and the privacy regulator.

  • Unidad Reguladora de Servicios de Comunicaciones (URSEC)

    Telecoms and postal services licensing and supervision.

    Working. We found no telecoms rule requiring data to stay in the country. We found no data retention duty either. Checked in its published rulebook on 19 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That Uruguayan telecoms law imposes no rule forcing data to stay in the country or traffic-data retention duty on operators

    The regulator's site serves the decree text through a third-party link we could not read. So we found no such rule, but we could not confirm it against the full text. Treat this as medium confidence, checked 19 August 2026.

  • That health data has no storage-location rule in Uruguay

    The 2017 national electronic health record decree contains no rule about where data must be stored. We did not obtain the Ministry of Public Health orders issued under it. If you are a regulated healthcare provider, check before you rely on this.

  • The exact adoption date of URCDP Resolution 8/026 on Council of Europe model contractual clauses

    The regulator's resolution index dates it 17 April 2026. The regulator's own news item announces approval on 1 June 2026. Both are on the regulator's site and they disagree. Plan to the earlier date.

  • A specific incident-reporting deadline in hours owed by financial firms to the Central Bank

    The consolidated rulebook requires continuous availability and supervisor access. We could not find a numbered incident-reporting deadline. If you are supervised, assume the 24-hour and 72-hour national deadlines apply. Ask your supervisor whether there is a third.

  • The US dollar value of the maximum fine

    We confirmed the indexed unit at 6.6353 pesos on 19 August 2026 from the national statistics institute. We did not confirm the peso-to-dollar rate on that date. The eighty thousand dollar figure is an approximation, not a checked conversion.

  • Whether any online gambling bill has actually been introduced in Parliament during 2026

    Only trade press reported the government's intention to present one in the first half of 2026. We found no official parliamentary text. So we record this as an intention, not as a bill in progress.

  • Whether the URCDP has issued any monetary fine in 2025 or 2026

    The complaint decisions we read ended without a fine. We could not read all of the more than one thousand published resolutions. So the absence of fines comes from a sample, and is not proven.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 90 days. Next check due 17 November 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.