Skip to the content
Global Data RulesData governance rules, country by country

Uruguay

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Uruguay copies the European model. Personal data may leave the country, but only to a destination the regulator has approved, or with consent, protective contract clauses or the regulator's permission. Every database must be registered before you use it. The regulator is small but real: it publishes decisions most months. Fines are capped low.

Data governance in Uruguay

The eight things that decide how you handle data about people in Uruguay. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you with no office in Uruguay. The law applies to any organisation that offers goods or services to people in Uruguay, that studies how they behave, or that uses equipment located in Uruguay, such as a network, a server or a data centre. There is no size or revenue threshold to fall below. If your only connection is data passing through Uruguay on its way somewhere else, you are excused from registering your databases, but only if you name a representative who lives in Uruguay.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

In general yes, but with paperwork. Uruguay bans sending personal data to a country that does not protect it well enough, and keeps a published list of the countries and schemes that do. Anywhere else needs consent, protective contract clauses, or the regulator's permission. Two areas are far harder: financial firms supervised by the central bank, and central government bodies.

High confidenceYes, with paperworkAllowlistA copy must stayNo — it stays put

Sending data out of the country

The model is an approved-destinations list, and the list is full, not empty. If the destination is on it, you send the data with no extra permission, though you still register the database. If it is not, you need the person's clear consent, or a contract with protective clauses, or written permission from the regulator. Since June 2026 the regulator recommends the Council of Europe's model contract clauses as the safest wording.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesGovernment sign-off neededExplicit consentNeeded for a contractLegal claimsSomeone's life is at riskAssess high-risk projects

The regulator, and whether it actually acts

The Personal Data Regulation and Control Unit, which sits inside the digital government agency. It is genuinely working: it is staffed, it publishes numbered decisions most months, it rules on complaints against private companies and even against the state bank, and it approves transfers abroad one by one. Its biggest fine is capped at about three point three million Uruguayan pesos, roughly eighty thousand US dollars. Cyber incidents go to a separate team in the same agency, and financial firms answer to the central bank as well.

High confidenceActiveFixed maximum fineOrder to stop

How long you must keep it — and when to delete it

Two forces pull in opposite directions. Company account books must be kept for twenty years, financial paperwork for ten, anti-money-laundering customer records for five years after the relationship ends, and security logs for at least twelve months. Pulling the other way, records of unpaid commercial debts about a person must come off a database after five years, extendable once by another five, and a debt that has been paid off may stay for at most five years and cannot be renewed.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count two clocks. If personal data is exposed, you have seventy-two hours from finding out to tell the privacy regulator, and you must also tell the people affected if the harm to them is serious. Separately, if you are a public body or a private operator of a critical service, you have twenty-four hours from finding out to report a cyber incident to the national cyber team. A bank hit by ransomware is running both clocks at once, plus its own reporting duty to the central bank.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend in Uruguay. Every database must be registered with the regulator, and that filing is the single most common thing foreign companies miss. Financial firms need two separate permissions to process data abroad, not one. The threshold for appointing a data protection officer is low. Being a United States company is not enough to be on the approved list. And selling software to a government ministry can drag you into a hosting rule you never priced in.

High confidenceRegister or notifyAppoint a data protection officerKeep the data in the countryPut a transfer safeguard in place

What's changing next

Nothing binding is scheduled to land in the next twelve months. Artificial intelligence rules are being built up step by step: the government agency was ordered to write a national data and artificial intelligence strategy and report to parliament with recommendations for a law, a governance decree followed in December 2025, and controlled testing spaces opened in May 2026 with the privacy regulator involved. A bill to regulate online betting was promised for 2026 but is not law. The bigger risk is the switches the government already holds.

Medium confidenceProposedArtificial intelligence

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Recopilacion de Normas de Regulacion y Control del Sistema Financiero, articulos 35.1.1, 35.3, 492 y 497

Directly binding regulation · Circular 2419 (resolution of 27 December 2022, in force from Diario Oficial 13 January 2023); consolidated text current to Circular 2506 of 23 June 2026

In forceA copy must stay

Banks and most other central-bank-supervised firms need express permission before any data is processed abroad, and must keep one backup copy inside Uruguay unless they build a controlled access point in the country instead. Big offshore arrangements also face country and counterparty rating tests.

In force since 13 January 2023

Enforced by Financial Services Superintendency, Central Bank of Uruguay

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

High confidence
Insurance

Recopilacion de Normas de Seguros y Reaseguros, articulos 16.1.1, 16.1.2, 16.3, 120.1 y 120.3

Regulator directive · Circular 2422 of 30 December 2022 (Superintendency resolution of 27 December 2022)

In forceA copy must stay

Insurers and reinsurers face the same rules as banks: permission before processing abroad, a backup copy inside Uruguay or a local access point instead, and supervisor access to everything wherever it sits. The regulator applies matching wording to securities market firms.

In force since 30 December 2022

Enforced by Financial Services Superintendency, Central Bank of Uruguay

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Government

Decreto N. 92/014, articulo 3 (centros de datos seguros) y articulo 5 (fiscalizacion y excepciones)

Directly binding regulation · Decreto 92/014 of 7 April 2014, published in the Diario Oficial on 24 April 2014

In forceNo — it stays put

Uruguayan central government bodies must keep their computer systems in secure data centres inside Uruguay, unless the system carries no risk or the digital government agency grants a specific exception. This reaches any cloud vendor selling to a ministry.

In force since 24 April 2014

Enforced by Agency for Electronic Government and the Information and Knowledge Society

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley N. 18.331 de Proteccion de Datos Personales y Accion de Habeas Data, as amended by articles 37 to 40 of Ley N. 19.670

Act of parliament · Ley 18.331 (11 August 2008); Ley 19.670 (15 October 2018), arts. 37-40; Decreto 414/009; Decreto 64/020 (17 February 2020)

In forceYes, with paperwork

Uruguay's general privacy law reaches foreign companies that target people in Uruguay or use equipment there. Data may only go to an approved destination, or with consent, protective clauses or the regulator's permission, and every database must be registered first.

In force since 18 August 2008But only enforceable from 17 February 2020

Enforced by Personal Data Regulation and Control Unit

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk

High confidence

Resolucion N. 63/023, ampliacion de jurisdicciones adecuadas, building on Resolucion N. 23/021 and complemented by Resolucion N. 8/026 on model contractual clauses

Adequacy decision · URCDP Resolucion 23/021 (8 June 2021); Resolucion 63/023 (21 November 2023); Resolucion 8/026 (2026)

In forceYes, with paperwork

The regulator publishes the list of destinations considered safe enough to receive personal data without extra permission. The list is full, not empty, and the regulator can rewrite it by its own resolution at any time.

In force since 21 November 2023

Enforced by Personal Data Regulation and Control Unit

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed

High confidence

Decreto N. 66/025, cometidos y atribuciones de la Direccion de Seguridad de la Informacion de AGESIC, reglamentando el articulo 80 de la Ley N. 20.212

Directly binding regulation · Ley 20.212 of 6 November 2023, art. 80; Decreto 66/025 promulgated 20 February 2025, published 14 March 2025

In forceYes — store it anywhere

Public bodies and private operators of critical services must report cyber incidents to the national cyber team within twenty-four hours, keep audit logs for at least a year and name an information security officer. This clock runs alongside, not instead of, the seventy-two hour privacy breach clock.

In force since 14 March 2025

Enforced by National Computer Security Incident Response Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Unidad Reguladora y de Control de Datos Personales (URCDP)

    General privacy law: database registration, complaints, international transfer authorisations, adequacy list.

    Staffed and functioning. Publishes numbered Executive Council resolutions most months; over one thousand are on the public register. Recent examples: complaint against the state bank BROU decided 19 December 2025, complaint against Alfa Plast 6 March 2026, complaint against G4S Secure Solutions Uruguay 24 April 2026, transfer authorisation for McKinsey and Company 18 June 2026, and database registration resolutions running to number 240 by 7 August 2026. Cash fines are rare in the published record and capped at 500,000 indexed units, roughly eighty thousand US dollars.

  • Agencia de Gobierno Electronico y Sociedad de la Informacion y del Conocimiento (AGESIC)

    Government cloud and data centre rules, national cybersecurity framework, national data and artificial intelligence strategy. Hosts the privacy regulator.

    Actively issuing policy: cybersecurity framework made mandatory under Decree 66/025 in 2025, artificial intelligence governance decree 276/025 in December 2025, and regulatory sandboxes launched in May 2026.

  • Superintendencia de Servicios Financieros, Banco Central del Uruguay

    Banks, credit administrators, financial services companies, payment and crowdfunding platforms, insurers, reinsurers and securities market participants. Authorises offshore data processing and enforces the in-country copy rule.

    Highly active rule-maker. The financial rulebook was current to Circular 2506 of 23 June 2026 and the securities rulebook to Circular 2508 of 7 August 2026 when checked.

  • CERTuy, Direccion de Seguridad de la Informacion de AGESIC

    Cyber incident reporting for public bodies and private operators of critical services.

    Given statutory footing by article 80 of Law 20.212 and Decree 66/025; a state cybersecurity coordination mechanism involving CERTuy, the Interior Ministry and the privacy regulator was publicised in December 2025.

  • Unidad Reguladora de Servicios de Comunicaciones (URSEC)

    Telecoms and postal services licensing and supervision.

    Operational, but we found no telecoms data-localisation or data-retention mandate in its published rulebook as at 19 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That Uruguayan telecoms law imposes no data-localisation or traffic-data retention duty on operators

    We checked the regulator's normative index and the telecoms licensing decree landing page, but the regulator's site serves the decree text through a third-party link we could not render. This is a negative finding, checked 19 August 2026, at medium confidence rather than a proven absence.

  • That health data has no storage-location rule in Uruguay

    The national electronic health record decree of 2017 contains no location clause, but Ministry of Public Health ordinances issued under it were not retrieved. Treat as unverified for regulated healthcare providers.

  • The exact adoption date of URCDP Resolution 8/026 on Council of Europe model contractual clauses

    The regulator's resolution index dates it 17 April 2026 while its own news item announces approval on 1 June 2026. Both are on the regulator's site and they disagree. Plan to the earlier date.

  • A specific incident-reporting deadline in hours owed by financial firms to the Central Bank

    The consolidated rulebook imposes continuous availability and supervisory access duties, but we did not locate a numeric incident-reporting clock. A supervised firm should assume the 24-hour and 72-hour national clocks apply and ask its supervisor about a third.

  • The US dollar value of the maximum fine

    We verified the indexed unit at 6.6353 pesos on 19 August 2026 from the national statistics institute, but did not verify the peso-to-dollar rate on that date. The eighty thousand dollar figure is an approximation, not a checked conversion.

  • Whether any online gambling bill has actually been introduced in Parliament during 2026

    Only trade press reported the government's intention to present one in the first half of 2026. We found no official parliamentary text, so this is recorded as intention, not as a bill in progress.

  • Whether the URCDP has issued any monetary fine in 2025 or 2026

    The published complaint decisions we opened ended without a fine. We could not read every one of the more than one thousand published resolutions, so the absence of fines is an inference from a sample, not a proven fact.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 90 days. Next check due 17 November 2026.

Read the exact prompt used to research this page

Put this next to another country

Uruguay versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.