Uruguay
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Uruguay copies the European model. Personal data may leave the country, but only to a destination the regulator has approved, or with consent, protective contract clauses or the regulator's permission. Every database must be registered before you use it. The regulator is small but real: it publishes decisions most months. Fines are capped low.
Data governance in Uruguay
The eight things that decide how you handle data about people in Uruguay. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you with no office in Uruguay. The law applies to any organisation that offers goods or services to people in Uruguay, that studies how they behave, or that uses equipment located in Uruguay, such as a network, a server or a data centre. There is no size or revenue threshold to fall below. If your only connection is data passing through Uruguay on its way somewhere else, you are excused from registering your databases, but only if you name a representative who lives in Uruguay.
Territorial reach was added by articles 37 to 40 of Law 19.670 of 15 October 2018 and spelled out in article 2 of Decree 64/020 of 17 February 2020. The regulator reads 'means situated in the country' very broadly: its own guidance for foreign entities says the means may be 'tecnicos, humanos, fisicos, logicos u otros' and that any of them creates a connecting point with Uruguayan territory. The transit-only carve-out is conditional on appointing a locally domiciled representative before the regulator. Note also that the law's parties cannot contract out of it: the guidance states that in no case may contracting parties exclude the application of Uruguayan law where it applies.
Sources
- Official sourceUnidad Reguladora y de Control de Datos Personales (URCDP)Guia para el cumplimiento de obligaciones de entidades extranjeras - ambito de aplicacion
gub.uy
Link checked 19 August 2026
- Official sourceDireccion Nacional de Impresiones y Publicaciones Oficiales (IMPO), official consolidated textDecreto 64/020, article 2 (scope; representative in national territory)
impo.com.uy
“siempre que ... el responsable del tratamiento designe un representante domiciliado en territorio nacional”
Link checked 19 August 2026
Where the data is allowed to live
In general yes, but with paperwork. Uruguay bans sending personal data to a country that does not protect it well enough, and keeps a published list of the countries and schemes that do. Anywhere else needs consent, protective contract clauses, or the regulator's permission. Two areas are far harder: financial firms supervised by the central bank, and central government bodies.
SECTOR BY SECTOR, checked 19 August 2026. BANKING and most other central-bank-supervised firms (a copy must stay in the country). Article 35.1.1 of the central bank's consolidated financial rulebook requires express prior authorisation from the Financial Services Superintendency for any outsourced service provided by a party abroad, and also where the provider sits in Uruguay but performs the service wholly or partly from abroad. Article 35.3 then says that where data is processed abroad, one of the backup copies required by article 492 'debera radicarse fisicamente en el Uruguay'. You may skip the in-country copy only if you build a single physical access point inside Uruguay, at head office or a branch, with the infrastructure and the decryption keys to reach every offshore system continuously, tested at least yearly. Where the offshore processing is judged 'significant' (more than 15 per cent of gross income, or more than 20 per cent of processing cost, or no realistic alternative provider), the host country must be rated BBB- or better, or the processor must be a bank rated BBB+ or better, or be inside the same financial group. The same article is applied, minus the 'significant' test, to credit administrators, financial services companies, representative offices and crowdfunding platform operators. INSURANCE and REINSURANCE (a copy must stay in the country). Articles 16.1.1, 16.3 and 120.3 of the insurance rulebook, replaced by Circular 2422 of 30 December 2022, carry word-for-word the same authorisation duty, the same in-Uruguay backup copy and the same unified access point alternative. SECURITIES and MARKETS (a copy must stay in the country). The securities rulebook, current to Circular 2508 of 7 August 2026, repeats the identical wording for stock exchanges, intermediaries, fund managers and other supervised market participants, cross-referring to its own article 255.2. CENTRAL GOVERNMENT (data must stay in the country). Article 3 of Decree 92/014 of 7 April 2014 requires Central Administration computer systems to be housed in secure data centres located in national territory, excepting only systems that pose no risk. AGESIC, the digital government agency, polices this and may grant exceptions on duly reasoned grounds. EDUCATION. No localisation rule found. Public education bodies still go through the regulator one transfer at a time: the national education technology plan Ceibal needed its own transfer authorisation in April 2026. HEALTH. No storage-location rule found in the national electronic health record decree, checked 19 August 2026. Health data is sensitive data under the general law, so a transfer impact assessment is required. TELECOMS, GAMBLING, MAPPING, DEFENCE. No data-localisation rule found, checked 19 August 2026. Online gambling is not yet regulated at all.
Sources
- Official sourceIMPO, official consolidated textLaw 18.331, article 23 (international transfer of data)
impo.com.uy
“Se prohibe la transferencia de datos personales de cualquier tipo con paises u organismos internacionales que no proporcionen niveles de proteccion adecuados”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero, articles 35.1.1, 35.3 and 492 (text current to Circular 2506 of 23 June 2026)
bcu.gub.uy
“Con relacion al resguardo de la informacion en el exterior, una de las copias a que refiere el articulo 492 debera radicarse fisicamente en el Uruguay y permanecer accesible a los funcionarios de la Superintendencia de Servicios Financieros”
Link checked 19 August 2026
- Official sourceIMPO, official text of the decree as published in the Diario OficialDecree 92/014, article 3 (Central Administration systems in national data centres)
impo.com.uy
“Los sistemas informaticos ... de la Administracion Central deberan estar alojados en centros de datos seguros situados en territorio nacional, exceptuandose aquellos que no constituyan un riesgo para el organismo”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayCircular 2422 of 30 December 2022 - insurance and reinsurance rulebook, data safeguarding and outsourcing
bcu.gub.uy
Link checked 19 August 2026
Sending data out of the country
The model is an approved-destinations list, and the list is full, not empty. If the destination is on it, you send the data with no extra permission, though you still register the database. If it is not, you need the person's clear consent, or a contract with protective clauses, or written permission from the regulator. Since June 2026 the regulator recommends the Council of Europe's model contract clauses as the safest wording.
Article 23 of Law 18.331 sets the ban and its exceptions. Resolution 23/021 of 8 June 2021 replaced the earlier 2019 list and, importantly, removed the United States. Resolution 63/023 of 21 November 2023 restored the current list: the European Union and European Economic Area member states, Andorra, Argentina, Canada for the private sector, Guernsey, the Isle of Man, the Faroe Islands, Israel, Japan, Jersey, New Zealand, the United Kingdom and Switzerland, plus two additions: South Korea for entities under its Personal Information Protection Act, and the United States only for organisations appearing on the Data Privacy Framework list published by the US Department of Commerce. Transfers remain subject to the limits and carve-outs in the underlying European adequacy decisions. Resolution 8/026, adopted in 2026 and announced by the regulator on 1 June 2026, recommends the Council of Europe model contractual clauses under Convention 108+. A data protection impact assessment is required before transferring to a place without adequate protection. Individual authorisations are granted case by case and published: examples during 2026 include Ceibal in April 2026 and McKinsey and Company in June 2026.
Sources
- Official sourceURCDPResolution 63/023 of 21 November 2023 - updated list of adequate jurisdictions
gub.uy
Link checked 19 August 2026
- Official sourceURCDPCambios en el regimen de transferencias internacionales de datos en Uruguay (Resolution 23/021 replacing 4/019; United States removed)
gub.uy
Link checked 19 August 2026
- Official sourceURCDPTransferencia - regulator's transfer hub, including Resolution 8/026 recommending Council of Europe model clauses and published individual transfer authorisations
gub.uy
Link checked 19 August 2026
The regulator, and whether it actually acts
The Personal Data Regulation and Control Unit, which sits inside the digital government agency. It is genuinely working: it is staffed, it publishes numbered decisions most months, it rules on complaints against private companies and even against the state bank, and it approves transfers abroad one by one. Its biggest fine is capped at about three point three million Uruguayan pesos, roughly eighty thousand US dollars. Cyber incidents go to a separate team in the same agency, and financial firms answer to the central bank as well.
The unit was created by Law 18.331 in 2008 with technical autonomy inside AGESIC. Observable evidence of activity as at 19 August 2026: over one thousand published Executive Council resolutions; Resolution 42/025 of 19 December 2025 deciding a complaint against Banco de la Republica Oriental del Uruguay (dismissed, no breach found); Resolution 4/026 of 6 March 2026 on a complaint against Alfa Plast; Resolution 9/026A of 24 April 2026 on a complaint against G4S Secure Solutions Uruguay; Resolution 12/026 of 18 June 2026 authorising a transfer for McKinsey and Company; and a steady stream of database registration approvals into August 2026. The sanction ladder in article 35 of Law 18.331 runs from observation, warning and fine of up to 500,000 indexed units, to a five-day suspension of the database and finally its closure. One indexed unit was worth 6.6353 pesos on 19 August 2026, so the ceiling is about 3.3 million pesos. Money fines appear rare in the published record; the unit's ordinary output is complaint rulings, opinions and registrations. That is why enforcement is rated active rather than aggressive.
Sources
- Official sourceURCDPConsejo Ejecutivo - published resolutions, including complaint decisions and transfer authorisations 2025-2026
gub.uy
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textLaw 18.331, article 35 (sanctioning powers)
impo.com.uy
“Multa de hasta 500.000 UI (quinientas mil unidades indexadas)”
Link checked 19 August 2026
- Official sourceInstituto Nacional de EstadisticaUnidad Indexada, August 2026 daily values (6.6353 pesos on 19 August 2026)
www5.ine.gub.uy
Link checked 19 August 2026
How long you must keep it — and when to delete it
Two forces pull in opposite directions. Company account books must be kept for twenty years, financial paperwork for ten, anti-money-laundering customer records for five years after the relationship ends, and security logs for at least twelve months. Pulling the other way, records of unpaid commercial debts about a person must come off a database after five years, extendable once by another five, and a debt that has been paid off may stay for at most five years and cannot be renewed.
FLOOR. Article 497 of the central bank rulebook keeps company books for the twenty years set by the Commercial Code, counted from the last entry, and keeps documents, forms, correspondence and every other operational record for not less than ten years. Article 297.2 requires anti-money-laundering customer files to be kept for at least five years after the relationship ends. Article 654 requires money transfer and cash-in-transit firms to keep transaction records for at least ten years. Article 10 of Decree 66/025 requires audit logs to be kept for at least twelve months. CEILING. Article 22 of Law 18.331 is the hard stop for credit and commercial debt data about individuals: five years from the debt arising, one single five-year renewal available only if requested in the thirty days before expiry, and a maximum non-renewable five years for debts already settled, which must be marked as settled. The general principles of the law also require data to be deleted when it is no longer needed for the purpose it was collected for. CONFLICT. Uruguay publishes no single tie-breaker. In practice the sector minimum wins for the sector record, because keeping it is a legal obligation, but that does not license reusing the data for anything else.
Sources
- Official sourceIMPO, official consolidated textLaw 18.331, article 22 (retention ceiling for commercial and credit data)
impo.com.uy
“Los datos personales relativos a obligaciones de caracter comercial de personas fisicas solo podran estar registrados por un plazo de cinco anos”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero, articles 297.2, 497 and 654 (retention floors)
bcu.gub.uy
“Los libros sociales originales o los soportes de informacion que contengan su reproduccion deberan conservarse hasta el cumplimiento del plazo de 20 (veinte) anos”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 66/025, article 10 (audit logs kept at least twelve months)
impo.com.uy
Link checked 19 August 2026
If something goes wrong
Count two clocks. If personal data is exposed, you have seventy-two hours from finding out to tell the privacy regulator, and you must also tell the people affected if the harm to them is serious. Separately, if you are a public body or a private operator of a critical service, you have twenty-four hours from finding out to report a cyber incident to the national cyber team. A bank hit by ransomware is running both clocks at once, plus its own reporting duty to the central bank.
CLOCK ONE, seventy-two hours. Decree 64/020 requires the controller to notify the regulator within a maximum of 72 hours of becoming aware of the breach, and to notify affected individuals in clear language where they are significantly affected. CLOCK TWO, twenty-four hours. Article 80 of Law 20.212 of 6 November 2023 requires public entities and private entities linked to critical services or sectors to report cybersecurity incidents to AGESIC within twenty-four hours of becoming aware. Article 10 of Decree 66/025, promulgated 20 February 2025 and published 14 March 2025, repeats the twenty-four hour duty to CERTuy, and article 12 adds a duty to report a potential incident completely and immediately. The decree also requires each covered entity to name an information security officer with technical independence. CLOCK THREE. Central-bank-supervised firms owe separate operational and outsourcing incident reporting to the Financial Services Superintendency; we did not verify a specific deadline in hours and have flagged that gap.
Sources
- Official sourceIMPO, official consolidated textDecree 64/020 (breach notification within 72 hours; DPO; impact assessments)
impo.com.uy
“plazo maximo de 72 horas de conocida la vulneracion”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textLaw 20.212, article 80 (national cyber incident registry; 24-hour reporting)
impo.com.uy
“entidades publicas y las entidades privadas vinculadas a servicios o sectores criticos del pais, deberan comunicar la ocurrencia de incidentes de ciberseguridad a AGESIC en un plazo de veinticuatro horas de conocido”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 66/025 of 20 February 2025 (duties of AGESIC's information security directorate; CERTuy reporting)
impo.com.uy
Link checked 19 August 2026
What catches people out
Five things that cost people their weekend in Uruguay. Every database must be registered with the regulator, and that filing is the single most common thing foreign companies miss. Financial firms need two separate permissions to process data abroad, not one. The threshold for appointing a data protection officer is low. Being a United States company is not enough to be on the approved list. And selling software to a government ministry can drag you into a hosting rule you never priced in.
1. REGISTRATION IS REAL AND IT IS THE MAIN EVENT. Registering each database with the regulator is a standing obligation, and the regulator's published output is dominated by these approvals: numbered registration resolutions ran into the 240s by 7 August 2026. There is no de minimis for a small customer list. 2. TWO PERMISSIONS, NOT ONE. The central bank spells out in Circular 2422 that its outsourcing authorisation is granted 'sin perjuicio de las inscripciones de las bases de datos y autorizaciones de transferencia internacional de datos personales que puedan corresponder ante la Unidad Reguladora y de Control de Datos Personales'. Getting the banking approval does not get you the privacy approval, and vice versa. 3. THE DATA PROTECTION OFFICER THRESHOLD IS LOW. Decree 64/020 requires one for all public bodies, for private bodies whose core business involves sensitive data, and for any private body handling the personal data of more than thirty-five thousand people. That last number catches mid-size retailers and employers that would be nowhere near a threshold elsewhere. 4. UNITED STATES ADEQUACY IS PARTIAL. The United States sits on the approved list only for organisations that appear on the Data Privacy Framework list kept by the US Department of Commerce. A US supplier that is not on that list is a non-adequate destination and needs clauses, consent or a specific authorisation. Uruguay removed the United States entirely from the list in 2021, so this has already flipped once. 5. GOVERNMENT CUSTOMERS BRING A HOSTING RULE. Decree 92/014 obliges Central Administration systems to sit in secure data centres on Uruguayan soil unless AGESIC grants a reasoned exception. A cloud vendor bidding to a ministry may need either local hosting or an exception it does not control.
Sources
- Official sourceURCDPURCDP Normativa - stream of database registration resolutions to August 2026
gub.uy
Link checked 19 August 2026
- Official sourceBanco Central del UruguayCircular 2422, article 16.1.1 - central bank authorisation is without prejudice to URCDP registration and transfer authorisation
bcu.gub.uy
“sin perjuicio de las inscripciones de las bases de datos y autorizaciones de transferencia internacional de datos personales que puedan corresponder ante la Unidad Reguladora y de Control de Datos Personales”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecree 64/020 (data protection officer required above 35,000 data subjects)
impo.com.uy
Link checked 19 August 2026
- Official sourceAGESICRequisitos de uso de la Nube para las entidades publicas
gub.uy
Link checked 19 August 2026
What's changing next
Nothing binding is scheduled to land in the next twelve months. Artificial intelligence rules are being built up step by step: the government agency was ordered to write a national data and artificial intelligence strategy and report to parliament with recommendations for a law, a governance decree followed in December 2025, and controlled testing spaces opened in May 2026 with the privacy regulator involved. A bill to regulate online betting was promised for 2026 but is not law. The bigger risk is the switches the government already holds.
COMING. Article 74 of Law 20.212 tasked AGESIC with designing a national data and artificial intelligence strategy jointly with the privacy regulator, and with delivering recommendations for legal regulation of artificial intelligence to parliament. Decree 276/025 of 2 December 2025 put the governance in place. On 26 May 2026 five state bodies, including AGESIC, the industry ministry, the innovation agency and the privacy regulator, launched controlled testing environments aimed specifically at data and artificial intelligence use. None of this is binding regulation yet. A government bill to regulate online gambling was trailed for the first half of 2026; we found no official text and it is not law. DORMANT SWITCHES, which matter more. 1. The privacy regulator can rewrite the approved-destinations list by its own resolution, with no consultation and no notice. It has done exactly that twice: removing the United States in June 2021 and partially restoring it in November 2023. Any adequacy finding you rely on can be withdrawn by a single resolution. 2. The Financial Services Superintendency decides, on its own judgement, whether a given offshore processing arrangement is 'significant'. That switch turns on host-country credit-rating conditions retrospectively for arrangements already running. 3. The same Superintendency may order a supervised firm to stop using a named outsourcer, a termination ground the rules require every outsourcing contract to contain. 4. AGESIC controls exceptions to the government hosting rule and may simply decline to renew one. 5. Uruguay ratified the modernised Council of Europe data protection convention, known as Convention 108+, through Law 19.948. Alignment work under it is the most likely driver of the next round of domestic change.
Sources
- Official sourceIMPO, official consolidated textLaw 20.212, article 74 (national data and artificial intelligence strategy; report to parliament)
impo.com.uy
Link checked 19 August 2026
- Official sourceMinisterio de Industria, Energia y MineriaOrganismos del Estado lanzaron instrumento de Entornos Controlados de Prueba (26 May 2026; Decree 276/025)
gub.uy
Link checked 19 August 2026
- Official sourceURCDPEvidence the adequacy list can be rewritten by resolution alone (United States removed in 2021)
gub.uy
Link checked 19 August 2026
- Secondary sourceYogonetGovernment to present an online gambling bill in the first half of 2026
yogonet.com
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Recopilacion de Normas de Regulacion y Control del Sistema Financiero, articulos 35.1.1, 35.3, 492 y 497
Directly binding regulation · Circular 2419 (resolution of 27 December 2022, in force from Diario Oficial 13 January 2023); consolidated text current to Circular 2506 of 23 June 2026
Banks and most other central-bank-supervised firms need express permission before any data is processed abroad, and must keep one backup copy inside Uruguay unless they build a controlled access point in the country instead. Big offshore arrangements also face country and counterparty rating tests.
Enforced by Financial Services Superintendency, Central Bank of Uruguay
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Keep the data in the countryOne of the required backup copies must be physically located in Uruguay and reachable by supervisors. Alternative: a single physical access point inside Uruguay, at head office or a branch, giving total continuous control of all offshore data, backups and decryption keys, tested at least once a year.
- Register or notifyExpress prior authorisation from the Financial Services Superintendency for any outsourcing provided from abroad, supported by the draft contract and a risk assessment.
- Written vendor contractMandatory clauses include the processing location, unrestricted supervisor audit access, return and deletion of data at contract end, continuity during intervention or liquidation, and termination on the supervisor's instruction.
- Hold a security certificateWhere offshore processing is judged significant: host country rated BBB- or better, or the processor is a bank rated BBB+ or better, or is inside the same financial group with recognised independent security, continuity and quality certifications.
- Keep data for a minimum period — 20 yearsCompany books twenty years; operational documents and safeguarded information at least ten years.
- Independent auditAnnual documented tests of the access point, of backup recovery and of the continuity plan.
What it costs if you get it wrong
- Order to stopThe Superintendency may revoke the outsourcing authorisation and order the firm to stop using the provider.
- Loss of your licencePersistent non-compliance with supervisory instructions.
Sources
- Official sourceBanco Central del UruguayRecopilacion de Normas de Regulacion y Control del Sistema Financiero (consolidated, current to Circular 2506 of 23 June 2026)
bcu.gub.uy
“Se admitira que no se radique una copia en Uruguay cuando las instituciones implementen y disponibilicen un espacio fisico con la infraestructura tecnologica necesaria para permitir el acceso y control total, continuo y permanente de todos los datos procesados en el exterior del pais”
Link checked 19 August 2026
Recopilacion de Normas de Seguros y Reaseguros, articulos 16.1.1, 16.1.2, 16.3, 120.1 y 120.3
Regulator directive · Circular 2422 of 30 December 2022 (Superintendency resolution of 27 December 2022)
Insurers and reinsurers face the same rules as banks: permission before processing abroad, a backup copy inside Uruguay or a local access point instead, and supervisor access to everything wherever it sits. The regulator applies matching wording to securities market firms.
Enforced by Financial Services Superintendency, Central Bank of Uruguay
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryOne backup copy physically in Uruguay, or a unified access point located in the country.
- Register or notifyExpress Superintendency authorisation for outsourcing performed from abroad; changes to scope need a fresh application.
- Extra vendor secrecy termsThe risk report must specifically assess the legal risk to information covered by secrecy duties under Uruguayan law.
- Secure the dataDaily backups, at least two copies, one stored a reasonable distance away in a different building, plus safeguarding of decryption keys.
What it costs if you get it wrong
- Order to stopAuthorisation may be revoked where the arrangement deviates from what was approved.
Sources
- Official sourceBanco Central del UruguayCircular N. 2422 - Recopilacion de Normas de Seguros y Reaseguros, modificaciones en lo relativo a resguardo de datos y tercerizaciones
bcu.gub.uy
“Con relacion al resguardo de la informacion en el exterior, una de las copias a que refiere el articulo 120.3 debera radicarse fisicamente en el Uruguay”
Link checked 19 August 2026
- Official sourceBanco Central del UruguayRecopilacion de Normas del Mercado de Valores (consolidated, current to Circular 2508 of 7 August 2026) - identical wording for securities market participants
bcu.gub.uy
Link checked 19 August 2026
Decreto N. 92/014, articulo 3 (centros de datos seguros) y articulo 5 (fiscalizacion y excepciones)
Directly binding regulation · Decreto 92/014 of 7 April 2014, published in the Diario Oficial on 24 April 2014
Uruguayan central government bodies must keep their computer systems in secure data centres inside Uruguay, unless the system carries no risk or the digital government agency grants a specific exception. This reaches any cloud vendor selling to a ministry.
Enforced by Agency for Electronic Government and the Information and Knowledge Society
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryCentral Administration computer systems must sit in secure data centres in national territory, except systems that pose no risk to the body under the annexed guidelines.
- Assess high-risk projectsA prior information risk analysis is required, and the digital government agency may grant exceptions on duly reasoned grounds.
Sources
- Official sourceIMPO, official text as published in the Diario OficialDecreto N. 92/014, articulo 3
impo.com.uy
“Los sistemas informaticos (art. 3 del Decreto N 451/009 de 28 de setiembre de 2009) de la Administracion Central deberan estar alojados en centros de datos seguros situados en territorio nacional”
Link checked 19 August 2026
- Official sourceAGESICRequisitos de uso de la Nube para las entidades publicas
gub.uy
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley N. 18.331 de Proteccion de Datos Personales y Accion de Habeas Data, as amended by articles 37 to 40 of Ley N. 19.670
Act of parliament · Ley 18.331 (11 August 2008); Ley 19.670 (15 October 2018), arts. 37-40; Decreto 414/009; Decreto 64/020 (17 February 2020)
Uruguay's general privacy law reaches foreign companies that target people in Uruguay or use equipment there. Data may only go to an approved destination, or with consent, protective clauses or the regulator's permission, and every database must be registered first.
Enforced by Personal Data Regulation and Control Unit
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk
What it makes you do
- Register or notifyEvery database must be registered with the regulator before use. There is no small-business exemption.
- Appoint a data protection officer — applies at: All public bodies; private bodies whose core business is sensitive data; private bodies processing data on more than 35,000 people., from 17 February 2020
- Appoint a local representativeRequired where the only link to Uruguay is data in transit, in exchange for exemption from database registration.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleRequired in clear language where the person is significantly affected.
- Assess high-risk projectsRequired before starting, including for any transfer to a destination without adequate protection.
- Put a transfer safeguard in place
- Delete data after a period — 5 yearsCommercial and credit debt data about individuals: five years, one renewal of five years, and five years non-renewable once the debt is settled.
What it costs if you get it wrong
- Fixed maximum fine: 500,000 Unidades Indexadas (about 3.3 million Uruguayan pesos on 19 August 2026) — about $80 thousandBreach of the data protection law by a database controller or processor.
- Order to stop: Five-day suspension of the database, then closure of the databaseRepeated or serious breach.
Sources
- Official sourceIMPO, official consolidated textLey N. 18.331 - Proteccion de Datos Personales y Accion de Habeas Data
impo.com.uy
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecreto 64/020 - regulation of articles 37 to 40 of Ley 19.670
impo.com.uy
“plazo maximo de 72 horas de conocida la vulneracion”
Link checked 19 August 2026
Resolucion N. 63/023, ampliacion de jurisdicciones adecuadas, building on Resolucion N. 23/021 and complemented by Resolucion N. 8/026 on model contractual clauses
Adequacy decision · URCDP Resolucion 23/021 (8 June 2021); Resolucion 63/023 (21 November 2023); Resolucion 8/026 (2026)
The regulator publishes the list of destinations considered safe enough to receive personal data without extra permission. The list is full, not empty, and the regulator can rewrite it by its own resolution at any time.
Enforced by Personal Data Regulation and Control Unit
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeApproved destinations: European Union and European Economic Area states, Andorra, Argentina, Canada (private sector), Guernsey, Isle of Man, Faroe Islands, Israel, Japan, Jersey, New Zealand, United Kingdom, Switzerland, South Korea (entities under its privacy law) and the United States only for organisations on the Data Privacy Framework list.
- Assess high-risk projectsRequired for transfers to any destination not on the list.
Sources
- Official sourceURCDPTransferencia internacional - regulator hub including Resolucion 8/026 recommending Council of Europe model contractual clauses
gub.uy
Link checked 19 August 2026
Decreto N. 66/025, cometidos y atribuciones de la Direccion de Seguridad de la Informacion de AGESIC, reglamentando el articulo 80 de la Ley N. 20.212
Directly binding regulation · Ley 20.212 of 6 November 2023, art. 80; Decreto 66/025 promulgated 20 February 2025, published 14 March 2025
Public bodies and private operators of critical services must report cyber incidents to the national cyber team within twenty-four hours, keep audit logs for at least a year and name an information security officer. This clock runs alongside, not instead of, the seventy-two hour privacy breach clock.
Enforced by National Computer Security Incident Response Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — applies at: Public entities and private entities linked to critical services or sectors., within 24 hours
- Keep logs — 1 year
- Appoint a data protection officerAn information security officer with technical independence, which is a separate role from the data protection officer under the privacy law.
- Secure the dataAdopt the National Cybersecurity Framework and effective measures for critical information assets.
What it costs if you get it wrong
- Order to stopThe information security directorate issues warnings and reports non-compliance to the General Assembly twice a year; there is no cash fine attached.
Sources
- Official sourceIMPO, official consolidated textLey N. 20.212, articulo 80 (Registro Nacional de Incidentes de Ciberseguridad)
impo.com.uy
“deberan comunicar la ocurrencia de incidentes de ciberseguridad a AGESIC en un plazo de veinticuatro horas de conocido”
Link checked 19 August 2026
- Official sourceIMPO, official consolidated textDecreto N. 66/025
impo.com.uy
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That Uruguayan telecoms law imposes no data-localisation or traffic-data retention duty on operators
We checked the regulator's normative index and the telecoms licensing decree landing page, but the regulator's site serves the decree text through a third-party link we could not render. This is a negative finding, checked 19 August 2026, at medium confidence rather than a proven absence.
That health data has no storage-location rule in Uruguay
The national electronic health record decree of 2017 contains no location clause, but Ministry of Public Health ordinances issued under it were not retrieved. Treat as unverified for regulated healthcare providers.
The exact adoption date of URCDP Resolution 8/026 on Council of Europe model contractual clauses
The regulator's resolution index dates it 17 April 2026 while its own news item announces approval on 1 June 2026. Both are on the regulator's site and they disagree. Plan to the earlier date.
A specific incident-reporting deadline in hours owed by financial firms to the Central Bank
The consolidated rulebook imposes continuous availability and supervisory access duties, but we did not locate a numeric incident-reporting clock. A supervised firm should assume the 24-hour and 72-hour national clocks apply and ask its supervisor about a third.
The US dollar value of the maximum fine
We verified the indexed unit at 6.6353 pesos on 19 August 2026 from the national statistics institute, but did not verify the peso-to-dollar rate on that date. The eighty thousand dollar figure is an approximation, not a checked conversion.
Whether any online gambling bill has actually been introduced in Parliament during 2026
Only trade press reported the government's intention to present one in the first half of 2026. We found no official parliamentary text, so this is recorded as intention, not as a bill in progress.
Whether the URCDP has issued any monetary fine in 2025 or 2026
The published complaint decisions we opened ended without a fine. We could not read every one of the more than one thousand published resolutions, so the absence of fines is an inference from a sample, not a proven fact.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 90 days. Next check due 17 November 2026.
Put this next to another country
Uruguay versus
Compare