Law / Bolivia

Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales

DS No. 1793, Reglamento a la Ley No. 164, art. 56 (Tratamiento de los Datos Personales), 13 de noviembre de 2013

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 13 November 2013.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain a person's prior knowledge and express consent before collecting, processing, blocking, cancelling, transferring, consulting, or interconnecting their personal data.
  • Before asking someone for their personal data, tell them it will be processed, why, who may receive it, who is responsible for it and how to reach that party, and that they may exercise access, rectification, updating, cancellation, objection, and revocation rights.
  • Do not use personal data for a purpose other than the one stated when it was collected.
  • Do not use, communicate, or transfer personal data to a third party without the data subject's consent or a competent court's written order.
  • Adopt technical and organisational measures, matched to the state of technology and the data's nature and risk, to keep personal data secure and prevent its alteration, loss, or unauthorised processing.

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 56 of the Reglamento para el Desarrollo de Tecnologías de Información y Comunicación, approved by Decreto Supremo No. 1793, sets a general set of personal-data-processing principles to guarantee personal data and its computer security.

Collecting, processing, blocking, cancelling, transferring, consulting, or interconnecting personal data, in the public and private sectors in all its forms, requires the data subject's prior knowledge and express consent, revocable for justified cause though not retroactively.

A person asked for personal data must be told beforehand that it will be processed, the purpose of collecting and registering it, its potential recipients, the identity and address of the party responsible for the processing, and the possibility of exercising rights of access, rectification, updating, cancellation, objection, and revocation.

Data may not be used for purposes other than those stated when collected, and may only be used, communicated, or transferred to a third party with the data subject's consent or a competent court's written order.

The party responsible for the processing, public or private, must adopt the technical and organisational measures necessary to secure the personal data and prevent its alteration, loss, or unauthorised processing, calibrated to the state of technology, the nature of the stored data, and the risks the data faces.

The Reglamento's own scope article states that it applies to natural or legal persons, public or private, engaged in activities or services related to digital certification, e-government, free software, and electronic commerce, so this chapter sits structurally within the Reglamento's title on digital-certificate holders even though its own text states the processing principles broadly, for the public and private sectors in all their forms.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Reglamento para el Desarrollo de Tecnologías de Información y Comunicación
annex to Decreto Supremo No. 1793 of 2013, full text republished by LexiVox

Back to the example  ·  Lint your app