Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form
Resolución 58/2022 Ministerio de Comunicaciones, "Reglamento para la Seguridad y Protección de los Datos Personales en Soporte Electrónico" (Gaceta Oficial de la República de Cuba, Ordinaria No. 90, GOC-2022-833-O90, 25 de agosto de 2022)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 February 2023.
A cross border transfer rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Host or replicate any registry, file, archive, or database containing personal data in electronic form only on servers located within Cuba's national territory, absent a case the law provides for.
- Guarantee the security of personal data in electronic form and adopt the necessary technical and administrative measures for its processing.
- Notify the competent authorities of cybersecurity incidents affecting personal data in electronic form under your custody.
- Let a telecommunications, application, or internet-service user access, update, and cancel their personal data on request, and disclose the purpose of data collection, privacy configuration options, and any tracking elements such as cookies.
Who enforces it
Enforcement body
Dirección General de Informática, Dirección de Inspección, and the territorial Control offices of the Ministry of Communications
What it reaches
Obligation class
Security, Transfer, Breach notice, Data subject rights, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Resolución 58/2022 of the Ministry of Communications implements Ley 149/2022's security duties for personal data processed in electronic form and binds public telecommunications and ICT operators and service providers, hosting providers, application providers, and private-network holders.
Article 7 requires that any registry, file, archive, or database containing personal data in electronic form be hosted or replicated only on servers located within the national territory, absent a case the law provides for. Controllers must guarantee the security of electronic personal data, adopt the necessary technical and administrative measures, and notify the competent authorities of cybersecurity incidents affecting personal data under their custody.
Controllers must also let data subjects who are users of public telecommunications, applications, and internet services access, update, and cancel their data on request, and disclose, in plain terms, the purpose of collection, privacy configuration options, and use of tracking elements such as cookies.
When LexLint raises it
automated_outreach
Read the law
Official text of Resolución 58/2022
Ministerio de Comunicaciones, as published in Gaceta Oficial de la República de Cuba, Ordinaria No. 90 (25 August 2022), in an Internet Archive capture