Ley No. 172-13 sobre Protección Integral de los Datos Personales
Ley No. 172-13, Gaceta Oficial No. 10737, 15 de diciembre de 2013
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 15 December 2013.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's free, conscious, and voluntary consent before forming a file, bank, or register that reveals their sensitive data (political opinions, religious or philosophical convictions, union affiliation, or health or sex-life information).
- Before transferring personal data outside the Dominican Republic, obtain the data subject's free authorization or rely on one of the law's specific statutory grounds for the transfer.
- Adopt the technical, organizational, and security measures necessary to prevent the alteration, loss, or unauthorized access of personal data.
- On request, let a data subject who appears in a public professional directory exclude their data from use for advertising or commercial prospecting purposes.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Correctional imprisonment of six months to two years and a fine of 100 to 150 times the minimum wage for violating the law's provisions (art. 88); a separate fine of 10 to 50 times the minimum wage applies to specific falsification or unauthorized-access conduct involving a credit-reporting file (art. 84).
Who enforces it
Enforcement body
Superintendencia de Bancos, for Sociedades de Información Crediticia (credit-reporting bureaus) only; no dedicated authority supervises personal-data processing generally
What it reaches
Obligation class
Consent, Data subject rights, Transfer, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 sets the law's object as the comprehensive protection of personal data held in public or private files, registers, or databases, and separately regulates the constitution and operation of Sociedades de Información Crediticia (credit-reporting bureaus, SIC).
The law defines sensitive data as data revealing political opinions, religious or philosophical convictions, union affiliation, or health or sex-life information, and article 75 bars forming a file that reveals such data without the person's free, conscious, and voluntary consent.
Article 80 restricts international transfer of personal data to cases where the data subject freely authorizes the transfer or a specific statutory ground applies, such as medical exchange for treatment or epidemiological research, or banking and securities transactions.
Article 88 sanctions any violation of the law with six months to two years of correctional imprisonment and a fine of 100 to 150 times the minimum wage, and article 84 separately fines specific falsification and unauthorized-access conduct while expressly preserving the person's right to recover civil damages for the violation of their privacy right under ordinary civil-law rules.
The Superintendencia de Bancos inspects and supervises credit-reporting files kept by Sociedades de Información Crediticia under articles 36 and 79 through 82, but the law creates no dedicated data-protection authority with jurisdiction over personal-data processing generally, and no breach-notification duty is imposed.
When LexLint raises it
automated_outreach
Read the law
Official text of Ley No. 172-13, reproduced by the Instituto Nacional de la Vivienda (INVI), a Dominican government portal
Gaceta Oficial No. 10737