Ley No. 787, Ley de Protección de Datos Personales, supervision, sanctions, and complaints
Ley No. 787, arts. 28-29, 34-35, 44-52 (supervision, sanctions, and complaints)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 29 March 2012.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect the Direccion de Proteccion de Datos Personales to advise, issue rules, request information, and impose administrative sanctions on you for a violation of this Act, and to accredit inspectors to verify your compliance.
- Cooperate with an accredited inspector's visit by allowing access to your data files, supplying the requested information and documents, including your registration and security measures, and allowing your equipment to be reviewed.
- Expect a warning or suspension of your processing operations for a minor infraction, such as processing without the required consent or failing to act on a data subject's request, and expect closure or cancellation of the data file, temporary or permanent, for a serious infraction, such as processing by fraudulent means, breaching professional secrecy, or keeping a file without the required security conditions.
- Expect a data subject to be able to bring an administrative protection action before the Direccion de Proteccion de Datos Personales and, once that route is exhausted, a constitutional amparo action before the courts.
If you get it wrong
Private right of actionNo
Who enforces it
Enforcement body
Direccion de Proteccion de Datos Personales (DIPRODAP), attached to the Ministry of Finance and Public Credit
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 28 creates the Direccion de Proteccion de Datos Personales, attached to the Ministry of Finance and Public Credit, with a director designated by that ministry's highest administrative authority, to control, supervise, and protect the processing of personal data in public and private data files.
Article 29 gives the Direccion de Proteccion de Datos Personales broad functions: advising on this Act's content and scope, issuing rules on confidentiality, integrity, and security, requesting information from public and private data file holders, imposing administrative sanctions on offenders, filing complaints with the competent authority, verifying registration requirements, accrediting inspectors, promoting self regulation models, opining on relevant bills, publicizing the right to informational self determination, and cooperating with foreign data protection authorities.
Article 34 lets an accredited inspector inspect on a complaint or on its own motion with judicial authorization, and article 35 requires a person or entity under inspection to allow the inspectors access to its data files, cooperate with the inspection, supply the requested information and documents, including its operating registration and security measures, and allow its equipment to be reviewed.
Article 44 classifies as a minor infraction processing personal data without the required express consent, failing to include, complete, rectify, update, suppress, block, or cancel data on request, failing to follow the Direccion de Proteccion de Datos Personales' instructions, collecting data through a form that lacks a clear notice that a file will be created, and sending advertising to a person who has refused it.
Article 45 classifies as a serious infraction processing personal data by fraudulent means or in violation of this Act, obstructing the right to informational self determination or unjustifiably denying requested information, breaching the professional secrecy this Act requires, repeating a minor infraction, keeping a data file without the minimum security, integrity, and confidentiality conditions the applicable rules require, or obstructing an inspection.
Article 46 gives the Direccion de Proteccion de Datos Personales power to impose the administrative sanctions of a warning or suspension of processing operations for a minor infraction, and closure or cancellation of the data file, temporary or permanent, for a serious infraction, without prejudice to any separate liability for damages or any criminal sanction.
Articles 47 through 51 give a data subject an administrative protection action before the Direccion de Proteccion de Datos Personales to learn of their processed data, to challenge a breach of confidentiality, integrity, or security, to correct false, inaccurate, outdated, omitted, or unlawfully processed information, to access information a public or private entity holds about them, and to demand correction, inclusion, suppression, blocking, or cancellation of their data, brought by the data subject, their guardian, their heirs, or a representative, and article 52 lets the data subject use a constitutional amparo action once the administrative route is exhausted, and lets a data controller separately challenge an administrative act under the law governing the Executive Power's procedures.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1dEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.