Law / United States / Puerto Rico

Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification)

Ley Núm. 111 de 7 de septiembre de 2005, según enmendada; 10 L.P.R.A. §§ 4051-4055

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A breach notification rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Notify affected Puerto Rico residents of a security breach of an information bank containing their personal information as expeditiously as possible.
  • Report the breach to the Department of Consumer Affairs within ten non-extendable days of detecting it.
  • Use direct written or authenticated electronic notice unless the cost would exceed $100,000 or 100,000 people are affected, in which case use the substitute-notice procedure (prominent posting plus media notice) instead.
  • Route a breach occurring at a government agency or public corporation to the Office of the Procurador del Ciudadano rather than the ordinary consumer notice path.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Civil fine the Secretary of Consumer Affairs may impose per violation; separate from a consumer's own right to sue for damages.

Rule
Per violation only
As of
5 September 2026
Minimum
500
Currency
USD
Per violation unit
Violation
Per violation amount
5,000

Who enforces it

Enforcement body

Departamento de Asuntos del Consumidor (DACO); Oficina del Procurador del Ciudadano for a breach at a government agency or public corporation

What it reaches

Obligation class

Breach notice, Disclosure, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Every entity, government or private, that owns or has custody of an information bank containing Puerto Rico residents' personal information must notify affected citizens of a security breach as expeditiously as possible, and must report the breach to the Department of Consumer Affairs within a non-extendable ten days, after which the Department publicly announces the breach within twenty-four hours.

A breach at a government agency or public corporation is instead routed to a specialized Ombudsman within the Office of the Procurador del Ciudadano. Direct written or authenticated electronic notice is required unless the cost would exceed $100,000 or the affected population 100,000 people, in which case substitute notice (prominent posting plus media notice) is permitted.

The Secretary of Consumer Affairs may impose a civil fine of $500 to $5,000 per violation; this does not affect a consumer's separate right to sue for damages. Article 11 states the Act takes effect one hundred and twenty days after its September 7, 2005 approval, other than Article 6, which took effect immediately; the source states this day-count rule rather than a calendar commencement date.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • deploys_chatbot

Read the law

official codified text (10 L.P.R.A. §§ 4051-4055), Puerto Rico Office of Management and Budget (OGP) Virtual Library

Back to the example  ·  Lint your app