Law / United States / Puerto Rico
Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification)
Ley Núm. 111 de 7 de septiembre de 2005, según enmendada; 10 L.P.R.A. §§ 4051-4055
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A breach notification rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Notify affected Puerto Rico residents of a security breach of an information bank containing their personal information as expeditiously as possible.
- Report the breach to the Department of Consumer Affairs within ten non-extendable days of detecting it.
- Use direct written or authenticated electronic notice unless the cost would exceed $100,000 or 100,000 people are affected, in which case use the substitute-notice procedure (prominent posting plus media notice) instead.
- Route a breach occurring at a government agency or public corporation to the Office of the Procurador del Ciudadano rather than the ordinary consumer notice path.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Civil fine the Secretary of Consumer Affairs may impose per violation; separate from a consumer's own right to sue for damages.
- Rule
- Per violation only
- As of
- 5 September 2026
- Minimum
- 500
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 5,000
Who enforces it
Enforcement body
Departamento de Asuntos del Consumidor (DACO); Oficina del Procurador del Ciudadano for a breach at a government agency or public corporation
What it reaches
Obligation class
Breach notice, Disclosure, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Every entity, government or private, that owns or has custody of an information bank containing Puerto Rico residents' personal information must notify affected citizens of a security breach as expeditiously as possible, and must report the breach to the Department of Consumer Affairs within a non-extendable ten days, after which the Department publicly announces the breach within twenty-four hours.
A breach at a government agency or public corporation is instead routed to a specialized Ombudsman within the Office of the Procurador del Ciudadano. Direct written or authenticated electronic notice is required unless the cost would exceed $100,000 or the affected population 100,000 people, in which case substitute notice (prominent posting plus media notice) is permitted.
The Secretary of Consumer Affairs may impose a civil fine of $500 to $5,000 per violation; this does not affect a consumer's separate right to sue for damages. Article 11 states the Act takes effect one hundred and twenty days after its September 7, 2005 approval, other than Article 6, which took effect immediately; the source states this day-count rule rather than a calendar commencement date.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachdeploys_chatbot