Ley N° 18.331, enforcement, sanctions and habeas data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect the Unidad Reguladora y de Control de Datos Personales to inspect your books, documents, and files, physical or electronic, demand your appearance to provide information, and, in serious cases, seize materials for up to six business days.
- Expect graduated administrative sanctions when you violate the law: observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database.
- Expect any person to be able to bring an effective habeas data judicial action against you to learn what personal data about them you hold, its purpose and use, and to demand its rectification, inclusion, suppression, or another appropriate remedy where the data is erroneous, false, prohibited from processing, discriminatory, or outdated.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Criminal exposure note
Ley N° 18.331 creates only administrative sanctions (art. 35); art. 11 cross-references the pre-existing professional-secrecy offense at art. 302 of the Penal Code rather than creating a new crime for a violation of this Act.
Who enforces it
Enforcement body
Unidad Reguladora y de Control de Datos Personales (URCDP)
What it reaches
Obligation class
Governance, Reporting
Who checks it
Audit expectation
on_request
Who audits it
Regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 31 creates the Unidad Reguladora y de Control de Datos Personales as a technically autonomous body within AGESIC, and article 34, as rewritten in 2010 and 2022, gives it the power to inspect a controller's or processor's books, documents, and files, demand their appearance to provide information, and, in serious cases, seize materials for up to six business days, with judicial backing for a search of private premises.
Article 35 arms the authority with graduated administrative sanctions for a violation of the law: observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database, and lets it seek judicial closure of a database found to infringe the law.
The Act creates no separate criminal offense of its own; article 11 only cross-references the pre-existing professional-secrecy offense at article 302 of the Penal Code.
Article 37 gives any person the right to bring an effective habeas data judicial action against a public or private database's controller to learn what personal data about them it holds, its purpose and use, and to demand its rectification, inclusion, suppression, or another appropriate remedy where the data is erroneous, false, prohibited from processing, discriminatory, or outdated, with articles 38 to 45 setting the court, standing, and summary procedure for that action.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.