Law / Uruguay

Ley N° 18.331, enforcement, sanctions and habeas data

Ley N° 18.331, arts. 31-36 y 37-45 (órgano de control, potestades sancionatorias y acción de habeas data)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Unidad Reguladora y de Control de Datos Personales to inspect your books, documents, and files, physical or electronic, demand your appearance to provide information, and, in serious cases, seize materials for up to six business days.
  • Expect graduated administrative sanctions when you violate the law: observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database.
  • Expect any person to be able to bring an effective habeas data judicial action against you to learn what personal data about them you hold, its purpose and use, and to demand its rectification, inclusion, suppression, or another appropriate remedy where the data is erroneous, false, prohibited from processing, discriminatory, or outdated.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Criminal exposure note

Ley N° 18.331 creates only administrative sanctions (art. 35); art. 11 cross-references the pre-existing professional-secrecy offense at art. 302 of the Penal Code rather than creating a new crime for a violation of this Act.

Who enforces it

Enforcement body

Unidad Reguladora y de Control de Datos Personales (URCDP)

What it reaches

Obligation class

Governance, Reporting

Who checks it

Audit expectation

on_request

Who audits it

Regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 31 creates the Unidad Reguladora y de Control de Datos Personales as a technically autonomous body within AGESIC, and article 34, as rewritten in 2010 and 2022, gives it the power to inspect a controller's or processor's books, documents, and files, demand their appearance to provide information, and, in serious cases, seize materials for up to six business days, with judicial backing for a search of private premises.

Article 35 arms the authority with graduated administrative sanctions for a violation of the law: observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database, and lets it seek judicial closure of a database found to infringe the law.

The Act creates no separate criminal offense of its own; article 11 only cross-references the pre-existing professional-secrecy offense at article 302 of the Penal Code.

Article 37 gives any person the right to bring an effective habeas data judicial action against a public or private database's controller to learn what personal data about them it holds, its purpose and use, and to demand its rectification, inclusion, suppression, or another appropriate remedy where the data is erroneous, false, prohibited from processing, discriminatory, or outdated, with articles 38 to 45 setting the court, standing, and summary procedure for that action.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app