Law / Uruguay

Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Ley N° 18.331, de 11 de agosto de 2008, arts. 37-40 según Ley N° 19.670, de 2018, y Decreto N° 64/020, de 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain free, prior, express, and informed consent before processing personal data, unless a narrow exception (data from public sources, a legal mandate, or a state function) applies.
  • Obtain the data subject's express written consent before collecting or processing sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life).
  • Let a person challenge, and obtain the criteria and program behind, any administrative act or private decision based solely on automated processing of their personal data that significantly affects them.
  • Transfer personal data outside Uruguay only to a country or organization with an adequate level of protection, under an enumerated exception, or with URCDP authorization of contractual safeguards.
  • Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures, and be able to demonstrate them.
  • If established outside Uruguay while offering goods or services to, or monitoring, people in Uruguay, or using means located there, designate a locally domiciled representative before the URCDP.
  • On learning of a security breach, notify the affected data subjects and the URCDP immediately and in detail, coordinating with CERTuy.
  • If a public entity, a state-linked private entity, or a private entity processing sensitive data as a main line of business or processing large volumes of data, designate a data-protection officer with technical autonomy.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Who enforces it

Enforcement body

Unidad Reguladora y de Control de Datos Personales (URCDP)

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Breach notice, Governance, DPIA, Security

Who checks it

Audit expectation

on_request

Who audits it

Regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 9 requires free, prior, express, and informed consent before processing personal data, subject to narrow exceptions including data drawn from public sources or gathered for a state function. Article 18 bars collecting sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life) without the data subject's express written consent, absent an interest-general legal authorization.

Article 16 gives a person the right to challenge an administrative act or private decision based solely on automated processing of personal data that significantly affects them, and to obtain from the controller the criteria and the program used to reach it.

Article 23 prohibits transferring personal data to a country or organization that does not provide an adequate level of protection, subject to enumerated exceptions (the data subject's unambiguous consent, contractual necessity, an important public interest, or a public register open to consultation) and to case-by-case authorization by the Unidad Reguladora y de Control de Datos Personales (URCDP) where a controller offers sufficient contractual safeguards.

Article 12, as rewritten by Ley N° 19.670 art. 39, imposes a proactive-accountability duty: privacy by design, privacy by default, and a data-protection impact assessment among the measures a controller and processor must adopt and be able to demonstrate.

Ley N° 19.670 art. 37 (2018), now regulated by Decreto N° 64/020 (2020), extends the law to a controller or processor established outside Uruguay when it offers goods or services to Uruguayan residents, monitors their behavior, or uses means located in the country, requiring a locally domiciled representative before the URCDP unless the means are used solely for transit.

Ley N° 19.670 art. 38 requires the controller or processor to notify both the data subjects and the URCDP immediately and in detail on learning of a security breach, coordinating with the national cybersecurity incident response centre (CERTuy).

Ley N° 19.670 art. 40 requires a public entity, a wholly or partly state-owned private entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, to designate a data-protection officer with technical autonomy.

Article 37's habeas data action lets any person bring an effective judicial claim to learn what personal data about them is held, for what purpose, and to demand its rectification, inclusion, or deletion where it is erroneous, false, outdated, unlawfully processed, or discriminatory.

Article 35 arms the URCDP with graduated administrative sanctions for a violation of the law (observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database); the law does not attach a criminal penalty to a breach of these duties.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions
  • deploys_chatbot

Read the law

Consolidated
currently updated text of Ley N° 18.331 and its amendments, Centro de Información Oficial (IMPO), Uruguay's official legislative database

Back to the example  ·  Lint your app