Ley N° 19.670, personal data breach notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2019.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the affected data subjects immediately and in detail on becoming aware of the breach, describing the measures adopted to address it.
- Notify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy).
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 38, now regulated by Decreto N° 64/020 of 2020, requires the controller or processor of a database, on becoming aware of a security breach, to inform both the affected data subjects and the Unidad Reguladora y de Control de Datos Personales immediately and in detail, together with the measures adopted, coordinating the response with the Centro Nacional de Respuesta a Incidentes de Seguridad Informática del Uruguay (CERTuy).
The provision states no fixed numeric deadline, only immediacy from the moment the controller or processor becomes aware of the breach, and leaves the detailed content of that notification to the implementing regulation, Decreto N° 64/020.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.