Law / Bolivia

Bolivia

7 of 9 named instruments researched to a stage, across three of the six areas of law we track: 6 in force and 1 proposed. As of 5 September 2026.

When they take effect6 of 7 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 6 instruments (6 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 4
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law4 instruments, 3 in force, 1 proposed

Research summary (167 words)

Bolivia has no comprehensive data-protection statute.

The constitutional habeas data action (CPE art. 130) lets any person compel a public or private data holder to disclose, rectify, or delete personal data affecting their privacy, image, honour, or reputation, and Ley No. 164 of 2011 places a narrower duty of communications secrecy and personal-data protection on telecommunications and ICT service providers, developed in more detail by the personal-data chapter of Decreto Supremo No. 1793 of 2013's implementing regulation.

Ley No. 1080 (Ley de Ciudadanía Digital), art. 12, separately binds public servants operating Bolivia's e-government interoperability platform to use the personal data it generates only for purposes established by law, a narrower government-sector duty distinct from the general regime.

AGETIC, the e-government agency, has circulated a comprehensive draft Anteproyecto de Ley de Protección de Datos Personales since at least 2018, most recently in April 2024, which as of 2026 had not been submitted to the Asamblea Legislativa Plurinacional for a floor vote and so imposes no binding obligations yet.

Comprehensive regime

Anteproyecto de Ley de Protección de Datos Personales (AGETIC)

Anteproyecto de Ley de Protección de Datos PersonalesAGETIC

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is proposed and binds nobody yet; what follows is what AGETIC's public presentation of the draft states it would do. The Anteproyecto de Ley de Protección de Datos Personales states its object as the protection of the personal data of natural persons contained in automated or non-automated, public or private files, records, or databases, with the stated purpose of guaranteeing the lawful, controlled, and informed processing of that data.

The presentation lists lawfulness, confidentiality, quality, purpose limitation, proportionality, security, transparency, loyalty, accountability, access, rectification, erasure, objection, processing limitation, portability, a right not to be subject to automated decisions, revocation, compensation, and information among its stated principles and rights.

It states the draft would secure personal data with adequate physical, technical, and administrative measures to prevent its alteration, loss, unauthorised or fraudulent access or use, and to guarantee its confidentiality, integrity, and availability. It also proposes a Data Protection Authority with powers of investigation, supervision, promotion, and sanction, to make sanctions for infractions effective in proportion to the violation committed.

What it requires

Ley General de Telecomunicaciones, Inviolabilidad y Secreto de las Comunicaciones y Protección de Datos Personales

Ley No. 164, arts. 56 (Protección de Datos Personales), promulgada 8 de agosto de 2011Ley No. 164 of 2011, full text republished by LexiVox

In force since 8 August 2011. Binds public and private bodies.

What this law does

Article 56 requires operators of public networks and providers of telecommunications and information and communication technology services to guarantee the inviolability and secrecy of communications, and equally the protection of users' personal data and privacy, except what is contemplated in telephone directories, invoices, and other matters established by regulation.

Article 57 is an interpretation rule directing that, where doubt exists in applying sector regulation between a user and a provider, the rule favouring the user applies; it does not itself impose a data-security or organisational-measures duty.

What it requires

Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales

DS No. 1793, Reglamento a la Ley No. 164, art. 56 (Tratamiento de los Datos Personales), 13 de noviembre de 2013Reglamento para el Desarrollo de Tecnologías de Información y Comunicación

In force since 13 November 2013. Binds public and private bodies.

What this law does

Article 56 of the Reglamento para el Desarrollo de Tecnologías de Información y Comunicación, approved by Decreto Supremo No. 1793, sets a general set of personal-data-processing principles to guarantee personal data and its computer security.

Collecting, processing, blocking, cancelling, transferring, consulting, or interconnecting personal data, in the public and private sectors in all its forms, requires the data subject's prior knowledge and express consent, revocable for justified cause though not retroactively.

A person asked for personal data must be told beforehand that it will be processed, the purpose of collecting and registering it, its potential recipients, the identity and address of the party responsible for the processing, and the possibility of exercising rights of access, rectification, updating, cancellation, objection, and revocation.

Data may not be used for purposes other than those stated when collected, and may only be used, communicated, or transferred to a third party with the data subject's consent or a competent court's written order.

The party responsible for the processing, public or private, must adopt the technical and organisational measures necessary to secure the personal data and prevent its alteration, loss, or unauthorised processing, calibrated to the state of technology, the nature of the stored data, and the risks the data faces.

The Reglamento's own scope article states that it applies to natural or legal persons, public or private, engaged in activities or services related to digital certification, e-government, free software, and electronic commerce, so this chapter sits structurally within the Reglamento's title on digital-certificate holders even though its own text states the processing principles broadly, for the public and private sectors in all their forms.

What it requires

Data subject rights

Constitución Política del Estado, Acción de Protección de Privacidad

CPE, art. 130 (Acción de Protección de Privacidad), promulgada 7 de febrero de 2009Constitución Política del Estado of 2009, full text republished by LexiVox, citing the official Gaceta Oficial de Bolivia origin

In force since 7 February 2009. Binds public and private bodies.

What this law does

Article 130 lets any individual or collective person who believes they are unduly or illegally prevented from knowing, objecting to, or obtaining the deletion or rectification of data registered by any physical, electronic, magnetic, or computer-based medium, in public or private files or data banks, file the Acción de Protección de Privacidad where that data affects their fundamental right to personal or family privacy, image, honour, or reputation; the action does not lie to lift press confidentiality.

Article 131 routes the action through the same procedure as the Acción de Amparo Constitucional and lets the competent court order the disclosure, deletion, or rectification of the challenged data, with an automatic review before the Tribunal Constitucional Plurinacional.

What it requires

Scraping law2 instruments, 2 in force

Research summary (240 words)

Bolivia has no scraping-specific statute, so general law governs each dimension separately.

The Código Penal's computer-crime articles, added by Ley No. 1768 of 1997, are the closest fit for unauthorized access: article 363 ter criminalizes appropriating, accessing, using, modifying, suppressing, or disabling data stored on a computer or other computer medium without authorization, causing harm to the data's owner, and article 363 bis separately criminalizes manipulating a data processing or transfer for undue financial benefit.

Ley No. 1005, Código del Sistema Penal, purported to abrogate Ley 1768 when it was promulgated on 15 December 2017, but its own transitory provisions deferred entry into force of the Code's rules, including that abrogation, for eighteen months, and Ley No. 1027 abrogated the Código del Sistema Penal in its entirety on 25 January 2018, well within that period, so articles 363 bis and 363 ter were never displaced.

No Bolivian statute or reported case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and none establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigns legal weight to a robots.txt directive. Bolivia's copyright statute, Ley No. 1322 of 1992, has no sui generis database right and no text-and-data-mining exception (see the aggregation-topic document for its quotation exception, art. 24).

Personal-data law reaching scraped personal data sits with the general habeas data action and the telecommunications and ICT-sector duties researched under the privacy topic, rather than in a scraping-specific personal-data provision.

Computer misuse

Código Penal, Alteración, Acceso y Uso Indebido de Datos Informáticos

Código Penal, art. 363 ter (Alteración, Acceso y Uso Indebido de Datos Informáticos), incorporado por Ley No. 1768 de 10 de marzo de 1997Ley de Modificaciones al Código Penal (Ley No. 1768), full text republished by LexiVox

In force since 10 March 1997. Binds public and private bodies.

What this law does

Article 363 ter, inserted alongside article 363 bis by Ley No. 1768, punishes whoever, without being authorized, appropriates, accesses, uses, modifies, suppresses, or disables data stored on a computer or any computer medium, causing harm to the owner of the information, with prestación de trabajo (a community-service sentence, one of the Código Penal's four principal penalties) of up to one year or a fine of up to two hundred day-fines (días multa).

Because it turns on acting sin estar autorizado (without authorization), this is the article that would reach a scraper who defeats an access control to appropriate or use data it was not authorized to take. Like article 363 bis, it was listed among the norms Ley No. 1005 purported to abrogate in 2017, but Ley 1005 was itself abrogated by Ley No. 1027 before Ley 1005's eighteen-month deferred entry into force elapsed, so article 363 ter was never actually displaced.

What it requires

Código Penal, Manipulación Informática

Código Penal, art. 363 bis (Manipulación Informática), incorporado por Ley No. 1768 de 10 de marzo de 1997Ley de Modificaciones al Código Penal (Ley No. 1768), full text republished by LexiVox

In force since 10 March 1997. Binds public and private bodies.

What this law does

Article 363 bis, inserted into the Código Penal's new computer-crimes chapter by Ley No. 1768, punishes whoever, intending to obtain an undue benefit for themselves or a third party, manipulates a computer data processing or transfer so that it produces an incorrect result or avoids a process whose result would have been correct, causing a property transfer to a third party's detriment, with reclusión (imprisonment) of one to five years and a fine of sixty to two hundred day-fines (días multa).

Ley No. 1005, Código del Sistema Penal, promulgated 15 December 2017, listed Ley 1768 among the norms it abrogated. Ley 1005's own transitory provisions state that the Code's rules would enter into force eighteen months after publication. Ley No. 1027 abrogated Ley 1005 in its entirety on 25 January 2018, about six weeks later and well inside that eighteen-month period, so article 363 bis was never actually displaced.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (197 words)

Bolivia has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question. Ley No. 1322 of 13 April 1992, sobre el Derecho de Autor, is the only relevant instrument.

Its Título VI, on limitations to copyright, does not exclude the news of the day or mere facts from protection, and it has no dedicated press-summary exception; its article 24 permits quoting an author generally, including short fragments of others' already-divulged works, for citation, analysis, commentary, or critical judgment, for teaching or research purposes, in accordance with honest practices and to the extent the purpose justifies, without becoming abusive.

Whether that quotation exception reaches a systematic news aggregator's reproduction of headlines and snippets, as opposed to a person quoting for the teaching or research purposes the article names, has not been tested in a reported Bolivian decision. The Law predates the concept of a machine-readable text-and-data-mining reservation and confers no sui generis database right, so no opt-out mechanism or database right exists either.

Snippet reproduction

Ley del Derecho de Autor, Límite de Cita

Ley No. 1322, art. 24 (Cita de Obras), de 13 de abril de 1992Ley No. 1322, de 13 de abril de 1992, sobre el Derecho de Autor, official text republished by WIPO Lex

In force since 13 April 1992. Binds public and private bodies.

What this law does

Article 24 of Ley No. 1322, in the Título VI chapter on limitations to copyright, permits quoting an author, meaning the inclusion in one's own work of short fragments of others' works, provided the quoted work has already been divulged, its source and author are credited, and the inclusion is made as a citation or for its analysis, commentary, or critical judgment, for teaching or research purposes, in accordance with honest practices and to the extent the pursued purpose justifies, without becoming abusive.

The neighbouring articles in the same chapter, 25 and 26, address a state compulsory-use power over works of great cultural value after a period out of print and heirs' inability to block republication after five years of inaction, neither of which reaches news reproduction or aggregation.

The Law contains no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright law, and no located case law on hyperlinking or framed display; whether article 24's quotation exception reaches a systematic aggregator's reproduction of headlines and snippets, rather than quotation for the teaching, research, analysis, or critical-commentary purposes the article names, has not been tested in a reported Bolivian decision.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.