Comprehensive regime
Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended
In force. Binds public and private bodies.
What this law does
Article 9 requires free, prior, express, and informed consent before processing personal data, subject to narrow exceptions including data drawn from public sources or gathered for a state function. Article 18 bars collecting sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life) without the data subject's express written consent, absent an interest-general legal authorization.
Article 16 gives a person the right to challenge an administrative act or private decision based solely on automated processing of personal data that significantly affects them, and to obtain from the controller the criteria and the program used to reach it.
Article 23 prohibits transferring personal data to a country or organization that does not provide an adequate level of protection, subject to enumerated exceptions (the data subject's unambiguous consent, contractual necessity, an important public interest, or a public register open to consultation) and to case-by-case authorization by the Unidad Reguladora y de Control de Datos Personales (URCDP) where a controller offers sufficient contractual safeguards.
Article 12, as rewritten by Ley N° 19.670 art. 39, imposes a proactive-accountability duty: privacy by design, privacy by default, and a data-protection impact assessment among the measures a controller and processor must adopt and be able to demonstrate.
Ley N° 19.670 art. 37 (2018), now regulated by Decreto N° 64/020 (2020), extends the law to a controller or processor established outside Uruguay when it offers goods or services to Uruguayan residents, monitors their behavior, or uses means located in the country, requiring a locally domiciled representative before the URCDP unless the means are used solely for transit.
Ley N° 19.670 art. 38 requires the controller or processor to notify both the data subjects and the URCDP immediately and in detail on learning of a security breach, coordinating with the national cybersecurity incident response centre (CERTuy).
Ley N° 19.670 art. 40 requires a public entity, a wholly or partly state-owned private entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, to designate a data-protection officer with technical autonomy.
Article 37's habeas data action lets any person bring an effective judicial claim to learn what personal data about them is held, for what purpose, and to demand its rectification, inclusion, or deletion where it is erroneous, false, outdated, unlawfully processed, or discriminatory.
Article 35 arms the URCDP with graduated administrative sanctions for a violation of the law (observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database); the law does not attach a criminal penalty to a breach of these duties.
What it requires