TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Dominican Republic TerraLex Guide to Data Protection Guide

Date posted:
15/08/2023
Last update:
12/03/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

Law No. 172-13 on Personal Data Protection (Personal Data Protection Law). Law No. 53-07 on High Technology Crimes and Offenses.

To whom do the laws apply?

The personal data protection laws in the Dominican Republic apply to all natural and legal persons, both public and private such as businesses and organizations, governmental entities, independent professionals, non-profit agencies, service providers, among others that process personal data in the Dominican Republic.

Scope of protection

What type of data is covered by the law?

Data protection laws in the Dominican Republic protect the privacy and integrity of personal data. They apply to different types of data, such as personal identification data, contact data, sensitive or special data, financial data, and employment data. Protected data may include names, surnames, identification numbers, addresses, financial information, health data, among others. The definitions and scope of protected data may change over time and with updates to laws and regulations.

What are the main exemptions (if any)?

The Personal Data Protection Law in the Dominican Republic establishes exceptions in which the processing of personal data without the consent of the data subject is permitted. These exceptions include implied consent, legal compliance, protection of vital interests, exercise of public rights and functions, and legitimate interests. Law No. 172-13 in its article 27 establishes the following exceptions to the requirement of consent for the processing and transfer of data when:

-Data obtained from publicly available sources. -Data collected for the exercise of functions proper to the powers of the State or by virtue of a legal obligation. -Data limited to name, identity and electoral card, passport, tax identification and other biographical information for marketing purposes. -Data derived from a commercial, labor or contractual, scientific or professional relationship necessary for its development or fulfillment. -Personal data received from clients by financial intermediation entities, Credit Information Companies (SIC) and entities that evaluate the risk of debtors, according to established conditions. -Provision of a specific law. -Transfer of data between government agencies. -Personal data related to health necessary for public health reasons, emergencies, or epidemiological studies, provided that the secrecy of the identity of the holders is preserved through appropriate mechanisms of dissociation. -Data dissociated in such a way that the data subjects are not identifiable. It is important to note that, although there are exceptions in which personal data may be processed without consent, certain requirements and limitations established by law must be complied with to ensure the protection and privacy of personal data.

What rights do the laws grant to the data owners?

Data protection laws in the Dominican Republic grant rights to data owners, such as access, rectification, cancellation, opposition, limitation, portability and not to be subject to automated decisions. These rights provide holders with control and protection over their personal data and must be exercised as established in the applicable legislation.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

In the Dominican Republic, Law No. 172-13 establishes legitimate grounds for the processing of personal data without the need for consent. These grounds include the fulfillment of legal obligations, the exercise of public functions, the protection of vital interests, the performance of contracts and the pursuit of legitimate interests. However, the processing must comply with the law and data protection principles. Each situation must be assessed in accordance with the relevant legal requirements.

What are the main obligations imposed by the law?

Law No. 172-13 on Personal Data Protection in the Dominican Republic establishes several obligations for entities responsible for data processing. These obligations include obtaining consent, informing the owner, ensuring security, retaining data for an adequate time, notifying security breaches, and complying with requirements for international data transfers.

Do the laws establish a data retention period to be observed?

Yes, Law No. 172-13 on Personal Data Protection in the Dominican Republic establishes provisions on the retention time of personal data According to Article 20 of the law, personal data must be retained for the time necessary to fulfill the purposes for which they were collected. This means that the entities responsible for processing must establish adequate and justified retention periods for the different types of data they process.

However, the law does not specify a specific retention period for all personal data, as the retention time may vary depending on the nature of the data and the purposes of the processing.

Must the data processing activities be recorded under the law?

According to Law No. 172-13 on Personal Data Protection in the Dominican Republic, entities responsible for the processing of personal data are obliged to register their data processing activities. This obligation is established in Article 25 of the law. The registration of data processing activities implies that the responsible entities must keep an updated record of all activities related to the processing of personal data that they carry out. This register must contain detailed information on the types of data being processed, the purposes of the processing, the security measures implemented, and other relevant details.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

In the Dominican Republic exist the General Directorate of Ethics and Government Integrity (DIGEIG), which is the governing body in the field of Access to Public Information.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

No.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

The Law that regulates the international transfer of data is No. 172-13, specifically in its article No. 80.

Is it necessary to notify the National Authority prior to the international transfer?

According to the law, it is necessary to notify the owner of the data.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

According to our law, the person responsible for the personal data file and in his case, the person in charge of the treatment, must adopt and implement the measures of security necessary to safeguard the data of a personal nature and avoid its alteration, loss, treatment, consultation, or access that has not been authorized. Consequently:

  1. It is prohibited to register personal data in files, registers or banks of data that do not meet technical conditions of integrity and security.
  2. Data providers, Credit Information Companies (SIC) and users or subscribers must adopt the measures and technical controls necessary to avoid the alteration, loss, treatment, or unauthorized access authority of the data on credit history that they manage or rest in the database of SIC.
  3. The SIC must adopt measures appropriate to protect your databases against natural hazards, such as accidental loss or destruction by accident, and against the risks such as unauthorized access, covert use of data or contamination by computer viruses.

Do the laws establish any kind of mandatory notification duty?

Yes, according to article 5.4 when personal data that requires consent of the owner of the data is collected, it is required prior notification. in order for it to be processed or transferred.

What are the sanctions for noncompliance with data protection laws?

The interested parties who, as a consequence of non-compliance with the provisions of the law, suffer damages, have the right to be compensated in accordance with common law. Penalties range from administrative, civil, and criminal sanctions, which are established in articles Nos. 81 to 88 of Law No. 172-13.

Other comments

Other comments

N/A

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.