Law / Dominican Republic

Ley No. 172-13 sobre Protección Integral de los Datos Personales

Ley No. 172-13, Gaceta Oficial No. 10737, 15 de diciembre de 2013, arts. 1-6, 27-28, 42-43, 60 y 63

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 December 2013.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's free, express, and conscious consent before processing or transferring their personal data, unless the law lists an exception.
  • Adopt the technical, organizational, and security measures necessary to prevent the alteration, loss, or unauthorized access of personal data, and maintain adequate information policies with security and control measures for every archive, registry, or databank you keep.
  • Keep personal data confidential under a duty of professional secrecy that continues after your relationship with the data subject or the data controller ends, unless a court relieves you of it for reasons of public security, national defense, or public health.
  • Register as a Sociedad de Información Crediticia with the Superintendencia de Bancos, after securing the Junta Monetaria's authorization, before operating as a credit reporting bureau.
  • As a Sociedad de Información Crediticia, use biometric identification techniques, such as comparing a consumer's photograph, to verify identity and make identity theft difficult when supplying a credit report, and protect the algorithms and technologies you use for that service under the strictest security and confidentiality.

What it reaches

Obligation class

Consent, Security, Governance, Licensing, Biometric

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 sets the law's object as the comprehensive protection of personal data held in public or private files, registers, databanks or other technical processing media, and separately regulates the constitution, organization and operation of Sociedades de Información Crediticia (SIC), the credit reporting bureaus.

Article 2 applies the law to personal data recorded in any databank susceptible to processing and to every later use of that data in the public and private spheres alike, and article 4 excludes only a narrow, exhaustive list: data an individual keeps for purely personal or domestic activity, files kept by the Dominican Republic's investigative and intelligence bodies for crime prevention and prosecution, data about deceased persons, and data limited to a professional's name, position, and business contact details.

Article 5 states the law's governing principles: files must be lawful and registered, data must be accurate and kept up to date, a data subject must be told the purpose of the processing and who is responsible for the file before consenting, processing requires the data subject's free, express and conscious consent unless an exception applies, the data controller and processor must adopt technical, organizational and security measures against alteration, loss or unauthorized access, everyone who handles the data owes a duty of professional secrecy that survives the end of their relationship with the data subject or the controller, data may not be collected by fraudulent or unlawful means, and data may only be collected for a determined, explicit and legitimate purpose.

Article 42 requires every archive, registry, or databank, public or private, to maintain adequate information policies guaranteeing security and control measures to prevent the improper handling of data subjects' information. Article 43 requires a Sociedad de Información Crediticia to register with the Superintendencia de Bancos once the Junta Monetaria has authorized it to operate, before it may begin operating as a credit bureau.

Article 60 requires a Sociedad de Información Crediticia to use biometric identification techniques, such as matching a consumer's photograph, to make identity theft difficult when a person contracts goods or services from a public or private entity, and article 63 requires it to adopt the security measures necessary to prevent improper handling of the information and to protect the algorithms and technologies it uses under the strictest security and confidentiality.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics
  • provides_financial_services

Read the law

Official text of Ley No. 172-13, reproduced by the Instituto Nacional de la Vivienda (INVI), a Dominican government portal
Gaceta Oficial No. 10737

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app