Law / Nicaragua

Ley No. 787, Ley de Protección de Datos Personales

Ley No. 787, 29-Mar-2012, Gaceta Oficial No. 61, arts. 1-6, 9, 11-13, 19, 22-24, 27

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 29 March 2012.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before processing personal data, obtain the data subject's consent, unless a listed exception applies.
  • Process personal data only to the extent adequate, proportional, and necessary for the stated purpose, and adopt technical and organizational security measures against unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination.
  • Keep personal data confidential under a duty of professional secrecy that survives the end of your relationship with the data controller, releasable only by judicial order for reasons of national security, national defense, public security, or public health.
  • Register with the data file register the Direccion de Proteccion de Datos Personales keeps before operating a data file, and wait for its registration decision within thirty days.
  • Do not retain personal data for longer than five years, or the term your contract with the data subject sets, once the data are no longer adequate, proportional, or necessary for their purpose.
  • Assign or transfer personal data domestically only for a purpose directly related to your legitimate interest and that of the recipient, and only with the data subject's prior, informed, and revocable consent, unless a listed exception applies.

What it reaches

Obligation class

Consent, Security, Governance, Licensing, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 states the Act's object as protecting a natural or legal person against automated or non-automated processing of their personal data held in public or private data files, to guarantee the right to personal and family privacy and the right to informational self determination, and article 2 applies it to the processing of personal data found in public and private data files alike.

Article 4 makes creating a data file lawful only when it is duly authorized and registered with the data subject's consent, unless the law excepts it, and bars a data file from serving a purpose other than one this Act permits. Article 5 requires that personal data be obtained only when adequate, proportional and necessary to the purpose for which it is collected and only by lawful means that guarantee the right to informational self determination.

Article 6 makes the data subject's consent, given by the data subject or their legal representative in writing or another suitable physical or electronic means and revocable without retroactive effect, the general basis for delivering personal data, except where a competent judicial authority so orders, the data first undergo a dissociation procedure, the purpose is to perform obligations arising from a legal relationship between the data subject and the controller, or the data are drawn from an unrestricted public access source and limited to name, national identity document number, and date of birth.

Article 9 requires that all processing be adequate, proportional, and necessary to the purpose for which the data were requested, and requires the data controller and, where applicable, the data processor, to adopt the technical and organizational measures necessary to guarantee the security of personal data and prevent unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination.

Article 11 requires the data controller to adopt the technical and organizational measures necessary to guarantee the integrity, confidentiality, and security of personal data, to prevent its corruption, loss, unauthorized consultation, processing, disclosure, transfer, or dissemination, and to detect intentional or unintentional deviations of private information, whether the risk comes from human action or the technical medium used.

Article 12 binds the data controller and anyone who takes part in any phase of processing personal data to professional secrecy, an obligation that survives the end of their relationship with the data controller, releasable only by judicial order and only for reasons of national security, national defense, public security, or public health.

Article 13 lets personal data be assigned or transferred domestically only for purposes directly related to the legitimate interest of the assignor and the assignee and with the data subject's prior consent, informed of the purpose of the assignment and the assignee's identity, revocable by written notice, except where a law so provides, the assignment is between state institutions in the exercise of their powers, it concerns public health, social interest, or national security, or a dissociation procedure has been applied.

Article 19, item f, limits the retention of personal data to five years, or to the term the parties' contract sets, or until the data are no longer adequate, proportional, and necessary for the purpose for which they were requested.

Article 22 requires every data controller to register with the data file register the Direccion de Proteccion de Datos Personales keeps, to wait thirty days for its registration decision, and to record the controller's name and domicile, the nature of the data held, how and when data are collected and updated, the data's destination and recipients, how the records interrelate, the security measures used, the retention period, and how a person can exercise their rights over the file.

Article 23 lets a public or private data file be created, modified, or extinguished only under this Act's provisions, which must state the file's characteristics and purpose, whose data it seeks, whether supplying it is mandatory or optional, and, on suppression, the file's destination or the measures taken to destroy it.

Article 54 excludes from this Act's application the information handled and regulated by the Comision Nacional de Microfinanzas, the Superintendencia de Bancos y de Otras Instituciones Financieras, the entities those regulators supervise, information exchanged under reciprocal supervisory agreements, and private credit bureaus handling credit information, without prejudice to this Act's general principles, the data subject's rights, and its other limitations.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app