Law / Uruguay

Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Ley N° 18.331 de 11 de agosto de 2008, arts. 1-12, 17, 20, 22, 24, 28-30, según Ley N° 19.670, de 2018, arts. 37 y 40, y Decreto N° 64/020, de 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's free, prior, express, and informed consent, documented in writing, before processing their personal data, unless a listed exception applies (data from public sources, a legal mandate, a state function, or a contractual, scientific, or professional relationship).
  • Communicate personal data to a third party only for a purpose directly tied to the sender's and recipient's legitimate interest, only with the data subject's prior consent, and only after telling them the purpose of the communication and identifying the recipient.
  • Adopt the security and confidentiality measures needed to prevent unauthorized alteration, loss, consultation, or processing of personal data, and store it so the data subject can exercise their right of access.
  • Adopt privacy-by-design, privacy-by-default, and data-protection impact assessment measures as part of a proactive-accountability duty, and be able to demonstrate their effective implementation.
  • Register any database of personal data you create, modify, or eliminate with the Unidad Reguladora y de Control de Datos Personales before operating it, and hold only the categories of data you declared in that registration.
  • If established outside Uruguay while offering goods or services to, or analyzing the behavior of, people in Uruguay, or using means located there, designate a locally domiciled representative before the Unidad Reguladora y de Control de Datos Personales.
  • If a public entity, a wholly or partly state-owned entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, designate a data-protection officer with technical autonomy.
  • Keep a negative record of a natural person's unpaid commercial obligation registered for no more than five years from its entry, renewable once for another five years if the debt remains unpaid, and update the record within days of being notified the debt was settled.
  • If you operate a public communications network or offer an electronic communications service, secure the network and the service, and tell subscribers about any particular risk of a security breach and the measures to take.

What it reaches

Obligation class

Consent, Disclosure, Security, DPIA, Governance, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 9 requires free, prior, express, and informed consent before processing personal data, documented in writing, subject to narrow exceptions for data drawn from public sources, gathered for a state function, or arising from a contractual, scientific, or professional relationship.

Article 10 requires the responsible party to adopt the security measures needed to prevent unauthorized alteration, loss, consultation, or processing of personal data, and article 11 binds anyone who legitimately accesses another party's database to reserve and professional secrecy, backed by the existing offense at article 302 of the Penal Code.

Article 12, as rewritten by Ley N° 19.670 art. 39 and regulated by Decreto N° 64/020 of 2020, imposes a proactive-accountability duty of privacy by design, privacy by default, and a data-protection impact assessment. Article 17 lets personal data be communicated to a third party only for a purpose tied to the sender's and recipient's legitimate interest and only with the data subject's prior consent.

Articles 24, 28, and 29 require every public or private database to be registered with the Unidad Reguladora y de Control de Datos Personales before it operates, declaring the categories of data it holds.

Ley N° 19.670 art. 37, now regulated by Decreto N° 64/020, extends the law to a controller or processor established outside Uruguay when it offers goods or services to Uruguayan residents, analyzes their behavior, or uses means located in the country, requiring a locally domiciled representative before the URCDP.

Ley N° 19.670 art. 40 requires a public entity, a wholly or partly state-owned entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, to designate a data-protection officer with technical autonomy.

Article 22 limits a negative commercial-debt record concerning a natural person to five years from its entry, renewable once, and article 20 requires an operator of a public communications network or electronic communications service to secure that network and warn subscribers of a particular security risk.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • provides_telecom_services

Read the law

Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app