Law / Cuba

Cuba

6 of 8 named instruments researched to a stage, across four of the six areas of law we track: 6 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 2
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law2 instruments, 2 in force

Research summary (129 words)

Cuba's comprehensive personal-data regime is Ley 149/2022 De Protección de Datos Personales, in force since 21 February 2023, which binds both natural persons as data subjects and any natural or legal person that processes personal data, covers personal data held in public as well as private registries, and gives data subjects a right to object to automated or non-automated processing that evaluates or profiles them.

A companion regulation, Resolución 58/2022 of the Ministry of Communications, imposes electronic-format security, cybersecurity-incident notification, and a national-server data-localization duty on telecommunications, hosting, application, and private-network operators. Both instruments took effect on the same date. National and international transfers of personal data are permitted only on a closed, enumerated list of grounds, which the law treats as an exception rather than a general rule.

Comprehensive regime

Ley 149/2022, De Protección de Datos Personales, general regime

Ley 149/2022 "De Protección de Datos Personales" (Gaceta Oficial de la República de Cuba, Ordinaria No. 90, GOC-2022-832-O90, 25 de agosto de 2022)Official text of Ley 149/2022 as published in Gaceta Oficial de la República de Cuba

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived October 23, 2022. Publisher's page: https://www.gacetaoficial.gob.cu/sites/default/files/goc-2022-o90_0_0.pdf

In force since 21 February 2023. Binds public and private bodies.

What this law does

Ley 149/2022 is Cuba's first comprehensive personal-data statute, binding natural persons with respect to their own data and any natural or legal person that processes personal data.

Article 15 lists sex, gender identity, sexual orientation, ethnic origin and skin color, health status, disability, genetic information, diagnostic test results, religious belief, political affiliation, and criminal record as sensitive data requiring the data subject's express consent to process, absent a statutory exception. Data subjects hold rights to access, rectify, and cancel their personal data, including data held in public as well as private registries.

They may also object to processing, automated or not, that evaluates their professional performance, economic situation, health, reliability, or behavior, or that risks harming them. A person or entity responsible for a registry, file, archive, or database must notify the competent authority of cybersecurity incidents affecting the personal data in its custody. National and international transfer of personal data is permitted only on an enumerated list of grounds rather than as a general rule.

Violations draw administrative sanctions from a warning up to a fine of up to 20,000 pesos, suspension of the database for up to five days, or closure of the registry, file, archive, or database, imposed by officials the responsible state body or entity has expressly authorized, without prejudice to any civil or criminal liability that may separately arise.

What it requires

Cross border transfer

Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form

Resolución 58/2022 Ministerio de Comunicaciones, "Reglamento para la Seguridad y Protección de los Datos Personales en Soporte Electrónico" (Gaceta Oficial de la República de Cuba, Ordinaria No. 90, GOC-2022-833-O90, 25 de agosto de 2022)Official text of Resolución 58/2022

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived October 23, 2022. Publisher's page: https://www.gacetaoficial.gob.cu/sites/default/files/goc-2022-o90_0_0.pdf

In force since 21 February 2023. Binds public and private bodies.

What this law does

Resolución 58/2022 of the Ministry of Communications implements Ley 149/2022's security duties for personal data processed in electronic form and binds public telecommunications and ICT operators and service providers, hosting providers, application providers, and private-network holders.

Article 7 requires that any registry, file, archive, or database containing personal data in electronic form be hosted or replicated only on servers located within the national territory, absent a case the law provides for. Controllers must guarantee the security of electronic personal data, adopt the necessary technical and administrative measures, and notify the competent authorities of cybersecurity incidents affecting personal data under their custody.

Controllers must also let data subjects who are users of public telecommunications, applications, and internet services access, update, and cancel their data on request, and disclose, in plain terms, the purpose of collection, privacy configuration options, and use of tracking elements such as cookies.

What it requires

Scraping law1 instrument, 1 in force

Research summary (177 words)

Cuba has no scraping-specific statute, so general law governs each dimension separately.

Título IX of the 2022 Penal Code (Ley 151/2022) criminalizes accessing an information system, storage device, program, database, or application without due authorization, with the purpose of appropriating, using, disclosing, or disseminating the information it stores, transmits, or captures, but a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that requirement, and no reported case has tested the point.

No Cuban court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. Cuba's 1977 copyright statute permits reproducing citations or fragments of a lawfully disclosed work for informational purposes, but Cuba has not enacted a text-and-data-mining exception and confers no sui generis database right.

Personal data scraped from a public Cuban page remains subject to Ley 149/2022's data-protection duties, which do not carve out publicly accessible information. No Cuban statute or reported case assigns legal weight to a robots.txt directive, establishes a scraping-specific unfair-competition or misappropriation doctrine, or imposes an AI-training-specific rule.

Computer misuse

Código Penal (Ley 151/2022), offenses against telecommunications and ICT security

Ley 151/2022, Código Penal, Título IX, Capítulo I (arts. 289-294)Official text of Ley 151/2022 (Código Penal) as published in Gaceta Oficial de la República de Cuba

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 1, 2022. Publisher's page: https://www.gacetaoficial.gob.cu/sites/default/files/goc-2022-o93_0.pdf

In force since 30 November 2022. Binds public and private bodies.

What this law does

Article 289 punishes violating legally established computer-security measures to use information technology media and affect the confidentiality, integrity, or availability of digital assets, with imprisonment of six months to two years or a fine of 200 to 500 cuotas, or both.

Article 290 punishes accessing or using, or letting another access or use, an information system, storage device, software, or database without due authorization, with the purpose of appropriating, using, knowing, disclosing, or disseminating the information it stores, transmits, or captures, with imprisonment of one to three years or a fine of 300 to 1,000 cuotas, or both; because the offense turns on lacking due authorization for a specific purpose rather than on defeating a technical access control, a scraper reading a public, unauthenticated page falls outside a plain reading of the provision unless it is shown to lack authorization for one of the stated purposes.

Article 291 punishes using equipment or procedures to obstruct lawful access to information systems, or scanning telecommunications and ICT services to detect security vulnerabilities, interrupt services, or obtain information about their operation or users, without authorization. Article 292 punishes any act intended to compromise the security of ICT-using systems and knowingly providing a service toward that end.

Article 293 punishes intercepting, manipulating, or interfering with an information or telematic system without authorization and with intent to cause damage, with an aggravated bracket where illegally obtained passwords or similar means are used. Article 294 punishes producing, trafficking, or introducing computer viruses or malicious code intended to disable ICT infrastructure.

Article 296 allows the sanction to be doubled where a grave harm results, an international or foreign system is affected, or a vital or strategic system is put at risk, and increased by half where the offender is an official or employee with custody of the affected system, and allows the accessory sanction of confiscation of property.

Each cuota's monetary value is fixed by the sentencing court between 10 and 200 pesos according to the convicted person's income, so the fine bracket named in each article above is not itself a single peso amount.

Cuba's separate telecommunications framework, Decreto-Ley 35/2021, and its implementing Resolución 105/2021 on cybersecurity-incident response (issued under the earlier Decreto 360/2019) impose incident-notification duties on network operators but create no distinct authorization or access regime for a third party reading data from a system.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (413 words)

Cuba's private-sector-facing information-security law sits in a 2019 regulatory package published the same day: Decreto No. 360/2019 ‘Sobre la Seguridad de las Tecnologías de la Información y la Comunicación y la Defensa del Ciberespacio Nacional’ and its implementing Reglamento de Seguridad de las TIC, approved by Resolución 128/2019 of the Ministry of Communications (MINCOM).

Both bind any entity or natural person in Cuba that owns or uses information and communication technologies, and the Reglamento names ‘las formas de propiedad y gestión no estatal’ (English: non-state forms of ownership and management), the umbrella term Cuban law uses for the self-employed and private cooperatives and, since Decreto-Ley 46/2021 legalized them, for micro, small and medium private enterprises (MIPYMEs), as bound parties that must comply even without specialized security staff.

That reach is administratively thin rather than deep: the operative duty is to design, implement and keep updated a TIC Security System and a written Security Plan proportionate to the entity's own assessed risk, with no product-specific technical standard, no pre-market security requirement for a manufacturer, and no dedicated vulnerability-disclosure channel, so this filing records no instrument that sets security requirements a product must meet before it reaches market.

A separate 2021 instrument, the Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad approved by Resolución 105/2021 of MINCOM, sets the incident-reporting duty implementing Decreto 360/2019's own call for a national response model.

It runs to the Cuban Computer Incident Response Team (CuCERT) inside MINCOM's Oficina de Seguridad para las Redes Informáticas (OSRI), and it expressly reaches natural persons and the holders of private data networks, not only state bodies.

Cuba's telecommunications sector is dominated by the state monopoly ETECSA, and Decreto-Ley 35/2021 ‘De las Telecomunicaciones, las Tecnologías de la Información y la Comunicación y el Uso del Espectro Radioeléctrico’ licenses network operators and service providers under a concession or authorization regime that a private or non-state actor can hold only with MINCOM's authorization, so no sector-specific security regime in this corpus binds a private telecommunications operator beyond the general TIC security baseline both instruments above already record.

Ley 149/2022's own data-protection-incident notification duty and Resolución 58/2022's security and data-localization duties for telecommunications, hosting, application and private-network operators are Cuba's breach-notification law and are recorded under the privacy topic rather than repeated here. The computer-misuse offenses in Ley 151/2022's Código Penal, Título IX, bind an intruder rather than a system operator or manufacturer, and they are recorded under the scraping topic.

Security baseline statutes

Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty

Decreto No. 360/2019 ‘Sobre la Seguridad de las Tecnologías de la Información y la Comunicación y la Defensa del Ciberespacio Nacional’… (Gaceta Oficial de la República de Cuba, Ordinaria No. 45, GOC-2019-549-O45, 4 de julio de 2019), arts. 10, 12, 17-20, 41, 56, 89, 109; and its implementing Reglamento de Seguridad de las Tecnologías de la Información y la Comunicación, approved by Resolución 128/2019 of the Ministry of Communications (GOC-2019-555-O45), arts. 2, 4-8, 50Official text of Decreto No. 360/2019 and Resolución 128/2019 as published in Gaceta Oficial de la República de Cuba

In force. Binds public and private bodies.

What this law does

Decreto No. 360/2019 sets Cuba's legal framework for the secure use of information and communication technologies (TIC) and binds bodies and organs of the Central State Administration, the Central Bank of Cuba, national entities, People's Power bodies, the state business system and budgeted units, cooperatives, mixed enterprises, nonprofit associative forms, political, social and mass organizations, and natural persons.

Its implementing Reglamento, approved the same day by Resolución 128/2019 of the Ministry of Communications, extends that list by name to non-state forms of ownership and management. Non-state forms of ownership and management and natural persons must comply with the Reglamento to the extent it applies to them even where they have no specialized security personnel.

Every entity that uses TIC must design, implement, manage and keep updated a TIC Security System proportionate to the importance of the assets it protects and the risks it faces, and must adopt a written TIC Security Plan setting out the policies, measures and procedures that follow from it.

An Internet access service provider must additionally draft internal security-operation procedures, name the person responsible for the security of its network, and adopt technical and organizational measures to prevent malware contamination and network attacks and intrusions. The Ministry of Communications licenses any entity that wishes to provide TIC security services to third parties. Only a state entity whose personnel reside permanently in the country may hold that license.

Producers of equipment and providers of network, program, application and IT services, whether domestic or foreign, are responsible for implementing the requirements that guarantee the secure operation of the equipment and services they supply.

Neither Decreto 360/2019 nor its Reglamento sets a specific technical security standard, a pre-market certification gate, a mandatory support period, or a dedicated vulnerability-disclosure channel that a manufacturer must meet, so this regime does not reach the product-security dimension this topic tracks.

A violation draws administrative sanctions, a preventive notice, temporary or partial invalidation or outright cancellation of an administrative authorization the Ministry of Communications granted, temporary or partial suspension or cancellation of computing and communications services contracted with an authorized enterprise, and confiscation of the means used to commit the infraction, rather than a monetary fine.

Neither Decreto 360/2019 nor its Reglamento states an entry-into-force date distinct from their shared Gaceta Oficial publication date of 4 July 2019.

What it requires

Vulnerability and incident reporting

Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad

Resolución 105/2021 of the Ministry of Communications ‘Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad’ (Gaceta Oficial de la República de Cuba, Ordinaria No. 92, GOC-2021-762-O92, 17 de agosto de 2021), arts. 1, 2, 21-23 and resolving clause SEGUNDOOfficial text of Resolución 105/2021 as published in Gaceta Oficial de la República de Cuba, Ordinaria No. 92 (17 August 2021)

In force. Binds public and private bodies.

What this law does

Resolución 105/2021 of the Ministry of Communications approves a Reglamento establishing the National Action Model for responding to cybersecurity incidents within the National Cyberspace, to guarantee an effective response for its protection.

The Reglamento applies to natural and legal persons, naming government bodies, diplomatic missions and Cuba's own commercial and cooperation representations abroad, the state business system, cooperatives, mixed enterprises and other foreign-investment forms, nonprofit associative forms, and the holders of data networks in the National Cyberspace.

A person directly responsible for the computing infrastructure where a cybersecurity incident occurs must report it to their immediate superior and to the Cuban Computer Incident Response Team (CuCERT), housed in the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI).

The holder of a private data network is separately responsible for ensuring that a cybersecurity event or incident affecting that network is recorded and classified, and for delivering the information that reporting to CuCERT requires. The holder of a private network belonging to a natural person, and a natural person individually, must also report a cybersecurity incident through the channel the Ministry of Communications publishes on its own website.

CuCERT receives and forwards incident information until a dedicated Cybersecurity entity, to be staffed jointly by the Ministries of Communications, of the Revolutionary Armed Forces and of the Interior, is created to take over that function.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (136 words)

Cuba has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law on hyperlinking or framing liability.

The operative instrument is Ley 14/1977 De Derecho de Autor, which lets a person, once a work is lawfully known to the public and its author and source are credited, reproduce citations or fragments for teaching, informational, critical, illustrative, or explanatory purposes, and separately lets a person reproduce, broadcast, or otherwise communicate to the public a political speech, report, conference, judicial debate, or similarly public-character work that has already been communicated or made known to the public, without the author's consent and without remuneration.

The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists.

Snippet reproduction

Ley 14/1977, De Derecho de Autor, press-review and public-communication exception

Ley 14/1977 De Derecho de Autor, art. 38Ley 14/1977 De Derecho de Autor, official text reproduced by WIPO Lex from a scanned Ministry of Justice edition

In force. Binds public and private bodies.

What this law does

Article 38 permits, without the author's consent and without remuneration but with mandatory credit to the author's name and the source, and provided the work is already known to the public: reproducing citations or fragments in written, sound, or visual form for teaching, informational, critical, illustrative, or explanatory purposes, to the extent the purpose pursued justifies; using a work, even in full where its brief length and nature justify it, as teaching illustration in publications or broadcasts; and reproducing, broadcasting, or otherwise communicating to the public any political speech, report, conference, or judicial debate, or other work of the same character, that has already been communicated or made known to the public, though including such a speech in a compiled collection of one author's works or in a collective work still requires the author's consent and remuneration.

The stored text of this 1977 law is a scanned, optical-character-recognized copy whose transcription is degraded throughout; the provisions above are read from that scan.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.