Comprehensive regime
Ley No. 172-13 sobre Protección Integral de los Datos Personales
Ley No. 172-13, Gaceta Oficial No. 10737, 15 de diciembre de 2013, arts. 1-6, 27-28, 42-43, 60 y 63Official text of Ley No. 172-13, reproduced by the Instituto Nacional de la Vivienda (INVI), a Dominican government portal
In force since 15 December 2013. Binds public and private bodies.
What this law does
Article 1 sets the law's object as the comprehensive protection of personal data held in public or private files, registers, databanks or other technical processing media, and separately regulates the constitution, organization and operation of Sociedades de Información Crediticia (SIC), the credit reporting bureaus.
Article 2 applies the law to personal data recorded in any databank susceptible to processing and to every later use of that data in the public and private spheres alike, and article 4 excludes only a narrow, exhaustive list: data an individual keeps for purely personal or domestic activity, files kept by the Dominican Republic's investigative and intelligence bodies for crime prevention and prosecution, data about deceased persons, and data limited to a professional's name, position, and business contact details.
Article 5 states the law's governing principles: files must be lawful and registered, data must be accurate and kept up to date, a data subject must be told the purpose of the processing and who is responsible for the file before consenting, processing requires the data subject's free, express and conscious consent unless an exception applies, the data controller and processor must adopt technical, organizational and security measures against alteration, loss or unauthorized access, everyone who handles the data owes a duty of professional secrecy that survives the end of their relationship with the data subject or the controller, data may not be collected by fraudulent or unlawful means, and data may only be collected for a determined, explicit and legitimate purpose.
Article 42 requires every archive, registry, or databank, public or private, to maintain adequate information policies guaranteeing security and control measures to prevent the improper handling of data subjects' information. Article 43 requires a Sociedad de Información Crediticia to register with the Superintendencia de Bancos once the Junta Monetaria has authorized it to operate, before it may begin operating as a credit bureau.
Article 60 requires a Sociedad de Información Crediticia to use biometric identification techniques, such as matching a consumer's photograph, to make identity theft difficult when a person contracts goods or services from a public or private entity, and article 63 requires it to adopt the security measures necessary to prevent improper handling of the information and to protect the algorithms and technologies it uses under the strictest security and confidentiality.
What it requires