Law / Nicaragua

Nicaragua

10 of 11 named instruments researched to a stage, across three of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect10 of 10 carry a date. Earlier is before 2014.
Before 2014: 8 instruments (8 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (144 words)

Nicaragua's comprehensive data-protection statute is Ley No. 787, Ley de Proteccion de Datos Personales, approved 21 March 2012 and in force since its publication in La Gaceta, Diario Oficial No. 61 of 29 March 2012, implemented by Reglamento No. 36-2012.

It binds processing of personal data in public and private data files alike, requires consent as the general basis for processing subject to listed exceptions, sets a narrower regime for sensitive categories, restricts cross-border transfer, and creates the Direccion de Proteccion de Datos Personales (DIPRODAP), attached to the Ministry of Finance and Public Credit, as supervisory authority.

The Act's own enforcement mechanism is administrative (warning, suspension, closure of a data file) rather than a monetary fine, and its remedy runs through an administrative complaint to DIPRODAP followed, once that route is exhausted, by a constitutional amparo action rather than a standalone civil damages claim.

Breach notification

Ley No. 787, Ley de Protección de Datos Personales, security incident notice

Ley No. 787, art. 11 (security incident notice to the affected institution)Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 11 requires the data controller to adopt the technical and organizational measures necessary to guarantee the integrity, confidentiality, and security of personal data and to detect intentional or unintentional deviations of private information, whatever the source of the risk.

Where the personal data concerned belong to a member of the National Police or the Army of Nicaragua and the required security measures fail or are not observed, article 11 requires the data controller to immediately inform the affected institution, though the Act states no equivalent duty to notify the Direccion de Proteccion de Datos Personales or the general public of a security breach.

What it requires

Comprehensive regime

Ley No. 787, Ley de Protección de Datos Personales

Ley No. 787, 29-Mar-2012, Gaceta Oficial No. 61, arts. 1-6, 9, 11-13, 19, 22-24, 27Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 1 states the Act's object as protecting a natural or legal person against automated or non-automated processing of their personal data held in public or private data files, to guarantee the right to personal and family privacy and the right to informational self determination, and article 2 applies it to the processing of personal data found in public and private data files alike.

Article 4 makes creating a data file lawful only when it is duly authorized and registered with the data subject's consent, unless the law excepts it, and bars a data file from serving a purpose other than one this Act permits. Article 5 requires that personal data be obtained only when adequate, proportional and necessary to the purpose for which it is collected and only by lawful means that guarantee the right to informational self determination.

Article 6 makes the data subject's consent, given by the data subject or their legal representative in writing or another suitable physical or electronic means and revocable without retroactive effect, the general basis for delivering personal data, except where a competent judicial authority so orders, the data first undergo a dissociation procedure, the purpose is to perform obligations arising from a legal relationship between the data subject and the controller, or the data are drawn from an unrestricted public access source and limited to name, national identity document number, and date of birth.

Article 9 requires that all processing be adequate, proportional, and necessary to the purpose for which the data were requested, and requires the data controller and, where applicable, the data processor, to adopt the technical and organizational measures necessary to guarantee the security of personal data and prevent unauthorized access, use, alteration, loss, disclosure, transfer, or dissemination.

Article 11 requires the data controller to adopt the technical and organizational measures necessary to guarantee the integrity, confidentiality, and security of personal data, to prevent its corruption, loss, unauthorized consultation, processing, disclosure, transfer, or dissemination, and to detect intentional or unintentional deviations of private information, whether the risk comes from human action or the technical medium used.

Article 12 binds the data controller and anyone who takes part in any phase of processing personal data to professional secrecy, an obligation that survives the end of their relationship with the data controller, releasable only by judicial order and only for reasons of national security, national defense, public security, or public health.

Article 13 lets personal data be assigned or transferred domestically only for purposes directly related to the legitimate interest of the assignor and the assignee and with the data subject's prior consent, informed of the purpose of the assignment and the assignee's identity, revocable by written notice, except where a law so provides, the assignment is between state institutions in the exercise of their powers, it concerns public health, social interest, or national security, or a dissociation procedure has been applied.

Article 19, item f, limits the retention of personal data to five years, or to the term the parties' contract sets, or until the data are no longer adequate, proportional, and necessary for the purpose for which they were requested.

Article 22 requires every data controller to register with the data file register the Direccion de Proteccion de Datos Personales keeps, to wait thirty days for its registration decision, and to record the controller's name and domicile, the nature of the data held, how and when data are collected and updated, the data's destination and recipients, how the records interrelate, the security measures used, the retention period, and how a person can exercise their rights over the file.

Article 23 lets a public or private data file be created, modified, or extinguished only under this Act's provisions, which must state the file's characteristics and purpose, whose data it seeks, whether supplying it is mandatory or optional, and, on suppression, the file's destination or the measures taken to destroy it.

Article 54 excludes from this Act's application the information handled and regulated by the Comision Nacional de Microfinanzas, the Superintendencia de Bancos y de Otras Instituciones Financieras, the entities those regulators supervise, information exchanged under reciprocal supervisory agreements, and private credit bureaus handling credit information, without prejudice to this Act's general principles, the data subject's rights, and its other limitations.

What it requires

Cross border transfer

Ley No. 787, Ley de Protección de Datos Personales, cross border transfer of data

Ley No. 787, arts. 14-15 (cross border transfer of data)Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 14 prohibits assigning or transferring personal data of any kind to a country or international organization that does not provide adequate levels of security and protection.

The prohibition does not apply to international judicial cooperation, an exchange of health data necessary for an epidemiological investigation, a banking or securities transfer under its own governing law, a transfer agreed under an international treaty Nicaragua has ratified, or international intelligence cooperation against organized crime, drug trafficking and controlled substances offences, offences against state security, or offences against the international order, each as defined in the laws the article names.

Article 15 requires the data controller, before transferring personal data, to act only on a legally authorized requester's petition stating its object and purpose, to verify that both parties meet the applicable security and confidentiality measures, to inform the data subject of the request and its purpose for their consent subject to article 14's exceptions, to prevent the information from reaching a third party, and to notify the Direccion de Proteccion de Datos Personales of the transfer made.

What it requires

Data subject rights

Ley No. 787, Ley de Protección de Datos Personales, rights of data subjects

Ley No. 787, arts. 7, 10, 16-21, 25-26 (rights of data subjects)Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 7 requires the data controller to inform a data subject, before obtaining their data, of the purpose and possible recipients, the existence and location of responsibility for the file, whether answering is mandatory or optional, the consequences of refusing or of inaccurate data, the data subject's rights of access, rectification, and cancellation, and, where data from public sources are used for advertising, the data's origin and the controller's identity in every communication.

Article 10 gives a data subject a digital right to be forgotten, letting them request that social networks, browsers, and servers suppress and cancel their personal data, and, once a contractual relationship with a public or private institution ends, letting them request that all personal data collected during that relationship be suppressed and cancelled.

Article 12 gives a data subject the right to be informed of the privacy policies a data controller adopts and to be notified of any change to them. Article 16 gives a data subject the right to request information from the Direccion de Proteccion de Datos Personales about the existence of data files, their purposes, and the identity of those responsible for them, through a public and free register.

Article 17 gives a data subject the right to request and obtain information about their personal data processed in public and private data files, including how the data were collected, why, and what transfers or assignments were made, the right to rectify, modify, suppress, complement, include, update, or cancel their data, a response within ten business days of the request, the right of their universal heirs to exercise this article's rights over a deceased person's data, and the right not to be compelled to supply sensitive personal data except as this Act's exceptions allow.

Article 18 requires the information given to a data subject to be clear and simple, to cover the whole of their own data even where they asked about only one aspect, never to reveal a third party's data, and to be supplied in writing, electronically, by phone, by image, or by any other means the data subject chooses, within the controller's technical capacity.

Article 19 gives a data subject the right to have their data rectified, modified, suppressed, complemented, included, updated, or cancelled, requires the data controller to act within five business days of the request and answer in writing, bars cancellation for reasons of social interest, national security, public health, or a third party's rights, requires the controller to notify any assignee of the correction within five business days, requires the controller to block disputed data while verifying a claimed error, and limits retention of the data to five years or the term the parties' contract sets.

Article 20 lets a data controller deny a rectification request only where a judicial decision so orders, and requires the controller to tell the data subject of that decision while still granting them access to their own data to exercise their defense. Article 21 makes exercising the rights of rectification, modification, suppression, complementation, inclusion, updating, and cancellation free of charge to the data subject.

Article 25 lets a data file built for advertising, promotions, offers, or direct sale include personal data only with the data subject's consent or from a publicly accessible source, gives the data subject free access to it, and lets them request removal from it at any time.

Article 26 requires an electronic advertisement to offer its recipient the means to refuse further advertising or revoke their consent, clearly and free of charge, and requires a marketing business to hold a contract proving the personal data it uses were obtained with the data subject's unambiguous, informed consent or from a public access source.

What it requires

Enforcement supervision

Ley No. 787, Ley de Protección de Datos Personales, supervision, sanctions, and complaints

Ley No. 787, arts. 28-29, 34-35, 44-52 (supervision, sanctions, and complaints)Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 28 creates the Direccion de Proteccion de Datos Personales, attached to the Ministry of Finance and Public Credit, with a director designated by that ministry's highest administrative authority, to control, supervise, and protect the processing of personal data in public and private data files.

Article 29 gives the Direccion de Proteccion de Datos Personales broad functions: advising on this Act's content and scope, issuing rules on confidentiality, integrity, and security, requesting information from public and private data file holders, imposing administrative sanctions on offenders, filing complaints with the competent authority, verifying registration requirements, accrediting inspectors, promoting self regulation models, opining on relevant bills, publicizing the right to informational self determination, and cooperating with foreign data protection authorities.

Article 34 lets an accredited inspector inspect on a complaint or on its own motion with judicial authorization, and article 35 requires a person or entity under inspection to allow the inspectors access to its data files, cooperate with the inspection, supply the requested information and documents, including its operating registration and security measures, and allow its equipment to be reviewed.

Article 44 classifies as a minor infraction processing personal data without the required express consent, failing to include, complete, rectify, update, suppress, block, or cancel data on request, failing to follow the Direccion de Proteccion de Datos Personales' instructions, collecting data through a form that lacks a clear notice that a file will be created, and sending advertising to a person who has refused it.

Article 45 classifies as a serious infraction processing personal data by fraudulent means or in violation of this Act, obstructing the right to informational self determination or unjustifiably denying requested information, breaching the professional secrecy this Act requires, repeating a minor infraction, keeping a data file without the minimum security, integrity, and confidentiality conditions the applicable rules require, or obstructing an inspection.

Article 46 gives the Direccion de Proteccion de Datos Personales power to impose the administrative sanctions of a warning or suspension of processing operations for a minor infraction, and closure or cancellation of the data file, temporary or permanent, for a serious infraction, without prejudice to any separate liability for damages or any criminal sanction.

Articles 47 through 51 give a data subject an administrative protection action before the Direccion de Proteccion de Datos Personales to learn of their processed data, to challenge a breach of confidentiality, integrity, or security, to correct false, inaccurate, outdated, omitted, or unlawfully processed information, to access information a public or private entity holds about them, and to demand correction, inclusion, suppression, blocking, or cancellation of their data, brought by the data subject, their guardian, their heirs, or a representative, and article 52 lets the data subject use a constitutional amparo action once the administrative route is exhausted, and lets a data controller separately challenge an administrative act under the law governing the Executive Power's procedures.

What it requires

Sensitive categories

Ley No. 787, Ley de Protección de Datos Personales, sensitive categories of data

Ley No. 787, arts. 3(g), 7(l), 8 (sensitive categories of data)Official text, Asamblea Nacional de Nicaragua legislation database (Normas Juridicas de Nicaragua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d

In force since 29 March 2012. Binds public and private bodies.

What this law does

Article 3, item g, defines sensitive personal data as any information revealing racial or ethnic origin, political affiliation, religious, philosophical, or moral belief, union membership, health or sex life, criminal record or administrative infractions, or economic or financial information, including credit and financial information and any other information that could motivate discrimination, with no reference to biometric or genetic data.

Article 7, item l, bars creating a data file that stores sensitive data, except as this Act provides, though a commercial company or nonprofit association may still keep its own members' data.

Article 8 divides personal data into categories: sensitive personal data may be obtained and processed only for reasons of general interest stated in the law, with the data subject's consent, or by judicial order, and data about criminal record or administrative infractions may be processed only by the competent public authorities within their own powers; health data held by a public or private hospital, clinic, or health center, and by health professionals, is limited to a patient's physical or mental health data and processed under professional secrecy; and commercial data on a company's customers, suppliers, and human resources, kept for advertising purposes or as reserved commercial or business information, may be disclosed only with the data subject's consent, by express law of social interest, or by judicial order.

Article 17, item e, gives every data subject the right not to be compelled to supply sensitive personal data, except as this Act's own exceptions provide.

What it requires

Scraping law3 instruments, 3 in force

Research summary (288 words)

Nicaragua has no scraping-specific statute, so general law governs each dimension separately.

Ley No. 1042, Ley Especial de Ciberdelitos (2020, amended in relevant part by Ley No. 1219 of 2024) criminalizes unauthorized access to a computer system and interference with or damage to a system or its data; article 4's unauthorized-access offense requires intentional access without authorization or in excess of the authorization granted, so a plain reading does not reach reading a public, unauthenticated page that defeats no access control. No Nicaraguan case on that point has been located.

No Nicaraguan court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Ley No. 312, Ley de Derecho de Autor y Derechos Conexos (1999, as amended) protects a compilation or database as an independent work only where the selection or arrangement of its contents is an intellectual creation, a compilation-copyright model rather than a sui generis database right, and its personal-use reproduction privilege expressly excludes reproducing the whole or an important part of a database in digital form.

Nicaragua has not enacted a text-and-data-mining exception; the general quotation right (fragment reproduction for citation, analysis, comment, or criticism, with source and author attribution) is the closest applicable ground.

Ley No. 787, Ley de Proteccion de Datos Personales, reaches personal data scraped from a public Nicaraguan source in the same way it reaches any other personal data, subject only to a narrow consent exception for name, national-identity-document number, and date-of-birth listings drawn from unrestricted public-access sources; that regime is researched in full under this jurisdiction's privacy-topic document.

No Nicaraguan statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Ley No. 1042, interference with and damage to computer systems, as reformed by Ley No. 1219

Ley No. 1042, as reformed by Ley No. 1219 (2024), arts. 8-10Official text of Ley No. 1219

In force since 12 September 2024. Binds public and private bodies.

What this law does

As reformed by Ley No. 1219, article 8 punishes intentionally interfering with or altering the operation of a computer system or its data, temporarily or permanently, with imprisonment of four to seven years and 300 to 600 day-fines, rising to seven to fifteen years and 600 to 1,000 day-fines where the target is a State system or one serving health, communications, financial, energy, water, transport, port, airport, public-safety, social-security, or education services.

Article 9 punishes violating a computer system's security to destroy, alter, duplicate, disable, or damage its data, processes, or their integrity, availability, or confidentiality, with imprisonment of seven to fifteen years and 600 to 1,000 day-fines.

Article 10 punishes destroying, damaging, modifying, or disabling a computer system or its components, with imprisonment of four to seven years and 300 to 600 day-fines (six months to one year and 200 to 500 day-fines where committed recklessly), rising to seven to fifteen years and 600 to 1,000 day-fines where the target serves public or financial services or holds personal data, sensitive personal data, or reserved information.

What it requires

Ley No. 1042, unauthorized access to computer systems

Ley No. 1042, 27-Oct-2020, arts. 4-5Official text of Ley No. 1042 as approved in 2020, Asamblea Nacional de Nicaragua legislation database

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/($All)/803E7C7FBCF44D7706258611007C6D87

In force since 29 December 2020. Binds public and private bodies.

What this law does

Article 4 punishes a person who intentionally and without authorization, or in excess of the authorization granted, accesses, intercepts, or partially or wholly uses a computer system, with imprisonment of one to three years and 200 to 500 day-fines.

Article 5 punishes accessing a program or stored data with intent to appropriate it or to commit another offense with it, with imprisonment of two to four years and 300 to 500 day-fines; both penalties increase by a third at their upper and lower limits when committed for commercial purposes or against a public office or a bank, microfinance institution, or other regulated financial entity. Neither article was among those Ley No. 1219 of 2024 reformed.

Article 47 of Ley No. 1042 repealed articles 192, 193, 194, 198, 245, and 246 of the prior Ley No. 641, Codigo Penal (2007), which had held Nicaragua's computer-offense provisions before this Act.

What it requires

Database right

Ley No. 312, protection of compilations and databases

Ley No. 312 (1999, as amended), arts. 14, 31.3Official consolidated text (Digesto Juridico), Asamblea Nacional de Nicaragua legislation database

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/87b347bc9bf5803c0625875e0076c6d9

In force since 31 August 1999.

What this law does

Article 14 protects a collection such as an anthology, a compilation of texts, or a database as an independent work, without prejudice to the copyright in the works it contains, only where the selection or arrangement of its materials constitutes an intellectual creation; Nicaragua confers no sui generis database right beyond that compilation-copyright model.

Article 31 permits reproducing a single copy of a published work without the author's authorization for personal use, but expressly excludes from that privilege the reproduction of the whole or an important part of a database in digital form, so bulk reproduction of a protected database is not covered even for personal use.

Nicaragua has not enacted a text-and-data-mining exception; the general quotation right at article 32, permitting reproduction of a fragment for citation, analysis, comment, or criticism to the extent justified by that purpose, in accordance with fair practice and with the source and author named, is the closest applicable ground for excerpting a protected compilation or database.

The criminal-sanctions chapter the 1999 Act originally carried for copyright violations has since been repealed; civil enforcement runs through article 97, which entitles a rights holder to seek cessation of the infringing activity and compensation for the moral and patrimonial harm caused.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (168 words)

Nicaragua has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no reported hot-news or misappropriation case. Ley No. 312, Ley de Derecho de Autor y Derechos Conexos (1999, as amended), addresses reproduction of news and journalism through two limitations on the author's exclusive right rather than through a dedicated aggregation regime.

Its general quotation right permits reproducing a fragment of a divulged work for citation, analysis, comment, or criticism, with source and author named.

Its press-specific limitation goes further for portions of articles on current economic, political, or religious affairs: another outlet of the same kind may reproduce, distribute, or publicly communicate them without the author's authorization unless that right has been expressly reserved, again with mandatory source and author attribution, and a related provision permits reproducing a work seen or heard in connection with covering a current event, to the extent the informational purpose justifies.

No Nicaraguan statute or reported case addresses hyperlinking, framing, or a text-and-data-mining opt-out mechanism as they bear on indexing news.

Snippet reproduction

Ley No. 312, quotation and press-reproduction limitations

Ley No. 312 (1999, as amended), arts. 32, 40-42Official consolidated text (Digesto Juridico), Asamblea Nacional de Nicaragua legislation database

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Publisher's page: http://legislacion.asamblea.gob.ni/normaweb.nsf/9e314815a08d4a6206257265005d21f9/87b347bc9bf5803c0625875e0076c6d9

In force since 31 August 1999.

What this law does

Article 32 permits reproducing a fragment of an already-divulged work without the author's authorization when done for citation, analysis, comment, or criticism, to the extent justified by that purpose, in accordance with fair practice, naming the source and the author.

Article 40 goes further for news: portions of articles on current economic, political, or religious affairs disseminated by the mass media may be reproduced, distributed, and publicly communicated by any other outlet of the same kind without the author's authorization, unless that right has been expressly reserved, again with the source and the author's name always clearly indicated.

Article 41 permits the mass media to reproduce speeches, addresses, and similar works delivered in public without the speaker's authorization, when done solely to report on current events and citing the author, while reserving to the author the right to publish a collection of such works. Article 42 permits reproducing a work seen or heard in connection with reporting on a current event, to the extent the informational purpose justifies, with total reproduction reserved to exceptional cases.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.