Law / Uruguay

Uruguay

11 of 14 named instruments researched to a stage, across three of the six areas of law we track: 11 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law7 instruments, 7 in force

Research summary (209 words)

Uruguay's Ley N° 18.331 of 11 August 2008, Protección de Datos Personales y Acción de Habeas Data, is a comprehensive, General Data Protection Regulation (GDPR)-comparable regime enforced by the Unidad Reguladora y de Control de Datos Personales (URCDP) and recognized by the European Commission as offering an adequate level of protection.

Ley N° 19.670 of 2018 added extraterritorial reach for a controller established abroad, a security-breach notification duty, and a mandatory data-protection-officer designation for large-scale or state-linked processors, both now regulated in detail by Decreto N° 64/020 of 2020.

Uruguay's definition of sensitive personal data (art. 4, literal E) reaches racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, and sexual life, and does not name biometric or genetic data as such; Ley N° 19.924 of 2020 instead added a dedicated biometric-data definition (art. 4, literal Ñ) and a standalone provision, art. 18-BIS, requiring a data-protection impact assessment before any biometric processing, so a service that captures a faceprint or voiceprint answers to that dedicated duty rather than to the sensitive-category rule.

The Act's habeas data action, at arts. 37 to 45, gives any person a judicial remedy to learn what personal data about them a public or private database holds and to demand its correction, inclusion, or deletion.

Biometric privacy

Ley N° 18.331, biometric data

Ley N° 18.331, arts. 4 (literal Ñ) y 18-BIS, según Ley N° 19.924, de 18 de diciembre de 2020 (datos biométricos)Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 4, literal Ñ, added by Ley N° 19.924 art. 86, defines biometric data as personal data obtained from a specific technical process relating to a natural person's physical, physiological, or behavioral characteristics that allow or confirm their unique identification, such as fingerprint data, image recognition, or voice recognition.

Article 18-BIS, added by Ley N° 19.924 art. 87, requires that any processing of biometric data first pass through a data protection impact assessment and fit within one of the lawful bases article 9 allows, a dedicated duty distinct from the sensitive-data list at article 4 literal E, which does not name biometric data.

What it requires

Breach notification

Ley N° 19.670, personal data breach notification

Ley N° 19.670, de 15 de octubre de 2018, art. 38, reglamentado por Decreto N° 64/020, de 2020 (notificación de vulneración de seguridad)Ley N° 19.670, de 15 de octubre de 2018, texto consolidado, Dirección Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force since 1 January 2019. Binds public and private bodies.

What this law does

Article 38, now regulated by Decreto N° 64/020 of 2020, requires the controller or processor of a database, on becoming aware of a security breach, to inform both the affected data subjects and the Unidad Reguladora y de Control de Datos Personales immediately and in detail, together with the measures adopted, coordinating the response with the Centro Nacional de Respuesta a Incidentes de Seguridad Informática del Uruguay (CERTuy).

The provision states no fixed numeric deadline, only immediacy from the moment the controller or processor becomes aware of the breach, and leaves the detailed content of that notification to the implementing regulation, Decreto N° 64/020.

What it requires

Comprehensive regime

Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Ley N° 18.331 de 11 de agosto de 2008, arts. 1-12, 17, 20, 22, 24, 28-30, según Ley N° 19.670, de 2018, arts. 37 y 40, y Decreto N° 64/020, de 2020Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 9 requires free, prior, express, and informed consent before processing personal data, documented in writing, subject to narrow exceptions for data drawn from public sources, gathered for a state function, or arising from a contractual, scientific, or professional relationship.

Article 10 requires the responsible party to adopt the security measures needed to prevent unauthorized alteration, loss, consultation, or processing of personal data, and article 11 binds anyone who legitimately accesses another party's database to reserve and professional secrecy, backed by the existing offense at article 302 of the Penal Code.

Article 12, as rewritten by Ley N° 19.670 art. 39 and regulated by Decreto N° 64/020 of 2020, imposes a proactive-accountability duty of privacy by design, privacy by default, and a data-protection impact assessment. Article 17 lets personal data be communicated to a third party only for a purpose tied to the sender's and recipient's legitimate interest and only with the data subject's prior consent.

Articles 24, 28, and 29 require every public or private database to be registered with the Unidad Reguladora y de Control de Datos Personales before it operates, declaring the categories of data it holds.

Ley N° 19.670 art. 37, now regulated by Decreto N° 64/020, extends the law to a controller or processor established outside Uruguay when it offers goods or services to Uruguayan residents, analyzes their behavior, or uses means located in the country, requiring a locally domiciled representative before the URCDP.

Ley N° 19.670 art. 40 requires a public entity, a wholly or partly state-owned entity, or a private entity that processes sensitive data as a main line of business or processes large volumes of data, to designate a data-protection officer with technical autonomy.

Article 22 limits a negative commercial-debt record concerning a natural person to five years from its entry, renewable once, and article 20 requires an operator of a public communications network or electronic communications service to secure that network and warn subscribers of a particular security risk.

What it requires

Cross border transfer

Ley N° 18.331, cross border transfer of personal data

Ley N° 18.331, art. 23 (transferencia internacional de datos personales)Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 23 prohibits transferring personal data of any kind to a country or international body that does not provide an adequate level of protection under international or regional legal standards.

That prohibition does not reach judicial cooperation, medical-data exchange for public health reasons, banking or stock-exchange transactions, a treaty Uruguay is party to, or intelligence cooperation against organized crime, terrorism, or drug trafficking, and it also yields where the data subject unambiguously consents, the transfer is contractually necessary, an important public interest or a legal proceeding requires it, the data subject's vital interest is at stake, or the transfer comes from a register meant to inform the public.

Absent an adequate-protection finding and outside those exceptions, the Unidad Reguladora y de Control de Datos Personales may still authorize a transfer, or a series of transfers, to a country that does not guarantee an adequate level of protection where the controller offers sufficient contractual safeguards for privacy and fundamental rights.

What it requires

Data subject rights

Ley N° 18.331, rights of data subjects

Ley N° 18.331, arts. 13-17 y 21, según Ley N° 20.075, de 2022, y Ley N° 18.719, de 2010 (derechos de los titulares de los datos)Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 13, as rewritten by Ley N° 20.075 art. 62, requires telling a data subject, before or when their data is collected, the purpose of the processing and who may receive it, the existence and identity of the database's controller, whether answering is mandatory, particularly for sensitive data, the consequences of refusing or of inaccuracy, the rights available under articles 14 to 16, whether the data will be transferred internationally, and, for an automated-decision process, the valuation criteria, the process applied, and the technology or program used.

Article 14 gives a data subject free access, at most every six months, to all information about them held in a public or private database, supplied within five business days in clear language, covering the whole record without revealing a third party's data.

Article 15 gives a right to rectification, updating, inclusion, or deletion of erroneous, false, or missing personal data, to be carried out within five business days of the request or explained in writing, with any recipient of the data notified of the change within five business days.

Article 16 lets a data subject challenge, and obtain the valuation criteria and the program behind, any administrative act or private decision based solely on automated processing of their personal data that offers an assessment of their character or personality. Article 17 conditions communicating personal data to a third party on the data subject's prior consent and on notice of the purpose and the recipient.

Article 21 lets a data subject request, at any time and free of charge, the withdrawal or blocking of their data from a marketing, canvassing, or profiling database.

What it requires

Enforcement supervision

Ley N° 18.331, enforcement, sanctions and habeas data

Ley N° 18.331, arts. 31-36 y 37-45 (órgano de control, potestades sancionatorias y acción de habeas data)Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 31 creates the Unidad Reguladora y de Control de Datos Personales as a technically autonomous body within AGESIC, and article 34, as rewritten in 2010 and 2022, gives it the power to inspect a controller's or processor's books, documents, and files, demand their appearance to provide information, and, in serious cases, seize materials for up to six business days, with judicial backing for a search of private premises.

Article 35 arms the authority with graduated administrative sanctions for a violation of the law: observation, warning, a fine of up to UI 500,000 (Unidades Indexadas, an inflation-linked accounting unit), a five-day suspension, or closure of the database, and lets it seek judicial closure of a database found to infringe the law.

The Act creates no separate criminal offense of its own; article 11 only cross-references the pre-existing professional-secrecy offense at article 302 of the Penal Code.

Article 37 gives any person the right to bring an effective habeas data judicial action against a public or private database's controller to learn what personal data about them it holds, its purpose and use, and to demand its rectification, inclusion, suppression, or another appropriate remedy where the data is erroneous, false, prohibited from processing, discriminatory, or outdated, with articles 38 to 45 setting the court, standing, and summary procedure for that action.

What it requires

Sensitive categories

Ley N° 18.331, sensitive personal data and health data

Ley N° 18.331, de 2008, arts. 4 (literal E), 18 y 19 (datos sensibles y datos relativos a la salud)Ley N 18.331 de 11 de agosto de 2008, texto consolidado, Direccion Nacional de Impresiones y Publicaciones Oficiales (IMPO)

In force. Binds public and private bodies.

What this law does

Article 18 bars requiring anyone to provide sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life, as article 4 literal E defines it), and permits its processing only with the data subject's express written consent.

Absent that consent, article 18 allows collection and processing only where an interest-general law authorizes it or the requesting body has a legal mandate, or for statistical or scientific purposes once the data is disassociated from its subject.

Article 18 also bars forming a database whose content directly or indirectly reveals sensitive data, except for a political party, union, church, or other nonprofit body that processes only its own members' data for its own political, religious, or similarly aligned purpose, and never without the member's consent to any further communication of that data.

Article 19 lets a public or private health establishment or a health professional collect and process a patient's physical or mental health data only under the rules of professional secrecy and the specific health-sector regulations, alongside this law.

What it requires

Scraping law3 instruments, 3 in force

Research summary (263 words)

Uruguay has no scraping-specific statute, so general law governs each dimension separately.

Código Penal art. 297 bis, inserted by Ley N° 20.327 of 2024, criminalises accessing, intercepting, publishing, selling, or transferring another's information held in digital form only when done without authorization and without just cause by computer or telematic means, so a plain reading leaves reading a public, unauthenticated page without defeating any access control outside the offence, and no reported Uruguayan case has tested the point.

No Uruguayan court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, so that dimension is unsettled rather than answered. Ley N° 9.739 of 1937, as amended, protects a compilation of data as a copyright work only for the originality of its selection or arrangement, expressly stating that the protection does not reach the data or materials themselves, and confers no sui generis database right distinct from that compilation copyright.

The same Law has no text-and-data-mining exception; its narrow free-use exceptions permit quoting a work for comment, criticism, or controversy, and reproducing news, reports, or journalistic information of general interest only in their exact, unaltered form with the source credited, which does not obviously reach an aggregator's or a model trainer's use of scraped text.

Uruguay's comprehensive privacy statute, Ley N° 18.331, reaches personal data an app scrapes from a public Uruguayan page, recorded under the privacy topic rather than duplicated here. No Uruguayan statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327

Ley N° 20.327, de 25 de septiembre de 2024, arts. 6 y 8, Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quinquiesOfficial text of Ley N° 20.327 inserting these articles into the Código Penal

In force. Binds public and private bodies.

What this law does

Article 297 bis (acceso ilícito a datos informáticos) punishes with six to twenty-four months' imprisonment anyone who, by computer or telematic means, without authorization and without just cause, accesses, interferes with, discloses, sells, or transfers another's information held on a digital medium; because the offence's trigger is acting without authorization, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

Article 297 ter punishes unauthorized interception of non-public data transmissions with the same six-to-twenty-four-month range.

Article 297 quater (vulneración de datos) punishes, with the same six-to-twenty-four-month range, accessing, appropriating, using, or modifying a third party's confidential data held on a digital or other medium without the holder's authorization, and separately punishes disclosing, revealing, or transferring such data to a third party with one to four years' imprisonment, aggravated where the data are personal data protected under Ley N° 18.331.

Article 358 quater (daño informático) punishes destroying, altering, or rendering unusable data or computer systems without authorization and with intent to cause harm with six to twenty-four months' imprisonment. Article 358 quinquies (abuso de los dispositivos) punishes producing, acquiring, importing, marketing, or supplying to a third party a program, system, or access credential unequivocally intended for committing an offence, with the same six-to-twenty-four-month range.

What it requires

Copyright and text and data mining (TDM)

Ley N° 9.739 arts. 44-45, illicit-reproduction rule and free-use exceptions for quotation and news

Ley N° 9.739, de 17 de diciembre de 1937, arts. 44 y 45Consolidated, currently updated text of Ley N° 9.739, Centro de Información Oficial (IMPO), Uruguay's official legislative database

In force. Binds public and private bodies.

What this law does

Article 44 treats reproducing, distributing, communicating, or making a work available to the public without the author's consent as illicit reproduction, so copying a copyrighted text found on the open web without permission or an applicable exception infringes unless article 45 covers it. Article 45 numeral 4 excepts a transcription made for the purpose of comment, criticism, or controversy, a general quotation right rather than a text-and-data-mining exception.

Article 45 numeral 3 excepts news, reports, journalistic information, or recordings of general interest, but only where the exact version is preserved and the source is stated, a condition suited to a verbatim press clipping rather than to extracting short snippets or training a model on the underlying text.

Uruguay has no text-and-data-mining exception and no machine-readable opt-out mechanism of that kind; a service that reproduces or trains on scraped copyrighted text rests only on the numeral 4 quotation ground if its use can be characterised as comment, criticism, or controversy.

What it requires

Database right

Ley N° 9.739 art. 5, compilation and database copyright protection

Ley N° 9.739, de 17 de diciembre de 1937, art. 5Consolidated, currently updated text of Ley N° 9.739, Centro de Información Oficial (IMPO), Uruguay's official legislative database

In force. Binds public and private bodies.

What this law does

Article 5 protects a compilation of data or other materials, in any form, as a copyright work when the selection or arrangement of its contents constitutes an intellectual creation, and states expressly that this protection does not extend to the underlying data or materials themselves and is without prejudice to any copyright that subsists in them separately.

Uruguay confers no sui generis database right distinct from this originality-based compilation copyright, so a database whose selection or arrangement is not itself an intellectual creation, such as a routine or exhaustive listing, receives no protection under this article, and copying the underlying facts or data out of a protected compilation does not infringe it.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (175 words)

Uruguay has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining regime, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

Ley N° 9.739 of 1937, as amended, protects expressions but not the ideas, procedures, operating methods, or facts they convey (art. 5), so a bare fact or news item carries no copyright regardless of who reports it first.

The same Law lets a person, without the author's consent, reproduce, distribute, communicate, or make available news, reports, journalistic information, or recordings of general interest, provided the exact version is kept and the source is credited (art. 45, numeral 3); that condition of exactness suits a traditional press clipping and has not been tested against a systematic aggregator's reproduction of headlines and short extracts in a reported Uruguayan decision.

Ley N° 9.739 predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Ley N° 9.739 art. 45, numeral 3, news and press-reproduction exception

Ley N° 9.739, de 17 de diciembre de 1937, art. 45, numeral 3Consolidated, currently updated text of Ley N° 9.739, Centro de Información Oficial (IMPO), Uruguay's official legislative database

In force. Binds public and private bodies.

What this law does

Article 45 lists cases that are not illicit reproduction. Numeral 3 excepts news, reports, journalistic information, or recordings of general interest from the consent that article 44 otherwise requires, on the sole conditions that the exact version is preserved and the source is stated.

The exception is not capped at a headline or short-extract length and is not confined to the press industry, but the requirement to keep the exact version suits reproducing a news item whole, the way a press clipping does, rather than obviously covering an aggregator's extraction of a headline or a short snippet distinct from the source's own wording. No reported Uruguayan decision has applied numeral 3 to a systematic news aggregator as opposed to a traditional press review or broadcaster.

Separately, article 5 confines copyright to expressions and excludes ideas, procedures, operating methods, and mathematical concepts as such, so a bare fact or the news of the day is never itself a protected work under Uruguayan law. Uruguay has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright law, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.