World Watch/Dominican Republic/Cybersecurity

Cybersecurity · Dominican Republic

Cybersecurity regulation in Dominican Republic (2026)

Sectoral rulesPatchwork led by Decree 230-18/313-22 (National Cybersecurity Strategy & National Cybersecurity Center–CNCS, CSIRT-RD), Decree 685-22 (mandatory incident notification for public entities), Law 53-07 (high-tech crimes), and the Monetary Authority's Cybersecurity and Information Security Regulation for the financial sector. A comprehensive 'Ley de Gestión de la Ciberseguridad' bill remains pending in Congress.Country index 64 · C+

Dominican Republic shaded by its cybersecurity status

The Dominican Republic has no comprehensive, in-force cybersecurity statute; obligations arise from a combination of executive decrees, a national strategy, the high-tech crime law, and a sector-specific financial regulation. A dedicated Cybersecurity Management Law was approved in first reading in the Senate (April 2024) but, as of 2025, remains under study and is not yet enacted. Mandatory incident-reporting duties currently apply to public-administration entities (via decree) and to regulated financial institutions (via the Monetary Authority's regulation).

Key points

No comprehensive law yet — bill pending

A 'Proyecto de Ley sobre Gestión de la Ciberseguridad' was approved in first reading by the Senate in April 2024 and would create a statutory National Cybersecurity Center covering public administration and critical infrastructure, but it remained under committee study in September 2025 and is not in force.

National strategy & CNCS created by decree

Decree 230-18 adopted the first National Cybersecurity Strategy and created the National Cybersecurity Center (CNCS) under the Ministry of the Presidency; Decree 313-22 updated and extended the strategy to 2030. The framework is executive/policy-based rather than a comprehensive statute.

Public-sector incident reporting — 24-hour duty

Decree 685-22 (Dec 2022) requires public-administration entities to report cybersecurity incidents in their technological infrastructure to the CSIRT-RD/CNCS within 24 hours of detection, and to notify affected individuals when data is compromised.

Financial-sector cyber regulation

Since 2018 the Monetary Authority (Central Bank + Superintendency of Banks) imposes a binding 'Reglamento de Seguridad Cibernética y de la Información' on financial-intermediation entities, including risk management and incident notification to the payment-system response center (SPRICS).

Cybercrime criminalization

Law 53-07 on High-Technology Crimes and Offenses (2007) criminalizes unauthorized system access, electronic fraud, and related conduct, providing the country's core penal framework for cyber offenses — distinct from operational cybersecurity obligations.

National CSIRT operational

The CSIRT-RD, housed within the CNCS, handles incident response for the State's critical and IT infrastructure, runs a security operations/monitoring function, and operates platforms for incident reporting and vulnerability disclosure.

Timeline - major decisions & events

Jan 1, 2025decisionofficial
2025–2027 National Cybersecurity Action Plan Launched

The CTEC and CNCS approved a new biennial action plan under the National Cybersecurity Strategy 2030, setting specific targets for capacity building, sectoral awareness campaigns, and incident-response protocols. It is the second implementation cycle following the 2022–2024 plan.

Centro Nacional de Ciberseguridad (CNCS)
Oct 22, 2024decisionofficial
Decree 612-24 Reorganizes Cybersecurity Governance; Creates CTEC and National Cryptographic Institute

President Abinader signed Decree 612-24, creating the Specialized Technical Commission on Cybersecurity (CTEC) under the National Security and Defense Council, transferring CSIRT-RD and the Strategy Coordination Team to the National Intelligence Directorate (DNI), and establishing a new National Cryptographic Institute (ICN).

Presidencia de la República Dominicana
Aug 1, 2024lawofficial
Electricity Regulator SIE Issues Cybersecurity Regulation for National Grid (SIE-077-2024)

After a public consultation, the Superintendencia de Electricidad published Resolution SIE-077-2024-ADM requiring all national electrical-system agents (generators, transmitters, distributors) to adopt cybersecurity management programs, with implementation entering force in early 2025.

Superintendencia de Electricidad (SIE)
Jan 1, 2022decisionofficial
Decree 313-22: National Cybersecurity Strategy 2030 Adopted

Decree 313-22 superseded the 2018–2021 strategy, extending the CNCS mandate to 31 December 2030 and establishing a rolling Action Plan (first cycle 2022–2024) with six objectives covering critical infrastructure protection, cybercrime capacity, and sectoral regulation.

Presidencia de la República Dominicana
Jan 1, 2021decisionofficial
INDOTEL Resolution 126-21: Binding Cybersecurity Rules for Internet Service Providers

The INDOTEL Board issued Resolution 126-21 imposing cybersecurity obligations on all licensed internet service providers, including establishment of an independent Cybersecurity Committee, defined organisational structures with dedicated capability, and incident-reporting requirements.

Instituto Dominicano de las Telecomunicaciones (INDOTEL)
Jun 15, 2018decisionofficial
Decree 230-18: First National Cybersecurity Strategy (2018–2021) and CNCS Established

President Medina signed Decree 230-18, launching the first National Cybersecurity Strategy with four pillars — legal/institutional strengthening, critical-infrastructure protection, cybersecurity culture, and international alliances — and creating the National Cybersecurity Center (CNCS) as the coordinating authority.

Presidencia de la República Dominicana
Dec 13, 2013lawofficial
Law No. 172-13: Personal Data Protection Law Enacted

Law 172-13 established the Dominican Republic's first comprehensive data-protection framework, requiring controllers to adopt technical security measures and granting data subjects rights to access, rectify, and delete personal data; the Ombudsman and Superintendent of Banks serve as enforcement bodies.

Portal Oficial del Estado Dominicano
Feb 7, 2013decisionofficial
Dominican Republic Becomes First Latin American Country to Ratify the Budapest Convention on Cybercrime

The Dominican Republic deposited its instrument of accession to the Council of Europe's Budapest Convention, becoming the first nation in Latin America and the Caribbean to ratify the treaty, strengthening mutual legal assistance and cross-border cybercrime prosecution capacity.

Council of Europe – Cybercrime Division
Apr 23, 2007lawofficial
Law No. 53-07 on High Technology Crimes Enacted

Law 53-07 criminalised unauthorised system access, data interception, computer fraud, cyberviolence, and child online exploitation — one of the first standalone cybercrime statutes in Latin America, drafted in alignment with the Budapest Convention even before formal ratification, and creating specialist enforcement units DICAT and DIDI.

Ministerio de Interior y Policía

Dominican Republic - other topics

Last verified 5/25/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →