Skip to content
World Watch/Dominican Republic/Data & Privacy

Data & Privacy · Dominican Republic

Data protection & privacy law in Dominican Republic (2026)

Comprehensive lawCountry index 64 · C+

Dominican Republic shaded by its data & privacy status

Data protection in Dominican Republic: comprehensive law.

FrameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (Ley No. 172-13 sobre Protección Integral de los Datos Personales), enacted 13 December 2013. No dedicated, independent data-protection authority exists; the Superintendency of Banks (Superintendencia de Bancos) supervises credit bureaus.

The Dominican Republic has an in-force, general data-protection statute, Law No. 172-13 (2013), built on a constitutional habeas data right (Art. 70), establishing data-subject rights, processing principles, and consent rules applicable to any public or private person processing personal data. However, the law has notable gaps: it does not create an independent, cross-sectoral supervisory authority, and a large share of its provisions is devoted specifically to credit-information companies (SIC), whose oversight falls to the Superintendency of Banks. Legal commentators and authorities widely acknowledge the need to modernize and align the regime with the GDPR and Ibero-American standards, and reform discussions remain ongoing as of 2026, but no replacement law has been enacted.

Key points

Comprehensive law in force

Law No. 172-13, promulgated 13 December 2013, is a general statute on the 'comprehensive protection of personal data' contained in public or private files, registries and databases. It applies to any natural or legal person, public or private, engaged in processing personal data.

Constitutional foundation (habeas data)

The regime rests on Article 70 of the 2010 Constitution, which guarantees the right to habeas data, allowing individuals to access, correct, update or delete their personal data held in registries or databases.

No independent supervisory authority

Unlike GDPR-style regimes, there is no dedicated, independent national data-protection authority overseeing private-sector processing generally. This is a recognized structural gap in the framework.

Sectoral enforcement: credit bureaus & consumers

A large portion of Law 172-13 regulates credit-information companies (SIC), whose constitution and operation are supervised by the Superintendency of Banks, which sanctions data infringements by credit bureaus. Pro Consumidor (consumer-protection agency) handles data-protection compliance in consumer matters.

Core data-subject rights and consent

The law grants rights of access, rectification, deletion/cancellation and objection, and conditions processing on prior, informed consent (written/express consent for credit reports), with heightened protection for sensitive data.

Reform and modernization pending

Authorities and practitioners acknowledge the need to modernize Law 172-13 to align with the EU GDPR and Ibero-American standards and to create an independent authority; reform discussions/draft proposals were ongoing as of 2026 but no new law has been enacted. Separately, the new Penal Code (entering into force August 2026) adds offenses for misuse of personal data, including corporate criminal liability.

Timeline - major decisions & events

Aug 5, 2026lawofficial
New Penal Code (Law 74-25, amended by Law 44-26) Enters Into Force with Criminal Personal-Data Offenses

Organic Law 74-25 took effect, replacing the 1884 Penal Code; Article 198 makes it a criminal offence to collect, store, or disclose personal data without prior consent. Corporate criminal liability under the code is deferred to November 5, 2026.

Presidencia de la República Dominicana
Jul 27, 2026law
Law No. 44-26 Amends 27 Articles of the New Penal Code Days Before Its Entry Into Force

Congress amended 27 articles of the newly enacted Penal Code — including provisions on privacy offences, freedom of expression, and corporate data liability — to ensure constitutional alignment before the code took effect on August 5.

PHLaw (analysis of official text)
Jan 1, 2016decision
Constitutional Court Ruling TC/0484/16: Core of Law 172-13 Upheld, Intelligence-Data Restriction Struck Down

The Tribunal Constitucional validated Articles 5.6c), 8, and 29 of Law 172-13 but struck down the article barring citizens from accessing intelligence-agency databases as unconstitutional, affirming that no personal data may be withheld from a data subject without explicit constitutional justification.

Fundación Microfinanzas BBVA (analysis of TC/0484/16)
Dec 13, 2013lawofficial
Law No. 172-13 on Comprehensive Protection of Personal Data Enacted

The primary data-protection statute — published in Official Gazette No. 10737 on 15 December 2013 — repealed Law 288-05, enshrined ARCO rights (access, rectification, cancellation, objection), codified the habeas data judicial action, mandated security safeguards, and set fines of 10–100× the minimum wage with INDOTEL as the principal supervisory authority.

Presidencia de la República Dominicana
Jan 1, 2013decisionofficial
PEDATEC Specialized Cyber-Prosecution Unit Established Within the Attorney General's Office

The Procuraduría Especializada en Crímenes y Delitos de Alta Tecnología (PEDATEC) was created to investigate and prosecute high-technology crimes — including unauthorized data access and data theft — under Law 53-07, providing practical enforcement capacity for digital personal-data violations.

Council of Europe Octopus Cybercrime Community
Jan 26, 2010lawofficial
2010 Dominican Constitution: Articles 44 and 70 Constitutionalize Privacy and Habeas Data

The promulgated Constitution formally recognized the right to privacy (Article 44) and the habeas data judicial action (Article 70) as fundamental rights, requiring personal data processing to respect the principles of legality, quality, loyalty, security, and purpose — forming the constitutional foundation for Law 172-13.

Organization of American States (OAS)
Jan 18, 2007lawofficial
Law No. 53-07 on High Technology Crimes Enters Into Force

The cybercrime law criminalised unauthorised system access, data interception, identity theft, and electronic fraud, providing the first criminal-law protection layer for digital personal data and aligning the Dominican Republic with the Budapest Convention's substantive standards.

WIPO Lex
Jan 1, 2006decisionofficial
INDOTEL Resolution No. 055-06: Telecom-Sector Personal Data Processing Framework

The National Telecommunications Institute established sector-specific data protection rules for telecoms and electronic-signature providers, requiring transparency, prior consent, and security safeguards — with INDOTEL empowered to inspect and sanction non-compliant entities, a supervisory role later codified under Law 172-13.

INDOTEL

Dominican Republic - other topics

Data & Privacy in other countries

Last verified 5/25/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →