Jurisdiction Guides / Americas
Costa Rica Privacy & Data Protection Laws
Every regime below can apply to a business handling Costa Rica residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to personal data contained in automated or manual databases held by public or private entities in Costa Rica, with an emphasis on informed consent, data-subject rights, and a mandatory registration of databases that distribute or trade personal data with the Agencia de Proteccion de Datos de los Habitantes (PRODHAB). It is a pre-GDPR-generation law without an explicit targeting clause reaching foreign controllers, so the trigger below is modeled on established presence only. Reform proposals to align it with GDPR concepts have circulated without enactment; a business with any Costa Rican entity or infrastructure should treat PRODHAB registration and the consent-first posture as the operative baseline.
Cross-Border Data Transfer · 1
Art. 14 sets a single gate: those responsible for public or private databases may transfer personal data only where the data subject has expressly and validly authorised the transfer, and only where doing so does not violate the Law's principles and rights. Costa Rica does not operate an adequacy list, and consent is doing all the work — which makes this a consent-based regime like Mexico's rather than an adequacy-based one like most of Latin America's. The teeth are in Art. 31, which classifies transferring data to third countries without consent as a GRAVE violation. Marked 'check': the operative texts are Spanish-language and were triangulated across independent legal-reference sources rather than read in the original; confirm with PRODHAB whether any additional conditions apply to international as distinct from domestic transfers.
Data Security & Breach Notification · 1
Art. 10 frames the duty as one owed to the individual rather than to the regulator: the responsible party must inform the data subject of any irregularity in the handling or storage of their data — loss, destruction, misplacement, or anything else arising from a security vulnerability — within five business days of the vulnerability occurring, so that the affected person can take protective measures, and must open a review within the same window to determine the extent of the impact and the corrective and preventive measures required. Marked 'check' on one specific point a reviewer must resolve: independent sources also describe a five-day report to PRODHAB, the supervisory authority, but that limb could not be tied to a provision of the Law or its Reglamento with confidence. Treat the data-subject duty as the solid part and confirm the regulator-facing limb directly with PRODHAB.
Other Americas jurisdictions