WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Costa Rica Privacy & Data Protection Laws

Every regime below can apply to a business handling Costa Rica residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 5, 2011 (Regulation in force March 5, 2013)
Law on the Protection of Persons Regarding the Processing of Their Personal Data
Costa Rica Law 8968
Verify details

Applies to personal data contained in automated or manual databases held by public or private entities in Costa Rica, with an emphasis on informed consent, data-subject rights, and a mandatory registration of databases that distribute or trade personal data with the Agencia de Proteccion de Datos de los Habitantes (PRODHAB). It is a pre-GDPR-generation law without an explicit targeting clause reaching foreign controllers, so the trigger below is modeled on established presence only. Reform proposals to align it with GDPR concepts have circulated without enactment; a business with any Costa Rican entity or infrastructure should treat PRODHAB registration and the consent-first posture as the operative baseline.

Ley No. 8968 (2011); Reglamento, Decreto Ejecutivo No. 37554-JPRead regulation →

Cross-Border Data Transfer · 1

September 5, 2011 (Ley 8968); Reglamento of October 30, 2012
Ley 8968, Proteccion de la Persona frente al tratamiento de sus datos personales — transfer of personal data
Costa Rica Ley 8968 Art. 14
Verify details

Art. 14 sets a single gate: those responsible for public or private databases may transfer personal data only where the data subject has expressly and validly authorised the transfer, and only where doing so does not violate the Law's principles and rights. Costa Rica does not operate an adequacy list, and consent is doing all the work — which makes this a consent-based regime like Mexico's rather than an adequacy-based one like most of Latin America's. The teeth are in Art. 31, which classifies transferring data to third countries without consent as a GRAVE violation. Marked 'check': the operative texts are Spanish-language and were triangulated across independent legal-reference sources rather than read in the original; confirm with PRODHAB whether any additional conditions apply to international as distinct from domestic transfers.

Ley N. 8968, Arts. 14 and 31; Reglamento, Decreto Ejecutivo N. 37554-JPRead regulation →

Data Security & Breach Notification · 1

September 5, 2011 (Ley 8968); Reglamento of October 30, 2012
Ley 8968, Proteccion de la Persona frente al tratamiento de sus datos personales — notification of irregularities
Costa Rica Ley 8968 breach duty
Verify details

Art. 10 frames the duty as one owed to the individual rather than to the regulator: the responsible party must inform the data subject of any irregularity in the handling or storage of their data — loss, destruction, misplacement, or anything else arising from a security vulnerability — within five business days of the vulnerability occurring, so that the affected person can take protective measures, and must open a review within the same window to determine the extent of the impact and the corrective and preventive measures required. Marked 'check' on one specific point a reviewer must resolve: independent sources also describe a five-day report to PRODHAB, the supervisory authority, but that limb could not be tied to a provision of the Law or its Reglamento with confidence. Treat the data-subject duty as the solid part and confirm the regulator-facing limb directly with PRODHAB.

Ley N. 8968 de 7 de julio de 2011, Art. 10; Reglamento, Decreto Ejecutivo N. 37554-JPRead regulation →

Other Americas jurisdictions