WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Uruguay Privacy & Data Protection Laws

Every regime below can apply to a business handling Uruguay residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

August 11, 2008; extraterritorial provisions added effective January 2019
Personal Data Protection and Habeas Data Action Law
Uruguay Law 18.331
Verify details

Uruguay holds a European Commission adequacy decision (2012) and, unusually for the region, added explicit GDPR-style extraterritoriality after the fact: Law 19.670 (Arts. 37-40) extends the regime to controllers and processors outside Uruguay that offer goods or services to people in Uruguay or monitor their behavior, and Decree 64/020 fleshed out breach notification, data-protection officers, and impact assessments. Database registration with the Unidad Reguladora y de Control de Datos Personales (URCDP) is required. The combination — small market, adequacy status, real extraterritorial reach — means a business serving Uruguayan customers can be in scope without any local footprint.

Ley No. 18.331 (2008), as extended by Ley No. 19.670 (2018) Arts. 37-40 and Decreto 64/020Read regulation →

Cross-Border Data Transfer · 1

August 11, 2008 (Ley 18.331); Decreto 64/020 from February 2020
Ley 18.331 de Proteccion de Datos Personales — international transfer of personal data
Uruguay Ley 18.331 Art. 23
Verify details

Art. 23 prohibits transferring personal data to countries or international organisations that do not provide adequate levels of protection, unless one of the listed exceptions applies. Uruguay is one of the few Latin American jurisdictions holding an EU adequacy decision, so transfers in the other direction are unrestricted from the EU's side — but that is not reciprocal, and Uruguay's own outbound restriction still binds. The URCDP has issued guidance on drafting contractual clauses for transfers to non-adequate countries, which is the practical route where no adequacy finding covers the destination. Marked 'check': the operative texts are Spanish-language and the URCDP's guidance instruments were triangulated across independent legal-reference sources rather than read in the original.

Ley N. 18.331, Art. 23; Decreto N. 64/020; URCDP Resolucion N. 41/021Read regulation →

Data Security & Breach Notification · 1

February 21, 2020 (Decreto 64/020, regulating Arts. 37-40 of Ley 19.670)
Personal data protection framework — communication of security breaches
Uruguay breach notification
Verify details

Where a security breach affecting personal data is confirmed, the responsible party must communicate it to the Unidad Reguladora y de Control de Datos Personales (URCDP) within a maximum of 72 hours of becoming aware, and the communication must state the actual or estimated date of the breach, its nature, the personal data affected, and the likely impacts. Affected data subjects must also be informed. Note where the duty comes from: not from Ley 18.331 itself, but from Arts. 37-40 of Ley 19.670 as regulated by Decreto 64/020 — so a reviewer looking only at the 2008 law will not find it. Uruguay holds an EU adequacy decision, which raises the practical stakes on maintaining a defensible incident process. Marked 'check': the operative texts are Spanish-language and were triangulated across independent legal-reference sources.

Ley N. 18.331; Ley N. 19.670, Arts. 37-40; Decreto N. 64/020 (published February 21, 2020)Read regulation →

Other Americas jurisdictions