Jurisdiction Guides / Americas
Uruguay Privacy & Data Protection Laws
Every regime below can apply to a business handling Uruguay residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Uruguay holds a European Commission adequacy decision (2012) and, unusually for the region, added explicit GDPR-style extraterritoriality after the fact: Law 19.670 (Arts. 37-40) extends the regime to controllers and processors outside Uruguay that offer goods or services to people in Uruguay or monitor their behavior, and Decree 64/020 fleshed out breach notification, data-protection officers, and impact assessments. Database registration with the Unidad Reguladora y de Control de Datos Personales (URCDP) is required. The combination — small market, adequacy status, real extraterritorial reach — means a business serving Uruguayan customers can be in scope without any local footprint.
Cross-Border Data Transfer · 1
Art. 23 prohibits transferring personal data to countries or international organisations that do not provide adequate levels of protection, unless one of the listed exceptions applies. Uruguay is one of the few Latin American jurisdictions holding an EU adequacy decision, so transfers in the other direction are unrestricted from the EU's side — but that is not reciprocal, and Uruguay's own outbound restriction still binds. The URCDP has issued guidance on drafting contractual clauses for transfers to non-adequate countries, which is the practical route where no adequacy finding covers the destination. Marked 'check': the operative texts are Spanish-language and the URCDP's guidance instruments were triangulated across independent legal-reference sources rather than read in the original.
Data Security & Breach Notification · 1
Where a security breach affecting personal data is confirmed, the responsible party must communicate it to the Unidad Reguladora y de Control de Datos Personales (URCDP) within a maximum of 72 hours of becoming aware, and the communication must state the actual or estimated date of the breach, its nature, the personal data affected, and the likely impacts. Affected data subjects must also be informed. Note where the duty comes from: not from Ley 18.331 itself, but from Arts. 37-40 of Ley 19.670 as regulated by Decreto 64/020 — so a reviewer looking only at the 2008 law will not find it. Uruguay holds an EU adequacy decision, which raises the practical stakes on maintaining a defensible incident process. Marked 'check': the operative texts are Spanish-language and were triangulated across independent legal-reference sources.
Other Americas jurisdictions