WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Ley 8968, Proteccion de la Persona frente al tratamiento de sus datos personales — notification of irregularities

Costa Rica Ley 8968 breach duty

Costa Rica · September 5, 2011 (Ley 8968); Reglamento of October 30, 2012

Verify details

Art. 10 frames the duty as one owed to the individual rather than to the regulator: the responsible party must inform the data subject of any irregularity in the handling or storage of their data — loss, destruction, misplacement, or anything else arising from a security vulnerability — within five business days of the vulnerability occurring, so that the affected person can take protective measures, and must open a review within the same window to determine the extent of the impact and the corrective and preventive measures required. Marked 'check' on one specific point a reviewer must resolve: independent sources also describe a five-day report to PRODHAB, the supervisory authority, but that limb could not be tied to a provision of the Law or its Reglamento with confidence. Treat the data-subject duty as the solid part and confirm the regulator-facing limb directly with PRODHAB.

Ley N. 8968 de 7 de julio de 2011, Art. 10; Reglamento, Decreto Ejecutivo N. 37554-JPRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.