Data Security & Breach Notification
Personal data protection framework — communication of security breaches
Uruguay · February 21, 2020 (Decreto 64/020, regulating Arts. 37-40 of Ley 19.670)
Verify detailsWhere a security breach affecting personal data is confirmed, the responsible party must communicate it to the Unidad Reguladora y de Control de Datos Personales (URCDP) within a maximum of 72 hours of becoming aware, and the communication must state the actual or estimated date of the breach, its nature, the personal data affected, and the likely impacts. Affected data subjects must also be informed. Note where the duty comes from: not from Ley 18.331 itself, but from Arts. 37-40 of Ley 19.670 as regulated by Decreto 64/020 — so a reviewer looking only at the 2008 law will not find it. Uruguay holds an EU adequacy decision, which raises the practical stakes on maintaining a defensible incident process. Marked 'check': the operative texts are Spanish-language and were triangulated across independent legal-reference sources.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.