EnglishEspañol
Costa Rica flag

Costa Rica

Costa Rica Data Privacy Laws: Ley 8968 and PRODHAB Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

Costa Rica Data Privacy Laws: Ley 8968 and PRODHAB Compliance Guide (2026)

Frequently Asked Questions

What is Ley 8968 and when did it come into force?

Ley No. 8968, formally titled the Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales, was enacted on July 7, 2011, and entered into force on September 5, 2011. It is Costa Rica's principal data protection statute, regulating how personal data is collected, stored, processed, and transferred in both the public and private sectors. Executive Decree 37554-JP, published in 2013, provides the implementing regulations.

What is PRODHAB and what powers does it have?

PRODHAB (Agencia de Proteccion de Datos de los Habitantes) is Costa Rica's independent data protection supervisory authority, created by Ley 8968. It registers databases, investigates data subject complaints, conducts inspections, issues directives published in La Gaceta, keeps the register of the protocolos minimos de actuacion that every responsible party must draft, and may impose administrative sanctions including fines of up to 30 base salaries (13,866,000 colones in 2026), written warnings, orders to delete, rectify, add to, or restrict the circulation of data, and suspension of a file for one to six months for very serious infractions. There is no permanent cancellation sanction; cancelling a registration is a voluntary procedure the owner initiates.

Do I need to register my database with PRODHAB?

Registration is required if your database is used for distributing, disclosing, or commercializing personal data. Two categories are exempt: databases used exclusively for internal operational purposes (HR records, customer records not shared commercially), and databases maintained by SUGEF-regulated financial institutions. The annual registration fee is USD 200 per database, payable in January. Failing to register when required is a very serious infraction under article 31(e) of Ley 8968, punishable by 15 to 30 base salaries plus suspension of the file for one to six months.

What type of consent is required under Costa Rican data privacy law?

Written consent is required for all personal data, not only for sensitive categories. Article 5.2 of Ley 8968 requires the consent to be recorded in writing, in a physical or electronic document, and it must be free, specific, informed, and unequivocal. Express consent is dispensed with in only three situations: a reasoned order from a competent judicial authority or from a special investigative commission of the Legislative Assembly, unrestricted-access data obtained from generally public sources, and data that must be handed over under a constitutional or legal provision. Sensitive data is a separate matter: article 9.1 prohibits processing it, subject to four narrow exceptions.

Can personal data be transferred outside Costa Rica?

Yes, but only with consent. Costa Rica has no adequacy regime and PRODHAB publishes no adequacy list. Article 14 of Ley 8968 allows a transfer only where the data subject has expressly and validly authorized it, and article 40 of Decree 37554-JP requires unequivocal, informed consent unless a legal provision says otherwise. The transferring party must also sign a contract binding the recipient to at least the same obligations (article 43) and must comply with the protocol it registered with PRODHAB (article 41). Sending personal data to a database in another country without the data subjects' consent is a very serious infraction under article 31(f), punishable by 15 to 30 base salaries plus suspension of the file. Moving data to your own processor or within the same economic interest group is not a transfer.

What penalties can PRODHAB impose for violations?

Sanctions are graduated by infraction severity under article 28 of Ley 8968. Minor infractions carry a fine of up to 5 base salaries. Serious infractions carry 5 to 20 base salaries. Very serious infractions carry 15 to 30 base salaries plus suspension of the file for one to six months. At the 2026 base salary of 462,200 colones, that means up to 2,311,000 colones, then 2,311,000 to 9,244,000 colones, then 6,933,000 to 13,866,000 colones. The maximum fine is 13,866,000 colones, roughly USD 30,500. PRODHAB may also issue written warnings and order data to be deleted, rectified, added to, or restricted in circulation.

Does Costa Rica require data breach notification?

Yes. Articles 38 and 39 of Decree 37554-JP have required breach notification since 2013. The responsible party has five business days from the moment the breach occurred to notify both the affected data subjects and PRODHAB, and the notice must state the nature of the incident, the personal data compromised, the corrective actions already taken, and where to obtain more information. Within the same five days the responsible party must begin an exhaustive review of the scope of the incident. PRODHAB publishes a guidance sheet, Informe de vulneracion, that restates the rule. Bill 23097 would move to a shorter GDPR-style deadline written into the statute; it would not create a first-ever obligation.

What is the constitutional basis for data protection in Costa Rica?

Article 24 of the Constitucion Politica de la Republica de Costa Rica guarantees the right to intimacy, freedom, and secrecy of communications. The Constitutional Chamber (Sala Constitucional) recognized in Decision 5802-99 that Article 24 encompasses the right of informational self-determination (autodeterminacion informativa): individuals hold an active constitutional right to control the flow of their personal information. Ley 8968 operationalizes this constitutional guarantee; it does not create the underlying right.

How does Costa Rica's law compare to the EU GDPR?

Both frameworks share core principles (purpose limitation, data quality, security, consent, and data subject rights), and the differences run in both directions. Costa Rica requires written consent for all personal data and recognizes only three narrow exceptions, where the GDPR offers six legal bases including legitimate interests. It prohibits sensitive data processing outside four statutory cases. It requires database registration for commercial processing, with a USD 200 annual fee. It has no adequacy regime, so every transfer depends on the data subject's express consent. It grants no data portability right, no general right to object to lawful processing, and no rules on automated decision-making. It does require breach notification, within five business days, under the regulation rather than the statute. Its maximum fine, about USD 30,500, is far below the GDPR ceiling. Bill 23097 would narrow most of these gaps if enacted.

What is the status of Costa Rica's data protection reform as of 2026?

Bill No. 23097, filed in the Legislative Assembly on 17 May 2022, proposes a complete GDPR-aligned replacement of Ley 8968. It has not been enacted. PRODHAB and the SINALEVI legal information system both record Ley 8968 as never having been reformed; only the regulation has changed, by Decree 40008-JP in 2016 and Decree 41582-JP in 2019. Costa Rican bills lapse four years after filing, so the bill reached its four-year deadline on 17 May 2026. The Legislative Assembly expediente system was unreachable during this review, so its current procedural status could not be confirmed and should be checked directly against the Assembly record.

How long may personal data be retained under Costa Rican law?

The ten-year cap comes from article 6.1 of Ley 8968 itself, restated in article 11 of Decree 37554-JP. It covers any personal data that could affect the data subject, not only data in registered databases. Since Decree 40008-JP in 2016, the ten years run from the date the purpose of processing ends rather than from the date of the recorded events. The cap does not apply where a special legal provision sets another period, where the parties agreed a different one, where a continuing relationship exists between them, or where there is a public interest in keeping the data. Where data must be kept longer, it has to be dissociated from the individual.

Updates

Corrected the article against the official texts of Ley 8968 and Decree 37554-JP: Costa Rica has no adequacy regime, so every transfer of personal data needs the data subject's express consent under article 14; breach notification to the affected people and to PRODHAB is mandatory within five business days under articles 38 and 39 of the regulation, not absent; written consent is required for all personal data and sensitive data is prohibited rather than permitted on consent; the serious-infraction fine band is 5 to 20 base salaries and failing to register a database is a very serious infraction; and the article citations, sensitive-data definition, retention rule, sanction list, data subject rights, and enforcement statistics were rebuilt from the Gaceta texts and PRODHAB's own published records.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Full audit-and-evolve refresh: expanded constitutional basis (Article 24, Decision 5802-99), PRODHAB structure and complaint statistics, database registration exemptions and fee, cross-border transfer rules, penalty calculation updated to the 2026 base salary (462,200 colones), reform bill status, Council of Europe Convention 108+ evaluation, and business compliance checklist. Word count raised from ~2,350 to ~5,400.

Reviewed and approved by an editor

Initial publication.

Sources and References

  1. PRODHAB - Agencia de Proteccion de Datos de los Habitantes (official site)(prodhab.go.cr).gov
  2. Ley No. 8968 de Proteccion de la Persona frente al Tratamiento de sus Datos Personales (full text, SCIJ)(pgrweb.go.cr).gov
  3. Decreto Ejecutivo 37554-JP - Reglamento a la Ley 8968 (full text, SCIJ)(pgrweb.go.cr).gov
  4. Constitucion Politica de la Republica de Costa Rica - Articulo 24 (SCIJ)(pgrweb.go.cr).gov
  5. Proyecto de Ley No. 23097 - Ley de Proteccion de Datos Personales (Asamblea Legislativa base text)(proyectos.conare.ac.cr).gov
  6. PRODHAB - Normativa: Ley 8968, Reglamento 37554-JP and the 2016 and 2019 amending decrees(prodhab.go.cr).gov
  7. OECD - Costa Rica country page (member since 2021)(oecd.org)
  8. Red Iberoamericana de Proteccion de Datos (RIPD)(redipd.org)
  9. Freedom House - Costa Rica: Freedom on the Net 2024(freedomhouse.org)
  10. Ministerio de Hacienda - Salarios base actual e historico (Circular 246-2025: 462,200 colones for 2026)(hacienda.go.cr).gov
  11. Ley N. 8968 as published in La Gaceta N. 170, 5 September 2011 (Imprenta Nacional)(imprentanacional.go.cr).gov
  12. Decreto Ejecutivo 37554-JP, Reglamento a la Ley 8968, Alcance 42 to La Gaceta N. 45, 5 March 2013(imprentanacional.go.cr).gov
  13. Decreto Ejecutivo 40008-JP (2016) amending the Reglamento, Alcance 287 to La Gaceta, 6 December 2016(imprentanacional.go.cr).gov
  14. Decreto Ejecutivo 41582-JP (2019) amending the Reglamento, Alcance 48 to La Gaceta, 4 March 2019(imprentanacional.go.cr).gov
  15. PRODHAB - Informe de vulneracion: five-business-day breach report duty under Reglamento arts. 38-39(prodhab.go.cr).gov
  16. PRODHAB - Informe de denuncias 2014-2025 (de-identified complaints register)(prodhab.go.cr).gov
  17. PRODHAB - Directriz PRODHAB-DIR-DN-001-2026 on personal data in debt collection, 17 July 2026(prodhab.go.cr).gov
  18. Council of Europe, T-PD(2020)08rev - Evaluation of the Republic of Costa Rica for accession to Convention 108+, 11 June 2021(rm.coe.int)
Share: