Costa Rica
Costa Rica Data Privacy Laws: Ley 8968 and PRODHAB Compliance Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

Costa Rica protects personal data under Ley No. 8968, a 2011 statute enforced by PRODHAB, the national supervisory authority. The law requires written, informed, express consent before any personal data may be collected or processed, grants individuals rights of access, rectification, and deletion, and authorizes fines of up to 30 base salaries for violations.
Costa Rica enacted Ley No. 8968 on July 7, 2011, making it one of the first Central American countries to adopt a comprehensive data protection statute. The law, formally titled the Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales, rests on the constitutional right to privacy enshrined in Article 24 of the Constitucion Politica, and its implementing regulation, Executive Decree 37554-JP, has been in force since 2013.
Information last verified on 2026-09-10. This article has not yet been reviewed by a licensed lawyer. It presents general legal information about Costa Rica's data protection framework; it does not constitute legal advice for any specific situation.
Jurisdiction scope: This article covers Costa Rica's national data protection framework under Ley 8968 and Decree 37554-JP, administered by PRODHAB. It does not address the laws of other Central American or Latin American countries. For Costa Rica recording consent rules, see our guide to Costa Rica recording laws.
Quick Answer: Costa Rica Data Privacy in Plain Terms
Costa Rica protects personal data through Ley 8968, which the Agencia de Proteccion de Datos de los Habitantes (PRODHAB) enforces as the country's independent supervisory authority. The law requires written, express, informed consent before personal data may be collected or processed; grants individuals rights of access, correction, and deletion together with the right to revoke consent; obligates data controllers that distribute, disclose, or commercialize personal data to register their databases with PRODHAB; allows a transfer of personal data only where the data subject has expressly authorized that specific transfer, since Costa Rica has no adequacy regime; requires notice of a security breach to the data subject and to PRODHAB within five business days; and authorizes fines of up to 30 base salaries for violations.
Constitutional Chamber Decision 5802-99 first recognized informational self-determination as a fundamental right under Article 24 of the Constitution, and Law 8968 translates that constitutional guarantee into operational obligations. A proposed replacement law (Bill 23097) that would align Costa Rica more closely with the EU General Data Protection Regulation was filed on 17 May 2022 and has not been enacted; Ley 8968 has never been amended.
Constitutional Basis: Article 24 and Informational Self-Determination
Costa Rica's data protection framework begins not in statute but in constitutional text. Article 24 of the Constitucion Politica de la Republica de Costa Rica provides:
"Se garantiza el derecho a la intimidad, a la libertad y al secreto de las comunicaciones. Son inviolables los documentos privados y las comunicaciones escritas, orales o de cualquier otro tipo de los habitantes de la Republica."
Translated: "The right to intimacy, freedom, and secrecy of communications is guaranteed. Private documents and written, oral, or any other type of communications of the inhabitants of the Republic are inviolable."
The Sala Constitucional (Constitutional Chamber of the Supreme Court) extended Article 24 beyond a passive shield against government surveillance. In Decision 5802-99, the Chamber recognized autodeterminacion informativa (informational self-determination) as an active constitutional right: individuals do not merely enjoy protection against unlawful disclosure of their data; they hold an affirmative right to know what personal information exists about them, to control how it is used, and to demand correction or deletion of inaccurate or illegitimately processed data.
This constitutional grounding distinguishes Costa Rica from many Latin American jurisdictions where data protection is entirely statutory. Because the right has constitutional rank, no ordinary law may eliminate it. Ley 8968 operationalizes the right; it does not create it. Any reform or replacement statute must preserve, not reduce, the constitutional floor.
The SCIJ database at pgrweb.go.cr hosts the official consolidated text of both Article 24 and Ley 8968.
Ley 8968: Scope, Definitions, and Core Principles
Ley 8968 applies to personal data held in automated and manual databases operated by any natural or legal person, public or private, within Costa Rican territory. It also applies to entities located outside Costa Rica that process data of individuals in the country where Costa Rican law governs the relationship.
Key Definitions
Article 3 of Ley 8968 establishes the working vocabulary:
Personal data (datos personales): any data concerning a natural person who is identified or identifiable.
Sensitive data (datos sensibles): information belonging to a person's private sphere, such as data revealing racial origin, political opinions, religious or spiritual convictions, socioeconomic status, biomedical or genetic information, and sexual life and orientation, among others. Two points surprise foreign compliance teams: socioeconomic status is a named sensitive category in Costa Rica, and biometric data and trade union membership are not. Sensitive data is prohibited from processing rather than merely restricted, as explained below.
Database (base de datos): any archive, file, register, or other structured set of personal data subject to automated or manual processing, whatever the manner of its creation, organization, or access.
Data processing (tratamiento de datos): any operation performed on personal data, including collection, recording, storage, organization, adaptation, modification, consultation, use, communication by transmission or dissemination, alignment or combination, and blocking or erasure.
Responsible party (responsable de la base de datos): the natural or legal person who decides the purpose and content of a database and the manner in which data is processed.
Data processor (encargado): any natural or legal person, public or private entity, or other body that processes personal data on behalf of the responsible party. This definition sits in article 2(k) of Decree 37554-JP, not in article 3 of the law.
Unrestricted-access personal data (datos personales de acceso irrestricto): data held in publicly accessible databases under special laws, usable consistently with the purpose for which it was collected. Article 9.3 expressly excludes exact home addresses, photographs, and private telephone numbers from this category.
Restricted-access personal data (datos personales de acceso restringido): data that forms part of a public register but is of interest only to the data subject or to the public administration. It may be processed only for public purposes or with the data subject's express consent.
Exemptions from the Law
Article 2 of Ley 8968 contains a single exclusion, and it is narrower than most summaries suggest:
- Databases kept by natural or legal persons for exclusively internal, personal, or domestic purposes, provided they are not sold or otherwise commercialized. Decree 40008-JP added that a database stays internal when it is shared inside one economic interest group, local or international, so long as there is no distribution, disclosure, or sale to third parties.
There is no national security exclusion and no journalism exclusion. State security and criminal investigation appear in article 8 as grounds for limiting rights in a specific case, which is a different thing: the law still applies.
Three further carve-outs sit in the regulation and in article 9.4 of the law rather than in article 2:
- Credit behaviour data, governed instead by the rules of the National Financial System
- Data about natural persons in their professional capacity, where processed for professional purposes or in compliance with legal duties
- Financial entities supervised by SUGEF, which do not have to register their databases with PRODHAB, although PRODHAB keeps full authority to regulate and supervise those databases
Core Principles
Ley 8968 articles 4 to 6 and 10 to 11, together with Decree 37554-JP, set out the principles governing all processing activities:
- Purpose limitation (principio de finalidad): data must be collected for a specific, explicit, and legitimate purpose, and not further processed in a manner incompatible with that purpose.
- Data quality (calidad de los datos): personal data must be accurate, complete, current, and relevant to the declared purpose.
- Security (seguridad): the responsible party must adopt technical and organizational measures appropriate to the risk of the processing.
- Confidentiality (confidencialidad): persons with access to personal data must keep it confidential, including after their role ends.
- Consent (consentimiento): processing requires the prior, free, specific, informed, and unequivocal consent of the data subject, recorded in writing, except in the three cases listed in article 5.2 of the law.
Legal Bases for Processing
Costa Rica does not use a menu of legal bases. Written informed consent is the general rule, and article 5.2 of Ley 8968 dispenses with express consent in only three cases. Article 5 of Decree 37554-JP repeats the same three.
| Situation | Condition |
|---|---|
| Judicial or legislative order | A reasoned order issued by a competent judicial authority, or a resolution adopted by a special investigative commission of the Legislative Assembly acting within its remit |
| Unrestricted-access public data | The data are datos personales de acceso irrestricto obtained from sources of general public access |
| Constitutional or legal mandate | The data must be handed over under a constitutional or legal provision |
There is no legitimate interests ground, no contractual necessity ground, no vital interests ground, and no public task ground in Costa Rican law. Those come from article 6 of the EU GDPR and have no counterpart here. A controller that processes personal data on a theory of contractual necessity instead of obtaining written consent commits a serious infraction under article 30(a).
A controller relying on unrestricted-access public data must still process it consistently with the purpose for which it was made public and with the general principles of Ley 8968.
Article 8 separately allows the rights and guarantees in the law to be limited, in a fair and reasonable way, for state security, the exercise of public authority, the prevention and investigation of criminal or professional disciplinary offences, the operation of statistical, historical, or scientific databases where individuals cannot be identified, the adequate provision of public services, and the efficient ordinary activity of the administration.
Consent Requirements
Consent under Ley 8968 must be free, specific, informed, unequivocal, and in writing. Article 5.2 says so directly: the consent "debera constar por escrito, ya sea en un documento fisico o electronico."
This is the requirement foreign compliance teams most often miss. Written consent applies to all personal data, not only to sensitive categories.
In writing means a physical or electronic document. Where consent is collected online, the responsible party must provide a procedure for giving it that meets the law (Decree 37554-JP article 5, as amended by Decree 40008-JP). Where consent is gathered inside a contract signed for another purpose, that contract must carry a specific and independent clause on the processing of personal data.
Informed means the data subject received, before consenting, clear notice of: the existence of the database; the purposes of collection; the recipients of the information and who may consult it; whether answers are mandatory or optional; the treatment the data will receive; the consequences of refusing to supply it; the rights the law grants; and the identity and address of the responsible party.
Unequivocal means consent is given by a means or by conduct that makes the grant provable beyond doubt and available for later consultation. Silence, pre-ticked boxes, and inaction do not qualify.
Free means consent is not coerced and not bundled with terms unrelated to the service the data subject is seeking.
The responsible party carries the burden of proving valid consent in every case (Decree 37554-JP article 6). Collecting data without informed consent, or by fraudulent, unfair, or unlawful means, is expressly prohibited by article 5 of the law.
Sensitive Data Is Prohibited, Not Merely Restricted
Article 9.1 does not create a written-consent route for sensitive data. It provides that no person may be compelled to supply sensitive data and then prohibits the processing of personal data revealing racial or ethnic origin, political opinions, religious, spiritual, or philosophical convictions, and data concerning health, life, and sexual orientation, among others.
The prohibition lifts in only four situations:
- Processing is necessary to safeguard the vital interest of the data subject or another person, where the data subject is physically or legally incapable of consenting
- Processing takes place in the course of the legitimate activities, and with appropriate safeguards, of a foundation, association, or other body with a political, philosophical, religious, or trade union purpose, limited to its members or to people in regular contact with it, and the data are not disclosed to third parties without consent
- The data have been made public voluntarily by the data subject, or are necessary for the recognition, exercise, or defence of a right in judicial proceedings
- Processing is necessary for prevention or medical diagnosis, the provision of health care or treatment, or the management of health services, carried out by a health professional bound by professional secrecy or by another person under an equivalent duty of secrecy
Processing sensitive data outside those four cases, by a private natural or legal person, is a very serious infraction under article 31(a). Where the law does permit sensitive data processing, article 37 of the regulation requires the security measures to be reviewed and updated at least once a year.
Withdrawal of Consent
Data subjects may withdraw consent at any time, in the same form in which it was given, and withdrawal has no retroactive effect. The responsible party must provide expeditious, simple, and free mechanisms for revocation (Decree 37554-JP article 7).
Article 8 of the regulation gives the responsible party five business days from receipt to act on the revocation and, within those same five days, to inform anyone it transferred the data to. Those recipients then have five business days of their own to give effect to the revocation. Where the data subject asks for confirmation that processing has stopped, article 9 requires a free written answer within three business days.
Data Subject Rights
Article 7 of Ley 8968, in Chapter II, enumerates the rights individuals hold over their personal data, and Chapter III of Decree 37554-JP (articles 12 to 26) governs how they are exercised. These rights are exercised first against the responsible party, and if that party fails to respond or the data subject is dissatisfied, the data subject may escalate to PRODHAB.
Right of Information (Derecho de Informacion)
Any person may query any public or private entity to learn whether that entity holds a database containing their personal data, what data it contains, the purpose of the database, and the identity of the responsible party. This right applies regardless of whether the data was provided by the data subject or collected from third parties.
Right of Access (Derecho de Acceso)
Data subjects may request a full copy of their personal data held in any database. Under article 7 of Ley 8968 and articles 18 and 21 of Decree 37554-JP, the responsible party must respond within five business days, counted from the day after the request is received. The answer must cover the whole record held about the data subject and be given in a legible, comprehensible format, with the meaning of any codes or abbreviations supplied. Every response is free of charge, with no annual cap.
The real constraint is a different one. Article 21 of the regulation lets a data subject query a given database at a minimum interval of six months. A data subject who states reasons and produces evidence of a violation may query sooner. If the responsible party considers the request abusive, it has five business days to refer the matter to PRODHAB, which decides within ten business days.
Right of Rectification (Derecho de Rectificacion)
Where personal data is inaccurate, incomplete, or confusing, the data subject may request correction under articles 23 and 24 of Decree 37554-JP. The request must identify the data and the correction sought and be accompanied by supporting documentation, and the responsible party has five business days to respond.
The duty to notify third parties attaches to revocation of consent rather than to rectification. Article 8 of the regulation is the provision that requires the responsible party to tell anyone it transferred the data to, within five business days.
Right of Deletion (Derecho de Supresion)
Article 7.2 of Ley 8968 lets a data subject obtain rectification, updating, cancellation, or elimination of personal data that was processed in breach of the law, is incomplete or inaccurate, or was collected without the data subject's authorization. Article 25 of Decree 37554-JP lets the data subject ask at any time for total or partial deletion.
Article 26 of the regulation then lists eight situations in which deletion may be refused:
- State security
- Data that must be kept under a constitutional or legal provision or a judicial decision
- Citizen security and the exercise of public authority
- Prevention, prosecution, investigation, detention, and punishment of criminal offences or of professional disciplinary offences
- Operation of databases used for statistical, historical, or scientific research where individuals cannot be identified
- The adequate provision of public services
- The efficient ordinary activity of the administration by official authorities
- Unrestricted-access personal data obtained from sources of general public access
Right to Revoke Consent (Derecho de Revocacion)
A data subject may withdraw consent at any time, in the same form in which it was given and without retroactive effect. Articles 7 to 10 of Decree 37554-JP set the procedure and the deadlines, and a responsible party that refuses expressly or tacitly to process a revocation can be reported to PRODHAB.
Costa Rican law does not grant a general right to object to otherwise lawful processing. Article 7 of Ley 8968 lists access, rectification, deletion, and the right to consent to a cesion of data, and the regulation lists access, rectification, modification, revocation, and elimination. A right of opposition would arrive only if Bill 23097 is enacted.
Timeframe Summary
| Right | Response Deadline |
|---|---|
| Information | Five business days |
| Access | Five business days |
| Rectification | Five business days |
| Deletion | Five business days (or statement of grounds for refusal) |
| Revocation of consent | Five business days to act and to notify anyone the data was transferred to; three business days to confirm processing has stopped |
Watch out: The five-business-day deadline runs from receipt of a complete, properly identified request. Responsible parties frequently delay by treating incomplete or ambiguous requests as not yet received. Data subjects should submit written requests with full identification and a clear description of the data at issue to start the clock clearly.
Security Breach Notification
Costa Rica does require breach notification. The common claim that it does not is wrong, and a business that relies on it will miss a legal deadline.
Article 38 of Decree 37554-JP (Vulnerabilidad de seguridad) requires the responsible party to inform the data subject of any irregularity in the processing or storage of their data, including loss, destruction, or misplacement, whether it results from a security breach or otherwise comes to the responsible party's knowledge. The deadline is five business days from the moment the breach occurred, so that the people affected can take protective steps. Within those same five days the responsible party must begin an exhaustive review to establish the scale of the harm and the corrective and preventive measures required.
Article 39 sets the minimum content and adds the regulator. The responsible party must inform the data subject and PRODHAB of at least four things:
- The nature of the incident
- The personal data compromised
- The corrective actions taken immediately
- The means or place where more information can be obtained
PRODHAB publishes a guidance sheet, Informe de vulneracion, that states the same rule: five business days from the events to send the report to the agency and to the affected data subjects, by letter or email signed by the person responsible for the information.
What Bill 23097 would change is the shape of the duty, not its existence. The reform would move to a GDPR-style short deadline and place the obligation in the statute rather than in the regulation.
PRODHAB: Structure, Powers, and Enforcement Record
The Agencia de Proteccion de Datos de los Habitantes (PRODHAB) was created by article 15 of Ley 8968, in Chapter IV. It operates as an organo de desconcentracion maxima attached to the Ministry of Justice and Peace, exercising regulatory, investigative, and sanctioning functions with technical and operational independence from the ministry's general hierarchy.
Core Functions
Registration and registry management: PRODHAB maintains a public registry of databases subject to the registration requirement. The registry is searchable, allowing data subjects to identify which entities hold data about them.
Inspection and audit: PRODHAB may conduct inspections of registered databases on its own initiative or following a complaint. Inspectors may review documentation, interview staff, and examine security measures.
Complaint handling: PRODHAB receives and investigates formal complaints from data subjects, and it publishes the de-identified case register as open data. That register records roughly 2,340 complaint files from 2014 through June 2025, of which about 1,750 were received through the end of 2023.
The sectors that generate the most complaints are credit bureaus (about 520 files), banking and finance (about 350), commercial businesses (about 340), and debt collection agencies (about 270). The most common ground by a wide margin is a request to delete or suppress personal data, which appears in roughly 1,180 files, followed by collection or processing without prior informed consent and by use of data for a purpose other than the one authorized.
Guidance and registered protocols: PRODHAB issues directives, which article 16(i) requires to be published in La Gaceta, and it keeps the register of protocolos minimos de actuacion.
Those protocols are not a voluntary code of conduct. Article 32 of Decree 37554-JP requires every responsible party to draft one and pass it to its data processor, and it must specify at least six things: internal privacy policies and manuals; a staff training and awareness programme; an internal control procedure for compliance with those policies; free and expeditious procedures for handling data subject questions, complaints, and requests; technical measures that keep a history of the data during processing; and a mechanism by which a transferring controller tells a receiving controller the conditions on which the data subject consented. The protocol and any later changes must be registered with PRODHAB, article 12 of the law makes registration a condition of validity, and article 33 of the regulation lets PRODHAB verify compliance at any time.
Sanctioning: PRODHAB may impose the graduated sanctions described in the Penalties section below. Sanction proceedings follow an adversarial administrative procedure in which the accused party may present evidence and argument before a final resolution is issued.
PRODHAB's own published case register shows complaint files that stay open across calendar years, and institutional capacity is among the issues the proposed reform legislation under Bill 23097 addresses.
On 17 July 2026 PRODHAB issued Directriz PRODHAB-DIR-DN-001-2026, a general directive addressed to every public or private entity that carries out or contracts debt collection. It limits collection of third-party data to cases where those third parties gave express informed consent, bars collection communications to people with no direct relationship to the debt who have not consented, bars use of workplace contact details for collection unless a final judicial order authorizes it for a specific and delimited purpose, requires the responsible party to be easily identifiable in every collection communication, and treats repetition of conduct already declared improper in final resolutions as an aggravating factor leading to ordinary sanction proceedings under articles 27 and 28.
Database Registration Requirement
One distinctive feature of Ley 8968 compared to the EU GDPR is the mandatory registration of certain databases with PRODHAB before processing begins.
Who Must Register
Registration is required for any natural or legal person, public or private, that maintains a database of personal data for the purposes of distributing, disclosing, or commercializing that data. This covers data brokers and list providers, marketing and advertising databases, credit reporting agencies, and companies that sell or license access to personal data.
Who Is Exempt
Two exemptions apply, the first from article 2 of Ley 8968 and article 3 of the regulation, the second from article 3 of the regulation as amended by Decree 40008-JP:
- Internal-use databases: entities that maintain databases of personal data solely for their own internal operational purposes (for example, HR records, customer service records, or supplier registers used exclusively by the data controller) are not required to register.
- SUGEF-regulated financial institutions: entities subject to the control and regulation of the Superintendencia General de Entidades Financieras (SUGEF) are exempt from PRODHAB registration for data processed under SUGEF's supervisory framework.
Registration Information Required
Article 44 of Decree 37554-JP sets the contents. A registration application must include: an authenticated application from the owner; designation of the responsible party before PRODHAB and before third parties, with a letter accepting the role; identification of the data processors and their contact details; the name and description of the database; the purposes and intended uses of the database; the categories of personal data processed and the procedures by which consent is obtained; the intended recipients; the security measures; and a copy of the protocolos minimos de actuacion. Internal and domestic databases are not registrable.
The annual registration fee is USD 200, payable between 1 and 31 January each year (article 33 of the law; articles 78 and 79 of the regulation). Processing personal data without being duly registered, where article 21 requires registration, is a very serious infraction under article 31(e): 15 to 30 base salaries plus suspension of the file for one to six months.
Retention Limit
The ten-year retention cap sits in the law itself, not in an amendment to the decree, and it is not confined to registered databases. Article 6.1 of Ley 8968 provides that personal data capable of affecting the data subject may not be kept once ten years have passed, and article 11 of Decree 37554-JP restates it.
Decree 40008-JP changed the starting point in 2016. The ten years now run from the date the purpose of the processing ends, not from the date of the recorded events. Four exceptions apply: a special legal provision setting another period, a different period agreed between the parties, a continuing relationship between them, or a public interest in keeping the data. Where data must be kept beyond the period, the law requires desasociacion, meaning the data are dissociated from the individual rather than simply held on.
Cross-Border Data Transfers
Article 14 of Ley 8968, which forms Chapter III of the law, governs transfers of personal data. Costa Rica does not use an adequacy model, and this is the most consequential difference for a company arriving with a GDPR playbook.
Consent Is the Only Gateway
Article 14 provides that responsible parties, public or private, may transfer data held in their databases only where the holder of the right has expressly and validly authorized that transfer, and only where the transfer does not breach the principles and rights the law recognizes.
Article 40 of Decree 37554-JP, as amended by Decree 40008-JP, adds that a transfer always requires the data subject's unequivocal and informed consent unless a legal provision says otherwise, and that the data must have been collected lawfully. Any sale of a file or database, in whole or in part, must meet the same requirements.
There is no adequacy determination power, no PRODHAB adequacy list, and no set of GDPR-style derogations. A controller that sends personal data abroad because the recipient country is treated as adequate elsewhere has no legal basis in Costa Rica.
What Counts as a Transfer
Under article 40 as amended, moving data from the responsible party to its data processor, to a technology intermediary or service provider, or to companies within the same economic interest group is not a transfer. A transfer is a cesion from the transferring responsible party to a receiving responsible party.
Two Obligations That Travel With the Transfer
- A contract with the recipient. Article 43 of the regulation requires the transferring party to put a contract in place that binds the receiving party to at least the same obligations the transferring party bears.
- Compliance with the registered protocol. Article 41 makes every transfer conditional on faithful compliance with the protocolos minimos de actuacion registered with PRODHAB. Article 42 places the burden of proving a lawful transfer on the responsible party.
The Penalty for Getting This Wrong
Transferring personal data of Costa Ricans, or of foreigners resident in the country, to databases in third countries without the data subjects' consent is a very serious infraction under article 31(f): 15 to 30 base salaries, currently 6,933,000 to 13,866,000 colones, plus suspension of the file for one to six months. Transferring in breach of Chapter III more generally is a serious infraction under article 30(b).
Practical Compliance Points
Organizations transferring personal data from Costa Rica should obtain written, specific, documented consent that identifies the transfer; retain proof of that consent, because the burden of proof sits with the controller; sign a contract imposing at least equivalent obligations on the recipient; draft and register a protocolo minimo de actuacion and follow it; and treat processor and intra-group flows separately, since those are not transfers under article 40.
Penalties and Enforcement
Chapter V of Ley 8968 establishes a graduated administrative sanction regime. Article 28 sets the sanctions, and articles 29, 30, and 31 list the minor, serious, and very serious infractions. Articles 33 and 34, which some summaries cite for penalties, are the canones: the annual USD 200 registration fee and the per-consultation fee on commercial sales.
Infraction Categories
Minor infractions (faltas leves), article 29, are only two: collecting personal data for use in a database without giving the data subject the full information article 5.1 requires, and collecting, storing, or transmitting third-party personal data through insecure mechanisms that do not guarantee the security and integrity of the data.
Serious infractions (faltas graves), article 30, are five: collecting, storing, transmitting, or otherwise using personal data without the data subject's informed and express consent; transferring personal data to other persons or companies in breach of Chapter III; using personal data for a purpose other than the one the data subject authorized; unjustifiably refusing a data subject access to data held about them; and unjustifiably refusing to delete or rectify data when clearly and unequivocally asked.
Very serious infractions (faltas gravisimas), article 31, are six: processing sensitive data by a private natural or legal person; obtaining personal data by deception, violence, or threat; revealing information held in a database that the party is legally bound to keep secret; knowingly giving a third party false or altered information from a data file; processing personal data without being registered with PRODHAB where article 21 requires it; and transferring personal data of Costa Ricans or residents to databases in third countries without the data subjects' consent.
Note where two commonly misfiled offences actually sit. Failure to register is very serious, not serious. Processing for a purpose other than the one consented to is serious, not very serious. Failing to comply with a PRODHAB order to correct or delete is handled under article 26, which exposes the party to the sanctions in this and other laws.
Sanction Scale
| Infraction Level | Fine Range | 2026 Colones Equivalent |
|---|---|---|
| Minor (article 29) | Up to 5 base salaries | Up to 2,311,000 colones |
| Serious (article 30) | 5 to 20 base salaries | 2,311,000 to 9,244,000 colones |
| Very serious (article 31) | 15 to 30 base salaries, plus suspension of the file for one to six months | 6,933,000 to 13,866,000 colones |
The base salary (salario base) used to calculate these fines is the base salary of the auxiliar judicial I post under the Ley de Presupuesto de la Republica, as article 28 specifies. For 2026 that figure is 462,200 colones, set by Circular No. 246-2025 and unchanged since 2021, per the Ministerio de Hacienda's published table. At 30 base salaries the maximum administrative fine is 13,866,000 colones, roughly USD 30,500 at the September 2026 reference rate of about 454 colones to the dollar.
Beyond fines, article 28 provides one further sanction and only one: suspension of the file for one to six months, available for very serious infractions. There is no permanent cancellation sanction and no gazette-publication sanction in the law or the regulation. Cancelling a registration is a voluntary procedure the owner or responsible party initiates under article 55 of the regulation, and the only La Gaceta publication duty in the statute is for PRODHAB's own directives under article 16(i).
PRODHAB may also issue written apercibimientos (article 70 of the regulation) and may order, on its own initiative or on request, the deletion, rectification, addition, or restriction of the circulation of data held in files and databases (article 16(f) and article 26 of the law).
How PRODHAB Sets the Amount
Neither Ley 8968 nor Decree 37554-JP contains a list of aggravating and mitigating factors of the kind found in article 83 of the EU GDPR. Article 70 of the regulation gives the only instruction: PRODHAB imposes the sanction according to the statutory tier the infraction falls into and the hecho generador, the conduct that produced it, in the final decision itself, listing the infractions committed, the amount, the payment deadline, and the account.
Two related rules matter in practice. Article 12 of the law gives data handled under a protocol registered with PRODHAB a rebuttable presumption of compliance, though for the specific purpose of authorizing a cesion of data rather than as a general mitigating factor. And PRODHAB's directive of 17 July 2026 treats repetition of conduct already declared improper in final resolutions as an aggravating circumstance in debt collection matters.
Pending Reforms and Legislative Developments
Costa Rica's data protection framework has attracted sustained reform pressure since approximately 2019, driven by OECD membership requirements, EU bilateral trade relations, and the domestic recognition that Ley 8968 predates the GDPR and lacks several features now considered standard.
Bill No. 23097: Proposed New Personal Data Protection Law
The most significant pending reform is Proyecto de Ley No. 23097, submitted to the Asamblea Legislativa in May 2022. The bill proposes complete repeal of Ley 8968 and its replacement with a new statute aligned with the EU GDPR, including:
- A "legitimate interests" legal basis for processing (absent from current law)
- A GDPR-style short breach notification deadline in the statute, replacing the five-business-day rule that articles 38 and 39 of the regulation already impose
- Data protection impact assessments (DPIAs) for high-risk processing
- Accountability obligations including data protection officers for large-scale processors
- A strengthened PRODHAB with greater autonomy and dedicated budget
- A raised maximum fine ceiling above the current 30-base-salary limit
- Data portability rights for data subjects
- Provisions governing automated decision-making and profiling
- A 12-month transition period after enactment
What can be confirmed about the bill is narrow. Its Assembly base text is signed and dated 17 May 2022. It has not become law: SINALEVI's record for Ley 8968 shows no affecting legislation, and PRODHAB's own Normativa page states that the law has never been reformed and that only the regulation has changed, by Decree 40008-JP in 2016 and Decree 41582-JP in 2019.
Costa Rican bills lapse four years after filing unless the Assembly renews them, so the fecha cuatrienal for Bill 23097 fell on 17 May 2026. The Assembly's expediente system was unreachable during this review, so we could not confirm whether the bill was archived on that date or carried forward. Treat it as a planning input rather than a scheduled change, and check the Assembly's expediente record before acting on it.
OECD Accession Alignment
Costa Rica joined the OECD on May 25, 2021. OECD membership has accelerated alignment with international privacy standards, including the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (revised 2013). These guidelines are reflected in PRODHAB's current guidance and in the reform proposals under Bill 23097.
Council of Europe Convention 108+ Process
Costa Rica has requested accession to Convention 108+, a process that was still at the exchange-of-views stage in the Council of Europe committee in November 2025 (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as modernized in 2018), and the Council of Europe's Consultative Committee published a full evaluation of Costa Rica for accession on 11 June 2021. Accession would bring Costa Rica into a binding treaty framework with substantive protections aligned with the GDPR. Costa Rica had not completed accession when this article was reviewed in September 2026.
Post-2022 Cybersecurity Context
Costa Rica's reform urgency increased following the April-May 2022 ransomware attacks attributed to the Conti group, which disrupted multiple government ministries and prompted a national cybersecurity emergency declaration. Those incidents exposed gaps in cybersecurity posture and breach response capacity. The breach notification duty in articles 38 and 39 of Decree 37554-JP already existed at the time. The reform debate has been about tightening it, moving to a shorter deadline and writing security-incident obligations into the statute rather than leaving them in the regulation.
Regional Role
Costa Rica participates in the Red Iberoamericana de Proteccion de Datos (RIPD), facilitating regulatory cooperation across Spanish- and Portuguese-speaking jurisdictions. PRODHAB has contributed to RIPD working groups on AI governance, cross-border transfer mechanisms, and supervisory cooperation.
Business Compliance: Practical Checklist
For businesses operating in or transferring data to or from Costa Rica, Ley 8968 imposes the following core obligations:
Audit your databases: Identify which databases contain personal data. Determine whether each is subject to the registration requirement (commercial distribution or disclosure purpose) or falls within an exemption (internal use; SUGEF-regulated institutions).
Register applicable databases: Submit a registration application to PRODHAB before beginning commercial use of any database subject to the requirement. Budget USD 200 per database per year.
Collect written consent, for every category of data: For each processing activity, prepare a written consent document, on paper or electronic, identifying the responsible party, stating the specific purpose, identifying any third-party recipients, explaining data subject rights, and describing how consent may be withdrawn. Where consent sits inside a contract signed for another purpose, give it a specific and independent clause. Keep the evidence: the burden of proving consent is always yours.
Do not process sensitive data unless an exception applies: If your processing touches racial or ethnic origin, political opinions, religious, spiritual, or philosophical convictions, socioeconomic status, biomedical or genetic information, or sexual life and orientation, start from the position that article 9.1 prohibits it. Processing is lawful only under one of the four statutory exceptions, and for a private entity, processing outside them is a very serious infraction.
Respond to data subject requests within five business days: Build an internal workflow that flags, acknowledges, and responds to access, rectification, deletion, and revocation requests on time. An unjustified refusal of access, deletion, or rectification is itself a serious infraction.
Obtain consent before any transfer: There is no adequacy list to consult. Before personal data leaves your control, obtain the data subject's express, informed, unequivocal authorization for that transfer, sign a contract binding the recipient to at least equivalent obligations, and keep the documentation. Movements to your own processor or within your economic interest group are not transfers under article 40.
Implement security measures: Decree 37554-JP requires technical and organizational measures appropriate to the risk, including access controls, encryption for sensitive data in transit and at rest, and documented incident response procedures. Where the law permits sensitive data processing, review those measures at least once a year.
Build a five-business-day breach process: Articles 38 and 39 of the regulation require notice to the affected data subjects and to PRODHAB within five business days of the incident, stating the nature of the incident, the data compromised, the immediate corrective actions, and where to get more information. Start the exhaustive internal review inside the same five days.
Write and register a protocolo minimo de actuacion: Article 32 of the regulation makes this mandatory, article 12 of the law makes registration with PRODHAB a condition of validity, and article 41 makes lawful transfers depend on following it.
Watch the reform, but comply with the law in force: Bill 23097 would give a 12-month transition period if enacted, and its four-year filing deadline passed on 17 May 2026 without confirmed passage. Ley 8968 as it stands is what binds you today. Any gap analysis against the bill (DPIA requirements, a legitimate interests basis, DPO appointments, a shorter breach deadline) is planning work, not a compliance deadline.
Disclaimer
This article presents general legal information about Costa Rica's data protection framework under Ley No. 8968 and Executive Decree 37554-JP, verified as of 10 September 2026. It does not constitute legal advice and does not address the specific situation of any individual or organization. Laws and regulations change, and the pending reform legislation described above may alter the obligations discussed here. Persons and businesses with specific questions about data protection compliance in Costa Rica should consult a lawyer licensed to practice Costa Rican law.
Authorities Cited
Frequently Asked Questions
What is Ley 8968 and when did it come into force?
Ley No. 8968, formally titled the Ley de Proteccion de la Persona frente al Tratamiento de sus Datos Personales, was enacted on July 7, 2011, and entered into force on September 5, 2011. It is Costa Rica's principal data protection statute, regulating how personal data is collected, stored, processed, and transferred in both the public and private sectors. Executive Decree 37554-JP, published in 2013, provides the implementing regulations.
What is PRODHAB and what powers does it have?
PRODHAB (Agencia de Proteccion de Datos de los Habitantes) is Costa Rica's independent data protection supervisory authority, created by Ley 8968. It registers databases, investigates data subject complaints, conducts inspections, issues directives published in La Gaceta, keeps the register of the protocolos minimos de actuacion that every responsible party must draft, and may impose administrative sanctions including fines of up to 30 base salaries (13,866,000 colones in 2026), written warnings, orders to delete, rectify, add to, or restrict the circulation of data, and suspension of a file for one to six months for very serious infractions. There is no permanent cancellation sanction; cancelling a registration is a voluntary procedure the owner initiates.
Do I need to register my database with PRODHAB?
Registration is required if your database is used for distributing, disclosing, or commercializing personal data. Two categories are exempt: databases used exclusively for internal operational purposes (HR records, customer records not shared commercially), and databases maintained by SUGEF-regulated financial institutions. The annual registration fee is USD 200 per database, payable in January. Failing to register when required is a very serious infraction under article 31(e) of Ley 8968, punishable by 15 to 30 base salaries plus suspension of the file for one to six months.
What type of consent is required under Costa Rican data privacy law?
Written consent is required for all personal data, not only for sensitive categories. Article 5.2 of Ley 8968 requires the consent to be recorded in writing, in a physical or electronic document, and it must be free, specific, informed, and unequivocal. Express consent is dispensed with in only three situations: a reasoned order from a competent judicial authority or from a special investigative commission of the Legislative Assembly, unrestricted-access data obtained from generally public sources, and data that must be handed over under a constitutional or legal provision. Sensitive data is a separate matter: article 9.1 prohibits processing it, subject to four narrow exceptions.
Can personal data be transferred outside Costa Rica?
Yes, but only with consent. Costa Rica has no adequacy regime and PRODHAB publishes no adequacy list. Article 14 of Ley 8968 allows a transfer only where the data subject has expressly and validly authorized it, and article 40 of Decree 37554-JP requires unequivocal, informed consent unless a legal provision says otherwise. The transferring party must also sign a contract binding the recipient to at least the same obligations (article 43) and must comply with the protocol it registered with PRODHAB (article 41). Sending personal data to a database in another country without the data subjects' consent is a very serious infraction under article 31(f), punishable by 15 to 30 base salaries plus suspension of the file. Moving data to your own processor or within the same economic interest group is not a transfer.
What penalties can PRODHAB impose for violations?
Sanctions are graduated by infraction severity under article 28 of Ley 8968. Minor infractions carry a fine of up to 5 base salaries. Serious infractions carry 5 to 20 base salaries. Very serious infractions carry 15 to 30 base salaries plus suspension of the file for one to six months. At the 2026 base salary of 462,200 colones, that means up to 2,311,000 colones, then 2,311,000 to 9,244,000 colones, then 6,933,000 to 13,866,000 colones. The maximum fine is 13,866,000 colones, roughly USD 30,500. PRODHAB may also issue written warnings and order data to be deleted, rectified, added to, or restricted in circulation.
Does Costa Rica require data breach notification?
Yes. Articles 38 and 39 of Decree 37554-JP have required breach notification since 2013. The responsible party has five business days from the moment the breach occurred to notify both the affected data subjects and PRODHAB, and the notice must state the nature of the incident, the personal data compromised, the corrective actions already taken, and where to obtain more information. Within the same five days the responsible party must begin an exhaustive review of the scope of the incident. PRODHAB publishes a guidance sheet, Informe de vulneracion, that restates the rule. Bill 23097 would move to a shorter GDPR-style deadline written into the statute; it would not create a first-ever obligation.
What is the constitutional basis for data protection in Costa Rica?
Article 24 of the Constitucion Politica de la Republica de Costa Rica guarantees the right to intimacy, freedom, and secrecy of communications. The Constitutional Chamber (Sala Constitucional) recognized in Decision 5802-99 that Article 24 encompasses the right of informational self-determination (autodeterminacion informativa): individuals hold an active constitutional right to control the flow of their personal information. Ley 8968 operationalizes this constitutional guarantee; it does not create the underlying right.
How does Costa Rica's law compare to the EU GDPR?
Both frameworks share core principles (purpose limitation, data quality, security, consent, and data subject rights), and the differences run in both directions. Costa Rica requires written consent for all personal data and recognizes only three narrow exceptions, where the GDPR offers six legal bases including legitimate interests. It prohibits sensitive data processing outside four statutory cases. It requires database registration for commercial processing, with a USD 200 annual fee. It has no adequacy regime, so every transfer depends on the data subject's express consent. It grants no data portability right, no general right to object to lawful processing, and no rules on automated decision-making. It does require breach notification, within five business days, under the regulation rather than the statute. Its maximum fine, about USD 30,500, is far below the GDPR ceiling. Bill 23097 would narrow most of these gaps if enacted.
What is the status of Costa Rica's data protection reform as of 2026?
Bill No. 23097, filed in the Legislative Assembly on 17 May 2022, proposes a complete GDPR-aligned replacement of Ley 8968. It has not been enacted. PRODHAB and the SINALEVI legal information system both record Ley 8968 as never having been reformed; only the regulation has changed, by Decree 40008-JP in 2016 and Decree 41582-JP in 2019. Costa Rican bills lapse four years after filing, so the bill reached its four-year deadline on 17 May 2026. The Legislative Assembly expediente system was unreachable during this review, so its current procedural status could not be confirmed and should be checked directly against the Assembly record.
How long may personal data be retained under Costa Rican law?
The ten-year cap comes from article 6.1 of Ley 8968 itself, restated in article 11 of Decree 37554-JP. It covers any personal data that could affect the data subject, not only data in registered databases. Since Decree 40008-JP in 2016, the ten years run from the date the purpose of processing ends rather than from the date of the recorded events. The cap does not apply where a special legal provision sets another period, where the parties agreed a different one, where a continuing relationship exists between them, or where there is a public interest in keeping the data. Where data must be kept longer, it has to be dissociated from the individual.
Updates
Corrected the article against the official texts of Ley 8968 and Decree 37554-JP: Costa Rica has no adequacy regime, so every transfer of personal data needs the data subject's express consent under article 14; breach notification to the affected people and to PRODHAB is mandatory within five business days under articles 38 and 39 of the regulation, not absent; written consent is required for all personal data and sensitive data is prohibited rather than permitted on consent; the serious-infraction fine band is 5 to 20 base salaries and failing to register a database is a very serious infraction; and the article citations, sensitive-data definition, retention rule, sanction list, data subject rights, and enforcement statistics were rebuilt from the Gaceta texts and PRODHAB's own published records.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Full audit-and-evolve refresh: expanded constitutional basis (Article 24, Decision 5802-99), PRODHAB structure and complaint statistics, database registration exemptions and fee, cross-border transfer rules, penalty calculation updated to the 2026 base salary (462,200 colones), reform bill status, Council of Europe Convention 108+ evaluation, and business compliance checklist. Word count raised from ~2,350 to ~5,400.
Reviewed and approved by an editor
Initial publication.
Sources and References
- PRODHAB - Agencia de Proteccion de Datos de los Habitantes (official site)(prodhab.go.cr).gov
- Ley No. 8968 de Proteccion de la Persona frente al Tratamiento de sus Datos Personales (full text, SCIJ)(pgrweb.go.cr).gov
- Decreto Ejecutivo 37554-JP - Reglamento a la Ley 8968 (full text, SCIJ)(pgrweb.go.cr).gov
- Constitucion Politica de la Republica de Costa Rica - Articulo 24 (SCIJ)(pgrweb.go.cr).gov
- Proyecto de Ley No. 23097 - Ley de Proteccion de Datos Personales (Asamblea Legislativa base text)(proyectos.conare.ac.cr).gov
- PRODHAB - Normativa: Ley 8968, Reglamento 37554-JP and the 2016 and 2019 amending decrees(prodhab.go.cr).gov
- OECD - Costa Rica country page (member since 2021)(oecd.org)
- Red Iberoamericana de Proteccion de Datos (RIPD)(redipd.org)
- Freedom House - Costa Rica: Freedom on the Net 2024(freedomhouse.org)
- Ministerio de Hacienda - Salarios base actual e historico (Circular 246-2025: 462,200 colones for 2026)(hacienda.go.cr).gov
- Ley N. 8968 as published in La Gaceta N. 170, 5 September 2011 (Imprenta Nacional)(imprentanacional.go.cr).gov
- Decreto Ejecutivo 37554-JP, Reglamento a la Ley 8968, Alcance 42 to La Gaceta N. 45, 5 March 2013(imprentanacional.go.cr).gov
- Decreto Ejecutivo 40008-JP (2016) amending the Reglamento, Alcance 287 to La Gaceta, 6 December 2016(imprentanacional.go.cr).gov
- Decreto Ejecutivo 41582-JP (2019) amending the Reglamento, Alcance 48 to La Gaceta, 4 March 2019(imprentanacional.go.cr).gov
- PRODHAB - Informe de vulneracion: five-business-day breach report duty under Reglamento arts. 38-39(prodhab.go.cr).gov
- PRODHAB - Informe de denuncias 2014-2025 (de-identified complaints register)(prodhab.go.cr).gov
- PRODHAB - Directriz PRODHAB-DIR-DN-001-2026 on personal data in debt collection, 17 July 2026(prodhab.go.cr).gov
- Council of Europe, T-PD(2020)08rev - Evaluation of the Republic of Costa Rica for accession to Convention 108+, 11 June 2021(rm.coe.int)