EnglishEspañol
Uruguay flag

Uruguay

Uruguay Data Privacy Laws: Law 18.331, URCDP, and EU Adequacy (2026)

By Recording Law Editorial TeamReviewed July 23, 202622 min read
Uruguay Data Privacy Laws: Law 18.331, URCDP, and EU Adequacy (2026)

Frequently Asked Questions

What is Uruguay's main data protection law?

Uruguay's main data protection law is Law No. 18.331, the Ley de Proteccion de Datos Personales y Accion de Habeas Data, enacted on 11 August 2008 and in force from 18 August 2008. It is implemented by Decree No. 414/009 of 2009 and has been amended by Decree No. 64/020 (2020), Law No. 19.924 (2020), and Law No. 20.075 (2022). The supervisory authority is the URCDP.

Does Uruguay still have EU adequacy status in 2026?

Yes. Uruguay obtained EU adequacy status under European Commission Decision 2012/484/EU on 21 August 2012. On 15 January 2024, the Commission completed its first GDPR-era review of 11 pre-GDPR adequacy decisions and confirmed that Uruguay continues to provide protection equivalent to the GDPR. As of May 2026, Uruguay retains full EU adequacy status, meaning personal data may flow from the EU and EEA to Uruguay without standard contractual clauses or other additional safeguards.

Does Uruguay have a 72-hour data breach notification rule?

Yes. Decree No. 64/020 of 21 February 2020 requires all data controllers and processors to notify the URCDP within a maximum of 72 hours of becoming aware of a personal data security incident. The notification must describe the nature of the breach, the categories and approximate number of records affected, and the measures taken. Where the breach poses a high risk to individuals, those individuals must also be notified without undue delay.

Is a Data Protection Officer required in Uruguay?

Under Decree 64/020, DPO appointment is mandatory for (1) all public-sector entities, (2) private entities whose core activity involves processing sensitive personal data, and (3) private entities that process personal data of more than 35,000 data subjects. The DPO must have specialist knowledge, be URCDP-accredited, and be formally appointed through the URCDP. Organisations that do not meet these thresholds are not required to appoint a DPO, but may do so voluntarily.

What rights do individuals have under Uruguayan data protection law?

Under Law 18.331, individuals have the right to information (to be informed when data about them is collected), the right of access (to receive a copy of their data within five business days), the right to rectification (to correct inaccurate data), the right to deletion (to have data removed when it is excessive, irrelevant, or unlawfully obtained), the right to object (including to direct marketing), and the right to pursue a habeas data action in court. The habeas data action is a constitutional judicial remedy that allows individuals to compel a court order for access, correction, or deletion.

Do organisations need to register databases with the URCDP?

Yes. Law 18.331 and Decree 414/009 require all personal data databases to be registered with the URCDP before processing begins. This applies to both public and private sector organisations. The registration must specify the purpose, categories of data, security measures, and identity of the controller. Failure to register is one of the most commonly sanctioned violations. The URCDP's National Registry of Databases is publicly accessible.

What are the penalties for violating Uruguay's data protection law?

The URCDP may impose administrative sanctions including: (1) a formal warning; (2) a fine of up to 500,000 indexed units (approximately USD 60,000-65,000); (3) suspension of database operations for up to five business days; and (4) judicial closure of the database. Penalties are calibrated to the gravity of the violation, the number of affected data subjects, the organisation's economic capacity, and its prior compliance history. Individuals may additionally pursue habeas data actions through the courts.

Is Uruguay a party to Convention 108+?

Yes. Uruguay was the first non-European state to accede to the original Convention 108 in 2013, and subsequently became the first state from the Americas to ratify Convention 108+ (Protocol CETS 223), the modernised version of the treaty. Convention 108+ adds requirements on accountability, DPIAs, supervisory authority independence, and data minimisation that align with current international standards.

How does Uruguay handle cross-border data transfers to non-adequate countries?

Transfers from Uruguay to countries not on the URCDP's adequate-countries list require a valid transfer mechanism. The available mechanisms are: URCDP-approved standard contractual clauses (Resolution 41/001 or the Ibero-American Network SCCs approved by Resolution 50/022 in December 2022); express data subject consent to the specific transfer; contractual necessity; international judicial cooperation; or public interest. For US entities, those that have adhered to the EU-U.S. Data Privacy Framework may qualify as adequate destinations if they extend those safeguards to Uruguayan transfers.

What is the habeas data action in Uruguay?

The habeas data action is a constitutional judicial remedy anchored in Article 72 of the Constitution through Article 1 of Law 18.331. It allows any individual to bring a court proceeding against a data controller (public or private) to obtain access to, rectification of, or deletion of their personal data. The action is available alongside the URCDP administrative complaints process and provides a direct judicial enforcement mechanism independent of the regulatory authority.

Does Uruguay have biometric data protection rules?

Yes. Law No. 19.924 of 18 December 2020 amended Law 18.331 to define biometric data as an especially protected category. Biometric data means personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics that allow unique identification, such as fingerprint data, facial recognition data, or voice recognition. Processing biometric data requires prior informed consent and a Data Protection Impact Assessment. If the DPIA identifies significant residual risk, the controller must notify the URCDP before processing begins.

Updates

Added URCDP Resolution No. 8/2026 (17 April 2026), which adopts the Council of Europe Convention 108+ Consultative Committee's three modular standard contractual clause templates as a further Article 23 transfer mechanism to non-adequate countries, complementing Resolutions 41/001 and 50/022. Added Decree No. 66/025 (20 February 2025), which extends AGESIC's cybersecurity framework to private essential-service operators and clarifies breach-notification coordination with the URCDP.

Expanded from ~2,450 to ~6,200 words. Added full coverage of Decree 64/020 (72-hour breach notification), DPO obligation thresholds, biometric data and DPIA requirements from Law 19.924 (2020), Law 20.075 (2022) amendments, Uruguay Convention 108+ ratification (first non-European state), EU adequacy 2024 [GDPR](/world-laws/world-data-privacy-laws)-era review reaffirmation, URCDP adequate-countries list and Resolution 50/022 Ibero-American SCCs, AGESIC National Data Strategy 2030, and updated penalty figures (up to 500,000 indexed units). Sources upgraded to primary Uruguayan government sources (gub.uy, impo.com.uy) and official EU and Council of Europe pages.

Sources and References

  1. Uruguay Law No. 18.331 on the Protection of Personal Data and Habeas Data Action (11 August 2008)(impo.com.uy).gov
  2. Decree No. 414/009 – Regulation of Law 18.331 on Personal Data Protection (31 August 2009), URCDP(gub.uy).gov
  3. Unidad Reguladora y de Control de Datos Personales (URCDP) – Official Site(gub.uy).gov
  4. European Commission – Adequacy Decisions (including Uruguay 2012/484/EU and 2024 review)(commission.europa.eu).gov
  5. Council of Europe – Uruguay Ratifies Convention 108+(coe.int).gov
  6. EU Article 29 Working Party Opinion WP177 on Uruguay (2010)(ec.europa.eu).gov
  7. Baker McKenzie – Security Requirements and Breach Notification in Uruguay(resourcehub.bakermckenzie.com)
  8. Baker McKenzie – DPOs and Notification Requirements in Uruguay(resourcehub.bakermckenzie.com)
  9. Baker McKenzie – Regulators, Enforcement Priorities and Penalties in Uruguay(resourcehub.bakermckenzie.com)
  10. Dentons – Uruguay Recent Resolutions on Adequate Countries and Organizations (October 2022)(dentons.com)
  11. European IP Helpdesk – The Uruguayan Law of Protection of Personal Data and Habeas Data Action (September 2024)(intellectual-property-helpdesk.ec.europa.eu).gov
  12. IAPP – European Commission Upholds 11 Adequacy Decisions (2024)(iapp.org)
  13. Lex Mundi – Global Data Privacy Guide: Uruguay(lexmundi.com)
Share: