{
 "jurisdiction_id": "UY",
 "jurisdiction": "Uruguay",
 "url": "https://dataprotection.gi/jurisdictions/uruguay/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 31,
  "sub_modules": 57,
  "source_register": 9
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core statutory architecture, regulator identity and material/territorial scope are well evidenced by primary EU adequacy documentation and confirmed by IAPP/DataGuidance secondary sources.",
   "claims": [
    {
     "statement": "The Unidad Reguladora y de Control de Datos Personales (URCDP) is Uruguay's data protection supervisory authority, created as a decentralized body under AGESIC to ensure observance of the right to personal data protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law No. 18.331 on the Protection of Personal Data and Habeas Data Action of 11 August 2008 is Uruguay's foundational data protection statute, largely based on the standards of EU Directive 95/46/EC.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A32012D0484",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 18.331 is further complemented by Decree No. 414/009 of 31 August 2009, which lays down the organisation, powers and functioning of the URCDP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A32012D0484",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law No. 19.670 of 15 October 2018 amended Law 18.331 to introduce the accountability (responsabilidad proactiva) principle and the DPO figure, later implemented via Decree No. 64/020 of 21 February 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/uruguay-data-transfers",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 18.331 governs personal data of both natural and legal persons processed in public- or private-sector databases, excluding data processed for purely personal/household purposes and databases for public security, defence or state security purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data controller or processor is deemed established in Uruguay for LPD purposes, including its extraterritorial application, when it carries out a stable activity there.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Uruguay's data protection regime imposes an obligation to register databases with the URCDP as part of its regulatory-judicial system of data protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Special-category/DPO and anonymisation findings are well sourced; granular lawful-basis and consent-threshold text was not independently retrieved in this pass.",
   "claims": [
    {
     "statement": "Uruguayan implementing rules require private entities that process sensitive personal data as their main business activity, as well as public entities, to appoint a data protection officer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The URCDP, jointly with AGESIC, issued a de-identification guide in September 2017 defining de-identification, anonymisation, re-identification and pseudonymisation under Uruguayan law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uruguay-urcdp-de-identification-guide-lays-foundations-adequate-data-anonymisation",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Implementing decree provisions require controllers and processors to incorporate dissociation, pseudonymisation and data-minimisation techniques into database design, processing operations and information systems.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Access, rectification/erasure and the Habeas Data enforcement route are well evidenced; portability and precise response-deadline figures are gaps.",
   "claims": [
    {
     "statement": "Data subjects in Uruguay have the right to access, obtaining explicit and unambiguous information about the destination and purpose of their personal data stored in databases.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects may request correction, updating, deletion, inclusion or suppression of their personal data from public or private databases where the data is erroneous or false.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Uruguayan data subjects are granted a two-step enforcement path: a prejudicial petition directly to the database controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Accountability, DPO, breach-notification and security-measure obligations are strongly evidenced across multiple secondary sources describing the 2018/2020 decree reforms.",
   "claims": [
    {
     "statement": "The accountability (responsabilidad proactiva) principle was introduced into Law 18.331 by the 2018 reform under Law 19.670, requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Implementing decree provisions set out the content, timing, procedence and scope of the data protection impact assessment obligation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Entities designating a DPO must communicate the appointment to the URCDP within 90 days of commencing processing; the DPO must have specialised legal knowledge of data protection and is bound to absolute confidentiality.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Upon detecting a security incident affecting personal data, controllers must minimise impacts within the first 24 hours and notify the URCDP within a maximum of 72 hours of becoming aware of the breach, with no minimum quantitative threshold for the notification duty.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects must be notified of a security breach, in clear and simple language, when the breach produces a 'significant' effect on their rights, an undetermined legal concept to be defined by the URCDP in practice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Proactive-accountability security measures adopted by controllers and processors must be documented, periodically reviewed, and evaluated for effectiveness.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "This module has the deepest, most consistent evidentiary base of the ten, anchored by a primary-source EU Commission decision plus multiple corroborating URCDP resolution descriptions.",
   "claims": [
    {
     "statement": "The European Commission adopted Implementing Decision 2012/484/EU on 21 August 2012, recognising Uruguay as ensuring an adequate level of protection for personal data transferred from the EU under Directive 95/46/EC.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A32012D0484",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 23 of Law 18.331 prohibits international transfers of personal data of any kind to countries or international organisations that do not provide adequate levels of protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The URCDP may authorise a transfer to a non-adequate country where the controller offers sufficient guarantees for the protection of individuals' fundamental rights, which may derive from appropriate contractual clauses.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "URCDP Resolution No 41/2021 of 8 September 2021 provides guidance on the minimum recommended content of appropriate contractual clauses for international transfers of personal data to non-adequate countries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "URCDP Resolution No 23/2021 of 8 June 2021 established the list of countries considered adequate for international data transfers, based on the Ibero-American Data Protection Standards and the EU GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the invalidation of the EU-US Privacy Shield and the CJEU's Schrems II ruling, URCDP Resolution No 23/2021 requires that transfers to the United States be justified via data-subject consent or one of the Article 23 exceptions, with URCDP authorisation where applicable.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 6 of Decree No. 64/2020 requires controllers to carry out an impact assessment before transferring data to states or organisations lacking an adequate level of data protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-guia-para-redaccion-de-clausulas-contractuales-para-transferencia-internacional-de-datos-a-paises-no-adecuados",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "URCDP Resolution No 63/2023 of 21 November 2023 recognised South Korea and entities certified under the EU-US Data Privacy Framework as providing an adequate level of data protection for cross-border transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/uruguay-urcdp-issues-adequacy-decision-south-korea-and",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "This module carries no confirmed claims; all seven sub-modules are gaps requiring dedicated follow-up research against Uruguayan sectoral statutes.",
   "claims": []
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No confirmed sub-module claims; this is a genuine regulatory gap or an under-researched area requiring dedicated follow-up.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "One sub-module (state-surveillance carve-outs) is evidenced from primary-adjacent sources; the remaining five sub-modules are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Law 18.331 excludes from its scope databases whose purpose is public security, defence or state security, subject to any specific regulating law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "No confirmed UY-specific claims for any of the five sub-modules; this is either a genuine regime gap or requires dedicated primary-text research against LPD articles on minors.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/uruguay/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator powers and private right of action are well evidenced; enforcement-activity index, funding/capacity, collective redress and 180-day recent developments are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Implementing decree provisions empower the URCDP to impose sanctions for non-compliance ranging from observations and warnings to closure of the database and the imposition of fines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/uruguay-dicta-nuevas-normas-sobre-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects may pursue a judicial Habeas Data action as a private right of action to enforce their data protection rights, in addition to filing complaints with the URCDP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/2012-10-01-uruguay-discusses-data-protection-landscape-upcoming-conference",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The URCDP has issued a series of resolutions and guidance since 2017-2023 (de-identification guide, SCC guidance, adequacy resolutions) evidencing active regulatory/guidance output, though no comprehensive public enforcement-fine index was located in this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uruguay-urcdp-de-identification-guide-lays-foundations-adequate-data-anonymisation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}