🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CR · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 9 sources retrieved model claude-sonnet-5 ·

Costa Rica

CR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 34 claims · 9 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator, statute and implementing decree are well corroborated across independent secondary sources; only territorial-scope detail is unconfirmed.

Primary frameworkLaw No. 8968 of 2011 (Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales) and Executive Decree No. 37554-JP of 2012, as amended by Decree No. 40008-JP of 2016
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — GreenCore regulator, statute and implementing decree are well corroborated across independent secondary sources; only territorial-scope detail is unconfirmed.

Sub-modules (5)

Regulator And AuthorityGreen

PRODHAB is the designated enforcement authority for Law No. 8968, structured as a maximum-decentralization body attached to the Ministry of Justice and Peace.

Claims: CLM-CR-4a19e2f0

Act And InstrumentsGreen

Primary instruments are Law No. 8968 (2011), Executive Decree No. 37554-JP (2012) and its 2016 amending Decree No. 40008-JP; two reform/replacement bills remain pending.

Claims: CLM-CR-7b2c9d81, CLM-CR-1e3f5a90

Material ScopeGreen

The Law applies to personal data held in both automated and manual databases.

Claims: CLM-CR-2c4d6e11

Territorial ScopeAmber

No confirming evidence was located in this run describing the Law's application to controllers not established in Costa Rica.

Absence provenance: not recorded. Searched: Costa Rica data protection law territorial scope non-established controllers, Ley 8968 ambito de aplicacion territorial.

Regulator Registration And FilingGreen

Qualifying databases (those administered for commercial distribution/dissemination or direct commercialization of personal data) must be registered with PRODHAB's Departamento de Archivo y Registro de Bases de Datos; purely internal databases and SUGEF-supervised financial-entity databases are exempt from registration (though not from PRODHAB oversight) following the 2016 reform.

Claims: CLM-CR-3d5e7f22, CLM-CR-4e6f8a33

Category narrative122 words

Costa Rica operates a comprehensive omnibus data-protection regime under Law No. 8968 of 2011, enforced by PRODHAB, a decentralized body attached to the Ministry of Justice and Peace. <cite index="13-1">The Law governs data protection in Costa Rica and has been enforceable in relation to organizations and individuals since July 7, 2012.</cite> <cite index="41-4">Since mid-2014 PRODHAB, described as the maximum-decentralization body attached to the Ministry of Justice and Peace, has worked in practice to consolidate the rights and guarantees provided by the Law enacted in September 2011.</cite> Two further bills (No. 22.388 and No. 23.097) remain pending and would reform or replace parts of the current regime. Territorial/extraterritorial scope for non-established controllers could not be confirmed from available secondary sources in this run.

Sources and claims (6)
  1. ConfirmedDataGuidance/OneTrustPRODHAB (Agencia de Proteccion de Datos de los Habitantes) is Costa Rica's data protection authority, structured as a maximum-decentralization body attached to the Ministry of Justice and Peace, and is responsible for enforcing Law No. 8968.
  2. ConfirmedDataGuidance/OneTrustLaw No. 8968 of 2011 has been enforceable in relation to organizations and individuals since July 7, 2012, and is complemented by Executive Decree No. 37554-JP of October 30, 2012, as amended by Decree No. 40008-JP of December 6, 2016.
  3. ProbableDataGuidance/OneTrustTwo additional bills, No. 22.388 (a reform of the existing Law) and No. 23.097 (a new data protection law), were pending before the Legislative Assembly as of the most recent secondary-source review in April 2026, with neither yet enacted.
  4. ConfirmedDataGuidance/OneTrustLaw No. 8968 is applicable to personal data contained in automated or manual databases.
  5. ConfirmedInternational Association of Privacy ProfessionalsFollowing the 2016 reform, only databases administered for the purpose of distributing or disseminating personal data with commercial intent, or those that directly commercialize such data, must be registered with PRODHAB; internal databases are exempt from registration though still subject to the Law.
  6. ConfirmedInternational Association of Privacy ProfessionalsDatabases of financial entities subject to the functional oversight of the Superintendencia General de Entidades Financieras (SUGEF) are exempt from the PRODHAB registration duty, without prejudice to remaining subject to PRODHAB's general control and oversight.

#

Consent-centric lawful basis is well evidenced; special-categories and pseudonymisation sub-modules carry unresolved gaps requiring primary-text verification.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberConsent-centric lawful basis is well evidenced; special-categories and pseudonymisation sub-modules carry unresolved gaps requiring primary-text verification.

Sub-modules (4)

Lawful BasesGreen

Express consent is established as the central processing principle under the Law.

Claims: CLM-CR-5f7a9b44

Special CategoriesRed

No confirming secondary-source detail was located on the statutory definition/treatment of special or sensitive categories of personal data under Law No. 8968 in this run.

Absence provenance: not recorded. Searched: Ley 8968 Costa Rica datos sensibles categorias especiales consentimiento expreso.

Pseudonymisation And AnonymisationRed

No evidence of a statutory pseudonymisation or anonymisation safe-harbour regime was located.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 anonymizacion seudonimizacion datos personales.

Category narrative98 words

Express, informed consent of the data subject is the central lawful basis under Law No. 8968, reinforced by sector practice requiring individualized, specific, freely-given and (in regulated sectors) written consent. <cite index="87-4">The Law has introduced data subject rights, including the right to access, rectify, or delete personal data, established express consent of the data subject as a central principle, and has also required that controllers and processors ensure adequate security safeguards to protect data.</cite> Statutory detail on the treatment of special/sensitive categories and on pseudonymisation/anonymisation safe-harbours could not be confirmed from the secondary sources reviewed in this run.

Sources and claims (3)
  1. ConfirmedDataGuidance/OneTrustLaw No. 8968 establishes express consent of the data subject as a central lawful basis for processing, alongside a duty on controllers and processors to maintain adequate security safeguards.
  2. ProbableInternational Association of Privacy ProfessionalsControllers, illustrated in the regulated fintech sector, must obtain individualized, specific, informed and freely given written consent disclosing the database's purpose, recipients, transfer arrangements and the data subject's rights.
  3. ConfirmedDataGuidance/OneTrustThe 2016 regulatory reform (Decree No. 40008-JP) refined the statutory definitions of database, consent, technological intermediary, data transfer and the right to be forgotten.

#

Access/rectification/erasure rights are confirmed and in force; portability and opt-out remain proposed-only; deadlines are unconfirmed.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberAccess/rectification/erasure rights are confirmed and in force; portability and opt-out remain proposed-only; deadlines are unconfirmed.

Sub-modules (5)

Access RightGreen

Data subjects have a statutory right to access their personal data held in registered databases.

Claims: CLM-CR-8c0d2e77

Rectification And ErasureGreen

Rights to rectify and delete personal data, including a right-to-be-forgotten concept refined in 2016, are in force.

Claims: CLM-CR-9d1e3f88

Restriction And ObjectionAmber

Data subjects may revoke previously given consent; controllers must facilitate exercise of this right.

Claims: CLM-CR-0e2f4a99

Data PortabilityAmber

Portability is not yet a statutory right; it is proposed only under pending Bill No. 23097.

Claims: CLM-CR-1f3a5b00

Deadlines And Response WindowsRed

No statutory response-window or deadline detail was confirmed from the sources reviewed.

Absence provenance: not recorded. Searched: Ley 8968 Costa Rica plazo respuesta derecho de acceso PRODHAB.

Category narrative99 words

Law No. 8968 grants data subjects rights of access, rectification and deletion, plus a right to revoke consent; a pending bill (No. 23097) would add data portability and an opt-out right, and a pending AI-regulation bill would reinforce ARCO rights specifically in AI-driven processing. <cite index="92-7,92-8">Bill No. 23097 for the Data Protection Law was introduced, on March 10, 2023, to the Costa Rica Legislative Assembly, and in particular introduces data subject rights such as the right to access, rectification, deletion, and data portability, as well as the right to opt-out of processing.</cite> Statutory response-window/deadline detail could not be confirmed.

Sources and claims (5)
  1. ConfirmedDataGuidance/OneTrustLaw No. 8968 grants data subjects the right to access personal data held about them in registered databases.
  2. ConfirmedDataGuidance/OneTrustLaw No. 8968 grants rights to rectify or delete personal data; the associated 'right to be forgotten' concept was further refined by the 2016 regulatory reform.
  3. ProbableInternational Association of Privacy ProfessionalsData subjects may revoke consent previously given for processing, and controllers must facilitate the exercise of this right alongside access and modification rights.
  4. ProbableDataGuidance/OneTrustData portability is proposed, not currently in force: pending Bill No. 23097, introduced March 10, 2023, would introduce a portability right and a right to opt out of processing.
  5. ProbableInternational Association of Privacy ProfessionalsCosta Rica's pending AI-regulation bill (analysed February 2026) would expressly reinforce data subjects' ARCO rights (access, rectification, cancellation and opposition) in AI-driven processing contexts, conditioning such processing on informed consent.

#

Security-safeguard and accountability/registration duties are confirmed and in force; breach notification, DPO and retention/disposal sub-modules are unconfirmed gaps.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberSecurity-safeguard and accountability/registration duties are confirmed and in force; breach notification, DPO and retention/disposal sub-modules are unconfirmed gaps.

Sub-modules (7)

Accountability And DpiaGreen

The 2016 reform reinforced the accountability principle by more precisely delimiting which databases must register under Article 21.

Claims: CLM-CR-3b5c7d22

Dpo RequirementsRed

No DPO appointment threshold or independence requirement was identified for Costa Rica.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 oficial de proteccion de datos DPO requisito.

Ropa RequirementsAmber

PRODHAB's database registry functions as the practical records-of-processing filing mechanism for qualifying databases.

Claims: CLM-CR-4c6d8e33

Joint Controller ArrangementsGreen

The GIE (grupo de interes economico) concept, introduced in 2016, permits continuous intra-group personal-data transfers among corporate affiliates without triggering registration of 'internal' databases.

Claims: CLM-CR-5d7e9f44

Security MeasuresGreen

Controllers and processors must ensure adequate security safeguards to protect personal data.

Claims: CLM-CR-6e8f0a55

Breach NotificationRed

No general mandatory security-breach notification duty to PRODHAB or to affected data subjects, analogous to GDPR Articles 33-34, was identified in the secondary sources reviewed.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 notificacion de brecha de seguridad PRODHAB plazo.

Retention And DisposalRed

No specific statutory retention-limit or disposal duty was confirmed.

Absence provenance: not recorded. Searched: Ley 8968 Costa Rica plazo de conservacion de datos eliminacion.

Category narrative66 words

Controllers and processors must maintain adequate security safeguards and, following the 2016 reform, are subject to a more precisely delimited registration/accountability duty under Article 21 of Law No. 8968; the 2016 reform also introduced the 'grupo de interes economico' (GIE) concept enabling intra-group transfers without triggering registration for internal databases. No mandatory breach-notification duty, DPO threshold, or retention-limit rule could be confirmed from the sources reviewed.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe 2016 regulatory reform reinforced the accountability principle by more precisely delimiting the content of Article 21 of Law No. 8968, which governs which databases must be registered with PRODHAB.
  2. ProbableInternational Association of Privacy ProfessionalsPRODHAB's Departamento de Archivo y Registro de Bases de Datos maintains a registry of qualifying databases, functioning as Costa Rica's equivalent to a records-of-processing filing mechanism.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe 2016 reform introduced the concept of a 'grupo de interes economico' (economic-interest group), permitting continuous and natural transfer of personal data among affiliates of multinational or local corporate groups for internal purposes without requiring registration of 'internal' databases.
  4. ConfirmedDataGuidance/OneTrustLaw No. 8968 requires that controllers and processors ensure adequate security safeguards to protect personal data.

#

Only the general transfer-conditions reform is confirmed; five of six sub-modules (adequacy received/granted, SCCs/BCRs, TIA, localisation) carry unresolved gaps.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — RedOnly the general transfer-conditions reform is confirmed; five of six sub-modules (adequacy received/granted, SCCs/BCRs, TIA, localisation) carry unresolved gaps.

Sub-modules (6)

Transfer MechanismsAmber

The 2016 reform amended the statutory conditions for data transfers, aiming for greater transfer fluidity while preserving PRODHAB oversight.

Claims: CLM-CR-7f9a1b66

Adequacy ReceivedRed

No adequacy decision covering Costa Rica issued by the European Commission or another regime was identified.

Absence provenance: not recorded. Searched: Costa Rica adecuacion datos personales Union Europea decision de adecuacion.

Adequacy GrantedRed

No evidence that PRODHAB maintains an outbound adequacy whitelist of other jurisdictions.

Absence provenance: not recorded. Searched: PRODHAB lista de paises con nivel adecuado de proteccion.

Sccs And BcrsRed

No SCC- or BCR-equivalent instrument under Costa Rican law was identified.

Absence provenance: not recorded. Searched: Costa Rica clausulas contractuales tipo normas corporativas vinculantes.

Transfer Impact AssessmentRed

No transfer-impact-assessment-equivalent duty was identified.

Absence provenance: not recorded. Searched: Costa Rica evaluacion de impacto de transferencia internacional de datos.

Data LocalisationAmber

No general data-localisation mandate was identified; the GIE intra-group transfer provisions suggest a permissive rather than localisation-oriented approach, though this is an inference rather than a confirmed express statutory rule.

Claims: CLM-CR-8a0b2c77

Category narrative61 words

The 2016 reform amended the conditions governing personal-data transfers under Law No. 8968 with the stated aim of generating greater fluidity in the transfer and commercialization of personal data while preserving PRODHAB's control competences. No adequacy decision received from or granted to another regime, SCC/BCR-equivalent instrument, transfer-impact-assessment duty, or data-localisation mandate could be confirmed from the sources reviewed in this run.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe 2016 regulatory reform amended the conditions governing personal-data transfers under Law No. 8968, seeking greater fluidity in transfer and commercialization of personal data while preserving PRODHAB's oversight competences.
  2. UncertainInternational Association of Privacy ProfessionalsNo general data-localisation mandate applicable to corporate-group data transfers under Costa Rican law was identified; the 2016 GIE provisions instead facilitate continuous intra-group cross-border transfer.

#

Financial-sector overlay is well evidenced (statute plus a concrete 2023 enforcement precedent); other sector sub-modules are unconfirmed gaps.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberFinancial-sector overlay is well evidenced (statute plus a concrete 2023 enforcement precedent); other sector sub-modules are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayGreen

SUGEF-supervised financial entities are exempt from PRODHAB registration but remain subject to its oversight; PRODHAB has exercised that oversight against the Banco Central de Costa Rica.

Claims: CLM-CR-9b1c3d88, CLM-CR-0c2d4e99

Health Sector OverlayRed

No health-sector-specific data protection overlay was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos salud sector sanitario ley especial.

Telecoms And EprivacyAmber

No current telecoms/ePrivacy-specific regime exists; the pending AI-regulation bill (Feb 2026 analysis) indicates it may contain telecom-user privacy provisions.

Claims: CLM-CR-1d3e5f00

Employment DataRed

No employment-sector-specific data protection rule was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos personales laborales empleados.

Credit And ScoringAmber

The Banco Central/PRODHAB dispute directly concerned personal credit-operation data from supervised financial intermediaries, illustrating PRODHAB jurisdiction over credit-data flows absent a dedicated credit-reporting statute.

Claims: CLM-CR-2e4f6a11

EducationRed

No education-sector-specific data protection rule was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos personales estudiantes centros educativos.

InsuranceRed

No insurance-sector-specific data protection rule was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos personales sector seguros.

Category narrative94 words

Financial-sector personal data is the best-evidenced sectoral overlay: SUGEF-supervised entities' databases are exempt from PRODHAB's registration duty but remain subject to its general control, as illustrated by PRODHAB's August 2023 precautionary-measure Resolution No. 697-2023 restricting a Banco Central de Costa Rica request for comprehensive credit-operation data. <cite index="61-6">On August 28, 2023, PRODHAB issued Resolution No. 697-2023, granting a precautionary measure described as marking a significant precedent for personal data protection in the country.</cite> No health, telecoms/ePrivacy (beyond a prospective reference in the pending AI bill), employment, education, or insurance sectoral overlay could be confirmed.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsDatabases of SUGEF-supervised financial entities are exempt from PRODHAB's registration duty while remaining subject to PRODHAB's general control and enforcement powers.
  2. ConfirmedInternational Association of Privacy ProfessionalsOn August 28, 2023, PRODHAB issued Resolution No. 697-2023, a precautionary measure suspending the Banco Central de Costa Rica's request for comprehensive credit-operation data, including identification documents, from supervised financial intermediaries, following a complaint by consumer association Asodidcu.
  3. UncertainInternational Association of Privacy ProfessionalsCosta Rica's pending AI-regulation bill, analysed in February 2026, may include provisions related to protecting the privacy of telecommunications-service users, though no enacted telecoms/ePrivacy-specific regime currently exists.
  4. ProbableInternational Association of Privacy ProfessionalsThe 2023 Banco Central/PRODHAB dispute concerned personal credit-operation data supplied by supervised financial intermediaries, illustrating PRODHAB's jurisdiction over credit-data flows in the absence of a dedicated credit-reporting statute.

#

No on-point sources found across any of the six declared sub-modules despite targeted search; this is treated as a genuine regulatory gap pending primary-text verification.

Traffic-light rationale — RedNo on-point sources found across any of the six declared sub-modules despite targeted search; this is treated as a genuine regulatory gap pending primary-text verification.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-consent-specific rule identified.

Absence provenance: not recorded. Searched: Costa Rica ley cookies consentimiento rastreo web.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: not recorded. Searched: Costa Rica prohibicion patrones oscuros diseno enganoso.

Opt Out SignalsRed

No Global-Privacy-Control or DAA-equivalent opt-out signal regime identified.

Absence provenance: not recorded. Searched: Costa Rica senal de exclusion global privacy control.

Clean Rooms And DcrRed

No clean-room / data-collaboration-room rule identified.

Absence provenance: not recorded. Searched: Costa Rica sala de datos limpia colaboracion de datos regulacion.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising regime identified.

Absence provenance: not recorded. Searched: Costa Rica venta de datos personales publicidad cruzada regulacion.

Direct MarketingRed

No marketing-specific consent or suppression rule beyond Law No. 8968's general consent principle was confirmed.

Claims: CLM-CR-3f5a7b22

Category narrative54 words

No dedicated adtech-specific instrument (cookie-consent statute, dark-pattern prohibition, Global-Privacy-Control-equivalent opt-out signal regime, clean-room rules, or CPRA-style 'sale/share' cross-context-advertising regime) was identified for Costa Rica. Commercial databases used for marketing purposes would fall under Law No. 8968's general consent and registration requirements, but no marketing-specific suppression or consent-threshold rule beyond that general framework was confirmed.

Sources and claims (1)
  1. UncertainDataGuidance/OneTrustNo dedicated direct-marketing consent or suppression statute was identified for Costa Rica; marketing databases would fall under Law No. 8968's general consent and registration requirements absent a marketing-specific rule.

#

No current in-force ADM/biometric/AI-specific regime exists, but an active, recently-analysed 2026 AI bill directly targets this module, warranting amber rather than red.

Traffic-light rationale — AmberNo current in-force ADM/biometric/AI-specific regime exists, but an active, recently-analysed 2026 AI bill directly targets this module, warranting amber rather than red.

Sub-modules (6)

Profiling RestrictionsRed

No current profiling restriction analogous to GDPR Article 22 was identified under Law No. 8968.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 restriccion de perfilamiento decisiones automatizadas.

Automated Decision Making TransparencyAmber

No current ADM transparency right exists; the pending AI bill would reinforce ARCO rights in AI-driven processing.

Claims: CLM-CR-4a6b8c33

Ai Risk AssessmentsAmber

The pending AI-regulation bill would create ARIA and a proportional sanctions regime for AI-related non-compliance.

Claims: CLM-CR-5b7c9d44

Biometric RegimeRed

No biometric-data-specific regime (facial recognition, fingerprint, gait) was identified.

Absence provenance: not recorded. Searched: Costa Rica regulacion datos biometricos reconocimiento facial.

Genetic DataRed

No genetic-data-specific regime was identified; overlaps with the unconfirmed special-categories gap in lawful_processing_and_special_data.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 datos geneticos regimen especial.

State Surveillance CarveoutsRed

No state-surveillance national-security carve-out provision was identified.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 excepcion seguridad nacional vigilancia estatal.

Category narrative100 words

Law No. 8968 currently contains no Article-22-equivalent profiling restriction, ADM transparency right, AI-specific risk-assessment duty, or biometric/genetic-data regime that could be confirmed. Costa Rica's pending AI-regulation bill (analysed by IAPP on February 17, 2026) would create an Autoridad Reguladora de Inteligencia Artificial (ARIA) tasked with supervising compliance and setting technical/ethical AI guidelines, condition personal-data processing on informed consent, reinforce ARCO rights, and establish proportional and dissuasive sanctions for non-compliance. <cite index="96-4">The bill also contemplates the creation of an Autoridad Reguladora de Inteligencia Artificial (ARIA), tasked with overseeing regulatory compliance and establishing technical and ethical guidelines for AI development and use.</cite>

Sources and claims (2)
  1. ProbableInternational Association of Privacy ProfessionalsCosta Rica's pending AI-regulation bill would condition personal-data processing on informed consent and expressly reinforce ARCO rights (access, rectification, cancellation and opposition) in AI-driven processing.
  2. ProbableInternational Association of Privacy ProfessionalsThe pending AI-regulation bill contemplates creating an Autoridad Reguladora de Inteligencia Artificial (ARIA) to supervise compliance and set technical/ethical AI guidelines, with proportional and dissuasive sanctions including fines and temporary or permanent prohibitions for non-compliance.

#

Genuine absence of findings across all five declared sub-modules; flagged explicitly rather than silently omitted.

Traffic-light rationale — RedGenuine absence of findings across all five declared sub-modules; flagged explicitly rather than silently omitted.

Sub-modules (5)

Age VerificationRed

No age-of-consent-for-processing threshold was identified.

Absence provenance: not recorded. Searched: Costa Rica Ley 8968 edad de consentimiento menores tratamiento de datos.

Minor Profiling BansRed

No minor-profiling ban was identified.

Absence provenance: not recorded. Searched: Costa Rica prohibicion perfilamiento de menores.

Education SettingsRed

No education-setting-specific rule was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos personales centros educativos estudiantes menores.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) protection provision was identified.

Absence provenance: not recorded. Searched: Costa Rica proteccion datos personas mayores incapacitadas.

Category narrative31 words

No child- or vulnerable-group-specific data protection provision (age of consent, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection) could be confirmed for Costa Rica in this run despite targeted search.

#

Regulator powers, a concrete 2023 enforcement precedent, a constitutional private-right-of-action route, and a within-180-day AI-bill development are all confirmed; funding/capacity and collective-redress detail remain thinner.

Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — GreenRegulator powers, a concrete 2023 enforcement precedent, a constitutional private-right-of-action route, and a within-180-day AI-bill development are all confirmed; funding/capacity and collective-redress detail remain thinner.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

PRODHAB may impose administrative fines for non-compliance and issue precautionary measures during rights-protection proceedings.

Claims: CLM-CR-6c8d0e55, CLM-CR-7d9e1f66

Enforcement Activity IndexAmber

PRODHAB's August 2023 Resolution No. 697-2023 is characterized by commentators as a significant enforcement precedent.

Claims: CLM-CR-8e0f2a77

Regulator Funding And CapacityRed

No funding or headcount data for PRODHAB was identified.

Absence provenance: not recorded. Searched: PRODHAB Costa Rica presupuesto personal capacidad.

Collective Redress And Class ActionsAmber

A consumer association (Asodidcu) brought the complaint underlying Resolution No. 697-2023 on behalf of affected data subjects, suggesting a practical associative-complaint avenue, though no dedicated statutory class-action mechanism was confirmed.

Claims: CLM-CR-9f1a3b88

Private Right Of ActionGreen

The Constitutional Court has recognized and protected the right to data protection since the 1990s on the basis of Article 24 of the Constitution, providing a constitutional-remedy route independent of the PRODHAB administrative process.

Claims: CLM-CR-0a2b4c99

Recent Developments 180DGreen

Within the last 180 days, IAPP published an analysis (February 17, 2026) of Costa Rica's pending AI-regulation bill, and DataGuidance (April 2026) confirmed Bill No. 23097 remains pending.

Claims: CLM-CR-1b3c5d00, CLM-CR-2c4d6e11b

Category narrative123 words

PRODHAB may impose administrative fines and issue precautionary measures (medidas cautelares) to secure the effective outcome of rights-protection proceedings, as demonstrated by the August 2023 Resolution No. 697-2023 against the Banco Central de Costa Rica. <cite index="61-2">Under Law No. 8968 of Protection of the Person against the Processing of their Personal Data, such measures may be ordered by the Data Protection Agency when necessary to secure the effective outcome of a rights-protection proceeding.</cite> A constitutional remedy route via the Sala Constitucional, recognized since the 1990s under Article 24 of the Constitution, provides an independent private right of action. The most significant recent development is the February 2026 IAPP analysis of Costa Rica's pending AI-regulation bill, which directly interfaces with the data protection framework.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsFailure to comply with Law No. 8968 and its consent/registration obligations could lead to administrative fines imposed by PRODHAB.
  2. ConfirmedInternational Association of Privacy ProfessionalsUnder Law No. 8968, PRODHAB may issue precautionary measures (medidas cautelares) when necessary to secure the effective outcome of a rights-protection proceeding.
  3. ProbableInternational Association of Privacy ProfessionalsPRODHAB's Resolution No. 697-2023, issued August 28, 2023, granting a precautionary measure against the Banco Central de Costa Rica, is described as marking a significant precedent for data protection enforcement in the country.
  4. ProbableInternational Association of Privacy ProfessionalsThe complaint underlying Resolution No. 697-2023 was filed by the consumer association Asodidcu on behalf of affected financial-sector data subjects, indicating associative complaints to PRODHAB are a practical avenue for collective redress, though no dedicated statutory class-action mechanism was confirmed.
  5. ConfirmedDataGuidance/OneTrustThe right to data protection has been recognized and protected in Costa Rica by the Constitutional Court since the 1990s on the basis of Article 24 of the Political Constitution, providing a constitutional remedy independent of the PRODHAB administrative process.
  6. ProbableInternational Association of Privacy ProfessionalsIAPP published an analysis on February 17, 2026 of Costa Rica's proposed AI-regulation bill, which would create an AI Regulatory Authority (ARIA) and directly interfaces with the existing data protection framework via informed consent and ARCO-rights provisions.
  7. ProbableDataGuidance/OneTrustAs of an April 2026 secondary-source review, Bill No. 23097 (introduced March 10, 2023), which would add data portability and opt-out rights, remained pending before the Legislative Assembly with no indication of enactment.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Costa Rica
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s), 9 source(s) in the cumulative register.