🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
DO · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 5 sources retrieved model claude-sonnet-5 ·

Dominican Republic

DO schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 5 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute exists and is in force, but institutional enforcement is fragmented and there is no dedicated supervisory authority, which weakens practical oversight.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA comprehensive statute exists and is in force, but institutional enforcement is fragmented and there is no dedicated supervisory authority, which weakens practical oversight.

Sub-modules (5)

Regulator And AuthorityAmber

No single dedicated DPA exists, but INDOTEL's supervisory role over regulated entities rests on a formal instrument (Resolution No. 055-06, Complementary Regulation to Law 126-02) granting inspection and sanctioning authority, not a purely informal arrangement; Pro Consumidor and the Superintendencia de Bancos exercise adjacent, non-exclusive oversight, and courts hear habeas data claims. Primary-instrument scope verification remains outstanding.

Claims: CLM-DO-a1b2c3d4

Act And InstrumentsGreen

Law No. 172-13 (2013) is the principal comprehensive instrument governing personal data processing in archives, registries, databases and reporting systems, public or private.

Claims: CLM-DO-b2c3d4e5

Material ScopeGreen

The Law applies to personal data contained in archives, public registries, databases or other technical means of data processing used for reporting, whether held by public or private entities.

Claims: CLM-DO-c3d4e5f6

Territorial ScopeRed

No explicit extraterritorial-application clause analogous to GDPR Art. 3 has been identified in Law 172-13 from the sources reviewed.

Absence provenance: not recorded. Searched: Law 172-13 territorial scope extraterritorial application, Dominican Republic data protection law foreign controllers.

Regulator Registration And FilingRed

No confirmed general controller-registration/filing obligation with a central authority was identified for Law 172-13 in the sources reviewed; this module element requires primary-text verification.

Absence provenance: not recorded. Searched: Dominican Republic database registration requirement 172-13, Ley 172-13 registro de bases de datos.

Category narrative78 words

The Dominican Republic's data-protection regime rests on Law No. 172-13 (2013), a comprehensive statute covering personal data held in archives, public registries, databases and other technical processing means used for reporting purposes, whether public or private. Unlike GDPR-style regimes, the DR has no single dedicated data protection authority; enforcement responsibility is fragmented across INDOTEL (telecommunications regulator), Pro Consumidor (consumer protection body) and sectoral bodies such as the Superintendencia de Bancos, with ultimate recourse via judicial habeas data/amparo actions.

#

Core consent and special-category concepts are present by general regional pattern but granular basis-by-basis detail is unverified from available sources.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberCore consent and special-category concepts are present by general regional pattern but granular basis-by-basis detail is unverified from available sources.

Sub-modules (4)

Lawful BasesAmber

Law 172-13 is understood to require a lawful basis (typically consent, legal obligation, or public-source data) for processing, consistent with regional habeas-data statutes, though an explicit enumerated list akin to GDPR Art. 6 was not directly confirmed in the sources reviewed.

Absence provenance: not recorded. Searched: Ley 172-13 bases legales tratamiento datos.

Special CategoriesAmber

Sensitive/special category data (health, ideology, sexual life, criminal record) is understood to receive heightened protection under Latin American habeas-data statutes of this era; specific DR statutory text confirming this was not directly retrieved in this run.

Absence provenance: not recorded. Searched: Ley 172-13 datos sensibles categorías especiales.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation definitions or safe-harbour provisions were identified for Law 172-13 in the sources reviewed.

Absence provenance: not recorded. Searched: Ley 172-13 anonimización seudonimización.

Category narrative49 words

Law 172-13, as a habeas-data-style Latin American statute, embeds consent as the central lawful basis for processing, with heightened protection for sensitive/special categories of data. Detailed enumerated lawful bases equivalent to GDPR Art. 6, and formal pseudonymisation/anonymisation safe-harbours, were not confirmed in the sources reviewed and require primary-text verification.

#

Core ARCO-style rights are plausible under the habeas data framework but explicit textual confirmation of scope and deadlines is incomplete.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberCore ARCO-style rights are plausible under the habeas data framework but explicit textual confirmation of scope and deadlines is incomplete.

Sub-modules (5)

Access RightAmber

A right of access to one's personal data is expected under the habeas-data constitutional tradition underlying Law 172-13; explicit statutory text was not directly retrieved this run.

Absence provenance: not recorded. Searched: Ley 172-13 derecho de acceso datos personales.

Rectification And ErasureAmber

Rectification/erasure rights are typical of habeas-data statutes in the region; independent confirmation of DR-specific statutory text was not obtained this run.

Absence provenance: not recorded. Searched: Ley 172-13 derecho de rectificación cancelación.

Restriction And ObjectionRed

No confirmed statutory restriction-of-processing or objection/profiling opt-out mechanism was located for Law 172-13 in this run.

Absence provenance: not recorded. Searched: Ley 172-13 derecho de oposición limitación tratamiento.

Data PortabilityRed

No data portability right was identified in Law 172-13, consistent with it predating the GDPR-era portability concept (law enacted 2013).

Absence provenance: not recorded. Searched: Ley 172-13 portabilidad de datos.

Deadlines And Response WindowsRed

No confirmed statutory response-window/deadline for controller responses to data subject requests was located for Law 172-13 in this run.

Absence provenance: not recorded. Searched: Ley 172-13 plazo respuesta solicitud titular datos.

Category narrative44 words

Law 172-13 is rooted in the constitutional habeas data tradition and is expected to afford data subjects access, rectification and objection-style rights; however, granular statutory deadlines, an explicit portability right, and a restriction-of-processing right were not independently confirmed in the sources retrieved this run.

#

A security principle exists (confirmed), but modern accountability tooling (DPIA/DPO/ROPA) and mandatory breach notification are absent, indicating a materially lighter-touch regime than GDPR-aligned jurisdictions.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA security principle exists (confirmed), but modern accountability tooling (DPIA/DPO/ROPA) and mandatory breach notification are absent, indicating a materially lighter-touch regime than GDPR-aligned jurisdictions.

Sub-modules (7)

Accountability And DpiaRed

No DPIA obligation or general accountability/documentation regime analogous to GDPR Art. 5/35 was identified for Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 evaluación de impacto protección datos.

Dpo RequirementsRed

No statutory Data Protection Officer appointment threshold was identified for Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 oficial de protección de datos.

Ropa RequirementsRed

No confirmed records-of-processing (ROPA) obligation was located for Law 172-13 in this run.

Absence provenance: not recorded. Searched: Ley 172-13 registro de actividades de tratamiento.

Joint Controller ArrangementsRed

No joint-controller framework analogous to GDPR Art. 26 was identified for Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 corresponsables tratamiento.

Security MeasuresGreen

Law 172-13 establishes a security principle applicable to data controllers, requiring appropriate safeguards for personal data held in archives, registries and databases.

Claims: CLM-DO-d4e5f6a7

Breach NotificationRed

Law 172-13 does not impose an obligation on controllers to notify data subjects or any administrative/judicial authority of a data breach; any such notice is voluntary and considered good practice rather than a legal duty.

Claims: CLM-DO-e5f6a7b8

Retention And DisposalRed

No confirmed statutory retention-limit or disposal-duty provision was located for Law 172-13 in this run.

Absence provenance: not recorded. Searched: Ley 172-13 plazo de conservación de datos.

Category narrative52 words

Law 172-13 establishes a general security-of-processing principle for controllers but does not impose a breach-notification obligation to data subjects or authorities; breach notice is voluntary/best-practice only. DPIA, DPO, ROPA and joint-controller obligations analogous to GDPR were not confirmed in the sources reviewed and likely do not exist in the current 2013-era statute.

#

No confirmed transfer-mechanism framework, adequacy status, or localisation mandate was located; this is a genuine regulatory gap rather than an omission, consistent with the statute's 2013-era scope.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — RedNo confirmed transfer-mechanism framework, adequacy status, or localisation mandate was located; this is a genuine regulatory gap rather than an omission, consistent with the statute's 2013-era scope.

Sub-modules (6)

Transfer MechanismsRed

No specific cross-border data transfer mechanism (adequacy, SCCs, BCRs, derogations) was identified in Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 transferencia internacional de datos.

Adequacy ReceivedRed

The Dominican Republic has not been identified as a recipient of an EU adequacy decision in the sources reviewed.

Absence provenance: not recorded. Searched: European Commission adequacy decisions list Dominican Republic.

Adequacy GrantedRed

No mechanism by which the Dominican Republic grants adequacy status to other jurisdictions was identified.

Absence provenance: not recorded. Searched: Dominican Republic adequacy decision granted other countries.

Sccs And BcrsRed

No SCC or BCR framework was identified under Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 cláusulas contractuales tipo normas corporativas vinculantes.

Transfer Impact AssessmentRed

No transfer impact assessment requirement was identified under Law 172-13.

Absence provenance: not recorded. Searched: Ley 172-13 evaluación de impacto de transferencia.

Data LocalisationRed

No general data-localisation mandate was identified for personal data under Law 172-13; sector-specific banking-data location rules under the financial regulator were not independently confirmed in this run.

Absence provenance: not recorded. Searched: Dominican Republic data localisation requirement banking financial data.

Category narrative45 words

Law 172-13 predates the modern SCC/BCR/TIA transfer-mechanism architecture, and no confirmed cross-border transfer regime, adequacy decision (received or granted), or data-localisation mandate specific to general personal data was identified in the sources reviewed. The Dominican Republic does not appear on published EU adequacy decision lists.

#

Financial and credit-reporting overlays are reasonably well evidenced; other sectoral overlays (health, employment, education, insurance) remain unconfirmed gaps.

Primary frameworkLaw No. 172-13 (2013); Monetary and Financial Law No. 183-02
Supervisory authoritySuperintendencia de Bancos de la República Dominicana
Traffic-light rationale — AmberFinancial and credit-reporting overlays are reasonably well evidenced; other sectoral overlays (health, employment, education, insurance) remain unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayAmber

Monetary and Financial Law No. 183-02 establishes the regulatory and institutional framework for the Dominican monetary and financial system, under which the Superintendencia de Bancos oversees confidentiality of banking-related personal/financial data.

Claims: CLM-DO-f6a7b8c9

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in the sources reviewed for this run.

Absence provenance: not recorded. Searched: Dominican Republic health data law confidentiality Ley General de Salud.

Telecoms And EprivacyAmber

INDOTEL, the Dominican Telecommunications Institute, exercises a regulatory role touching on data/consumer protection in electronic commerce, evidenced by its joint 2019 e-commerce guidance with Pro Consumidor addressing personal and financial data safeguards for online consumers.

Claims: CLM-DO-a7b8c9d0

Employment DataRed

No employment-sector-specific data protection code was confirmed for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic labor code employee data protection.

Credit And ScoringAmber

Law 172-13's formal title references its application to databases used for reporting, indicating the statute's origins are closely tied to credit-bureau/credit-reporting data practices.

Claims: CLM-DO-b8c9d0e1

EducationRed

No education-sector-specific data protection rules were confirmed for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic student data protection education law.

InsuranceRed

No insurance-sector-specific data protection rules were confirmed for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic insurance sector data protection rules.

Category narrative66 words

The financial sector is overlaid by Monetary and Financial Law No. 183-02, which establishes the regulatory and institutional framework for the Dominican monetary and financial system including bank confidentiality obligations. Law 172-13's own title indicates a strong original focus on databases used for credit reporting. Telecommunications-related data practices intersect with INDOTEL's mandate. Health, employment, education and insurance sector-specific data overlays were not confirmed in this run.

#

No binding adtech-specific commercial privacy framework exists; only non-binding consumer guidance was located.

Traffic-light rationale — RedNo binding adtech-specific commercial privacy framework exists; only non-binding consumer guidance was located.

Sub-modules (6)

Cookies And TrackersAmber

No binding cookie/tracker consent regime was identified; the 2019 INDOTEL/Pro Consumidor e-commerce guide recommends consumer awareness of supplier privacy policies but does not impose binding cookie-consent obligations.

Claims: CLM-DO-c9d0e1f2

Dark PatternsRed

No dark-pattern prohibition was identified for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic dark patterns law consumer interface.

Opt Out SignalsRed

No recognized opt-out signal framework (e.g. Global Privacy Control) was identified as legally recognized in the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation was identified for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic data clean room regulation.

Cross Context AdvertisingRed

No cross-context advertising / sale-or-share framework analogous to CPRA was identified for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic cross-context advertising data sale law.

Direct MarketingRed

No direct-marketing-specific consent/suppression regime was confirmed for the Dominican Republic beyond the general consent principles implied by Law 172-13.

Absence provenance: not recorded. Searched: Dominican Republic direct marketing consent suppression law.

Category narrative48 words

No ePrivacy-style cookie/tracker consent statute, dark-pattern prohibition, recognized opt-out signal framework, clean-room regime, or cross-context-advertising rule was identified for the Dominican Republic. The closest identified artifact is the 2019 joint INDOTEL/Pro Consumidor e-commerce guidance, which recommends consumer-facing privacy-policy awareness practices but is non-binding guidance rather than binding law.

#

No sources located confirming any algorithmic, biometric, or AI-specific governance framework distinct from the general 2013 data protection statute.

Traffic-light rationale — AmberNo sources located confirming any algorithmic, biometric, or AI-specific governance framework distinct from the general 2013 data protection statute.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art. 22 was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic profiling restriction automated decision law.

Automated Decision Making TransparencyRed

No automated-decision-making transparency or explanation right was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic automated decision-making transparency right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment law or state-level AI transparency mandate was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic artificial intelligence law risk assessment.

Biometric RegimeAmber

No dedicated biometric-data protection regime (facial recognition, fingerprint, gait) distinct from the general Law 172-13 framework was confirmed for the Dominican Republic in this run.

Absence provenance: not recorded. Searched: Dominican Republic biometric data law facial recognition regulation.

Genetic DataRed

No dedicated genetic-data regime was confirmed for the Dominican Republic; genetic data would likely fall under any general sensitive-category treatment of Law 172-13, which itself was not independently verified in this run.

Absence provenance: not recorded. Searched: Dominican Republic genetic data protection law.

State Surveillance CarveoutsRed

No codified state-surveillance carve-out or national-security exemption text was confirmed for Law 172-13 in this run.

Absence provenance: not recorded. Searched: Ley 172-13 excepción seguridad nacional vigilancia estatal.

Category narrative43 words

No profiling-restriction, automated-decision-making transparency right, AI-specific risk-assessment regime, dedicated biometric-data regime, genetic-data regime, or codified state-surveillance carve-out was identified for the Dominican Republic in the sources reviewed. This is treated as a genuine regulatory gap for this module rather than a silent omission.

#

No sources located confirming any children- or vulnerable-group-specific data protection provisions; genuine regulatory gap.

Traffic-light rationale — RedNo sources located confirming any children- or vulnerable-group-specific data protection provisions; genuine regulatory gap.

Sub-modules (5)

Age VerificationRed

No statutory age-of-consent threshold for data processing was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic age of consent data processing minors.

Minor Profiling BansRed

No minor-profiling ban was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic minors profiling ban advertising.

Education SettingsRed

No education-setting-specific data protection rule was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic student data protection school law.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data protection provision was identified for the Dominican Republic.

Absence provenance: not recorded. Searched: Dominican Republic dependent adults data protection incapacitated.

Category narrative30 words

No age-of-consent threshold, parental-consent mechanism (COPPA/GDPR Art. 8 analogue), minor-profiling ban, education-setting-specific rule, or dependent-adult protection provision was identified for the Dominican Republic's data protection framework in the sources reviewed.

#

A private judicial right of action exists, but there is no confirmed administrative penalty regime, enforcement activity index, or regulator capacity data, and no material recent developments were found.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA private judicial right of action exists, but there is no confirmed administrative penalty regime, enforcement activity index, or regulator capacity data, and no material recent developments were found.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

No confirmed administrative investigative or fining power vested in a single DP regulator was identified for the Dominican Republic; redress instead runs through civil courts.

Claims: CLM-DO-d0e1f2a3

Enforcement Activity IndexRed

No significant recent enforcement decisions or fines specific to Law 172-13 were identified in the sources reviewed for the last 12 months.

Absence provenance: not recorded. Searched: Dominican Republic data protection enforcement action fine 2025 2026.

Regulator Funding And CapacityRed

No funding or headcount data is applicable given the absence of a dedicated DPA; this is a structural gap rather than an omission.

Absence provenance: not recorded. Searched: Dominican Republic data protection authority budget headcount.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism specific to data protection violations was identified for the Dominican Republic in this run; Pro Consumidor's general consumer-complaint/conciliation channel was noted but not confirmed as DP-specific.

Absence provenance: not recorded. Searched: Dominican Republic collective redress class action data protection.

Private Right Of ActionGreen

Data subjects whose rights are violated under Law 172-13, including in connection with a data breach, may bring a direct civil suit against the liable party, since the Law does not channel redress exclusively through an administrative regulator.

Claims: CLM-DO-e1f2a3b4

Recent Developments 180DRed

No material Dominican Republic-specific data protection legislative, regulatory, or case-law developments were identified within the 180 days preceding this run (searches for a new DR data protection bill, dedicated DPA creation, or amendments in 2025-2026 returned no confirming results).

Absence provenance: not recorded. Searched: Dominican Republic data protection authority draft bill 2025 create agency, Dominican Republic new data protection bill 2024 2025 draft law.

Category narrative66 words

Law 172-13 does not establish an administrative-fine regime comparable to GDPR; redress is primarily judicial. Data subjects whose rights are violated (including via a data breach) may sue the liable party directly through civil/habeas-data litigation, rather than through an empowered administrative regulator issuing penalties. No significant recent DR-specific data protection enforcement actions or legislative developments were identified within the last 180 days of the run date.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Dominican Republic
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 5 source(s) in the cumulative register.