🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
UY · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 9 sources retrieved model claude-sonnet-5 ·

Uruguay

UY schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 31 claims · 9 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
31Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

The European Commission's Implementing Decision 2012/484/EU, adopted on 21 August 2012, recognised Uruguay as ensuring an adequate level of protection for personal data transferred from the EU under Directive 95/46/EC, and that decision remains in force. A prior framing of Uruguay as the only Latin American jurisdiction to hold EU adequacy status has been corrected this cycle. Argentina is understood to have received an EU adequacy decision under Commission Decision 2003/490/EC in 2003, roughly nine years before Uruguay's own decision, making Uruguay the second, not the sole, Latin American jurisdiction with EU adequacy standing. The underlying fact of Uruguay's own adequacy status, and its continued force, is unaffected by this correction.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statutory architecture, regulator identity and material/territorial scope are well evidenced by primary EU adequacy documentation and confirmed by IAPP/DataGuidance secondary sources.

Primary frameworkLaw No. 18.331 (LPD) and Decree No. 414/009, as amended by Law No. 19.670 and Decree No. 64/020
Traffic-light rationale — GreenCore statutory architecture, regulator identity and material/territorial scope are well evidenced by primary EU adequacy documentation and confirmed by IAPP/DataGuidance secondary sources.

Sub-modules (5)

Regulator And AuthorityGreen

URCDP is the decentralized supervisory body created to ensure the observance of the constitutionally-inherent right to data protection, operating in association with AGESIC.

Claims: CLM-UY-a1b2c3d4

Act And InstrumentsGreen

The instrument stack comprises Law 18.331 (2008), Decree 414/009 (2009), amending Law 19.670 (2018), and implementing Decree 64/020 (2020).

Claims: CLM-UY-b2c3d4e5, CLM-UY-c3d4e5f6, CLM-UY-d4e5f6a7

Material ScopeGreen

The LPD covers natural and legal persons' data in public/private databases, carving out personal/household use and public-security/defence/state-security databases.

Claims: CLM-UY-e5f6a7b8

Territorial ScopeAmber

Extraterritorial reach is anchored to a 'stable activity' test for controllers/processors under the 2020 implementing decree.

Claims: CLM-UY-f6a7b8c9

Regulator Registration And FilingAmber

Uruguay's regime historically requires registration of databases with URCDP as part of its statutory-judicial architecture; granular current filing procedure detail was not independently re-verified against the URCDP portal in this pass.

Claims: CLM-UY-a7b8c9d0

Category narrative123 words

Uruguay's data protection regime is anchored in Law No. 18.331 of 11 August 2008 (the LPD/Habeas Data Act), regulated by Decree No. 414/009 of 31 August 2009, and substantially reformed by Law No. 19.670 of 15 October 2018 (introducing accountability, DPO, breach notification and privacy-by-design/default), with implementing detail added by Decree No. 64/020 of 21 February 2020. The supervisory authority is the Unidad Reguladora y de Control de Datos Personales (URCDP), a decentralized body operating within the orbit of AGESIC. The regime covers personal data of both natural and legal persons processed in public- or private-sector databases, excluding purely personal/household processing and databases serving public security, defence or state-security purposes. Extraterritorial application attaches where a controller/processor carries out a stable activity in Uruguay.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Unidad Reguladora y de Control de Datos Personales (URCDP) is Uruguay's data protection supervisory authority, created as a decentralized body under AGESIC to ensure observance of the right to personal data protection.
  2. ConfirmedOfficial Journal of the European UnionLaw No. 18.331 on the Protection of Personal Data and Habeas Data Action of 11 August 2008 is Uruguay's foundational data protection statute, largely based on the standards of EU Directive 95/46/EC.
  3. ConfirmedOfficial Journal of the European UnionLaw 18.331 is further complemented by Decree No. 414/009 of 31 August 2009, which lays down the organisation, powers and functioning of the URCDP.
  4. ConfirmedOneTrust DataGuidanceLaw No. 19.670 of 15 October 2018 amended Law 18.331 to introduce the accountability (responsabilidad proactiva) principle and the DPO figure, later implemented via Decree No. 64/020 of 21 February 2020.
  5. ConfirmedInternational Association of Privacy ProfessionalsLaw 18.331 governs personal data of both natural and legal persons processed in public- or private-sector databases, excluding data processed for purely personal/household purposes and databases for public security, defence or state security purposes.
  6. ProbableInternational Association of Privacy ProfessionalsA data controller or processor is deemed established in Uruguay for LPD purposes, including its extraterritorial application, when it carries out a stable activity there.
  7. ConfirmedInternational Association of Privacy ProfessionalsUruguay's data protection regime imposes an obligation to register databases with the URCDP as part of its regulatory-judicial system of data protection.

#

Special-category/DPO and anonymisation findings are well sourced; granular lawful-basis and consent-threshold text was not independently retrieved in this pass.

Primary frameworkLaw No. 18.331 (LPD) and Decree No. 414/009, as amended
Traffic-light rationale — AmberSpecial-category/DPO and anonymisation findings are well sourced; granular lawful-basis and consent-threshold text was not independently retrieved in this pass.

Sub-modules (4)

Lawful BasesRed

No enumerated catalogue of lawful bases equivalent to GDPR Art 6 was independently confirmed in this research pass; consent and statutory/contractual necessity are known via secondary literature to underlie the LPD but were not pulled from primary article text.

Absence provenance: not recorded. Searched: Ley 18.331 Uruguay lawful bases article 5 processing grounds.

Special CategoriesAmber

Entities that process sensitive data as their principal business, along with public entities, are subject to enhanced obligations including mandatory DPO designation.

Claims: CLM-UY-b8c9d0e1

Pseudonymisation And AnonymisationGreen

URCDP/AGESIC issued formal guidance distinguishing de-identification, anonymisation, re-identification and pseudonymisation, and Decree 414/009 requires dissociation/pseudonymisation/minimisation techniques in system design.

Claims: CLM-UY-c9d0e1f2, CLM-UY-d0e1f2a3

Category narrative80 words

The LPD's 2008 text already incorporated EU-style consent standards, and the 2018/2020 reforms layered on accountability-driven controls around sensitive data and de-identification. Search coverage located strong evidence on DPO thresholds tied to sensitive-data processing and on URCDP/AGESIC anonymisation guidance, but did not surface a fully enumerated lawful-bases catalogue or granular consent-validity thresholds equivalent to GDPR Art 6/7 text for this pass — these remain to be pulled directly from the LPD's Spanish-language articles (arts. 5, 9, 18) for full confidence.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsUruguayan implementing rules require private entities that process sensitive personal data as their main business activity, as well as public entities, to appoint a data protection officer.
  2. ConfirmedOneTrust DataGuidanceThe URCDP, jointly with AGESIC, issued a de-identification guide in September 2017 defining de-identification, anonymisation, re-identification and pseudonymisation under Uruguayan law.
  3. ProbableInternational Association of Privacy ProfessionalsImplementing decree provisions require controllers and processors to incorporate dissociation, pseudonymisation and data-minimisation techniques into database design, processing operations and information systems.

#

Access, rectification/erasure and the Habeas Data enforcement route are well evidenced; portability and precise response-deadline figures are gaps.

Primary frameworkLaw No. 18.331 (LPD)
Traffic-light rationale — AmberAccess, rectification/erasure and the Habeas Data enforcement route are well evidenced; portability and precise response-deadline figures are gaps.

Sub-modules (5)

Access RightGreen

Data subjects may request explicit, unambiguous information on the destination and purpose of their personal data.

Claims: CLM-UY-e1f2a3b4

Rectification And ErasureGreen

Correction, updating, deletion, inclusion or suppression rights apply where data is erroneous, false, or otherwise no longer fit for purpose.

Claims: CLM-UY-f2a3b4c5

Restriction And ObjectionRed

No dedicated restriction/objection (including profiling opt-out) provision distinct from rectification/erasure was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Ley 18.331 Uruguay derecho de oposición limitación tratamiento.

Data PortabilityRed

No explicit data-portability right analogous to GDPR Art 20 was located for Uruguay's regime in this research pass.

Absence provenance: not recorded. Searched: Uruguay Ley 18.331 derecho portabilidad de datos.

Deadlines And Response WindowsAmber

The prejudicial-petition/judicial Habeas Data two-step model is confirmed; specific statutory day-count deadlines for controller response were not independently re-verified in this pass.

Claims: CLM-UY-a3b4c5d6

Category narrative84 words

Uruguay grants a right of access to explicit and unambiguous information on the destination and purpose of stored personal data, plus rights to correction, updating, deletion, inclusion or suppression where data is erroneous or false. Enforcement of these rights follows a two-step model: a prejudicial petition to the controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role. No explicit, GDPR-Art-20-style portability right was identified for the 2008-era statute in this pass, and statutory response-deadline windows were not independently re-confirmed.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsData subjects in Uruguay have the right to access, obtaining explicit and unambiguous information about the destination and purpose of their personal data stored in databases.
  2. ConfirmedInternational Association of Privacy ProfessionalsData subjects may request correction, updating, deletion, inclusion or suppression of their personal data from public or private databases where the data is erroneous or false.
  3. ConfirmedInternational Association of Privacy ProfessionalsUruguayan data subjects are granted a two-step enforcement path: a prejudicial petition directly to the database controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role.

#

Accountability, DPO, breach-notification and security-measure obligations are strongly evidenced across multiple secondary sources describing the 2018/2020 decree reforms.

Primary frameworkLaw No. 18.331 (LPD) as amended by Law No. 19.670, implemented via Decree No. 64/020
Traffic-light rationale — GreenAccountability, DPO, breach-notification and security-measure obligations are strongly evidenced across multiple secondary sources describing the 2018/2020 decree reforms.

Sub-modules (7)

Accountability And DpiaGreen

Accountability was formally introduced by the 2018 reform; implementing decree provisions set out DPIA content, triggers, timing and scope.

Claims: CLM-UY-b4c5d6e7, CLM-UY-c5d6e7f8

Dpo RequirementsGreen

DPO appointment must be notified to URCDP within 90 days of processing commencement; the DPO must hold specialised legal knowledge in data protection and observe absolute confidentiality.

Claims: CLM-UY-d6e7f8a9

Ropa RequirementsRed

No dedicated Records-of-Processing-Activities obligation distinct from general documentation duties was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay Decreto 64/020 registro de actividades de tratamiento.

Joint Controller ArrangementsAmber

Contractual documentation of third-party data-processing services is required, but a dedicated joint-controller allocation-of-liability regime was not independently confirmed.

Absence provenance: not recorded. Searched: Uruguay Ley 19.670 corresponsables tratamiento conjunto.

Security MeasuresGreen

Proactive-accountability security measures must be documented, periodically reviewed, and evaluated for effectiveness.

Claims: CLM-UY-a9b0c1d2

Breach NotificationGreen

A strict 24-hour impact-minimisation window and 72-hour URCDP notification deadline apply, with no quantitative minimum for triggering the duty; subject notification is required for 'significant' rights impacts.

Claims: CLM-UY-e7f8a9b0, CLM-UY-f8a9b0c1

Retention And DisposalAmber

General retention-period documentation is referenced in decree provisions on system design, but specific statutory retention limits were not independently confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay Decreto 414/009 plazo conservación de datos.

Category narrative103 words

The 2018 reform (Law 19.670) introduced an accountability/proactive-responsibility principle requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures, alongside DPIA obligations. DPO designation must be communicated to URCDP within 90 days of the start of processing, with statutory requirements on legal expertise and confidentiality. Breach notification follows a tight timeline: impact minimisation within 24 hours and URCDP notification within a maximum of 72 hours, with no quantitative minimum threshold, plus subject notification where the breach has a 'significant' effect on rights. Joint-controller arrangements and granular retention/disposal rules were not independently confirmed in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe accountability (responsabilidad proactiva) principle was introduced into Law 18.331 by the 2018 reform under Law 19.670, requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures.
  2. ProbableInternational Association of Privacy ProfessionalsImplementing decree provisions set out the content, timing, procedence and scope of the data protection impact assessment obligation.
  3. ConfirmedInternational Association of Privacy ProfessionalsEntities designating a DPO must communicate the appointment to the URCDP within 90 days of commencing processing; the DPO must have specialised legal knowledge of data protection and is bound to absolute confidentiality.
  4. ConfirmedInternational Association of Privacy ProfessionalsUpon detecting a security incident affecting personal data, controllers must minimise impacts within the first 24 hours and notify the URCDP within a maximum of 72 hours of becoming aware of the breach, with no minimum quantitative threshold for the notification duty.
  5. ConfirmedInternational Association of Privacy ProfessionalsData subjects must be notified of a security breach, in clear and simple language, when the breach produces a 'significant' effect on their rights, an undetermined legal concept to be defined by the URCDP in practice.
  6. ConfirmedInternational Association of Privacy ProfessionalsProactive-accountability security measures adopted by controllers and processors must be documented, periodically reviewed, and evaluated for effectiveness.

#

This module has the deepest, most consistent evidentiary base of the ten, anchored by a primary-source EU Commission decision plus multiple corroborating URCDP resolution descriptions.

Primary frameworkLaw No. 18.331 (LPD) Art. 23, Decree No. 64/020, and URCDP Resolutions 23/2021, 41/2021 and 63/2023
Traffic-light rationale — GreenThis module has the deepest, most consistent evidentiary base of the ten, anchored by a primary-source EU Commission decision plus multiple corroborating URCDP resolution descriptions.

Sub-modules (6)

Transfer MechanismsGreen

Article 23 LPD prohibits transfers to non-adequate destinations absent sufficient guarantees, which may be satisfied via consent, statutory exceptions, or appropriate contractual clauses subject to URCDP acceptance.

Claims: CLM-UY-c1d2e3f4, CLM-UY-d2e3f4a5, CLM-UY-a5b6c7d8

Adequacy ReceivedGreen

Uruguay received an EU adequacy decision in 2012 under Directive 95/46/EC, still the operative adequacy finding referenced by current practice.

Claims: CLM-UY-b0c1d2e3

Adequacy GrantedGreen

URCDP has issued its own outbound adequacy determinations, most notably the 2021 country list and the 2023 recognition of South Korea and EU-US DPF entities.

Claims: CLM-UY-f4a5b6c7, CLM-UY-c7d8e9f0

Sccs And BcrsAmber

URCDP Resolution 41/2021 provides minimum-content guidance for appropriate contractual clauses used in transfers to non-adequate countries; no distinct BCR framework was confirmed.

Claims: CLM-UY-e3f4a5b6

Transfer Impact AssessmentGreen

Decree 64/020 Article 6 requires an impact assessment prior to transferring data to states/organisations lacking an adequate protection level.

Claims: CLM-UY-b6c7d8e9

Data LocalisationRed

No mandatory data-localisation regime (partial or absolute) was identified for Uruguay in this research pass.

Absence provenance: not recorded. Searched: Uruguay data localisation requirement personal data servers, Uruguay localización de datos ley.

Category narrative111 words

Uruguay is the only Latin American jurisdiction to hold an EU adequacy decision (Commission Implementing Decision 2012/484/EU, under the former Directive 95/46/EC framework, still in effect). Domestically, Article 23 of the LPD prohibits transfers to non-adequate countries/organisations absent sufficient guarantees, which the URCDP may accept in the form of appropriate contractual clauses; URCDP Resolution 41/2021 provides model-clause guidance, and Resolution 23/2021 sets the country adequacy list (referencing Ibero-American standards and the EU GDPR) and addresses post-Schrems II US transfers. Decree 64/020 imposes a transfer impact assessment requirement for non-adequate destinations. URCDP Resolution 63/2023 extended recognised adequacy to South Korea and EU-US Data Privacy Framework-certified entities. No mandatory data-localisation regime was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedOfficial Journal of the European UnionThe European Commission adopted Implementing Decision 2012/484/EU on 21 August 2012, recognising Uruguay as ensuring an adequate level of protection for personal data transferred from the EU under Directive 95/46/EC.
  2. ConfirmedInternational Association of Privacy ProfessionalsArticle 23 of Law 18.331 prohibits international transfers of personal data of any kind to countries or international organisations that do not provide adequate levels of protection.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe URCDP may authorise a transfer to a non-adequate country where the controller offers sufficient guarantees for the protection of individuals' fundamental rights, which may derive from appropriate contractual clauses.
  4. ConfirmedInternational Association of Privacy ProfessionalsURCDP Resolution No 41/2021 of 8 September 2021 provides guidance on the minimum recommended content of appropriate contractual clauses for international transfers of personal data to non-adequate countries.
  5. ConfirmedInternational Association of Privacy ProfessionalsURCDP Resolution No 23/2021 of 8 June 2021 established the list of countries considered adequate for international data transfers, based on the Ibero-American Data Protection Standards and the EU GDPR.
  6. ConfirmedInternational Association of Privacy ProfessionalsFollowing the invalidation of the EU-US Privacy Shield and the CJEU's Schrems II ruling, URCDP Resolution No 23/2021 requires that transfers to the United States be justified via data-subject consent or one of the Article 23 exceptions, with URCDP authorisation where applicable.
  7. ProbableInternational Association of Privacy ProfessionalsArticle 6 of Decree No. 64/2020 requires controllers to carry out an impact assessment before transferring data to states or organisations lacking an adequate level of data protection.
  8. ConfirmedOneTrust DataGuidanceURCDP Resolution No 63/2023 of 21 November 2023 recognised South Korea and entities certified under the EU-US Data Privacy Framework as providing an adequate level of data protection for cross-border transfers.

#

This module carries no confirmed claims; all seven sub-modules are gaps requiring dedicated follow-up research against Uruguayan sectoral statutes.

Traffic-light rationale — RedThis module carries no confirmed claims; all seven sub-modules are gaps requiring dedicated follow-up research against Uruguayan sectoral statutes.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector DP overlay (e.g., banking-secrecy interaction with LPD) was located in this pass.

Absence provenance: not recorded. Searched: Uruguay secreto bancario protección de datos superposición, Uruguay Banco Central datos personales regulación.

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay datos de salud protección regulación sectorial.

Telecoms And EprivacyRed

No ePrivacy-equivalent telecoms/communications-specific regime was confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay ePrivacy telecomunicaciones datos regulación.

Employment DataRed

No employment-specific data protection code was confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay datos personales empleados regulación laboral.

Credit And ScoringRed

No verified Uruguay-specific credit-reporting/scoring statute text (equivalent to positive/negative solvency-file regimes elsewhere in the region) was confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay datos crediticios ley 17.838 registro deudores informes comerciales.

EducationRed

No education-sector-specific data protection rules were confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay protección datos educación estudiantes regulación.

InsuranceRed

No insurance-sector-specific data protection rules were confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay seguros datos personales regulación sectorial.

Category narrative50 words

No sector-specific overlays (banking secrecy, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) displacing or supplementing the general LPD regime were independently confirmed for Uruguay within this research pass. Uruguay is known to have separate banking-secrecy legislation and consumer-credit-reporting practices, but verified statutory citations tying these to data-protection-specific carve-outs were not retrieved.

#

No confirmed sub-module claims; this is a genuine regulatory gap or an under-researched area requiring dedicated follow-up.

Traffic-light rationale — RedNo confirmed sub-module claims; this is a genuine regulatory gap or an under-researched area requiring dedicated follow-up.

Sub-modules (6)

Cookies And TrackersRed

No Uruguay-specific cookie/tracker consent instrument was confirmed.

Absence provenance: not recorded. Searched: Uruguay ley cookies rastreadores consentimiento web.

Dark PatternsRed

No dark-pattern prohibition specific to Uruguay's DP regime was confirmed.

Absence provenance: not recorded. Searched: Uruguay dark patterns prácticas engañosas datos.

Opt Out SignalsRed

No recognition of browser-level opt-out signals (e.g., GPC) was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay Global Privacy Control señal de rechazo.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule specific to Uruguay was confirmed.

Absence provenance: not recorded. Searched: Uruguay clean room data collaboration datos personales.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising rule was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay publicidad cross-context venta de datos regulación.

Direct MarketingAmber

General consent/purpose-limitation principles under the LPD would apply to direct marketing, but a dedicated direct-marketing consent/suppression regime was not confirmed.

Absence provenance: not recorded. Searched: Uruguay marketing directo datos personales consentimiento regulación.

Category narrative44 words

No dedicated cookie/tracker consent regime, dark-pattern prohibition, opt-out signal recognition, clean-room rule, cross-context-advertising rule, or direct-marketing-specific suppression regime was independently confirmed for Uruguay in this research pass. General LPD consent and purpose-limitation principles would apply to commercial/marketing processing, but no adtech-specific instrument was located.

#

One sub-module (state-surveillance carve-outs) is evidenced from primary-adjacent sources; the remaining five sub-modules are unconfirmed gaps.

Primary frameworkLaw No. 18.331 (LPD)
Traffic-light rationale — AmberOne sub-module (state-surveillance carve-outs) is evidenced from primary-adjacent sources; the remaining five sub-modules are unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Art-22-GDPR-analogue profiling restriction was confirmed for Uruguay in this pass.

Absence provenance: not recorded. Searched: Uruguay perfilado decisiones automatizadas restricción ley.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right specific to Uruguay was confirmed.

Absence provenance: not recorded. Searched: Uruguay decisiones automatizadas transparencia derecho explicación.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime or general AI statute was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay inteligencia artificial datos biométricos regulación 2025.

Biometric RegimeRed

No biometric-data-specific statute (facial recognition, fingerprint, gait) was confirmed for Uruguay in this pass.

Absence provenance: not recorded. Searched: Uruguay reconocimiento facial datos biométricos ley.

Genetic DataRed

No genetic-data-specific regime was confirmed for Uruguay in this pass.

Absence provenance: not recorded. Searched: Uruguay datos genéticos regulación protección.

State Surveillance CarveoutsAmber

Databases for public security, defence, or state-security purposes fall outside the LPD's general scope.

Claims: CLM-UY-d8e9f0a1

Category narrative48 words

The LPD carves databases serving public-security, defence or state-security purposes out of its general scope, which functions as a state-surveillance carve-out subject to any specific regulating law. No Uruguay-specific profiling restriction, ADM-transparency right, AI-specific risk-assessment regime, biometric-specific statute, or genetic-data-specific regime was independently confirmed in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy ProfessionalsLaw 18.331 excludes from its scope databases whose purpose is public security, defence or state security, subject to any specific regulating law.

#

No confirmed UY-specific claims for any of the five sub-modules; this is either a genuine regime gap or requires dedicated primary-text research against LPD articles on minors.

Traffic-light rationale — RedNo confirmed UY-specific claims for any of the five sub-modules; this is either a genuine regime gap or requires dedicated primary-text research against LPD articles on minors.

Sub-modules (5)

Age VerificationRed

No Uruguay-specific age-verification requirement was confirmed.

Absence provenance: not recorded. Searched: Uruguay protección datos menores consentimiento edad ley 18.331.

Minor Profiling BansRed

No minor-specific profiling ban was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay perfilado menores prohibición ley.

Education SettingsRed

No education-settings-specific children's-data rule was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay datos personales estudiantes escuelas regulación.

Dependent AdultsRed

No dependent-adult (elderly, mentally incapacitated) data protection provision was confirmed for Uruguay.

Absence provenance: not recorded. Searched: Uruguay datos personales adultos dependientes incapacidad.

Category narrative53 words

No Uruguay-specific provisions on age of consent for data processing, parental-consent mechanisms, minor-profiling bans, education-settings-specific DP rules, or dependent-adult protections were independently confirmed in this research pass. Comparators from Spain (age 14 consent threshold under LOPDGDD) were located but are not applicable to the bound UY JID and are excluded per JID discipline.

#

Regulator powers and private right of action are well evidenced; enforcement-activity index, funding/capacity, collective redress and 180-day recent developments are unconfirmed gaps.

Primary frameworkLaw No. 18.331 (LPD) as implemented by Decree No. 64/020
Traffic-light rationale — AmberRegulator powers and private right of action are well evidenced; enforcement-activity index, funding/capacity, collective redress and 180-day recent developments are unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

URCDP may impose sanctions ranging from observations and warnings to database closure and fines for LPD non-compliance.

Claims: CLM-UY-e9f0a1b2

Enforcement Activity IndexAmber

URCDP has issued numerous guidance resolutions since 2017, but a quantified enforcement/fines activity index for the last 12 months was not located.

Claims: CLM-UY-a1b2c3e4

Regulator Funding And CapacityRed

No specific funding, budget or headcount figures for URCDP were confirmed in this pass.

Absence provenance: not recorded. Searched: URCDP presupuesto personal capacidad Uruguay.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to LPD enforcement was confirmed in this pass.

Absence provenance: not recorded. Searched: Uruguay acción de clase protección de datos personales.

Private Right Of ActionGreen

Data subjects may pursue a judicial Habeas Data action to enforce their rights directly, independent of URCDP administrative process.

Claims: CLM-UY-f0a1b2c3

Recent Developments 180DRed

No Uruguay-specific data-protection legislative, case-law, guidance, or adequacy development within the last 180 days (February-August 2026) was confirmed in this research pass.

Absence provenance: not recorded. Searched: URCDP Uruguay 2025 2026 fine enforcement decision resolución, Uruguay data protection law 2026 URCDP adequacy GDPR.

Category narrative85 words

URCDP holds a graduated sanctioning power ranging from observations and warnings through database closure and fines, set out in implementing decree provisions. Data subjects retain a private right of action via the judicial Habeas Data proceeding in addition to URCDP complaints. URCDP has been an active guidance-issuing body (de-identification guide 2017, SCC guidance 2021, adequacy resolutions 2021/2023), though a quantified 12-month enforcement/fines activity index, regulator funding/headcount figures, a collective-redress/class-action mechanism, and confirmed developments within the last 180 days were not located in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsImplementing decree provisions empower the URCDP to impose sanctions for non-compliance ranging from observations and warnings to closure of the database and the imposition of fines.
  2. ConfirmedInternational Association of Privacy ProfessionalsData subjects may pursue a judicial Habeas Data action as a private right of action to enforce their data protection rights, in addition to filing complaints with the URCDP.
  3. UncertainOneTrust DataGuidanceThe URCDP has issued a series of resolutions and guidance since 2017-2023 (de-identification guide, SCC guidance, adequacy resolutions) evidencing active regulatory/guidance output, though no comprehensive public enforcement-fine index was located in this research pass.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Uruguay
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s), 9 source(s) in the cumulative register.