Not publishable as-is. 3 of 7 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. None of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2); we look for at least 3. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Costa Rica
CRschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated update date not yet available · 10 categories · 34
claims · 9 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
No content recorded at this JID path.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Core regulator, statute and implementing decree are well corroborated across independent secondary sources; only territorial-scope detail is unconfirmed.
Primary frameworkLaw No. 8968 of 2011 (Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales) and Executive Decree No. 37554-JP of 2012, as amended by Decree No. 40008-JP of 2016
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — GreenCore regulator, statute and implementing decree are well corroborated across independent secondary sources; only territorial-scope detail is unconfirmed.
Sub-modules (5)
Regulator And AuthorityGreen
PRODHAB is the designated enforcement authority for Law No. 8968, structured as a maximum-decentralization body attached to the Ministry of Justice and Peace.
Claims (1):
PRODHAB (Agencia de Proteccion de Datos de los Habitantes) is Costa Rica's data protection authority, structured as a maximum-decentralization body attached to the Ministry of Justice and Peace, and is responsible for enforcing Law No. 8968.
Act And InstrumentsGreen
Primary instruments are Law No. 8968 (2011), Executive Decree No. 37554-JP (2012) and its 2016 amending Decree No. 40008-JP; two reform/replacement bills remain pending.
Claims (2):
Law No. 8968 of 2011 has been enforceable in relation to organizations and individuals since July 7, 2012, and is complemented by Executive Decree No. 37554-JP of October 30, 2012, as amended by Decree No. 40008-JP of December 6, 2016.
Two additional bills, No. 22.388 (a reform of the existing Law) and No. 23.097 (a new data protection law), were pending before the Legislative Assembly as of the most recent secondary-source review in April 2026, with neither yet enacted.
Material ScopeGreen
The Law applies to personal data held in both automated and manual databases.
Claims (1):
Law No. 8968 is applicable to personal data contained in automated or manual databases.
Territorial ScopeAmber
No confirming evidence was located in this run describing the Law's application to controllers not established in Costa Rica.
Absence provenance: unavailable. Searched: Costa Rica data protection law territorial scope non-established controllers, Ley 8968 ambito de aplicacion territorial.
Regulator Registration And FilingGreen
Qualifying databases (those administered for commercial distribution/dissemination or direct commercialization of personal data) must be registered with PRODHAB's Departamento de Archivo y Registro de Bases de Datos; purely internal databases and SUGEF-supervised financial-entity databases are exempt from registration (though not from PRODHAB oversight) following the 2016 reform.
Claims (2):
Following the 2016 reform, only databases administered for the purpose of distributing or disseminating personal data with commercial intent, or those that directly commercialize such data, must be registered with PRODHAB; internal databases are exempt from registration though still subject to the Law.
Databases of financial entities subject to the functional oversight of the Superintendencia General de Entidades Financieras (SUGEF) are exempt from the PRODHAB registration duty, without prejudice to remaining subject to PRODHAB's general control and oversight.
Category narrative122 words
Costa Rica operates a comprehensive omnibus data-protection regime under Law No. 8968 of 2011, enforced by PRODHAB, a decentralized body attached to the Ministry of Justice and Peace. <cite index="13-1">The Law governs data protection in Costa Rica and has been enforceable in relation to organizations and individuals since July 7, 2012.</cite> <cite index="41-4">Since mid-2014 PRODHAB, described as the maximum-decentralization body attached to the Ministry of Justice and Peace, has worked in practice to consolidate the rights and guarantees provided by the Law enacted in September 2011.</cite> Two further bills (No. 22.388 and No. 23.097) remain pending and would reform or replace parts of the current regime. Territorial/extraterritorial scope for non-established controllers could not be confirmed from available secondary sources in this run.
Sources and claims (6)
UncertainDataGuidance/OneTrust — PRODHAB (Agencia de Proteccion de Datos de los Habitantes) is Costa Rica's data protection authority, structured as a maximum-decentralization body attached to the Ministry of Justice and Peace, and is responsible for enforcing Law No. 8968.observed
UncertainDataGuidance/OneTrust — Law No. 8968 of 2011 has been enforceable in relation to organizations and individuals since July 7, 2012, and is complemented by Executive Decree No. 37554-JP of October 30, 2012, as amended by Decree No. 40008-JP of December 6, 2016.observed
UncertainDataGuidance/OneTrust — Two additional bills, No. 22.388 (a reform of the existing Law) and No. 23.097 (a new data protection law), were pending before the Legislative Assembly as of the most recent secondary-source review in April 2026, with neither yet enacted.observed
UncertainDataGuidance/OneTrust — Law No. 8968 is applicable to personal data contained in automated or manual databases.observed
UncertainInternational Association of Privacy Professionals — Following the 2016 reform, only databases administered for the purpose of distributing or disseminating personal data with commercial intent, or those that directly commercialize such data, must be registered with PRODHAB; internal databases are exempt from registration though still subject to the Law.observed
UncertainInternational Association of Privacy Professionals — Databases of financial entities subject to the functional oversight of the Superintendencia General de Entidades Financieras (SUGEF) are exempt from the PRODHAB registration duty, without prejudice to remaining subject to PRODHAB's general control and oversight.observed
Consent-centric lawful basis is well evidenced; special-categories and pseudonymisation sub-modules carry unresolved gaps requiring primary-text verification.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberConsent-centric lawful basis is well evidenced; special-categories and pseudonymisation sub-modules carry unresolved gaps requiring primary-text verification.
Sub-modules (4)
Lawful BasesGreen
Express consent is established as the central processing principle under the Law.
Claims (1):
Law No. 8968 establishes express consent of the data subject as a central lawful basis for processing, alongside a duty on controllers and processors to maintain adequate security safeguards.
Consent ThresholdsGreen
Consent must be individualized, specific, informed and freely given; in regulated sectors (e.g. fintech) it must be obtained in writing and disclose database purpose, recipients and transfer arrangements. The 2016 reform refined the statutory definition of informed consent.
Claims (2):
Controllers, illustrated in the regulated fintech sector, must obtain individualized, specific, informed and freely given written consent disclosing the database's purpose, recipients, transfer arrangements and the data subject's rights.
The 2016 regulatory reform (Decree No. 40008-JP) refined the statutory definitions of database, consent, technological intermediary, data transfer and the right to be forgotten.
Special CategoriesRed
No confirming secondary-source detail was located on the statutory definition/treatment of special or sensitive categories of personal data under Law No. 8968 in this run.
Absence provenance: unavailable. Searched: Ley 8968 Costa Rica datos sensibles categorias especiales consentimiento expreso.
Pseudonymisation And AnonymisationRed
No evidence of a statutory pseudonymisation or anonymisation safe-harbour regime was located.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 anonymizacion seudonimizacion datos personales.
Category narrative98 words
Express, informed consent of the data subject is the central lawful basis under Law No. 8968, reinforced by sector practice requiring individualized, specific, freely-given and (in regulated sectors) written consent. <cite index="87-4">The Law has introduced data subject rights, including the right to access, rectify, or delete personal data, established express consent of the data subject as a central principle, and has also required that controllers and processors ensure adequate security safeguards to protect data.</cite> Statutory detail on the treatment of special/sensitive categories and on pseudonymisation/anonymisation safe-harbours could not be confirmed from the secondary sources reviewed in this run.
Sources and claims (3)
UncertainDataGuidance/OneTrust — Law No. 8968 establishes express consent of the data subject as a central lawful basis for processing, alongside a duty on controllers and processors to maintain adequate security safeguards.observed
UncertainInternational Association of Privacy Professionals — Controllers, illustrated in the regulated fintech sector, must obtain individualized, specific, informed and freely given written consent disclosing the database's purpose, recipients, transfer arrangements and the data subject's rights.observed
UncertainDataGuidance/OneTrust — The 2016 regulatory reform (Decree No. 40008-JP) refined the statutory definitions of database, consent, technological intermediary, data transfer and the right to be forgotten.observed
Access/rectification/erasure rights are confirmed and in force; portability and opt-out remain proposed-only; deadlines are unconfirmed.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberAccess/rectification/erasure rights are confirmed and in force; portability and opt-out remain proposed-only; deadlines are unconfirmed.
Sub-modules (5)
Access RightGreen
Data subjects have a statutory right to access their personal data held in registered databases.
Claims (1):
Law No. 8968 grants data subjects the right to access personal data held about them in registered databases.
Rectification And ErasureGreen
Rights to rectify and delete personal data, including a right-to-be-forgotten concept refined in 2016, are in force.
Claims (1):
Law No. 8968 grants rights to rectify or delete personal data; the associated 'right to be forgotten' concept was further refined by the 2016 regulatory reform.
Restriction And ObjectionAmber
Data subjects may revoke previously given consent; controllers must facilitate exercise of this right.
Claims (1):
Data subjects may revoke consent previously given for processing, and controllers must facilitate the exercise of this right alongside access and modification rights.
Data PortabilityAmber
Portability is not yet a statutory right; it is proposed only under pending Bill No. 23097.
Claims (1):
Data portability is proposed, not currently in force: pending Bill No. 23097, introduced March 10, 2023, would introduce a portability right and a right to opt out of processing.
Deadlines And Response WindowsRed
No statutory response-window or deadline detail was confirmed from the sources reviewed.
Absence provenance: unavailable. Searched: Ley 8968 Costa Rica plazo respuesta derecho de acceso PRODHAB.
Category narrative99 words
Law No. 8968 grants data subjects rights of access, rectification and deletion, plus a right to revoke consent; a pending bill (No. 23097) would add data portability and an opt-out right, and a pending AI-regulation bill would reinforce ARCO rights specifically in AI-driven processing. <cite index="92-7,92-8">Bill No. 23097 for the Data Protection Law was introduced, on March 10, 2023, to the Costa Rica Legislative Assembly, and in particular introduces data subject rights such as the right to access, rectification, deletion, and data portability, as well as the right to opt-out of processing.</cite> Statutory response-window/deadline detail could not be confirmed.
Sources and claims (5)
UncertainDataGuidance/OneTrust — Law No. 8968 grants data subjects the right to access personal data held about them in registered databases.observed
UncertainDataGuidance/OneTrust — Law No. 8968 grants rights to rectify or delete personal data; the associated 'right to be forgotten' concept was further refined by the 2016 regulatory reform.observed
UncertainInternational Association of Privacy Professionals — Data subjects may revoke consent previously given for processing, and controllers must facilitate the exercise of this right alongside access and modification rights.observed
UncertainDataGuidance/OneTrust — Data portability is proposed, not currently in force: pending Bill No. 23097, introduced March 10, 2023, would introduce a portability right and a right to opt out of processing.observed
UncertainInternational Association of Privacy Professionals — Costa Rica's pending AI-regulation bill (analysed February 2026) would expressly reinforce data subjects' ARCO rights (access, rectification, cancellation and opposition) in AI-driven processing contexts, conditioning such processing on informed consent.observed
Security-safeguard and accountability/registration duties are confirmed and in force; breach notification, DPO and retention/disposal sub-modules are unconfirmed gaps.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberSecurity-safeguard and accountability/registration duties are confirmed and in force; breach notification, DPO and retention/disposal sub-modules are unconfirmed gaps.
Sub-modules (7)
Accountability And DpiaGreen
The 2016 reform reinforced the accountability principle by more precisely delimiting which databases must register under Article 21.
Claims (1):
The 2016 regulatory reform reinforced the accountability principle by more precisely delimiting the content of Article 21 of Law No. 8968, which governs which databases must be registered with PRODHAB.
Dpo RequirementsRed
No DPO appointment threshold or independence requirement was identified for Costa Rica.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 oficial de proteccion de datos DPO requisito.
Ropa RequirementsAmber
PRODHAB's database registry functions as the practical records-of-processing filing mechanism for qualifying databases.
Claims (1):
PRODHAB's Departamento de Archivo y Registro de Bases de Datos maintains a registry of qualifying databases, functioning as Costa Rica's equivalent to a records-of-processing filing mechanism.
Joint Controller ArrangementsGreen
The GIE (grupo de interes economico) concept, introduced in 2016, permits continuous intra-group personal-data transfers among corporate affiliates without triggering registration of 'internal' databases.
Claims (1):
The 2016 reform introduced the concept of a 'grupo de interes economico' (economic-interest group), permitting continuous and natural transfer of personal data among affiliates of multinational or local corporate groups for internal purposes without requiring registration of 'internal' databases.
Security MeasuresGreen
Controllers and processors must ensure adequate security safeguards to protect personal data.
Claims (1):
Law No. 8968 requires that controllers and processors ensure adequate security safeguards to protect personal data.
Breach NotificationRed
No general mandatory security-breach notification duty to PRODHAB or to affected data subjects, analogous to GDPR Articles 33-34, was identified in the secondary sources reviewed.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 notificacion de brecha de seguridad PRODHAB plazo.
Retention And DisposalRed
No specific statutory retention-limit or disposal duty was confirmed.
Absence provenance: unavailable. Searched: Ley 8968 Costa Rica plazo de conservacion de datos eliminacion.
Category narrative66 words
Controllers and processors must maintain adequate security safeguards and, following the 2016 reform, are subject to a more precisely delimited registration/accountability duty under Article 21 of Law No. 8968; the 2016 reform also introduced the 'grupo de interes economico' (GIE) concept enabling intra-group transfers without triggering registration for internal databases. No mandatory breach-notification duty, DPO threshold, or retention-limit rule could be confirmed from the sources reviewed.
Sources and claims (4)
UncertainInternational Association of Privacy Professionals — The 2016 regulatory reform reinforced the accountability principle by more precisely delimiting the content of Article 21 of Law No. 8968, which governs which databases must be registered with PRODHAB.observed
UncertainInternational Association of Privacy Professionals — PRODHAB's Departamento de Archivo y Registro de Bases de Datos maintains a registry of qualifying databases, functioning as Costa Rica's equivalent to a records-of-processing filing mechanism.observed
UncertainInternational Association of Privacy Professionals — The 2016 reform introduced the concept of a 'grupo de interes economico' (economic-interest group), permitting continuous and natural transfer of personal data among affiliates of multinational or local corporate groups for internal purposes without requiring registration of 'internal' databases.observed
UncertainDataGuidance/OneTrust — Law No. 8968 requires that controllers and processors ensure adequate security safeguards to protect personal data.observed
Only the general transfer-conditions reform is confirmed; five of six sub-modules (adequacy received/granted, SCCs/BCRs, TIA, localisation) carry unresolved gaps.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended by Decree No. 40008-JP of 2016)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — RedOnly the general transfer-conditions reform is confirmed; five of six sub-modules (adequacy received/granted, SCCs/BCRs, TIA, localisation) carry unresolved gaps.
Sub-modules (6)
Transfer MechanismsAmber
The 2016 reform amended the statutory conditions for data transfers, aiming for greater transfer fluidity while preserving PRODHAB oversight.
Claims (1):
The 2016 regulatory reform amended the conditions governing personal-data transfers under Law No. 8968, seeking greater fluidity in transfer and commercialization of personal data while preserving PRODHAB's oversight competences.
Adequacy ReceivedRed
No adequacy decision covering Costa Rica issued by the European Commission or another regime was identified.
Absence provenance: unavailable. Searched: Costa Rica adecuacion datos personales Union Europea decision de adecuacion.
Adequacy GrantedRed
No evidence that PRODHAB maintains an outbound adequacy whitelist of other jurisdictions.
Absence provenance: unavailable. Searched: PRODHAB lista de paises con nivel adecuado de proteccion.
Sccs And BcrsRed
No SCC- or BCR-equivalent instrument under Costa Rican law was identified.
Absence provenance: unavailable. Searched: Costa Rica clausulas contractuales tipo normas corporativas vinculantes.
Transfer Impact AssessmentRed
No transfer-impact-assessment-equivalent duty was identified.
Absence provenance: unavailable. Searched: Costa Rica evaluacion de impacto de transferencia internacional de datos.
Data LocalisationAmber
No general data-localisation mandate was identified; the GIE intra-group transfer provisions suggest a permissive rather than localisation-oriented approach, though this is an inference rather than a confirmed express statutory rule.
Claims (1):
No general data-localisation mandate applicable to corporate-group data transfers under Costa Rican law was identified; the 2016 GIE provisions instead facilitate continuous intra-group cross-border transfer.
Category narrative61 words
The 2016 reform amended the conditions governing personal-data transfers under Law No. 8968 with the stated aim of generating greater fluidity in the transfer and commercialization of personal data while preserving PRODHAB's control competences. No adequacy decision received from or granted to another regime, SCC/BCR-equivalent instrument, transfer-impact-assessment duty, or data-localisation mandate could be confirmed from the sources reviewed in this run.
Sources and claims (2)
UncertainInternational Association of Privacy Professionals — The 2016 regulatory reform amended the conditions governing personal-data transfers under Law No. 8968, seeking greater fluidity in transfer and commercialization of personal data while preserving PRODHAB's oversight competences.observed
UncertainInternational Association of Privacy Professionals — No general data-localisation mandate applicable to corporate-group data transfers under Costa Rican law was identified; the 2016 GIE provisions instead facilitate continuous intra-group cross-border transfer.observed
Financial-sector overlay is well evidenced (statute plus a concrete 2023 enforcement precedent); other sector sub-modules are unconfirmed gaps.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — AmberFinancial-sector overlay is well evidenced (statute plus a concrete 2023 enforcement precedent); other sector sub-modules are unconfirmed gaps.
Sub-modules (7)
Financial Sector OverlayGreen
SUGEF-supervised financial entities are exempt from PRODHAB registration but remain subject to its oversight; PRODHAB has exercised that oversight against the Banco Central de Costa Rica.
Claims (2):
Databases of SUGEF-supervised financial entities are exempt from PRODHAB's registration duty while remaining subject to PRODHAB's general control and enforcement powers.
On August 28, 2023, PRODHAB issued Resolution No. 697-2023, a precautionary measure suspending the Banco Central de Costa Rica's request for comprehensive credit-operation data, including identification documents, from supervised financial intermediaries, following a complaint by consumer association Asodidcu.
Health Sector OverlayRed
No health-sector-specific data protection overlay was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos salud sector sanitario ley especial.
Telecoms And EprivacyAmber
No current telecoms/ePrivacy-specific regime exists; the pending AI-regulation bill (Feb 2026 analysis) indicates it may contain telecom-user privacy provisions.
Claims (1):
Costa Rica's pending AI-regulation bill, analysed in February 2026, may include provisions related to protecting the privacy of telecommunications-service users, though no enacted telecoms/ePrivacy-specific regime currently exists.
Employment DataRed
No employment-sector-specific data protection rule was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos personales laborales empleados.
Credit And ScoringAmber
The Banco Central/PRODHAB dispute directly concerned personal credit-operation data from supervised financial intermediaries, illustrating PRODHAB jurisdiction over credit-data flows absent a dedicated credit-reporting statute.
Claims (1):
The 2023 Banco Central/PRODHAB dispute concerned personal credit-operation data supplied by supervised financial intermediaries, illustrating PRODHAB's jurisdiction over credit-data flows in the absence of a dedicated credit-reporting statute.
EducationRed
No education-sector-specific data protection rule was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos personales estudiantes centros educativos.
InsuranceRed
No insurance-sector-specific data protection rule was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos personales sector seguros.
Category narrative94 words
Financial-sector personal data is the best-evidenced sectoral overlay: SUGEF-supervised entities' databases are exempt from PRODHAB's registration duty but remain subject to its general control, as illustrated by PRODHAB's August 2023 precautionary-measure Resolution No. 697-2023 restricting a Banco Central de Costa Rica request for comprehensive credit-operation data. <cite index="61-6">On August 28, 2023, PRODHAB issued Resolution No. 697-2023, granting a precautionary measure described as marking a significant precedent for personal data protection in the country.</cite> No health, telecoms/ePrivacy (beyond a prospective reference in the pending AI bill), employment, education, or insurance sectoral overlay could be confirmed.
Sources and claims (4)
UncertainInternational Association of Privacy Professionals — Databases of SUGEF-supervised financial entities are exempt from PRODHAB's registration duty while remaining subject to PRODHAB's general control and enforcement powers.observed
UncertainInternational Association of Privacy Professionals — On August 28, 2023, PRODHAB issued Resolution No. 697-2023, a precautionary measure suspending the Banco Central de Costa Rica's request for comprehensive credit-operation data, including identification documents, from supervised financial intermediaries, following a complaint by consumer association Asodidcu.observed
UncertainInternational Association of Privacy Professionals — Costa Rica's pending AI-regulation bill, analysed in February 2026, may include provisions related to protecting the privacy of telecommunications-service users, though no enacted telecoms/ePrivacy-specific regime currently exists.observed
UncertainInternational Association of Privacy Professionals — The 2023 Banco Central/PRODHAB dispute concerned personal credit-operation data supplied by supervised financial intermediaries, illustrating PRODHAB's jurisdiction over credit-data flows in the absence of a dedicated credit-reporting statute.observed
No on-point sources found across any of the six declared sub-modules despite targeted search; this is treated as a genuine regulatory gap pending primary-text verification.
Traffic-light rationale — RedNo on-point sources found across any of the six declared sub-modules despite targeted search; this is treated as a genuine regulatory gap pending primary-text verification.
Sub-modules (6)
Cookies And TrackersRed
No cookie/tracker-consent-specific rule identified.
Absence provenance: unavailable. Searched: Costa Rica ley cookies consentimiento rastreo web.
No Global-Privacy-Control or DAA-equivalent opt-out signal regime identified.
Absence provenance: unavailable. Searched: Costa Rica senal de exclusion global privacy control.
Clean Rooms And DcrRed
No clean-room / data-collaboration-room rule identified.
Absence provenance: unavailable. Searched: Costa Rica sala de datos limpia colaboracion de datos regulacion.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' cross-context-advertising regime identified.
Absence provenance: unavailable. Searched: Costa Rica venta de datos personales publicidad cruzada regulacion.
Direct MarketingRed
No marketing-specific consent or suppression rule beyond Law No. 8968's general consent principle was confirmed.
Claims (1):
No dedicated direct-marketing consent or suppression statute was identified for Costa Rica; marketing databases would fall under Law No. 8968's general consent and registration requirements absent a marketing-specific rule.
Category narrative54 words
No dedicated adtech-specific instrument (cookie-consent statute, dark-pattern prohibition, Global-Privacy-Control-equivalent opt-out signal regime, clean-room rules, or CPRA-style 'sale/share' cross-context-advertising regime) was identified for Costa Rica. Commercial databases used for marketing purposes would fall under Law No. 8968's general consent and registration requirements, but no marketing-specific suppression or consent-threshold rule beyond that general framework was confirmed.
Sources and claims (1)
UncertainDataGuidance/OneTrust — No dedicated direct-marketing consent or suppression statute was identified for Costa Rica; marketing databases would fall under Law No. 8968's general consent and registration requirements absent a marketing-specific rule.observed
No current in-force ADM/biometric/AI-specific regime exists, but an active, recently-analysed 2026 AI bill directly targets this module, warranting amber rather than red.
Traffic-light rationale — AmberNo current in-force ADM/biometric/AI-specific regime exists, but an active, recently-analysed 2026 AI bill directly targets this module, warranting amber rather than red.
Sub-modules (6)
Profiling RestrictionsRed
No current profiling restriction analogous to GDPR Article 22 was identified under Law No. 8968.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 restriccion de perfilamiento decisiones automatizadas.
Automated Decision Making TransparencyAmber
No current ADM transparency right exists; the pending AI bill would reinforce ARCO rights in AI-driven processing.
Claims (1):
Costa Rica's pending AI-regulation bill would condition personal-data processing on informed consent and expressly reinforce ARCO rights (access, rectification, cancellation and opposition) in AI-driven processing.
Ai Risk AssessmentsAmber
The pending AI-regulation bill would create ARIA and a proportional sanctions regime for AI-related non-compliance.
Claims (1):
The pending AI-regulation bill contemplates creating an Autoridad Reguladora de Inteligencia Artificial (ARIA) to supervise compliance and set technical/ethical AI guidelines, with proportional and dissuasive sanctions including fines and temporary or permanent prohibitions for non-compliance.
Biometric RegimeRed
No biometric-data-specific regime (facial recognition, fingerprint, gait) was identified.
Absence provenance: unavailable. Searched: Costa Rica regulacion datos biometricos reconocimiento facial.
Genetic DataRed
No genetic-data-specific regime was identified; overlaps with the unconfirmed special-categories gap in lawful_processing_and_special_data.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 datos geneticos regimen especial.
State Surveillance CarveoutsRed
No state-surveillance national-security carve-out provision was identified.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 excepcion seguridad nacional vigilancia estatal.
Category narrative100 words
Law No. 8968 currently contains no Article-22-equivalent profiling restriction, ADM transparency right, AI-specific risk-assessment duty, or biometric/genetic-data regime that could be confirmed. Costa Rica's pending AI-regulation bill (analysed by IAPP on February 17, 2026) would create an Autoridad Reguladora de Inteligencia Artificial (ARIA) tasked with supervising compliance and setting technical/ethical AI guidelines, condition personal-data processing on informed consent, reinforce ARCO rights, and establish proportional and dissuasive sanctions for non-compliance. <cite index="96-4">The bill also contemplates the creation of an Autoridad Reguladora de Inteligencia Artificial (ARIA), tasked with overseeing regulatory compliance and establishing technical and ethical guidelines for AI development and use.</cite>
Sources and claims (2)
UncertainInternational Association of Privacy Professionals — Costa Rica's pending AI-regulation bill would condition personal-data processing on informed consent and expressly reinforce ARCO rights (access, rectification, cancellation and opposition) in AI-driven processing.observed
UncertainInternational Association of Privacy Professionals — The pending AI-regulation bill contemplates creating an Autoridad Reguladora de Inteligencia Artificial (ARIA) to supervise compliance and set technical/ethical AI guidelines, with proportional and dissuasive sanctions including fines and temporary or permanent prohibitions for non-compliance.observed
Genuine absence of findings across all five declared sub-modules; flagged explicitly rather than silently omitted.
Traffic-light rationale — Not assessedGenuine absence of findings across all five declared sub-modules; flagged explicitly rather than silently omitted.
Sub-modules (5)
Age VerificationRed
No age-of-consent-for-processing threshold was identified.
Absence provenance: unavailable. Searched: Costa Rica Ley 8968 edad de consentimiento menores tratamiento de datos.
Parental ConsentRed
No parental-consent mechanism analogous to GDPR Article 8 or COPPA was identified.
Absence provenance: unavailable. Searched: Costa Rica consentimiento parental proteccion datos menores.
Minor Profiling BansRed
No minor-profiling ban was identified.
Absence provenance: unavailable. Searched: Costa Rica prohibicion perfilamiento de menores.
Education SettingsRed
No education-setting-specific rule was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos personales centros educativos estudiantes menores.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated) protection provision was identified.
Absence provenance: unavailable. Searched: Costa Rica proteccion datos personas mayores incapacitadas.
Category narrative31 words
No child- or vulnerable-group-specific data protection provision (age of consent, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection) could be confirmed for Costa Rica in this run despite targeted search.
Regulator powers, a concrete 2023 enforcement precedent, a constitutional private-right-of-action route, and a within-180-day AI-bill development are all confirmed; funding/capacity and collective-redress detail remain thinner.
Primary frameworkLaw No. 8968 of 2011 and Executive Decree No. 37554-JP (as amended)
Supervisory authorityPRODHAB (Agencia de Protección de Datos de los Habitantes)
Traffic-light rationale — GreenRegulator powers, a concrete 2023 enforcement precedent, a constitutional private-right-of-action route, and a within-180-day AI-bill development are all confirmed; funding/capacity and collective-redress detail remain thinner.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
PRODHAB may impose administrative fines for non-compliance and issue precautionary measures during rights-protection proceedings.
Claims (2):
Failure to comply with Law No. 8968 and its consent/registration obligations could lead to administrative fines imposed by PRODHAB.
Under Law No. 8968, PRODHAB may issue precautionary measures (medidas cautelares) when necessary to secure the effective outcome of a rights-protection proceeding.
Enforcement Activity IndexAmber
PRODHAB's August 2023 Resolution No. 697-2023 is characterized by commentators as a significant enforcement precedent.
Claims (1):
PRODHAB's Resolution No. 697-2023, issued August 28, 2023, granting a precautionary measure against the Banco Central de Costa Rica, is described as marking a significant precedent for data protection enforcement in the country.
Regulator Funding And CapacityRed
No funding or headcount data for PRODHAB was identified.
Absence provenance: unavailable. Searched: PRODHAB Costa Rica presupuesto personal capacidad.
Collective Redress And Class ActionsAmber
A consumer association (Asodidcu) brought the complaint underlying Resolution No. 697-2023 on behalf of affected data subjects, suggesting a practical associative-complaint avenue, though no dedicated statutory class-action mechanism was confirmed.
Claims (1):
The complaint underlying Resolution No. 697-2023 was filed by the consumer association Asodidcu on behalf of affected financial-sector data subjects, indicating associative complaints to PRODHAB are a practical avenue for collective redress, though no dedicated statutory class-action mechanism was confirmed.
Private Right Of ActionGreen
The Constitutional Court has recognized and protected the right to data protection since the 1990s on the basis of Article 24 of the Constitution, providing a constitutional-remedy route independent of the PRODHAB administrative process.
Claims (1):
The right to data protection has been recognized and protected in Costa Rica by the Constitutional Court since the 1990s on the basis of Article 24 of the Political Constitution, providing a constitutional remedy independent of the PRODHAB administrative process.
Recent Developments 180DGreen
Within the last 180 days, IAPP published an analysis (February 17, 2026) of Costa Rica's pending AI-regulation bill, and DataGuidance (April 2026) confirmed Bill No. 23097 remains pending.
Claims (2):
IAPP published an analysis on February 17, 2026 of Costa Rica's proposed AI-regulation bill, which would create an AI Regulatory Authority (ARIA) and directly interfaces with the existing data protection framework via informed consent and ARCO-rights provisions.
As of an April 2026 secondary-source review, Bill No. 23097 (introduced March 10, 2023), which would add data portability and opt-out rights, remained pending before the Legislative Assembly with no indication of enactment.
Category narrative123 words
PRODHAB may impose administrative fines and issue precautionary measures (medidas cautelares) to secure the effective outcome of rights-protection proceedings, as demonstrated by the August 2023 Resolution No. 697-2023 against the Banco Central de Costa Rica. <cite index="61-2">Under Law No. 8968 of Protection of the Person against the Processing of their Personal Data, such measures may be ordered by the Data Protection Agency when necessary to secure the effective outcome of a rights-protection proceeding.</cite> A constitutional remedy route via the Sala Constitucional, recognized since the 1990s under Article 24 of the Constitution, provides an independent private right of action. The most significant recent development is the February 2026 IAPP analysis of Costa Rica's pending AI-regulation bill, which directly interfaces with the data protection framework.
Sources and claims (7)
UncertainInternational Association of Privacy Professionals — Failure to comply with Law No. 8968 and its consent/registration obligations could lead to administrative fines imposed by PRODHAB.observed
UncertainInternational Association of Privacy Professionals — Under Law No. 8968, PRODHAB may issue precautionary measures (medidas cautelares) when necessary to secure the effective outcome of a rights-protection proceeding.observed
UncertainInternational Association of Privacy Professionals — PRODHAB's Resolution No. 697-2023, issued August 28, 2023, granting a precautionary measure against the Banco Central de Costa Rica, is described as marking a significant precedent for data protection enforcement in the country.observed
UncertainInternational Association of Privacy Professionals — The complaint underlying Resolution No. 697-2023 was filed by the consumer association Asodidcu on behalf of affected financial-sector data subjects, indicating associative complaints to PRODHAB are a practical avenue for collective redress, though no dedicated statutory class-action mechanism was confirmed.observed
UncertainDataGuidance/OneTrust — The right to data protection has been recognized and protected in Costa Rica by the Constitutional Court since the 1990s on the basis of Article 24 of the Political Constitution, providing a constitutional remedy independent of the PRODHAB administrative process.observed
UncertainInternational Association of Privacy Professionals — IAPP published an analysis on February 17, 2026 of Costa Rica's proposed AI-regulation bill, which would create an AI Regulatory Authority (ARIA) and directly interfaces with the existing data protection framework via informed consent and ARCO-rights provisions.observed
UncertainDataGuidance/OneTrust — As of an April 2026 secondary-source review, Bill No. 23097 (introduced March 10, 2023), which would add data portability and opt-out rights, remained pending before the Legislative Assembly with no indication of enactment.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 3 failing check(s).
schema_valid
pass
min_architecture_patterns
0
min_red_flags
0
min_controls
0
worked_examples_count
0
decision_tree_nodes
0
counterparty_diligence_questions
0
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
board_briefing_present
FAIL
every_practical_object_has_source_id
FAIL
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Costa Rica
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (34 category placement(s)), 9 source(s) in the cumulative register.
Audit trail
Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.
No Tier-1 primary source (official La Gaceta text of Law No. 8968, the Executive Decrees, or the PRODHAB regulator homepage) could be directly retrieved in this run; all findings rest on Tier-3 secondary legal-intelligence commentary (DataGuidance notes/jurisdiction pages and IAPP articles), including a recent February 2026 IAPP analysis of a pending AI-regulation bill that falls within the 180-day recent-developments window. regulator_and_framework, data_subject_rights, controller_processor_duties (partially), sectoral_watch (financial sub-module), and enforcement_and_redress modules have multiple corroborating T3 sources with reasonable confidence. cross_border_and_adequacy, adtech_and_commercial_privacy, and children_and_vulnerable_groups modules returned little to no on-point evidence despite targeted search and are flagged module-wide with absent_field_provenance rather than silently omitted. algorithmic_biometric_and_surveillance_governance relies heavily on a single pending-bill source rather than in-force law.
Unresolved questions (8):
Does Law No. 8968 or its Executive Decree impose a mandatory security-breach notification duty to PRODHAB and/or affected data subjects, and if so within what timeline?
What is the statutory definition and treatment of special/sensitive categories of personal data (health, biometric, genetic, ethnic, political, sexual, criminal) under Law No. 8968?
Is there a DPO-equivalent appointment threshold or independence requirement under Costa Rican law?
Has the European Commission or any other data protection regime issued an adequacy determination covering Costa Rica, or has PRODHAB issued its own outbound adequacy whitelist?
What is the current legislative status of Bill No. 22.388 and Bill No. 23.097 as of the run date, and is either likely to be enacted in the near term?
Does Law No. 8968 or the pending AI-regulation bill contain any child/minor-specific consent, age-verification, or profiling provisions?
Does Costa Rica impose any data-localisation requirement for specific sectors (e.g., financial, health) beyond the general GIE intra-group transfer allowance?
What are PRODHAB's current funding, headcount, and case-processing-capacity figures?