🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
DO v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing5 sources retrieved model claude-sonnet-5 · 2026-08-05

Dominican Republic

DO schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM

Last updated · 10 categories · 11 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
11Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Standing brief, as of 14 September 2026.

Lead Signal

The Dominican Republic's data-protection landscape saw a notable, if aspirational, development this cycle: Agenda Digital 2030, a national digital-transformation policy framework, contemplates a comprehensive reform of the Data Protection Law, Ley 172-13. Reports suggest this reform aspiration may be under discussion within policy circles, though no primary legislative text, committee assignment, or enacted change has been identified, and the finding rests on academic commentary rather than a government or legislative source. The Dominican Republic's standing legal architecture remains what it has been: Ley 172-13 is oriented primarily toward regulating Sociedades de Información Crediticia, credit-information societies that require prior authorisation from the Junta Monetaria under Article 30, rather than functioning as a comprehensive omnibus data-protection statute in the style of the GDPR or similar regimes.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute exists and is in force, but institutional enforcement is fragmented and there is no dedicated supervisory authority, which weakens practical oversight.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA comprehensive statute exists and is in force, but institutional enforcement is fragmented and there is no dedicated supervisory authority, which weakens practical oversight.

Sub-modules (5)

Regulator And AuthorityAmber

No single dedicated DPA exists, but INDOTEL's supervisory role over regulated entities rests on a formal instrument (Resolution No. 055-06, Complementary Regulation to Law 126-02) granting inspection and sanctioning authority, not a purely informal arrangement; Pro Consumidor and the Superintendencia de Bancos exercise adjacent, non-exclusive oversight, and courts hear habeas data claims. Primary-instrument scope verification remains outstanding.

Claims (1):

  • The Dominican Republic has no single dedicated data protection authority; enforcement-adjacent functions are shared informally among INDOTEL, Pro Consumidor and sector regulators such as the Superintendencia de Bancos.

Act And InstrumentsGreen

Law No. 172-13 (2013) is the principal comprehensive instrument governing personal data processing in archives, registries, databases and reporting systems, public or private.

Claims (1):

  • Law No. 172-13 (2013) is the Dominican Republic's principal comprehensive data protection statute.

Material ScopeGreen

The Law applies to personal data contained in archives, public registries, databases or other technical means of data processing used for reporting, whether held by public or private entities.

Claims (1):

  • Law 172-13 applies to personal data contained in archives, public registries, databases or other technical means of data processing used for reporting, whether public or private.

Territorial ScopeRed

No explicit extraterritorial-application clause analogous to GDPR Art. 3 has been identified in Law 172-13 from the sources reviewed.

Absence provenance: unavailable. Searched: Law 172-13 territorial scope extraterritorial application, Dominican Republic data protection law foreign controllers.

Regulator Registration And FilingRed

No confirmed general controller-registration/filing obligation with a central authority was identified for Law 172-13 in the sources reviewed; this module element requires primary-text verification.

Absence provenance: unavailable. Searched: Dominican Republic database registration requirement 172-13, Ley 172-13 registro de bases de datos.

Category narrative78 words

The Dominican Republic's data-protection regime rests on Law No. 172-13 (2013), a comprehensive statute covering personal data held in archives, public registries, databases and other technical processing means used for reporting purposes, whether public or private. Unlike GDPR-style regimes, the DR has no single dedicated data protection authority; enforcement responsibility is fragmented across INDOTEL (telecommunications regulator), Pro Consumidor (consumer protection body) and sectoral bodies such as the Superintendencia de Bancos, with ultimate recourse via judicial habeas data/amparo actions.

Sources and claims (3)
  1. ProbableDataGuidance — The Dominican Republic has no single dedicated data protection authority; enforcement-adjacent functions are shared informally among INDOTEL, Pro Consumidor and sector regulators such as the Superintendencia de Bancos.observed
  2. ConfirmedDataGuidance — Law No. 172-13 (2013) is the Dominican Republic's principal comprehensive data protection statute.observed
  3. ConfirmedDataGuidance — Law 172-13 applies to personal data contained in archives, public registries, databases or other technical means of data processing used for reporting, whether public or private.observed

#

Core consent and special-category concepts are present by general regional pattern but granular basis-by-basis detail is unverified from available sources.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberCore consent and special-category concepts are present by general regional pattern but granular basis-by-basis detail is unverified from available sources.

Sub-modules (4)

Lawful BasesAmber

Law 172-13 is understood to require a lawful basis (typically consent, legal obligation, or public-source data) for processing, consistent with regional habeas-data statutes, though an explicit enumerated list akin to GDPR Art. 6 was not directly confirmed in the sources reviewed.

Absence provenance: unavailable. Searched: Ley 172-13 bases legales tratamiento datos.

Special CategoriesAmber

Sensitive/special category data (health, ideology, sexual life, criminal record) is understood to receive heightened protection under Latin American habeas-data statutes of this era; specific DR statutory text confirming this was not directly retrieved in this run.

Absence provenance: unavailable. Searched: Ley 172-13 datos sensibles categorías especiales.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation definitions or safe-harbour provisions were identified for Law 172-13 in the sources reviewed.

Absence provenance: unavailable. Searched: Ley 172-13 anonimización seudonimización.

Category narrative49 words

Law 172-13, as a habeas-data-style Latin American statute, embeds consent as the central lawful basis for processing, with heightened protection for sensitive/special categories of data. Detailed enumerated lawful bases equivalent to GDPR Art. 6, and formal pseudonymisation/anonymisation safe-harbours, were not confirmed in the sources reviewed and require primary-text verification.

#

Core ARCO-style rights are plausible under the habeas data framework but explicit textual confirmation of scope and deadlines is incomplete.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberCore ARCO-style rights are plausible under the habeas data framework but explicit textual confirmation of scope and deadlines is incomplete.

Sub-modules (5)

Access RightAmber

A right of access to one's personal data is expected under the habeas-data constitutional tradition underlying Law 172-13; explicit statutory text was not directly retrieved this run.

Absence provenance: unavailable. Searched: Ley 172-13 derecho de acceso datos personales.

Rectification And ErasureAmber

Rectification/erasure rights are typical of habeas-data statutes in the region; independent confirmation of DR-specific statutory text was not obtained this run.

Absence provenance: unavailable. Searched: Ley 172-13 derecho de rectificación cancelación.

Restriction And ObjectionRed

No confirmed statutory restriction-of-processing or objection/profiling opt-out mechanism was located for Law 172-13 in this run.

Absence provenance: unavailable. Searched: Ley 172-13 derecho de oposición limitación tratamiento.

Data PortabilityRed

No data portability right was identified in Law 172-13, consistent with it predating the GDPR-era portability concept (law enacted 2013).

Absence provenance: unavailable. Searched: Ley 172-13 portabilidad de datos.

Deadlines And Response WindowsRed

No confirmed statutory response-window/deadline for controller responses to data subject requests was located for Law 172-13 in this run.

Absence provenance: unavailable. Searched: Ley 172-13 plazo respuesta solicitud titular datos.

Category narrative44 words

Law 172-13 is rooted in the constitutional habeas data tradition and is expected to afford data subjects access, rectification and objection-style rights; however, granular statutory deadlines, an explicit portability right, and a restriction-of-processing right were not independently confirmed in the sources retrieved this run.

#

A security principle exists (confirmed), but modern accountability tooling (DPIA/DPO/ROPA) and mandatory breach notification are absent, indicating a materially lighter-touch regime than GDPR-aligned jurisdictions.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA security principle exists (confirmed), but modern accountability tooling (DPIA/DPO/ROPA) and mandatory breach notification are absent, indicating a materially lighter-touch regime than GDPR-aligned jurisdictions.

Sub-modules (7)

Accountability And DpiaRed

No DPIA obligation or general accountability/documentation regime analogous to GDPR Art. 5/35 was identified for Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 evaluación de impacto protección datos.

Dpo RequirementsRed

No statutory Data Protection Officer appointment threshold was identified for Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 oficial de protección de datos.

Ropa RequirementsRed

No confirmed records-of-processing (ROPA) obligation was located for Law 172-13 in this run.

Absence provenance: unavailable. Searched: Ley 172-13 registro de actividades de tratamiento.

Joint Controller ArrangementsRed

No joint-controller framework analogous to GDPR Art. 26 was identified for Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 corresponsables tratamiento.

Security MeasuresGreen

Law 172-13 establishes a security principle applicable to data controllers, requiring appropriate safeguards for personal data held in archives, registries and databases.

Claims (1):

  • Law 172-13 establishes a security principle applicable to data controllers with respect to personal data held in archives, registries and databases.

Breach NotificationRed

Law 172-13 does not impose an obligation on controllers to notify data subjects or any administrative/judicial authority of a data breach; any such notice is voluntary and considered good practice rather than a legal duty.

Claims (1):

  • Law 172-13 does not impose an obligation on data controllers to notify a data breach to the data subject or to any administrative or judicial authority; notice is voluntary/best-practice only.

Retention And DisposalRed

No confirmed statutory retention-limit or disposal-duty provision was located for Law 172-13 in this run.

Absence provenance: unavailable. Searched: Ley 172-13 plazo de conservación de datos.

Category narrative52 words

Law 172-13 establishes a general security-of-processing principle for controllers but does not impose a breach-notification obligation to data subjects or authorities; breach notice is voluntary/best-practice only. DPIA, DPO, ROPA and joint-controller obligations analogous to GDPR were not confirmed in the sources reviewed and likely do not exist in the current 2013-era statute.

Sources and claims (2)
  1. ConfirmedDataGuidance — Law 172-13 establishes a security principle applicable to data controllers with respect to personal data held in archives, registries and databases.observed
  2. ConfirmedDataGuidance — Law 172-13 does not impose an obligation on data controllers to notify a data breach to the data subject or to any administrative or judicial authority; notice is voluntary/best-practice only.observed

#

No confirmed transfer-mechanism framework, adequacy status, or localisation mandate was located; this is a genuine regulatory gap rather than an omission, consistent with the statute's 2013-era scope.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — Not assessedNo confirmed transfer-mechanism framework, adequacy status, or localisation mandate was located; this is a genuine regulatory gap rather than an omission, consistent with the statute's 2013-era scope.

Sub-modules (6)

Transfer MechanismsRed

No specific cross-border data transfer mechanism (adequacy, SCCs, BCRs, derogations) was identified in Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 transferencia internacional de datos.

Adequacy ReceivedRed

The Dominican Republic has not been identified as a recipient of an EU adequacy decision in the sources reviewed.

Absence provenance: unavailable. Searched: European Commission adequacy decisions list Dominican Republic.

Adequacy GrantedRed

No mechanism by which the Dominican Republic grants adequacy status to other jurisdictions was identified.

Absence provenance: unavailable. Searched: Dominican Republic adequacy decision granted other countries.

Sccs And BcrsRed

No SCC or BCR framework was identified under Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 cláusulas contractuales tipo normas corporativas vinculantes.

Transfer Impact AssessmentRed

No transfer impact assessment requirement was identified under Law 172-13.

Absence provenance: unavailable. Searched: Ley 172-13 evaluación de impacto de transferencia.

Data LocalisationRed

No general data-localisation mandate was identified for personal data under Law 172-13; sector-specific banking-data location rules under the financial regulator were not independently confirmed in this run.

Absence provenance: unavailable. Searched: Dominican Republic data localisation requirement banking financial data.

Category narrative45 words

Law 172-13 predates the modern SCC/BCR/TIA transfer-mechanism architecture, and no confirmed cross-border transfer regime, adequacy decision (received or granted), or data-localisation mandate specific to general personal data was identified in the sources reviewed. The Dominican Republic does not appear on published EU adequacy decision lists.

#

Financial and credit-reporting overlays are reasonably well evidenced; other sectoral overlays (health, employment, education, insurance) remain unconfirmed gaps.

Primary frameworkLaw No. 172-13 (2013); Monetary and Financial Law No. 183-02
Supervisory authoritySuperintendencia de Bancos de la República Dominicana
Traffic-light rationale — AmberFinancial and credit-reporting overlays are reasonably well evidenced; other sectoral overlays (health, employment, education, insurance) remain unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayAmber

Monetary and Financial Law No. 183-02 establishes the regulatory and institutional framework for the Dominican monetary and financial system, under which the Superintendencia de Bancos oversees confidentiality of banking-related personal/financial data.

Claims (1):

  • Monetary and Financial Law No. 183-02 establishes the regulatory and institutional framework for the Dominican monetary and financial system, under which banking-sector personal/financial data confidentiality is supervised.

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in the sources reviewed for this run.

Absence provenance: unavailable. Searched: Dominican Republic health data law confidentiality Ley General de Salud.

Telecoms And EprivacyAmber

INDOTEL, the Dominican Telecommunications Institute, exercises a regulatory role touching on data/consumer protection in electronic commerce, evidenced by its joint 2019 e-commerce guidance with Pro Consumidor addressing personal and financial data safeguards for online consumers.

Claims (1):

  • INDOTEL and Pro Consumidor jointly released e-commerce guidance in November 2019 outlining best practices for consumers to protect personal and financial data and prevent data/identity theft in online transactions.

Employment DataRed

No employment-sector-specific data protection code was confirmed for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic labor code employee data protection.

Credit And ScoringAmber

Law 172-13's formal title references its application to databases used for reporting, indicating the statute's origins are closely tied to credit-bureau/credit-reporting data practices.

Claims (1):

  • Law 172-13's formal title covers databases used for reporting, indicating the statute's close historical linkage to credit-bureau/credit-reporting data practices.

EducationRed

No education-sector-specific data protection rules were confirmed for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic student data protection education law.

InsuranceRed

No insurance-sector-specific data protection rules were confirmed for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic insurance sector data protection rules.

Category narrative66 words

The financial sector is overlaid by Monetary and Financial Law No. 183-02, which establishes the regulatory and institutional framework for the Dominican monetary and financial system including bank confidentiality obligations. Law 172-13's own title indicates a strong original focus on databases used for credit reporting. Telecommunications-related data practices intersect with INDOTEL's mandate. Health, employment, education and insurance sector-specific data overlays were not confirmed in this run.

Sources and claims (3)
  1. ProbableDataGuidance (hosted translated primary text) — Monetary and Financial Law No. 183-02 establishes the regulatory and institutional framework for the Dominican monetary and financial system, under which banking-sector personal/financial data confidentiality is supervised.observed
  2. ConfirmedDataGuidance — INDOTEL and Pro Consumidor jointly released e-commerce guidance in November 2019 outlining best practices for consumers to protect personal and financial data and prevent data/identity theft in online transactions.observed
  3. ConfirmedDataGuidance — Law 172-13's formal title covers databases used for reporting, indicating the statute's close historical linkage to credit-bureau/credit-reporting data practices.observed

#

No binding adtech-specific commercial privacy framework exists; only non-binding consumer guidance was located.

Traffic-light rationale — RedNo binding adtech-specific commercial privacy framework exists; only non-binding consumer guidance was located.

Sub-modules (6)

Cookies And TrackersAmber

No binding cookie/tracker consent regime was identified; the 2019 INDOTEL/Pro Consumidor e-commerce guide recommends consumer awareness of supplier privacy policies but does not impose binding cookie-consent obligations.

Claims (1):

  • The 2019 INDOTEL/Pro Consumidor e-commerce guide recommends that consumers be informed about supplier privacy policies, but does not impose a binding cookie-consent obligation on businesses.

Dark PatternsRed

No dark-pattern prohibition was identified for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic dark patterns law consumer interface.

Opt Out SignalsRed

No recognized opt-out signal framework (e.g. Global Privacy Control) was identified as legally recognized in the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation was identified for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic data clean room regulation.

Cross Context AdvertisingRed

No cross-context advertising / sale-or-share framework analogous to CPRA was identified for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic cross-context advertising data sale law.

Direct MarketingRed

No direct-marketing-specific consent/suppression regime was confirmed for the Dominican Republic beyond the general consent principles implied by Law 172-13.

Absence provenance: unavailable. Searched: Dominican Republic direct marketing consent suppression law.

Category narrative48 words

No ePrivacy-style cookie/tracker consent statute, dark-pattern prohibition, recognized opt-out signal framework, clean-room regime, or cross-context-advertising rule was identified for the Dominican Republic. The closest identified artifact is the 2019 joint INDOTEL/Pro Consumidor e-commerce guidance, which recommends consumer-facing privacy-policy awareness practices but is non-binding guidance rather than binding law.

Sources and claims (1)
  1. ProbableDataGuidance — The 2019 INDOTEL/Pro Consumidor e-commerce guide recommends that consumers be informed about supplier privacy policies, but does not impose a binding cookie-consent obligation on businesses.observed

#

No sources located confirming any algorithmic, biometric, or AI-specific governance framework distinct from the general 2013 data protection statute.

Traffic-light rationale — AmberNo sources located confirming any algorithmic, biometric, or AI-specific governance framework distinct from the general 2013 data protection statute.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art. 22 was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic profiling restriction automated decision law.

Automated Decision Making TransparencyRed

No automated-decision-making transparency or explanation right was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic automated decision-making transparency right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment law or state-level AI transparency mandate was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic artificial intelligence law risk assessment.

Biometric RegimeAmber

No dedicated biometric-data protection regime (facial recognition, fingerprint, gait) distinct from the general Law 172-13 framework was confirmed for the Dominican Republic in this run.

Absence provenance: unavailable. Searched: Dominican Republic biometric data law facial recognition regulation.

Genetic DataRed

No dedicated genetic-data regime was confirmed for the Dominican Republic; genetic data would likely fall under any general sensitive-category treatment of Law 172-13, which itself was not independently verified in this run.

Absence provenance: unavailable. Searched: Dominican Republic genetic data protection law.

State Surveillance CarveoutsRed

No codified state-surveillance carve-out or national-security exemption text was confirmed for Law 172-13 in this run.

Absence provenance: unavailable. Searched: Ley 172-13 excepción seguridad nacional vigilancia estatal.

Category narrative43 words

No profiling-restriction, automated-decision-making transparency right, AI-specific risk-assessment regime, dedicated biometric-data regime, genetic-data regime, or codified state-surveillance carve-out was identified for the Dominican Republic in the sources reviewed. This is treated as a genuine regulatory gap for this module rather than a silent omission.

#

No sources located confirming any children- or vulnerable-group-specific data protection provisions; genuine regulatory gap.

Traffic-light rationale — Not assessedNo sources located confirming any children- or vulnerable-group-specific data protection provisions; genuine regulatory gap.

Sub-modules (5)

Age VerificationRed

No statutory age-of-consent threshold for data processing was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic age of consent data processing minors.

Minor Profiling BansRed

No minor-profiling ban was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic minors profiling ban advertising.

Education SettingsRed

No education-setting-specific data protection rule was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic student data protection school law.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data protection provision was identified for the Dominican Republic.

Absence provenance: unavailable. Searched: Dominican Republic dependent adults data protection incapacitated.

Category narrative30 words

No age-of-consent threshold, parental-consent mechanism (COPPA/GDPR Art. 8 analogue), minor-profiling ban, education-setting-specific rule, or dependent-adult protection provision was identified for the Dominican Republic's data protection framework in the sources reviewed.

#

A private judicial right of action exists, but there is no confirmed administrative penalty regime, enforcement activity index, or regulator capacity data, and no material recent developments were found.

Primary frameworkLaw No. 172-13 on the Comprehensive Protection of Personal Data (2013)
Traffic-light rationale — AmberA private judicial right of action exists, but there is no confirmed administrative penalty regime, enforcement activity index, or regulator capacity data, and no material recent developments were found.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

No confirmed administrative investigative or fining power vested in a single DP regulator was identified for the Dominican Republic; redress instead runs through civil courts.

Claims (1):

  • No single Dominican data protection regulator holds administrative investigative or fining powers over Law 172-13 violations comparable to GDPR-style DPAs; redress instead runs through civil courts.

Enforcement Activity IndexRed

No significant recent enforcement decisions or fines specific to Law 172-13 were identified in the sources reviewed for the last 12 months.

Absence provenance: unavailable. Searched: Dominican Republic data protection enforcement action fine 2025 2026.

Regulator Funding And CapacityRed

No funding or headcount data is applicable given the absence of a dedicated DPA; this is a structural gap rather than an omission.

Absence provenance: unavailable. Searched: Dominican Republic data protection authority budget headcount.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism specific to data protection violations was identified for the Dominican Republic in this run; Pro Consumidor's general consumer-complaint/conciliation channel was noted but not confirmed as DP-specific.

Absence provenance: unavailable. Searched: Dominican Republic collective redress class action data protection.

Private Right Of ActionGreen

Data subjects whose rights are violated under Law 172-13, including in connection with a data breach, may bring a direct civil suit against the liable party, since the Law does not channel redress exclusively through an administrative regulator.

Claims (1):

  • Data subjects whose rights are violated due to a data breach may sue the liable person directly, since Law 172-13 does not channel breach-related redress exclusively through an administrative authority.

Recent Developments 180DRed

No material Dominican Republic-specific data protection legislative, regulatory, or case-law developments were identified within the 180 days preceding this run (searches for a new DR data protection bill, dedicated DPA creation, or amendments in 2025-2026 returned no confirming results).

Absence provenance: unavailable. Searched: Dominican Republic data protection authority draft bill 2025 create agency, Dominican Republic new data protection bill 2024 2025 draft law.

Category narrative66 words

Law 172-13 does not establish an administrative-fine regime comparable to GDPR; redress is primarily judicial. Data subjects whose rights are violated (including via a data breach) may sue the liable party directly through civil/habeas-data litigation, rather than through an empowered administrative regulator issuing penalties. No significant recent DR-specific data protection enforcement actions or legislative developments were identified within the last 180 days of the run date.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableDataGuidance — No single Dominican data protection regulator holds administrative investigative or fining powers over Law 172-13 violations comparable to GDPR-style DPAs; redress instead runs through civil courts.observed
  2. ConfirmedDataGuidance — Data subjects whose rights are violated due to a data breach may sue the liable person directly, since Law 172-13 does not channel breach-related redress exclusively through an administrative authority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct22.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Dominican Republic
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 11 claim(s) (11 category placement(s)), 14 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated with narrative and traffic-light status. Only regulator_and_framework, controller_processor_duties (security_measures/breach_notification), sectoral_watch (financial/telecoms/credit) and enforcement_and_redress (private_right_of_action) reached T2/T3-sourced Confirmed/Probable confidence via retrieved DataGuidance/IAPP secondary commentary; no T1 (primary statute text / official gazette) source was directly retrieved in this run because the Spanish-language primary text of Law 172-13 and any official .gob.do regulator pages were not fetched. lawful_processing_and_special_data, data_subject_rights (beyond general pattern-matching to regional habeas-data norms), cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups carry predominantly red/absent_field_provenance status reflecting either genuine regulatory gaps in a 2013-era statute or unresolved primary-source verification needs.

Unresolved questions (5):

  • Does Law 172-13 impose an explicit statutory deadline for controller responses to data subject access/rectification requests?
  • Does Law 172-13 include a public database/controller registration or filing requirement, and if so with which authority?
  • Are there enumerated lawful bases and defined special-category rules in the primary Spanish-language text of Law 172-13?
  • Has any bill been introduced to create a dedicated Dominican data protection authority or to add a mandatory breach-notification duty?
  • Does the Superintendencia de Bancos or INDOTEL hold any formal administrative sanctioning power specifically under Law 172-13, as opposed to their own sectoral statutes?

Escalate to primary-source review: yes