Skip to content

Evidence request lists

Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CR Ley 8968: Datos Sensibles, Seguridad y Confidencialidad

CR-8968-Art.10
Seguridad de los datos

The person responsible for the database must adopt the technical and organisational measures necessary to guarantee the security of personal data and prevent their alteration, accidental or unlawful destruction, loss, unauthorised processing or access.

Artefacts an auditor will ask for
  • Documented technical and organisational security measures for each database
  • Access controls, integrity and availability safeguards
  • Evidence measures are proportionate to the data sensitivity
Where this commonly fails
  • No documented security measures
  • Unauthorised access not prevented
  • Security not adjusted for sensitive data
CR-8968-Art.11
Deber de confidencialidad

The person responsible and all who intervene in any phase of processing personal data are bound by professional secrecy and a duty of confidentiality, which subsists even after the relationship with the database owner ends.

Artefacts an auditor will ask for
  • Confidentiality undertakings signed by staff and processors
  • Evidence the duty persists after engagement ends
Where this commonly fails
  • No confidentiality agreements
  • Confidentiality not extended to processors
CR-8968-Art.12
Protocolos de actuacion

Persons responsible for databases must prepare and keep up to date an action protocol setting out the technical, organisational and security steps they will follow; public databases and private databases that distribute or market data must register their protocols with the Prodhab.

Artefacts an auditor will ask for
  • Current written action protocol (protocolo de actuacion)
  • Evidence of registration of the protocol with Prodhab where required
Where this commonly fails
  • No action protocol maintained
  • Protocol not registered with Prodhab when required
CR-8968-Art.13
Garantias efectivas

The data subject is guaranteed effective means to enforce the Law, including the ability to lodge complaints and obtain remedies where their rights over their personal data are infringed.

Artefacts an auditor will ask for
  • Internal complaint-handling procedure for data subjects
  • Records of remedies provided
Where this commonly fails
  • No complaint mechanism for data subjects
CR-8968-Art.9
Categorias particulares de los datos (datos sensibles)

No person may be compelled to provide sensitive data. The processing of personal data revealing racial or ethnic origin, political opinions, religious or spiritual convictions, socio-economic condition, biometric or genetic information, sexual orientation, or trade-union membership, among others, is prohibited save for the narrow exceptions the Law allows. Special rules also govern data on minors.

Artefacts an auditor will ask for
  • Identification of any sensitive-data processing and the specific legal exception relied upon
  • Heightened safeguards for sensitive categories
  • Controls for data concerning minors
Where this commonly fails
  • Collecting sensitive data without a valid exception
  • Compelling provision of sensitive data
  • No special protection for minors' data

CR Ley 8968: Denuncias, Procedimiento y Regimen Sancionatorio

CR-8968-Art.24
Denuncia

Any person may lodge a complaint with the Prodhab where they consider that the processing of their personal data infringes the Law, initiating the supervisory and, where appropriate, sanctioning process.

Artefacts an auditor will ask for
  • Internal readiness to respond to Prodhab complaints concerning the organisation
Where this commonly fails
  • No process to respond to a Prodhab complaint
CR-8968-Art.25
Tramite de las denuncias

Establishes the procedure by which the Prodhab handles complaints, including notification of the responsible party, the opportunity to be heard, and gathering of evidence before resolution.

Artefacts an auditor will ask for
  • Evidence of participation in the Prodhab complaint procedure where applicable
  • Document retention enabling response to a complaint
Where this commonly fails
  • Inability to produce processing records during a complaint
CR-8968-Art.27
Procedimiento sancionatorio

Sets out the sanctioning procedure applied by the Prodhab, observing due process before any sanction is imposed for breaches of the Law.

Artefacts an auditor will ask for
  • Records demonstrating compliance posture available for a sanctioning procedure
  • Remediation evidence for any identified breach
Where this commonly fails
  • No remediation record
  • No readiness for a sanctioning procedure
CR-8968-Art.28
Sanciones (multas)

Provides for sanctions for breaches of the Law without prejudice to applicable criminal penalties: minor faults are punished with a fine of up to five base salaries of a judicial auxiliary I; serious faults with five to twenty base salaries; and very serious faults with the highest fines and possible suspension of database operation.

Artefacts an auditor will ask for
  • Risk assessment of exposure to Ley 8968 fines
  • Controls mapped to avoid minor, serious and very serious faults
Where this commonly fails
  • Underestimating fine exposure
  • No mapping of practices to the fault tiers
CR-8968-Art.29-31
Tipificacion de faltas (leves, graves, gravisimas)

Classifies infringements into minor (faltas leves), serious (faltas graves) and very serious (faltas gravisimas) faults, such as failing to register databases, processing without consent, processing sensitive data unlawfully, transferring data unlawfully, or obstructing the Prodhab, each tier carrying escalating sanctions.

Artefacts an auditor will ask for
  • Controls addressing each tipified fault (registration, consent, sensitive data, transfers, cooperation)
  • Internal audit verifying none of the tipified conducts occur
Where this commonly fails
  • Unregistered databases
  • Processing sensitive data unlawfully
  • Obstructing the Prodhab
CR-8968-Art.33
Canon por regulacion y administracion de bases de datos

Establishes the annual fee (canon) payable to the Prodhab by persons responsible for registered databases for the regulation and administration of those databases.

Artefacts an auditor will ask for
  • Evidence of payment of the annual Prodhab canon for registered databases
Where this commonly fails
  • Non-payment of the regulatory canon for a registered database

CR Ley 8968: Derechos del Titular (ARCO)

CR-8968-Art.7
Derechos de acceso, rectificacion, supresion y cesion (ARCO)

The data subject is guaranteed the right to access, rectify or erase their personal data and to consent to the transfer of their data. The person responsible for the database must comply with the request free of charge and resolve it within five business days of receipt.

Artefacts an auditor will ask for
  • Documented ARCO request procedure with the five-business-day resolution timeline
  • Logs of access, rectification, erasure and cession-consent requests and responses
  • Evidence requests are handled free of charge
Where this commonly fails
  • Charging for rights requests
  • Exceeding the five-day statutory deadline
  • No erasure or rectification workflow
CR-8968-Art.8
Excepciones a la autodeterminacion informativa

Defines the limited exceptions where the right to informational self-determination may be restricted, including national security, prevention or prosecution of crime, and other public-interest grounds established by law, applied restrictively.

Artefacts an auditor will ask for
  • Documented legal basis for any restriction relied upon
  • Record of exceptions invoked and their justification
Where this commonly fails
  • Over-broad use of exceptions
  • No documented basis for restricting rights

CR Ley 8968: Disposiciones Generales y Ambito

CR-8968-Art.1
Objetivo y fin (autodeterminacion informativa)

The Law's purpose is to guarantee any natural or legal person, regardless of nationality, residence or domicile, respect for their fundamental rights, specifically their right to informational self-determination in relation to their life or private property and other rights of the personality, as well as the defence of their freedom and equality with respect to the automated or manual processing of their personal data.

Artefacts an auditor will ask for
  • Documented determination that the organisation processes personal data of individuals and is subject to Ley 8968
  • Privacy governance charter referencing the right to informational self-determination
Where this commonly fails
  • No recognition of Ley 8968 applicability
  • Treating informational self-determination as optional
CR-8968-Art.2
Ambito de aplicacion

The Law applies to personal data held in automated or manual databases of public and private bodies, and to any subsequent processing of those data. It does not apply to databases kept by natural persons for exclusively personal or domestic use.

Artefacts an auditor will ask for
  • Inventory of automated and manual databases holding personal data
  • Scoping analysis distinguishing covered databases from personal/domestic-use exemption
Where this commonly fails
  • Excluding manual files from scope
  • Claiming domestic-use exemption for commercial processing
CR-8968-Art.3
Definiciones

Defines key terms including personal data, sensitive data, public-access databases, person responsible for the database, data subject, processing of personal data, and informational self-determination, establishing the scope of the obligations that follow.

Artefacts an auditor will ask for
  • Mapping of the organisation's data and roles to the Law's defined terms
  • Classification of databases as public-access or restricted
Where this commonly fails
  • Misclassifying sensitive data as ordinary
  • Undefined controller/processor roles

CR Ley 8968: PRODHAB y Registro de Bases de Datos

CR-8968-Art.15
Agencia de Proteccion de Datos de los Habitantes (Prodhab)

Creates the Agencia de Proteccion de Datos de los Habitantes (Prodhab) as a maximally deconcentrated body attached to the Ministry of Justice and Peace, with its own instrumental legal personality, as the supervisory authority for personal data protection.

Artefacts an auditor will ask for
  • Evidence of registration and interaction with Prodhab as the supervisory authority
  • Awareness of Prodhab's jurisdiction over the organisation's databases
Where this commonly fails
  • Treating Prodhab oversight as inapplicable
  • No point of contact for the supervisory authority
CR-8968-Art.16
Atribuciones de la Prodhab

Sets out the powers of the Prodhab, including ensuring compliance with the Law, requiring information, ordering blocking or deletion, conducting inspections, imposing sanctions, keeping the register of databases, and issuing guidelines on data protection.

Artefacts an auditor will ask for
  • Records of cooperation with Prodhab inspections and information requests
  • Implementation of Prodhab orders (blocking, deletion, corrective measures)
Where this commonly fails
  • Failing to cooperate with Prodhab inspections
  • Ignoring Prodhab corrective orders
CR-8968-Art.21
Registro de archivos y bases de datos

Persons responsible for databases that distribute, market or otherwise transfer personal data must register their databases in the register kept by the Prodhab, providing the prescribed information about the database and its processing.

Artefacts an auditor will ask for
  • Evidence of registration of in-scope databases with Prodhab
  • Record of the information submitted at registration and its updates
Where this commonly fails
  • Operating a registrable database without registration
  • Failing to update the registration on material changes
CR-8968-Art.22
Divulgacion del registro

The register of databases held by the Prodhab is public, supporting transparency about which databases exist and the processing they carry out.

Artefacts an auditor will ask for
  • Accurate public register entry for the organisation's databases
Where this commonly fails
  • Inaccurate or outdated public register entry

CR Ley 8968: Principios y Consentimiento

CR-8968-Art.4
Principio de autodeterminacion informativa

Everyone has the right to informational self-determination, which includes the right to know of, access, rectify, and have erased their personal data, and to consent to the transfer of their data, exercised against any holder of a database.

Artefacts an auditor will ask for
  • Procedures enabling data subjects to know of, access, rectify, erase and consent to transfer of their data
  • Records of self-determination requests handled
Where this commonly fails
  • No channel for self-determination requests
  • Ignoring the right to know of processing
CR-8968-Art.5
Principio de consentimiento informado

Personal data may only be collected and processed with the data subject's express, free, individualised and informed consent, which must be obtained in advance and may be revoked. The data subject must be informed of the existence and purpose of the database, the recipients, the mandatory or optional nature of replies, the consequences of providing or refusing data, and the rights they hold.

Artefacts an auditor will ask for
  • Consent records showing express, informed, prior consent per data subject
  • Information notice content matching the Law's required elements
  • Mechanism to revoke consent
Where this commonly fails
  • Implied or bundled consent
  • Notice missing recipients or purpose
  • No revocation mechanism
CR-8968-Art.6
Principio de calidad de la informacion

Personal data must be current, truthful, accurate and adequate for the purpose for which they were collected; processing must be lawful, fair and limited to the stated purpose. Data must be kept only as long as necessary and stored so the data subject can exercise their rights.

Artefacts an auditor will ask for
  • Data quality and accuracy maintenance procedures
  • Purpose-specification records per database
  • Retention limits tied to the collection purpose
Where this commonly fails
  • Retaining data beyond purpose
  • No accuracy/update process
  • Repurposing data beyond the stated purpose

CR Ley 8968: Transferencia Internacional de Datos

CR-8968-Art.14
Transferencia de datos personales (regla general)

Controllers of public or private databases may only transfer the data they hold when the data subject has expressly and validly authorised the transfer, and the transfer does not infringe the principles and rights recognised by the Law.

Artefacts an auditor will ask for
  • Records of express, valid authorisation for each transfer
  • Assessment that transfers respect the Law's principles and rights
Where this commonly fails
  • Transferring data without express authorisation
  • Transfers that bypass the Law's principles
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP framework page.