Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CR Ley 8968: Datos Sensibles, Seguridad y Confidencialidad
The person responsible for the database must adopt the technical and organisational measures necessary to guarantee the security of personal data and prevent their alteration, accidental or unlawful destruction, loss, unauthorised processing or access.
- Documented technical and organisational security measures for each database
- Access controls, integrity and availability safeguards
- Evidence measures are proportionate to the data sensitivity
- No documented security measures
- Unauthorised access not prevented
- Security not adjusted for sensitive data
The person responsible and all who intervene in any phase of processing personal data are bound by professional secrecy and a duty of confidentiality, which subsists even after the relationship with the database owner ends.
- Confidentiality undertakings signed by staff and processors
- Evidence the duty persists after engagement ends
- No confidentiality agreements
- Confidentiality not extended to processors
Persons responsible for databases must prepare and keep up to date an action protocol setting out the technical, organisational and security steps they will follow; public databases and private databases that distribute or market data must register their protocols with the Prodhab.
- Current written action protocol (protocolo de actuacion)
- Evidence of registration of the protocol with Prodhab where required
- No action protocol maintained
- Protocol not registered with Prodhab when required
The data subject is guaranteed effective means to enforce the Law, including the ability to lodge complaints and obtain remedies where their rights over their personal data are infringed.
- Internal complaint-handling procedure for data subjects
- Records of remedies provided
- No complaint mechanism for data subjects
No person may be compelled to provide sensitive data. The processing of personal data revealing racial or ethnic origin, political opinions, religious or spiritual convictions, socio-economic condition, biometric or genetic information, sexual orientation, or trade-union membership, among others, is prohibited save for the narrow exceptions the Law allows. Special rules also govern data on minors.
- Identification of any sensitive-data processing and the specific legal exception relied upon
- Heightened safeguards for sensitive categories
- Controls for data concerning minors
- Collecting sensitive data without a valid exception
- Compelling provision of sensitive data
- No special protection for minors' data
CR Ley 8968: Denuncias, Procedimiento y Regimen Sancionatorio
Any person may lodge a complaint with the Prodhab where they consider that the processing of their personal data infringes the Law, initiating the supervisory and, where appropriate, sanctioning process.
- Internal readiness to respond to Prodhab complaints concerning the organisation
- No process to respond to a Prodhab complaint
Establishes the procedure by which the Prodhab handles complaints, including notification of the responsible party, the opportunity to be heard, and gathering of evidence before resolution.
- Evidence of participation in the Prodhab complaint procedure where applicable
- Document retention enabling response to a complaint
- Inability to produce processing records during a complaint
Sets out the sanctioning procedure applied by the Prodhab, observing due process before any sanction is imposed for breaches of the Law.
- Records demonstrating compliance posture available for a sanctioning procedure
- Remediation evidence for any identified breach
- No remediation record
- No readiness for a sanctioning procedure
Provides for sanctions for breaches of the Law without prejudice to applicable criminal penalties: minor faults are punished with a fine of up to five base salaries of a judicial auxiliary I; serious faults with five to twenty base salaries; and very serious faults with the highest fines and possible suspension of database operation.
- Risk assessment of exposure to Ley 8968 fines
- Controls mapped to avoid minor, serious and very serious faults
- Underestimating fine exposure
- No mapping of practices to the fault tiers
Classifies infringements into minor (faltas leves), serious (faltas graves) and very serious (faltas gravisimas) faults, such as failing to register databases, processing without consent, processing sensitive data unlawfully, transferring data unlawfully, or obstructing the Prodhab, each tier carrying escalating sanctions.
- Controls addressing each tipified fault (registration, consent, sensitive data, transfers, cooperation)
- Internal audit verifying none of the tipified conducts occur
- Unregistered databases
- Processing sensitive data unlawfully
- Obstructing the Prodhab
Establishes the annual fee (canon) payable to the Prodhab by persons responsible for registered databases for the regulation and administration of those databases.
- Evidence of payment of the annual Prodhab canon for registered databases
- Non-payment of the regulatory canon for a registered database
CR Ley 8968: Derechos del Titular (ARCO)
The data subject is guaranteed the right to access, rectify or erase their personal data and to consent to the transfer of their data. The person responsible for the database must comply with the request free of charge and resolve it within five business days of receipt.
- Documented ARCO request procedure with the five-business-day resolution timeline
- Logs of access, rectification, erasure and cession-consent requests and responses
- Evidence requests are handled free of charge
- Charging for rights requests
- Exceeding the five-day statutory deadline
- No erasure or rectification workflow
Defines the limited exceptions where the right to informational self-determination may be restricted, including national security, prevention or prosecution of crime, and other public-interest grounds established by law, applied restrictively.
- Documented legal basis for any restriction relied upon
- Record of exceptions invoked and their justification
- Over-broad use of exceptions
- No documented basis for restricting rights
CR Ley 8968: Disposiciones Generales y Ambito
The Law's purpose is to guarantee any natural or legal person, regardless of nationality, residence or domicile, respect for their fundamental rights, specifically their right to informational self-determination in relation to their life or private property and other rights of the personality, as well as the defence of their freedom and equality with respect to the automated or manual processing of their personal data.
- Documented determination that the organisation processes personal data of individuals and is subject to Ley 8968
- Privacy governance charter referencing the right to informational self-determination
- No recognition of Ley 8968 applicability
- Treating informational self-determination as optional
The Law applies to personal data held in automated or manual databases of public and private bodies, and to any subsequent processing of those data. It does not apply to databases kept by natural persons for exclusively personal or domestic use.
- Inventory of automated and manual databases holding personal data
- Scoping analysis distinguishing covered databases from personal/domestic-use exemption
- Excluding manual files from scope
- Claiming domestic-use exemption for commercial processing
Defines key terms including personal data, sensitive data, public-access databases, person responsible for the database, data subject, processing of personal data, and informational self-determination, establishing the scope of the obligations that follow.
- Mapping of the organisation's data and roles to the Law's defined terms
- Classification of databases as public-access or restricted
- Misclassifying sensitive data as ordinary
- Undefined controller/processor roles
CR Ley 8968: PRODHAB y Registro de Bases de Datos
Creates the Agencia de Proteccion de Datos de los Habitantes (Prodhab) as a maximally deconcentrated body attached to the Ministry of Justice and Peace, with its own instrumental legal personality, as the supervisory authority for personal data protection.
- Evidence of registration and interaction with Prodhab as the supervisory authority
- Awareness of Prodhab's jurisdiction over the organisation's databases
- Treating Prodhab oversight as inapplicable
- No point of contact for the supervisory authority
Sets out the powers of the Prodhab, including ensuring compliance with the Law, requiring information, ordering blocking or deletion, conducting inspections, imposing sanctions, keeping the register of databases, and issuing guidelines on data protection.
- Records of cooperation with Prodhab inspections and information requests
- Implementation of Prodhab orders (blocking, deletion, corrective measures)
- Failing to cooperate with Prodhab inspections
- Ignoring Prodhab corrective orders
Persons responsible for databases that distribute, market or otherwise transfer personal data must register their databases in the register kept by the Prodhab, providing the prescribed information about the database and its processing.
- Evidence of registration of in-scope databases with Prodhab
- Record of the information submitted at registration and its updates
- Operating a registrable database without registration
- Failing to update the registration on material changes
The register of databases held by the Prodhab is public, supporting transparency about which databases exist and the processing they carry out.
- Accurate public register entry for the organisation's databases
- Inaccurate or outdated public register entry
CR Ley 8968: Principios y Consentimiento
Everyone has the right to informational self-determination, which includes the right to know of, access, rectify, and have erased their personal data, and to consent to the transfer of their data, exercised against any holder of a database.
- Procedures enabling data subjects to know of, access, rectify, erase and consent to transfer of their data
- Records of self-determination requests handled
- No channel for self-determination requests
- Ignoring the right to know of processing
Personal data may only be collected and processed with the data subject's express, free, individualised and informed consent, which must be obtained in advance and may be revoked. The data subject must be informed of the existence and purpose of the database, the recipients, the mandatory or optional nature of replies, the consequences of providing or refusing data, and the rights they hold.
- Consent records showing express, informed, prior consent per data subject
- Information notice content matching the Law's required elements
- Mechanism to revoke consent
- Implied or bundled consent
- Notice missing recipients or purpose
- No revocation mechanism
Personal data must be current, truthful, accurate and adequate for the purpose for which they were collected; processing must be lawful, fair and limited to the stated purpose. Data must be kept only as long as necessary and stored so the data subject can exercise their rights.
- Data quality and accuracy maintenance procedures
- Purpose-specification records per database
- Retention limits tied to the collection purpose
- Retaining data beyond purpose
- No accuracy/update process
- Repurposing data beyond the stated purpose
CR Ley 8968: Transferencia Internacional de Datos
Controllers of public or private databases may only transfer the data they hold when the data subject has expressly and validly authorised the transfer, and the transfer does not infringe the principles and rights recognised by the Law.
- Records of express, valid authorisation for each transfer
- Assessment that transfers respect the Law's principles and rights
- Transferring data without express authorisation
- Transfers that bypass the Law's principles
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP framework page.