Skip to content

Evidence request lists

Law No. 172-13 on the Protection of Personal Data

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

ARCO Rights + Habeas Data + Article 70 Constitution

DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition
Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70

Dominican Republic Law 172-13 ARCO Rights (Acceso + Rectificacion + Cancelacion + Oposicion - Access + Rectification + Cancellation + Opposition) following the LatAm regional ARCO tradition + supplemented by Constitutional habeas data remedy (Article 70 Dominican Constitution). Article 13 Right of Access (Derecho de Acceso) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + 30-day response standard + free first request + reasonable subsequent fee. Article 14 Right of Rectification (Derecho de Rectificacion) - to correct inaccurate + incomplete + outdated data + 30-day response + propagation to recipients. Article 15 Right of Cancellation (Derecho de Cancelacion) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + Habeas Data court order + 5-year retention for credit information (Article 31 specif

Artefacts an auditor will ask for
  • ARCO rights request handling SLAs (30-day) + log
  • Habeas Data response procedure
  • Tribunal Superior Administrativo response plan
  • Public Defender liaison
  • Identity verification policy
  • Free first request evidence
Where this commonly fails
  • Slow ARCO response
  • No Habeas Data procedure
  • Identity verification mishandled
  • No appeals procedure
  • Long ARCO response times

Cross-Border + Vendor Mgmt + Marketing + Article 80

DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26
Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80

Dominican Republic Law 172-13 Articles 23-24 + 26 + 80 Cross-Border + Third Parties + Marketing. Article 80 Cross-Border Data Transfers (Transferencias Internacionales) - transfer of personal data outside Dominican Republic permitted where: (1) destination jurisdiction provides adequate level of protection (Superintendencia de Bancos assessment + LatAm CBPR consideration + APEC Privacy Framework); (2) explicit informed consent of data subject; (3) Performance of contract; (4) Vital interests; (5) Compelling public interest; (6) Standard Contractual Clauses (recommended model) + Binding Corporate Rules equivalent + Codes of Conduct. Recognised adequate jurisdictions: EU/EEA + UK + Convention 108 parties (Mexico + Uruguay + Colombia + Argentina + Brazil LGPD + Chile + Peru + EU member states + Morocco + Tunisia). Schrems II Transfer Impact Assessment + supplementary measures. Article 23-24

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • Article 80 lawful-basis documentation
  • SCC executed copies
  • Vendor contracts
  • Joint controllership allocation
  • Marketing opt-in evidence
  • Schrems II TIA
  • INDOTEL coordination for telecoms
Where this commonly fails
  • Transfer without lawful basis
  • No vendor contracts
  • No marketing opt-in
  • Missing TIA
  • No INDOTEL liaison

Database Registration + SIC + Superintendencia de Bancos

DOM172-Database-Registration-Article-30-Credit-Information-Bureaus-SIC-Superintendencia-Bancos-Healthcare-Sector
Dominican Republic Law 172-13 Database Registration + Credit Information Bureaus + SIC + Superintendencia de Bancos

Dominican Republic Law 172-13 Articles 30-32 + 5-7 Sector-Specific Provisions. Article 30 Database Registration (Registro de Bases de Datos) - public and private databases of personal data must register with Superintendencia de Bancos for credit information bureaus + sectoral regulator for other databases + free + searchable public register + transparency function. Article 5-7 Credit Information Bureaus (Sociedades de Informacion Crediticia - SIC) - DataCredito + TransUnion + Buro de Credito + Cicla + others registered with Superintendencia de Bancos + Article 6 mandatory consent for credit data processing + Article 7 data retention (positive 5 years from latest update + negative 4 years from cessation of obligation + bankruptcy 7 years + judicial sanctions 10 years) + Article 31 right of access to credit history + Article 32 dispute resolution and rectification procedures + Superintende

Artefacts an auditor will ask for
  • SB database registration evidence
  • SIC compliance attestation (DataCredito + TransUnion + Buro)
  • Retention schedule by data category (positive 5y + negative 4y + bankruptcy 7y + judicial 10y)
  • Healthcare data Hospital records compliance
  • AMD professional secrecy attestation
  • Public register accessibility
Where this commonly fails
  • No database registration
  • SIC retention non-compliance
  • Healthcare without Public Health Law alignment
  • Missing public register

Lawful Basis + Consent + Notice + Article 4-12

DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation
Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12

Dominican Republic Law 172-13 Articles 4-12 + 26-28 Lawful Basis for Processing. Article 4 Principles: (a) Lawfulness (Lealtad) - fair + lawful processing; (b) Quality (Calidad) - accurate + complete + up-to-date + relevant; (c) Purpose Specification (Finalidad) - specific + explicit + legitimate purposes; (d) Proportionality (Proporcionalidad) - adequate + relevant + not excessive; (e) Security (Seguridad) - appropriate measures; (f) Confidentiality (Confidencialidad) - duty of secrecy; (g) Information (Informacion) - transparency to data subject. Article 6 Consent of Holder (consentimiento) - express + written or unequivocal + informed + free + specific + revocable + verifiable. Alternative lawful bases: (1) Legal obligation; (2) Contractual performance; (3) Vital interest; (4) Compelling public interest authorised by law; (5) Statistical or scientific research (anonymised); (6) Specif

Artefacts an auditor will ask for
  • Lawful basis register
  • Consent records (express written + verifiable)
  • Spanish privacy notices
  • Information at collection evidence
  • Quality control evidence (accuracy + completeness)
  • Withdrawal mechanism evidence
Where this commonly fails
  • Bundled consent
  • Notice not in Spanish
  • No quality control programme
  • Withdrawal harder than giving
  • No information duty fulfilment

Scope + Ley 172-13 + Constitution Art.44 + Habeas Data

DOM172-Scope-Ley172-13-13December2013-Effective15December2013-Constitution-Article-44-Habeas-Data-Superintendencia-Bancos
Dominican Republic Law 172-13 Scope + 13 December 2013 + Constitution Article 44 + Habeas Data

Dominican Republic Law No. 172-13 on the Protection of Personal Data (Ley No. 172-13 sobre Proteccion de Datos de Caracter Personal) promulgated 13 December 2013 + effective 15 December 2013. Foundational Dominican Republic data protection statute. Constitutional anchor Dominican Republic Constitution Article 44 paragraph 2 right to privacy + Article 70 habeas data (constitutional remedy for personal data protection). Initially focused on credit information bureaus (Sociedades de Informacion Crediticia - SIC) with Superintendencia de Bancos (SB) as credit-information sector lead regulator + extended interpretation to broader personal data processing. NO comprehensive general data protection authority yet (DPA designation pending) - mixed-regulator approach with sector-specific oversight via Superintendencia de Bancos + INDOTEL telecommunications + Ministry of Industry + Protecom (consume

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • Superintendencia de Bancos registration
  • Habeas Data response procedure
  • Constitution Article 44 compliance memo
  • Modernisation Bill 2024 readiness gap analysis
Where this commonly fails
  • No SB registration
  • Missing Habeas Data response procedure
  • Treating Law 172-13 same as GDPR
  • No Modernisation readiness

Security + Article 25 + Breach Notification + Article 22

DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22
Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

Dominican Republic Law 172-13 Articles 21-25 + 33-35 Security Measures and Incident Handling. Article 25 Security Measures (Medidas de Seguridad) - appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + including: (1) Encryption at rest and in transit for sensitive and credit information data + AES-256 minimum + TLS 1.3 + key management; (2) Pseudonymisation and anonymisation techniques where applicable; (3) Access control (RBAC + least privilege + segregation of duties + privileged access management) + identity and authentication management; (4) Logging + monitoring + audit trails + minimum 5-year retention for credit information records + 1-year general; (5) Vulnerability management + patching + penetration testing + secure SDLC; (6) Physical security + data centre Tier III + biometric access + CCTV + visitor management; (7) Backup +

Artefacts an auditor will ask for
  • Encryption at rest + in transit configuration
  • RBAC + PAM evidence
  • SIEM + monitoring 5-year retention for credit info
  • Breach notification procedure + 72-hour evidence
  • SB Circular 02-13 + 03-13 compliance
  • CSIRT charter + tabletop records
  • CNCS + DICAT coordination records
Where this commonly fails
  • Unencrypted data
  • No SIEM
  • Late breach notification
  • No CSIRT
  • Missing CNCS liaison
  • Inadequate retention

Sensitive Data + Confidentiality + Articles 9-12

DOM172-Sensitive-Personal-Data-Confidentiality-Duty-Articles-9-12-Special-Categories-Health-Genetic-Religious-Political
Dominican Republic Law 172-13 Sensitive Data + Confidentiality + Articles 9-12 + Special Categories

Dominican Republic Law 172-13 Articles 9-12 + 26-27 Sensitive Personal Data and Confidentiality. Article 9 Sensitive Data (Datos Sensibles) categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + sexual life + sexual orientation + biometric + genetic + criminal record + administrative sanctions + ideological beliefs + intimate convictions. Article 10 Sensitive Data processing prohibition - prohibited except: (1) explicit informed written consent; (2) compelling public interest authorised by specific law; (3) vital interest of data subject; (4) medical treatment + healthcare by professional bound by professional secrecy; (5) research with safeguards + anonymisation; (6) judicial proceedings; (7) statistical (anonymised). Article 11 Special protections for healthcare data + medical records + hospital r

Artefacts an auditor will ask for
  • Sensitive data inventory + Article 9 categories
  • Explicit written consent for sensitive
  • Healthcare data Public Health Law compliance evidence
  • Children data CONANI coordination + parental consent
  • Professional secrecy attestation
  • DPIA for sensitive processing
Where this commonly fails
  • Sensitive without explicit consent
  • Healthcare without Public Health Law alignment
  • No parental consent for minors
  • Missing professional secrecy controls

Supervisory + Sanctions + Governance + Modernisation 2024

DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation
Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

Dominican Republic Law 172-13 enforcement and governance framework. Mixed-regulator approach with Superintendencia de Bancos (credit-information sector + general consumer banking) + INDOTEL telecommunications + Protecom consumer protection + sectoral regulators + Public Defender (Defensor del Pueblo) constitutional rights protection + Office of the Attorney General criminal investigation + pending establishment of National Data Protection Agency via 2024 Modernisation Bill. Article 77 Sanctions and Penalties (Sanciones y Penalidades) - administrative + criminal. Administrative: warnings + reprimands + revocation of authorisation + temporary or permanent ban + fines DOP 50K-50M per violation + cumulative. Criminal Article 364 Penal Code unauthorised disclosure 3 months-2 years imprisonment + DOP 100K-1M fines + aggravated for sensitive data + corporate criminal liability. Article 78 Inves

Artefacts an auditor will ask for
  • SB engagement + inspection response records
  • Sanctions exposure register (DOP 50K-50M + criminal Article 364)
  • DPO designation records (mandatory under 2024 Bill)
  • ROPA + DPIA per processing
  • Modernisation Bill 2024 readiness gap analysis
  • Tribunal Superior Administrativo response procedure
  • Iberoamerican Data Protection Network (RIPD) coordination
Where this commonly fails
  • No DPO
  • No SB response plan
  • No Modernisation readiness
  • Missing ROPA + DPIA
  • No sanctions exposure analysis
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Law No. 172-13 on the Protection of Personal Data framework page.