Law No. 172-13 on the Protection of Personal Data
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
ARCO Rights + Habeas Data + Article 70 Constitution
Dominican Republic Law 172-13 ARCO Rights (Acceso + Rectificacion + Cancelacion + Oposicion - Access + Rectification + Cancellation + Opposition) following the LatAm regional ARCO tradition + supplemented by Constitutional habeas data remedy (Article 70 Dominican Constitution). Article 13 Right of Access (Derecho de Acceso) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + 30-day response standard + free first request + reasonable subsequent fee. Article 14 Right of Rectification (Derecho de Rectificacion) - to correct inaccurate + incomplete + outdated data + 30-day response + propagation to recipients. Article 15 Right of Cancellation (Derecho de Cancelacion) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + Habeas Data court order + 5-year retention for credit information (Article 31 specif
- ARCO rights request handling SLAs (30-day) + log
- Habeas Data response procedure
- Tribunal Superior Administrativo response plan
- Public Defender liaison
- Identity verification policy
- Free first request evidence
- Slow ARCO response
- No Habeas Data procedure
- Identity verification mishandled
- No appeals procedure
- Long ARCO response times
Cross-Border + Vendor Mgmt + Marketing + Article 80
Dominican Republic Law 172-13 Articles 23-24 + 26 + 80 Cross-Border + Third Parties + Marketing. Article 80 Cross-Border Data Transfers (Transferencias Internacionales) - transfer of personal data outside Dominican Republic permitted where: (1) destination jurisdiction provides adequate level of protection (Superintendencia de Bancos assessment + LatAm CBPR consideration + APEC Privacy Framework); (2) explicit informed consent of data subject; (3) Performance of contract; (4) Vital interests; (5) Compelling public interest; (6) Standard Contractual Clauses (recommended model) + Binding Corporate Rules equivalent + Codes of Conduct. Recognised adequate jurisdictions: EU/EEA + UK + Convention 108 parties (Mexico + Uruguay + Colombia + Argentina + Brazil LGPD + Chile + Peru + EU member states + Morocco + Tunisia). Schrems II Transfer Impact Assessment + supplementary measures. Article 23-24
- Cross-border transfer inventory
- Article 80 lawful-basis documentation
- SCC executed copies
- Vendor contracts
- Joint controllership allocation
- Marketing opt-in evidence
- Schrems II TIA
- INDOTEL coordination for telecoms
- Transfer without lawful basis
- No vendor contracts
- No marketing opt-in
- Missing TIA
- No INDOTEL liaison
Database Registration + SIC + Superintendencia de Bancos
Dominican Republic Law 172-13 Articles 30-32 + 5-7 Sector-Specific Provisions. Article 30 Database Registration (Registro de Bases de Datos) - public and private databases of personal data must register with Superintendencia de Bancos for credit information bureaus + sectoral regulator for other databases + free + searchable public register + transparency function. Article 5-7 Credit Information Bureaus (Sociedades de Informacion Crediticia - SIC) - DataCredito + TransUnion + Buro de Credito + Cicla + others registered with Superintendencia de Bancos + Article 6 mandatory consent for credit data processing + Article 7 data retention (positive 5 years from latest update + negative 4 years from cessation of obligation + bankruptcy 7 years + judicial sanctions 10 years) + Article 31 right of access to credit history + Article 32 dispute resolution and rectification procedures + Superintende
- SB database registration evidence
- SIC compliance attestation (DataCredito + TransUnion + Buro)
- Retention schedule by data category (positive 5y + negative 4y + bankruptcy 7y + judicial 10y)
- Healthcare data Hospital records compliance
- AMD professional secrecy attestation
- Public register accessibility
- No database registration
- SIC retention non-compliance
- Healthcare without Public Health Law alignment
- Missing public register
Lawful Basis + Consent + Notice + Article 4-12
Dominican Republic Law 172-13 Articles 4-12 + 26-28 Lawful Basis for Processing. Article 4 Principles: (a) Lawfulness (Lealtad) - fair + lawful processing; (b) Quality (Calidad) - accurate + complete + up-to-date + relevant; (c) Purpose Specification (Finalidad) - specific + explicit + legitimate purposes; (d) Proportionality (Proporcionalidad) - adequate + relevant + not excessive; (e) Security (Seguridad) - appropriate measures; (f) Confidentiality (Confidencialidad) - duty of secrecy; (g) Information (Informacion) - transparency to data subject. Article 6 Consent of Holder (consentimiento) - express + written or unequivocal + informed + free + specific + revocable + verifiable. Alternative lawful bases: (1) Legal obligation; (2) Contractual performance; (3) Vital interest; (4) Compelling public interest authorised by law; (5) Statistical or scientific research (anonymised); (6) Specif
- Lawful basis register
- Consent records (express written + verifiable)
- Spanish privacy notices
- Information at collection evidence
- Quality control evidence (accuracy + completeness)
- Withdrawal mechanism evidence
- Bundled consent
- Notice not in Spanish
- No quality control programme
- Withdrawal harder than giving
- No information duty fulfilment
Scope + Ley 172-13 + Constitution Art.44 + Habeas Data
Dominican Republic Law No. 172-13 on the Protection of Personal Data (Ley No. 172-13 sobre Proteccion de Datos de Caracter Personal) promulgated 13 December 2013 + effective 15 December 2013. Foundational Dominican Republic data protection statute. Constitutional anchor Dominican Republic Constitution Article 44 paragraph 2 right to privacy + Article 70 habeas data (constitutional remedy for personal data protection). Initially focused on credit information bureaus (Sociedades de Informacion Crediticia - SIC) with Superintendencia de Bancos (SB) as credit-information sector lead regulator + extended interpretation to broader personal data processing. NO comprehensive general data protection authority yet (DPA designation pending) - mixed-regulator approach with sector-specific oversight via Superintendencia de Bancos + INDOTEL telecommunications + Ministry of Industry + Protecom (consume
- Applicability assessment
- Personal data inventory
- Superintendencia de Bancos registration
- Habeas Data response procedure
- Constitution Article 44 compliance memo
- Modernisation Bill 2024 readiness gap analysis
- No SB registration
- Missing Habeas Data response procedure
- Treating Law 172-13 same as GDPR
- No Modernisation readiness
Security + Article 25 + Breach Notification + Article 22
Dominican Republic Law 172-13 Articles 21-25 + 33-35 Security Measures and Incident Handling. Article 25 Security Measures (Medidas de Seguridad) - appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + including: (1) Encryption at rest and in transit for sensitive and credit information data + AES-256 minimum + TLS 1.3 + key management; (2) Pseudonymisation and anonymisation techniques where applicable; (3) Access control (RBAC + least privilege + segregation of duties + privileged access management) + identity and authentication management; (4) Logging + monitoring + audit trails + minimum 5-year retention for credit information records + 1-year general; (5) Vulnerability management + patching + penetration testing + secure SDLC; (6) Physical security + data centre Tier III + biometric access + CCTV + visitor management; (7) Backup +
- Encryption at rest + in transit configuration
- RBAC + PAM evidence
- SIEM + monitoring 5-year retention for credit info
- Breach notification procedure + 72-hour evidence
- SB Circular 02-13 + 03-13 compliance
- CSIRT charter + tabletop records
- CNCS + DICAT coordination records
- Unencrypted data
- No SIEM
- Late breach notification
- No CSIRT
- Missing CNCS liaison
- Inadequate retention
Sensitive Data + Confidentiality + Articles 9-12
Dominican Republic Law 172-13 Articles 9-12 + 26-27 Sensitive Personal Data and Confidentiality. Article 9 Sensitive Data (Datos Sensibles) categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + sexual life + sexual orientation + biometric + genetic + criminal record + administrative sanctions + ideological beliefs + intimate convictions. Article 10 Sensitive Data processing prohibition - prohibited except: (1) explicit informed written consent; (2) compelling public interest authorised by specific law; (3) vital interest of data subject; (4) medical treatment + healthcare by professional bound by professional secrecy; (5) research with safeguards + anonymisation; (6) judicial proceedings; (7) statistical (anonymised). Article 11 Special protections for healthcare data + medical records + hospital r
- Sensitive data inventory + Article 9 categories
- Explicit written consent for sensitive
- Healthcare data Public Health Law compliance evidence
- Children data CONANI coordination + parental consent
- Professional secrecy attestation
- DPIA for sensitive processing
- Sensitive without explicit consent
- Healthcare without Public Health Law alignment
- No parental consent for minors
- Missing professional secrecy controls
Supervisory + Sanctions + Governance + Modernisation 2024
Dominican Republic Law 172-13 enforcement and governance framework. Mixed-regulator approach with Superintendencia de Bancos (credit-information sector + general consumer banking) + INDOTEL telecommunications + Protecom consumer protection + sectoral regulators + Public Defender (Defensor del Pueblo) constitutional rights protection + Office of the Attorney General criminal investigation + pending establishment of National Data Protection Agency via 2024 Modernisation Bill. Article 77 Sanctions and Penalties (Sanciones y Penalidades) - administrative + criminal. Administrative: warnings + reprimands + revocation of authorisation + temporary or permanent ban + fines DOP 50K-50M per violation + cumulative. Criminal Article 364 Penal Code unauthorised disclosure 3 months-2 years imprisonment + DOP 100K-1M fines + aggravated for sensitive data + corporate criminal liability. Article 78 Inves
- SB engagement + inspection response records
- Sanctions exposure register (DOP 50K-50M + criminal Article 364)
- DPO designation records (mandatory under 2024 Bill)
- ROPA + DPIA per processing
- Modernisation Bill 2024 readiness gap analysis
- Tribunal Superior Administrativo response procedure
- Iberoamerican Data Protection Network (RIPD) coordination
- No DPO
- No SB response plan
- No Modernisation readiness
- Missing ROPA + DPIA
- No sanctions exposure analysis
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Law No. 172-13 on the Protection of Personal Data framework page.