The framework
The Dominican Republic's framework rests on Law 172-13 on Personal Data Protection, adopted in 2013, with the Superintendence of Banks as the supervisory authority.
That puts the Dominican Republic in the global opt-in majority, where permission comes before processing and marketing waits for consent.
Key instruments
Law 172-13 on Personal Data Protection
Law 172-13 is comprehensive in text but its supervision is anchored in credit reporting; a modern replacement bill with a real DPA has been under discussion for years.
Marketing and advertising
Consent-first on paper, credit-data enforcement in practice. That single sentence decides most channel plans here.
Cross-border transfers
Transfers abroad rest mainly on the individual's consent. Whatever the local mechanism, EU-origin data carries the GDPR's transfer chapter with it into this market.
Enforcement and penalties
Fines apply, mostly in the credit-reporting context. Read the ceiling together with the authority's track record, which prices the risk.