DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Americas · In force · Opt-in

🇩🇴 Dominican Republic Data Privacy Laws

Law 172-13 is comprehensive in text but its supervision is anchored in credit reporting; a modern replacement bill with a real DPA has been under discussion for years.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
Law 172-13 on Personal Data Protection
Year
2013
Authority
Superintendence of Banks (credit data); no general DPA
Marketing consent
Consent-first on paper, credit-data enforcement in practice.
Transfers
Transfers abroad rest mainly on the individual's consent.
Penalties
Fines apply, mostly in the credit-reporting context.

The framework

The Dominican Republic's framework rests on Law 172-13 on Personal Data Protection, adopted in 2013, with the Superintendence of Banks as the supervisory authority.

That puts the Dominican Republic in the global opt-in majority, where permission comes before processing and marketing waits for consent.

Key instruments

Law 172-13 on Personal Data Protection

2013 · In force

Law 172-13 is comprehensive in text but its supervision is anchored in credit reporting; a modern replacement bill with a real DPA has been under discussion for years.

Marketing and advertising

Consent-first on paper, credit-data enforcement in practice. That single sentence decides most channel plans here.

Cross-border transfers

Transfers abroad rest mainly on the individual's consent. Whatever the local mechanism, EU-origin data carries the GDPR's transfer chapter with it into this market.

Enforcement and penalties

Fines apply, mostly in the credit-reporting context. Read the ceiling together with the authority's track record, which prices the risk.

Cite this page: "Dominican Republic Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/dominican-republic.html. Accessed [date].