SecurePrivacy Logo

Dominican Republic Personal Data Protection Law

View Law Text
Maximum Fine
DOP 20M
Scope
National
Regulator
PRODACOM
Enacted
2022

Need Help with Dominican Republic Personal Data Protection Law Compliance?

Get expert guidance on implementing Dominican Republic's data protection requirements and ensuring ongoing compliance for your organization.

Get Expert Help

Overview

The Personal Data Protection Law establishes comprehensive requirements for the processing of personal data in the Dominican Republic, enforced by PRODACOM.

Key Facts

  • Enacted in 2022
  • Enforced by Data Protection Authority (PRODACOM)
  • Includes strict data protection requirements

Key Principles

Lawfulness and Consent

Personal data must be processed lawfully and with proper authorization.

Requirements

  • Obtain valid consent
  • Identify legal basis
  • Document processing grounds
  • Regular compliance reviews
  • Maintain consent records

Examples

  • Consent mechanisms
  • Legal basis documentation
  • Processing records
  • Compliance reports

Transparency

Data processing must be transparent to data subjects.

Requirements

  • Provide clear privacy notices
  • Inform of processing purposes
  • Disclose data sharing
  • Update privacy information
  • Document communications

Examples

  • Privacy notices
  • Processing notifications
  • Communication records
  • Information updates

Data Security

Implementation of appropriate security measures to protect personal data.

Requirements

  • Implement security controls
  • Regular risk assessments
  • Staff training
  • Incident response plans
  • Security monitoring

Examples

  • Security policies
  • Training programs
  • Incident procedures
  • Monitoring systems

Compliance Requirements

Registration Requirements

Organizations must register their data processing activities with PRODACOM.

Implementation Steps

  • Submit registration application
  • Document processing activities
  • Pay registration fees
  • Maintain registration status
  • Update when changes occur

Required Documentation

  • Registration certificates
  • Processing records
  • Payment receipts
  • Status updates
  • Change notifications

Data Protection Measures

Implementation of appropriate technical and organizational measures to protect personal data.

Implementation Steps

  • Conduct risk assessments
  • Implement security controls
  • Train staff on security
  • Regular security audits
  • Document security measures

Required Documentation

  • Security policies
  • Risk assessments
  • Training records
  • Audit reports
  • Security documentation

International Data Transfers

Requirements for transferring personal data outside Dominican Republic.

Implementation Steps

  • Assess recipient country adequacy
  • Implement transfer safeguards
  • Obtain necessary approvals
  • Document transfers
  • Monitor compliance

Required Documentation

  • Transfer assessments
  • Safeguard documentation
  • Approval records
  • Transfer logs
  • Monitoring reports

Enforcement & Penalties

Administrative Penalties

PRODACOM can impose administrative penalties for violations of the Personal Data Protection Law.

Penalty Categories

Severe Violations
Up to DOP 20M
For serious breaches of data protection requirements
Processing Violations
Up to DOP 10M
For unauthorized processing of personal data
Documentation Violations
Up to DOP 5M
For failure to maintain required documentation

Example Cases

Financial Institution
DOP 15M
2023 - Unauthorized data sharing with third parties
Telecommunications Company
DOP 8M
2022 - Insufficient security measures leading to data breach

Criminal Penalties

Serious violations may result in criminal prosecution.

Penalty Categories

Intentional Violations
Up to DOP 20M and imprisonment
For deliberate violations of the law
False Statements
Up to DOP 10M
For providing false information to authorities
Obstruction
Up to DOP 5M
For obstructing investigations

Example Cases

Data Breach Case
DOP 18M
2023 - Intentional exposure of sensitive personal data
Compliance Violation
DOP 12M
2022 - Repeated non-compliance with authority orders