Database

Browse Database

URUGUAY

Since June 2001

Pillar Online sales and transactions  |  Indicator Restrictions on domain names
Technical Instructions: Registration of Names under the ".UY" Domain
In accordance with Art. 9 of the Technical Instructions: Registration of Names under the ".UY" Domain, the applicant for a domain name registration must communicate the registered address of the holder(s) and the address in Uruguay for contractual and extra-contractual purposes of these instructions.
Coverage Horizontal

URUGUAY

Since August 2000, last amended in November 2023

Pillar Online sales and transactions  |  Indicator Framework for consumer protection applicable to online commerce
Law No. 17,250 - Consumer Relations and Consumer defence Law (Ley No. 17.250 - Ley de Relaciones de Consumo y Defensa del Consumidor del Consumidor)
The Consumer Relations and Consumer Defence Law provides a comprehensive consumer protection framework that applies to online transactions. The law covers competition, product and user safety, environmental concerns, and financial regulations.
Coverage E-commerce sector

URUGUAY

N/A

Pillar Online sales and transactions  |  Indicator Ratification of the UN Convention on the Use of Electronic Communications in International Contracts
Lack of signature of the UN Convention on the Use of Electronic Communications in International Contracts
Uruguay has not signed the United Nations (UN) Convention on the Use of Electronic Communications in International Contracts.
Coverage Horizontal

URUGUAY

N/A

Pillar Online sales and transactions  |  Indicator UNCITRAL Model Law on Electronic Commerce
Lack of adoption of UNCITRAL Model Law on Electronic Commerce
Uruguay has not adopted national legislation based on or influenced by the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Commerce.
Coverage Horizontal

URUGUAY

N/A

Pillar Online sales and transactions  |  Indicator UNCITRAL Model Law on Electronic Signatures
Lack of adoption of UNCITRAL Model Law on Electronic Signatures
Uruguay has not adopted national legislation based on or influenced by the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Signatures.
Coverage Horizontal

URUGUAY

N/A

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
Lack of adoption of WTO Telecom Reference Paper
Uruguay has not appended the WTO Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

URUGUAY

N/A

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Presence of an independent telecom authority
It is reported that the Communications Services Regulatory Unit (URSEC), the executive authority for the supervision and administration of services in the telecommunications sector, is independent from the government in the decision-making process. In accordance with national legislation (Law 17.296), the URSEC has been established as a decentralised and autonomous public entity.
Coverage Telecommunications sector

URUGUAY

Since April 2014

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Decree No. 92/014 (Decreto No. 92/014)
Pursuant to Art. 3 of Decree No. 92/014, the computer systems of the Central Administration are required to be housed within secure data centres located in Uruguay, except in instances where the associated public entity is not exposed to risk, as determined by specific guidelines outlined in the aforementioned Decree. Accordingly, unless such risk is absent, public entities forming part of the Central Administration must retain their data within the national territory. The guidelines in question establish general requirements pertaining to infrastructure and operational standards, including telecommunications systems, architectural design, electrical and mechanical systems, access control and security measures, system monitoring, service availability, and service level provisions.
Coverage Public sector

URUGUAY

Since December 2022

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Circular No. 2419/2022
According to Art. 35.1.1 of Circular No. 2419/2022 of the Central Bank of Uruguay, institutions of financial intermediation regulated by the Central Bank of Uruguay (BCU) or the Superintendence of Financial Services must obtain express authorisation from the Superintendence when outsourcing services to third parties located abroad. Express authorisation is also required when the third party is located in Uruguay, but the outsourced service is provided wholly or partially in or from abroad.
The authorisation request must include the draft service contract and a risk assessment report covering the risks associated with the outsourcing arrangement, including the financial and technical solvency of the provider and subcontractors, as well as legal risks affecting information subject to secrecy under Uruguayan law.
In this regard, the BCU has maintained that cloud computing services may be classified as a form of data processing outsourcing. Consequently, in order for a financial services institution to engage the services of a foreign cloud computing provider, it must first submit a formal request for authorisation to the BCU. In addition, the financial institution is obliged to establish a local data backup or maintain a unified access point on its premises (Art. 35.3).
Coverage Financial sector

URUGUAY

Since August 2008, last amended in October 2022

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Law No. 18.331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
Art. 23 of Law No. 18.331 stipulates that international transfers of personal data are permissible only where the recipient country or international organisation ensures a level of protection deemed adequate by the Uruguayan Data Protection Authority (URCDP). Transfers to jurisdictions lacking such adequacy may proceed solely under the statutory exceptions or with prior authorisation from the URCDP. The law provides the following exceptions:
- international judicial cooperation under an applicable treaty or convention;
- exchange of medical data where necessary for the treatment of the data subject or for public health purposes;
- banking or stock exchange transfers relating to the relevant transactions and in compliance with applicable legislation;
- agreements concluded within the framework of international treaties to which Uruguay is a party;
- cooperation between intelligence agencies to combat organised crime, terrorism, and drug trafficking;
- where the data subject has given unequivocal consent to the transfer;
- where the transfer is necessary for the performance of a contract with the data subject or for pre-contractual measures at their request;
- where the transfer is necessary for the conclusion or performance of a contract in the data subject’s interest between the controller and a third party;
- where the transfer is necessary or legally required to safeguard an important public interest or for the establishment, exercise, or defence of legal claims;
- where the transfer is necessary to protect the vital interests of the data subject; and
- where the transfer originates from a public register established by law for public consultation, provided the legal conditions for such consultation are met.
The URCDP maintains a list of jurisdictions and organisations recognised as providing adequate protection. These include: the Member States of the European Union and the European Economic Area; Andorra; Argentina; the Canadian private sector; Guernsey; the Isle of Man; the Faroe Islands; Israel; Japan; Jersey; New Zealand; the United Kingdom; Switzerland; organisations listed under the U.S. Department of Commerce Data Privacy Framework; and entities subject to the Republic of Korea’s Personal Information Protection Act.
Coverage Horizontal

URUGUAY

Since October 2016, entry into force in December 2018
Since April 2021, entry into force in August 2023

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Chile-Uruguay Free Trade Agreement (Acuerdo de Libre Comercio entre la República de Chile y la República Oriental del Uruguay)

Mercosur Agreement on Electronic Commerce (Acuerdo sobre Comercio Electrónico del Mercosur)
Uruguay has joined two agreements with binding commitments to open transfers of data across borders. Art. 8.10 of the Chile-Uruguay Free Trade Agreement provides that each Party shall permit the cross-border transfer of information by electronic means, including personal information, where this activity is for the conduct of the business of a person of a Party. In addition, Art. 8.11 states that a Party may not require a person of the other Party to use or locate computer facilities in the territory of that Party as a condition for doing business in that territory. Similar requirements are found in Arts. 7 and 8 of the Mercosur Agreement on Electronic Commerce, ratified by Uruguay in September 2022 and in force between Paraguay and Uruguay since August 2023.
Coverage Horizontal

URUGUAY

Since August 2008, last amended in October 2022

Pillar Domestic data policies  |  Indicator Framework for data protection
Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
Uruguay has a data protection framework established in Law No. 18.331 - Personal Data Protection Law.
Coverage Horizontal

URUGUAY

Since March 2014, as amended in October 2021

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Decree No. 1/1113 on the Procedures and Protocol to be Followed by Operators Providing, or Capable of Providing, Publicly Available Telecommunications Services or Establishing or Operating Public Telecommunications Networks (Decreto No. 1/1113 sobre el Procedimiento y Protocolo que Deberán Seguir los Operadores que Presten o Estén en Condiciones de Prestar Servicios de Telecomunicaciones Disponibles al Público o de Establecer o Explotar Redes Públicas de Telecomunicaciones)
Decree No. 359/021 amended the procedure governing the lawful interception of communications by telecommunications operators, originally established under Decree No. I/1113 of 13 March 2014, and introduced a specific chapter on the retention of communications data.
Under Section 37.1, telecommunications operators are required to keep communications data available online for consultation by the authorised agent, subject to a judicial order, for a period of two years from the date on which the communication took place. The same provision allows certain categories of data to be retained offline for up to five years, where this is provided by regulation.
Coverage Telecommunications sector

URUGUAY

Since October 2018
Since May 2020
Since February 2020

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law No. 19,670 - Approval of the Financial Statements and Balance Sheet of Budget Execution (Ley No. 19.670 - Aprobación de Rendición de Cuentas y Balance de Ejecución Presupuestal)

Resolution No. 32/20 - Executive Council of the Regulatory and Control Unit of Personal Data (Resolución 32/20 - Consejo Ejecutivo de la Unidad Reguladora y de Control de Datos Personales)

Decree 64/2020 (Decreto No. 64/020)
According to the Art. 40 of Law No 19,670, the appointment of a Data Protection Officer (DPO) is mandatory in the following cases: (i) public state or non-state entities, (ii) private or partially state-owned entities, (iii) private entities which process sensitive data as a core activity, and (iv) private entities which process large scales of data (Art. 10 of Decree 64/2020 establishes that large scales of data mean the data processing of more than 35,000 data subjects).
The appointment of a DPO must be submitted to the Regulatory Unit for the Control of Personal Data (URCDP) for approval. If the legal and technical requirements are not met, the Regulator is empowered to refuse or revoke (as the case may be) the submission/authorisation to the appointed DPO, as set forth in Resolution No. 32/20. The delegate is responsible for advising the organisations they represent on compliance with the rules set forth in Law No. 18,331 on Personal Data Protection. In addition, they serve as the main point of contact with the URCDP, among other functions.
Coverage Horizontal

URUGUAY

Since February 2020
Since August 2008, last amended in October 2022

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Decree 64/2020 (Decreto No. 64/020)

Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
According to Art. 6 of Decree 64/2020, prior to the start of processing, the controller and the processor shall, in certain circumstances, carry out an assessment of the impact on the protection of personal data (DPIA).
According to Art. 10, the controller and the processor shall assess the DPIA when the processing operations may:
- Use sensitive data as a core business.
- Project permanent or stable processing of the specially protected data referred to in Chapter IV of Law No. 18.331 of August 11, 2008, or data related to the commission of criminal, civil, or administrative offences.
- Involve an evaluation of personal aspects of the data subjects to create or use personal profiles, in particular by analysing or predicting aspects related to their work performance, economic situation, health, personal preferences or interests, behavioural reliability, financial solvency, and location.
- To process data of groups of persons in a situation of special vulnerability and, in particular, of minors or persons with disabilities.
- Processing of large volumes of personal data.
- Transfer of personal data to other States or international organisations for which there is no adequate level of protection.
- Others determined by the Regulatory and Control Unit of Personal Data.
Coverage Horizontal

Report issue     Report new measure