Database

Browse Database

URUGUAY

N/A

Pillar Technical standards applied to ICT goods and online services  |  Sub-pillar Self-certification for product safety
Lack of self-certification of conformity
It is reported that self-declaration of conformity (SDoC) is not allowed for foreign companies for any radio transmitting devices, such as cellular exchanges, radio alarm devices, wireless remote controls, wireless microphones, cellular phones, cordless phones, radio communications transceiver equipment, wireless network cards, wifi/bluetooth transmitter devices, drone transceivers, among others. The approvals in Uruguay are regulated by the Regulatory Unit of Communications Service (URSEC). The approvals, once obtained, are valid for 15 years. Typically, approvals can be obtained in less than 10 weeks without the need for in-country testing.
Coverage Radio transmitting devices

URUGUAY

Since August 2014

Pillar Online sales and transactions  |  Sub-pillar Threshold for ‘De Minimis’ rule
Decree No. 356/014 Regulation of the Regime of International Postal Commissions (Decreto No. 356/014 Regulación del Régimen de Encomiendas Postales Internacionales)
Decree No. 356/014 sets some rules regarding the de minimis threshold, which is the minimum value of goods below which customs do not charge duties. According to Arts. 3-4 of the Decree, the de minimis threshold applied to purchases by non-express mail is equal to USD 50, while for purchases by express mail, it is equal to USD 200. Moreover, the de minimis applies under certain conditions: only up to 3 purchases per year, for non-commercial purposes, by a natural person of legal age with a valid Uruguayan identity card, and when the gross weight of the items does not exceed 20 kilograms.
Coverage Horizontal

URUGUAY

Since June 2001

Pillar Online sales and transactions  |  Sub-pillar Restrictions on domain names
Technical Instructions: Registration of Names under the ".UY" Domain
In accordance with Art. 9 of the Technical Instructions: Registration of Names under the ".UY" Domain, the applicant for a domain name registration must communicate the registered address of the holder(s) and the address in Uruguay for contractual and extra-contractual purposes of these instructions.
Coverage Horizontal

URUGUAY

Since August 2000

Pillar Online sales and transactions  |  Sub-pillar Framework for consumer protection applicable to online commerce
Law No. 17,250 - Consumer Relations and Consumer defence Law (Ley No. 17.250 - Ley de Relaciones de Consumo y Defensa del Consumidor del Consumidor)
The Consumer Relations and Consumer defence Law provides a comprehensive consumer protection framework that applies to online transactions. The law covers competition, product and user safety, environmental concerns, and financial regulations.
Coverage E-commerce sector

URUGUAY

N/A

Pillar Online sales and transactions  |  Sub-pillar Ratification of the United Nations (UN) Convention on the Use of Electronic Communications in International Contracts
Lack of signature of the UN Convention on the Use of Electronic Communications in International Contracts
Uruguay has not signed the United Nations (UN) Convention on the Use of Electronic Communications in International Contracts.
Coverage Horizontal

URUGUAY

Since August 2008

Pillar Cross-border data policies  |  Sub-pillar Conditional flow regime
Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
According to Art. 23 of Law No. 18.331 - Personal Data Protection Law, the transfer of personal data to countries or international organisations that do not provide adequate levels of protection is prohibited. The prohibition shall not apply in the case of:
- International judicial cooperation, in accordance with the respective international instrument, whether Treaty or Convention, takes into account the case's circumstances;
- Exchange of medical data when so required by the affected person's treatment for public health or hygiene reasons;
- Banking or stock exchange transfers in relation to the respective transactions and in accordance with the applicable legislation;
- Agreements within the framework of international treaties to which the Oriental Republic of Uruguay is a party;
- International cooperation between intelligence agencies in the fight against organised crime, terrorism fight against organised crime, terrorism, and drug trafficking.
Coverage Horizontal

URUGUAY

Since October 2016, entry into force in December 2018
Since April 2021, entry into force in August 2023

Pillar Cross-border data policies  |  Sub-pillar Participation in trade agreements committing to open cross-border data flows
Chile-Uruguay Free Trade Agreement (Acuerdo de Libre Comercio entre la República de Chile y la República Oriental del Uruguay)

Mercosur Agreement on Electronic Commerce (Acuerdo sobre Comercio Electrónico del Mercosur)
Uruguay has joined two agreements with binding commitments to open transfers of data across borders. Art. 8.10 of the Chile-Uruguay Free Trade Agreement provides that each Party shall permit the cross-border transfer of information by electronic means, including personal information, where this activity is for the conduct of the business of a person of a Party. In addition, Art. 8.11 states that a Party may not require a person of the other Party to use or locate computer facilities in the territory of that Party as a condition for doing business in that territory. Similar requirements are found in Arts. 7 and 8 of the Mercosur Agreement on Electronic Commerce, ratified by Uruguay in September 2022 and in force between Paraguay and Uruguay since August 2023.
Coverage Horizontal

URUGUAY

Since August 2008

Pillar Domestic data policies  |  Sub-pillar Framework for data protection
Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
Uruguay has a data protection framework established in Law No. 18.331 - Personal Data Protection Law.
Coverage Horizontal

URUGUAY

Since October 2018
Since May 2020
Since February 2020

Pillar Domestic data policies  |  Sub-pillar Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law No. 19,670 - Approval of the Financial Statements and Balance Sheet of Budget Execution (Ley No. 19.670 - Aprobación de Rendición de Cuentas y Balance de Ejecución Presupuestal)

Resolution No. 32/20 - Executive Council of the Regulatory and Control Unit of Personal Data (Resolución 32/20 - Consejo Ejecutivo de la Unidad Reguladora y de Control de Datos Personales)

Decree 64/2020 (Decreto No. 64/020)
According to the Art. 40 of Law No 19,670, the appointment of a Data Protection Officer (DPO) is mandatory in the following cases: (i) public state or non-state entities, (ii) private or partially state-owned entities, (iii) private entities which process sensitive data as a core activity, and (iv) private entities which process large scales of data (Art. 10 of Decree 64/2020 establishes that large scales of data mean the data processing of more than 35,000 data subjects).

The appointment of a DPO must be submitted for approval by the Regulatory Unit for the Control of Personal Data (URCDP). If the legal and technical requirements are not met, the Regulator is empowered to refuse or revoke (as the case may be) the submission/authorisation to the appointed DPO, as set forth in Resolution No. 32/20. The delegate is responsible for advising the organisations they represent on compliance with the rules set forth in Law No. 18,331 on Personal Data Protection. In addition to this, they are also responsible for serving as the main point of contact with the URCDP, along with several other functions.
Coverage Horizontal

URUGUAY

Since February 2020
Since August 2008

Pillar Domestic data policies  |  Sub-pillar Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Decree 64/2020 (Decreto No. 64/020)

Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
According to Art. 6 of Decree 64/2020, prior to the start of the processing, the controller and the processor shall carry out an assessment of the impact on the protection of personal data (DPIA) in certain circumstances.
According to Art. 10, the controller and the processor shall carry out an assessment of the DPIA when the processing operations may:
- Use sensitive data as a core business.
- Project permanent or stable processing of the specially protected data referred to in Chapter IV of Law No. 18.331 of August 11, 2008, or data related to the commission of criminal, civil, or administrative offences.
- Involve an evaluation of personal aspects of the data subjects to create or use personal profiles, in particular by analysing or predicting aspects related to their work performance, economic situation, health, personal preferences or interests, behavioural reliability, behavioural reliability, financial solvency, and location.
- To process data of groups of persons in a situation of special vulnerability and, in particular, of minors or persons with disabilities.
- Processing of large volumes of personal data.
- Transfer of personal data to other States or international organisations for which there is no adequate level of protection.
- Others determined by the Regulatory and Control Unit of Personal Data.
Coverage Horizontal

URUGUAY

N/A

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
It is reported that a basic legal framework on intermediary liability for copyright infringement is absent in Uruguay's law and jurisprudence.
Coverage Internet intermediaries

URUGUAY

N/A

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringements
It is reported that a basic legal framework on intermediary liability beyond copyright infringement is absent in Uruguay's law and jurisprudence.
Coverage Internet intermediaries

URUGUAY

Since October 2014

Pillar Intermediary liability  |  Sub-pillar User identity requirement
Decree No. 274/014 (Decreto No. 274/014 Reglamentación del Art. 75 de la Ley 19.149, Relativo a las Prestaciones de Empresas Operadoras de Servicios de Telefonía Móvil)
According to Arts. 1 and 2 of Decree No. 274/014, mobile service providers must maintain an up-to-date register of individuals or legal entities contracting prepaid or postpaid services. Additionally, individuals or legal entities wishing to contract these services are required to provide the identification data specified in Art. 4, which includes the subscriber's name, legal identification document, and address.
Coverage Telecommunications sector

URUGUAY

Since July 1974
Since January 2015

Pillar Telecom infrastructure & competition  |  Sub-pillar Licensing restrictions to operate in the telecom market
Decree-Law No. 14235: Law Creating ANTEL (Decreto Ley No. 14235: Ley de Creación de ANTEL)

Law No. 19,307 on Media (Ley de Medios No. 19307)
Art. 6 of Law 14,235 establishes that the National Telecommunications Administration of Uruguay (ANTEL) has a monopoly on telecommunications services. As this law predates the Internet, it has generated uncertainty about the scope of ANTEL's monopoly. In practice, other companies have been operating in the market, although the operator was never granted licenses to provide data transmission services until June 2022. The situation changed as a result of a court ruling in 2016. Following an appeal by a group of companies, the Uruguayan Court of Justice declared Art. 56 of the 2015 Media Law invalid, thus allowing holders of audiovisual communication services to apply for licenses to provide broadband and Internet access services.
Coverage Telecommunications sector

URUGUAY

N/A

Pillar Telecom infrastructure & competition  |  Sub-pillar Signature of the World Trade Organization (WTO) Telecom Reference Paper
Lack of adoption of WTO Telecom Reference Paper
Uruguay has not appended the WTO Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

Report issue     Report new measure