Database

Browse Database

URUGUAY

Since October 2018
Since May 2020
Since February 2020

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law No. 19,670 - Approval of the Financial Statements and Balance Sheet of Budget Execution (Ley No. 19.670 - Aprobación de Rendición de Cuentas y Balance de Ejecución Presupuestal)

Resolution No. 32/20 - Executive Council of the Regulatory and Control Unit of Personal Data (Resolución 32/20 - Consejo Ejecutivo de la Unidad Reguladora y de Control de Datos Personales)

Decree 64/2020 (Decreto No. 64/020)
According to the Art. 40 of Law No 19,670, the appointment of a Data Protection Officer (DPO) is mandatory in the following cases: (i) public state or non-state entities, (ii) private or partially state-owned entities, (iii) private entities which process sensitive data as a core activity, and (iv) private entities which process large scales of data (Art. 10 of Decree 64/2020 establishes that large scales of data mean the data processing of more than 35,000 data subjects).
The appointment of a DPO must be submitted to the Regulatory Unit for the Control of Personal Data (URCDP) for approval. If the legal and technical requirements are not met, the Regulator is empowered to refuse or revoke (as the case may be) the submission/authorisation to the appointed DPO, as set forth in Resolution No. 32/20. The delegate is responsible for advising the organisations they represent on compliance with the rules set forth in Law No. 18,331 on Personal Data Protection. In addition, they serve as the main point of contact with the URCDP, among other functions.
Coverage Horizontal

URUGUAY

Since February 2020
Since August 2008, last amended in October 2022

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Decree 64/2020 (Decreto No. 64/020)

Law No. 18,331 - Personal Data Protection Law (Ley No. 18.331 - Ley de Protección de Datos Personales)
According to Art. 6 of Decree 64/2020, prior to the start of processing, the controller and the processor shall, in certain circumstances, carry out an assessment of the impact on the protection of personal data (DPIA).
According to Art. 10, the controller and the processor shall assess the DPIA when the processing operations may:
- Use sensitive data as a core business.
- Project permanent or stable processing of the specially protected data referred to in Chapter IV of Law No. 18.331 of August 11, 2008, or data related to the commission of criminal, civil, or administrative offences.
- Involve an evaluation of personal aspects of the data subjects to create or use personal profiles, in particular by analysing or predicting aspects related to their work performance, economic situation, health, personal preferences or interests, behavioural reliability, financial solvency, and location.
- To process data of groups of persons in a situation of special vulnerability and, in particular, of minors or persons with disabilities.
- Processing of large volumes of personal data.
- Transfer of personal data to other States or international organisations for which there is no adequate level of protection.
- Others determined by the Regulatory and Control Unit of Personal Data.
Coverage Horizontal

URUGUAY

N/A

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
It is reported that a basic legal framework on intermediary liability for copyright infringement is absent in Uruguay's law and jurisprudence.
Coverage Internet intermediaries

URUGUAY

N/A

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringements
It is reported that a basic legal framework on intermediary liability beyond copyright infringement is absent in Uruguay's law and jurisprudence.
Coverage Internet intermediaries

URUGUAY

Since October 2014, last amended in August 2021

Pillar Intermediary liability  |  Indicator User identity requirement
Decree No. 274/014 (Decreto No. 274/014 Reglamentación del Art. 75 de la Ley 19.149, Relativo a las Prestaciones de Empresas Operadoras de Servicios de Telefonía Móvil)
According to Arts. 1 and 2 of Decree No. 274/014, mobile service providers must maintain an up-to-date register of individuals or legal entities contracting prepaid or postpaid services. Additionally, individuals or legal entities wishing to contract for these services are required to provide the identification data specified in Art. 4, including the subscriber's name, legal identification document, and address.
Coverage Telecommunications sector

URUGUAY

Since November 2024

Pillar Quantitative trade restrictions for ICT goods and online services  |  Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Decree No. 292/024 – Regulations on the Integrated Management of Waste Electrical and Electronic Equipment (WEEE) (Decreto No. 292/024 - Reglamento para la Gestión Integral de Residuos de Aparatos Eléctricos y Electrónicos (RAEE))
Art. 12 of the Regulation approved by Decree No. 292/024, requires prior authorisation from the Ministry of Environment for the importation of used general-use electrical and electronic equipment and used components intended for reuse, commercialisation, repair or reconditioning. The Regulation defines the covered equipment functionally rather than by HS code, and the Ministry’s implementing classification includes monitors, screens and small information-technology and telecommunications equipment.
Coverage Used ICT products

URUGUAY

N/A

Pillar Technical standards applied to ICT goods and online services  |  Indicator Self-certification for product safety
Lack of self-certification of conformity
It is reported that self-declaration of conformity (SDoC) is not allowed for foreign companies for any radio transmitting devices, such as cellular exchanges, radio alarm devices, wireless remote controls, wireless microphones, cellular phones, cordless phones, radio communications transceiver equipment, wireless network cards, wifi/bluetooth transmitter devices, drone transceivers, among others. The approvals in Uruguay are regulated by the Regulatory Unit of Communications Service (URSEC). The approvals, once obtained, are valid for 15 years. Typically, approvals can be obtained in less than 10 weeks without in-country testing.
Coverage Radio transmitting devices

URUGUAY

N/A

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
Lack of adoption of WTO Telecom Reference Paper
Uruguay has not appended the WTO Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

URUGUAY

N/A

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Presence of an independent telecom authority
It is reported that the Communications Services Regulatory Unit (URSEC), the executive authority for the supervision and administration of services in the telecommunications sector, is independent from the government in the decision-making process. In accordance with national legislation (Law 17.296), the URSEC has been established as a decentralised and autonomous public entity.
Coverage Telecommunications sector

URUGUAY

Since April 2014

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Decree No. 92/014 (Decreto No. 92/014)
Pursuant to Art. 3 of Decree No. 92/014, the computer systems of the Central Administration are required to be housed within secure data centres located in Uruguay, except in instances where the associated public entity is not exposed to risk, as determined by specific guidelines outlined in the aforementioned Decree. Accordingly, unless such risk is absent, public entities forming part of the Central Administration must retain their data within the national territory. The guidelines in question establish general requirements pertaining to infrastructure and operational standards, including telecommunications systems, architectural design, electrical and mechanical systems, access control and security measures, system monitoring, service availability, and service level provisions.
Coverage Public sector

URUGUAY

Since December 2022

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Circular No. 2419/2022
According to Art. 35.1.1 of Circular No. 2419/2022 of the Central Bank of Uruguay, institutions of financial intermediation regulated by the Central Bank of Uruguay (BCU) or the Superintendence of Financial Services must obtain express authorisation from the Superintendence when outsourcing services to third parties located abroad. Express authorisation is also required when the third party is located in Uruguay, but the outsourced service is provided wholly or partially in or from abroad.
The authorisation request must include the draft service contract and a risk assessment report covering the risks associated with the outsourcing arrangement, including the financial and technical solvency of the provider and subcontractors, as well as legal risks affecting information subject to secrecy under Uruguayan law.
In this regard, the BCU has maintained that cloud computing services may be classified as a form of data processing outsourcing. Consequently, in order for a financial services institution to engage the services of a foreign cloud computing provider, it must first submit a formal request for authorisation to the BCU. In addition, the financial institution is obliged to establish a local data backup or maintain a unified access point on its premises (Art. 35.3).
Coverage Financial sector

URUGUAY

Since June 2012, last amended in December 2025
Since December 2010, last amended in May 2013

Pillar Public procurement of ICT goods and online services  |  Indicator Other limitations on foreign participation in public procurement
Orderly Text of Accounting and Financial Administration (TOCAF) (Texto Ordenado de Contabilidad y Administración Financiera (TOCAF))

Decree No. 371/010 regulating the Public Procurement Subprogramme for the Development of Micro, Small and Medium-sized Enterprises (Decreto No. 371/010 el cual Reglamenta el Subprograma de Contratación Pública para el Desarrollo de las Micro, Pequeñas y Medianas Empresas)
Art. 59 of the Consolidated Text on Accounting and Financial Administration (TOCAF) establishes the Public Procurement Program for Development, which authorises the use of special procurement regimes and procedures to support domestic suppliers, particularly micro, small, and medium-sized enterprises (MSMEs).
Within this framework, instruments such as price-preference margins and market-reservation mechanisms may be applied in favour of domestic producers and suppliers. The price preference margin may reach up to twice the margins established in Art. 58 (which go from 8% to 16%), while procurement reserved for the market may not exceed 10% of the total contracts and purchases of the same agency in the relevant fiscal year. Art. 60 further provides that the program shall include, inter alia, a Subprogram for Public Procurement for Scientific and Technological Development and Innovation, coordinated by the National Agency for Research and Innovation.
Decree No. 371/010, which regulates the Public Procurement Subprogramme for the Development of MSMEs, further operationalises this framework by setting eligibility conditions.
Coverage Horizontal

URUGUAY

N/A

Pillar Public procurement of ICT goods and online services  |  Indicator Signatory of the WTO Agreement on Government Procurement (GPA) with coverage of the most relevant services sectors (CPC 752, 754, 84)
Lack of participation in the WTO Agreement on Government Procurement (GPA)
Uruguay is not a party to the World Trade Organization (WTO) Agreement on Government Procurement (GPA), nor does it have observer status.
Coverage Horizontal

URUGUAY

Since January 1998, last amended in December 2025

Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade  |  Indicator Maximum foreign equity share
Law No. 16906 - Investment Promotion and Protection Law (Ley No. 16906 - Ley de Promoción y Protección de Inversiones)
According to Art. 2 of the Investment Promotion and Protection Law 16906, the State of Uruguay establishes equal treatment in the regime of admission and treatment of investments made by foreign and domestic investors.
Coverage Horizontal

URUGUAY

Since January 2025

Pillar Intellectual Property Rights (IPRs)  |  Indicator Participation in the Patent Cooperation Treaty (PCT)
Patent Cooperation Treaty (PCT)
Uruguay is a party to the Patent Cooperation Treaty (PCT).
Coverage Horizontal

Report issue     Report new measure