Uruguay
Summary
Law: Law No. 18.331 on the Protection of Personal Data and the Habeas Data Action 2008 (only available in Spanish here) (the Law), Decree No. 414/009 Regulating Law 18.331 Relating to the Protection of Personal Data (only available in Spanish here) ('the Decree'), and Decree No. 64/020 on the Regulation of Articles 37-40 of Law No. 19.670 of 15 October 2018 (only available in Spanish here) (the 2020 Decree)
Regulator: The Uruguayan data protection authority (URCDP)
Summary: Law No. 18.331 on the Protection of Personal Data and the Habeas Data Action 2008 (only available in Spanish here) (the Law) The Law and Decree No. 414/009 Regulating Law 18.331 Relating to the Protection of Personal Data (only available in Spanish here) (the Decree) entered into effect on August 18, 2008, and September 15, 2009, respectively. Both the Law and the Decree are closely aligned with the GDPR and provide for legal bases of processing, controller and processor obligations, and data subject rights.
Furthermore, the Decree No. 64/020 on the Regulation of Articles 37-40 of Law No. 19.670 of 15 October 2018 (only available in Spanish here) (the 2020 Decree) established new obligations relating to breach notification, Privacy by Design, data protection officer appointments, Data Protection Impact Assessments (DPIAs), and security measures. Law No. 20075 of 20 October 2022 (only available in Spanish here) (Law No. 20075) entered into force on January 1, 2023, and amends the Uruguayan data protection system. Specifically, Law No. 20075 introduced amendments including disclosure to data subjects, as well as the powers of the Uruguayan data protection authority (URCDP).
Notably, Uruguay obtained an adequacy decision from the EU in 2012, and in 2013, Uruguay ratified the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108). Additionally, in 2021, Uruguay ratified the Modernised Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+).