Law No. 172-13 on the Protection of Personal Data
Supervisory + Sanctions + Governance + Modernisation 2024

Law No. 172-13 on the Protection of Personal Data Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation: Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

Dominican Republic Law 172-13 enforcement and governance framework. Mixed-regulator approach with Superintendencia de Bancos (credit-information sector + general consumer banking) + INDOTEL telecommunications + Protecom consumer protection + sectoral regulators + Public Defender (Defensor del Pueblo) constitutional rights protection + Office of the Attorney General criminal investigation + pending establishment of National Data Protection Agency via 2024 Modernisation Bill. Article 77 Sanctions and Penalties (Sanciones y Penalidades) - administrative + criminal. Administrative: warnings + reprimands + revocation of authorisation + temporary or permanent ban + fines DOP 50K-50M per violation + cumulative. Criminal Article 364 Penal Code unauthorised disclosure 3 months-2 years imprisonment + DOP 100K-1M fines + aggravated for sensitive data + corporate criminal liability. Article 78 Investigation + inspection powers + production of records + access to systems + interviews. Article 79 Judicial review by Tribunal Superior Administrativo + appeal to Supreme Court of Justice (Suprema Corte de Justicia) + Constitutional Tribunal for constitutional challenges. Modernisation 2024 Bill anticipated additions: independent National Data Protection Agency + GDPR + Convention 108+ alignment + DPO mandatory + 72-hour breach notification + Privacy by Design + Privacy by Default + administrative fines up to DOP 1B or 4% turnover + Accountability principle + DPIA mandatory + Records of Processing Activities + Data Protection by Default. Supervisory cooperation with Iberoamerican Data Protection Network (RIPD) + Convention 108+ Committee + LatAm + Caribbean cooperation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 207 controls across 82 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 5 controls

FDA 21 CFR Part 11 · 4 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

IEEE 7000 · 4 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

FISMA · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

Japan AI Guidelines · 3 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 3 controls

API 1164 · 2 controls

  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

IEEE 1686 · 2 controls

ISMAP (Japan) · 2 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

India DPDP Act · 2 controls

Indonesia PDP Law · 2 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • ASD37-27 Outbound data loss prevention (Very Good)
  • 4.3.1 Risk Assessment and Impact Analysis
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management

FedRAMP Rev 5 · 1 control

GRI Standards · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ISSB Standards · 1 control

  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • RUSPD-4 Special Categories, Biometric Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 207 it maps to, and the evidence behind each claim, over MCP and REST.