Uruguay Personal Data Protection Act (Law No. 18.331)
Uruguay's Personal Data Protection Act (Law No. 18.331 of 2008) establishes a comprehensive data protection framework. The Regulatory and Control Unit for Personal Data (URCDP) oversees compliance. Uruguay holds EU adequacy recognition (since 2012), making it one of only two Latin American countries with this status. The law establishes processing principles, data subject rights, database registration, and cross-border transfer provisions.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art.1 | Purpose |
| Art.2 | Definitions |
| Art.3 | Cybersecurity Policy |
| Art.4 | Credit Information Business Licensing |
| Art.8 | Prohibited Acts |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — General Principles
| Code | Title |
|---|---|
| URY-3 | Principle of Lawfulness (Article 5) |
| URY-4 | Prior Informed Consent (Article 9) |
| URY-5 | Data Security (Article 10) |
| URY-6 | Duty of Confidentiality (Article 11) |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Direct Data Flows |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Special Categories of Data
| Code | Title |
|---|---|
| URY-10 | Sensitive Data (Article 18) |
| URY-11 | Health Data |
Chapter V — Supervisory Authority (URCDP)
| Code | Title |
|---|---|
| URY-12 | Regulatory and Control Body |
| URY-13 | Database Registration |
Chapter VI — Cross-Border Transfers
| Code | Title |
|---|---|
| URY-14 | International Transfers |
Chapter VII — Habeas Data
| Code | Title |
|---|---|
| URY-15 | Habeas Data Action (Article 38) |
| URY-16 | Penalties and Sanctions |
Rights and Cross-Border
Data subject rights and international transfers
Maps to 547 other frameworks
Frequently Asked Questions
What is Uruguay Personal Data Protection Act (Law No. 18.331)?
Uruguay Personal Data Protection Act (Law No. 18.331) is a compliance framework from Uruguay with 8 domains and 38 controls. Uruguay's Personal Data Protection Act (Law No. 18.331 of 2008) establishes a comprehensive data protection framework. The Regulatory and Control Unit for Personal Data (URCDP) oversees compliance. Uruguay holds EU adequacy recognition (since 2012), making it one of only two Latin American countries with this status. The law establishes processing principles, data subject rights, database registration, and cross-border transfer provisions. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Uruguay Personal Data Protection Act (Law No. 18.331) have?
Uruguay Personal Data Protection Act (Law No. 18.331) has 38 controls organised across 8 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter II — General Principles (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Uruguay Personal Data Protection Act (Law No. 18.331) map to?
Uruguay Personal Data Protection Act (Law No. 18.331) maps to 547 other compliance frameworks. The top mapping partners are Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (37% coverage), EU Network Code on Cybersecurity for the Electricity Sector (34% coverage), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Uruguay Personal Data Protection Act (Law No. 18.331) compliance?
Start your Uruguay Personal Data Protection Act (Law No. 18.331) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uruguay Personal Data Protection Act (Law No. 18.331) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required