Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP
Costa Rica's Law for the Protection of Persons Regarding the Processing of Their Personal Data (Law No. 8968 of 2011), as amended by Executive Decree No. 42089-MGP in 2023, establishes a comprehensive data protection framework. The Data Protection Agency (Agencia de Protección de Datos, APD) oversees compliance. The law establishes principles for lawful, fair, and transparent processing of personal data, including purpose limitation, data minimization, accuracy, storage limitation, and accountability.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Automated Decisions
| Code | Title |
|---|---|
| CR-8968-A20 | Automated Decision Making |
Breach Response
| Code | Title |
|---|---|
| CR-8968-A15 | Breach Notification to PRODHAB and Data Subjects |
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Fundamental Principles
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
Chapter III - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
| Cl. 10 | Right to Correction |
| Cl. 11 | Right to Erasure |
| Cl. 12 | Right to Data Portability |
| Cl. 9 | Right to Access |
Chapter IV - Obligations of Data Controllers
| Code | Title |
|---|---|
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 31 | Designation of Chief Privacy Officer |
| Art. 33 | Criminal Offences |
Chapter V - PRODHAB and Institutional Framework
| Code | Title |
|---|---|
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
Chapter VI - Sanctions and Penalties
| Code | Title |
|---|---|
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 31 | Designation of Chief Privacy Officer |
| Art. 32 | Entry into Force |
Classification
| Code | Title |
|---|---|
| CR-8968-A3 | Data Classification Tiers |
Confidentiality
| Code | Title |
|---|---|
| CR-8968-A12 | Confidentiality Obligation |
Consent
| Code | Title |
|---|---|
| CR-8968-A5 | Informed Consent Requirements |
Cross-Border
| Code | Title |
|---|---|
| CR-8968-A13 | International Data Transfers |
Data Quality
| Code | Title |
|---|---|
| CR-8968-A10 | Data Quality Obligation |
Data Subject Rights
| Code | Title |
|---|---|
| CR-8968-A1 | Right to Informational Self-Determination |
| CR-8968-A8 | Data Subject Access Right (ARCO) |
| CR-8968-A9 | Right to Cancellation and Erasure |
Enforcement
| Code | Title |
|---|---|
| CR-8968-A22 | Sanctions and Penalties |
Principles
| Code | Title |
|---|---|
| CR-8968-A4 | Principles of Processing |
Processors
| Code | Title |
|---|---|
| CR-8968-A14 | Processor Engagement Requirements |
Registration
| Code | Title |
|---|---|
| CR-8968-A21 | PRODHAB Fees and Annual Reporting |
| CR-8968-A7 | Database Registration with PRODHAB |
Retention
| Code | Title |
|---|---|
| CR-8968-A18 | Retention and Disposal |
Security
| Code | Title |
|---|---|
| CR-8968-A11 | Security Protocol Requirement |
Sensitive Data
| Code | Title |
|---|---|
| CR-8968-A6 | Sensitive Data Special Protection |
Supervisory Authority
| Code | Title |
|---|---|
| CR-8968-A16 | PRODHAB Inspection and Cooperation |
Transparency
| Code | Title |
|---|---|
| CR-8968-A17 | Privacy Notice Disclosures |
Vulnerable Populations
| Code | Title |
|---|---|
| CR-8968-A19 | Children and Vulnerable Data Subjects |
Your Compliance Coverage
If you comply with Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP, you already cover:
EU AI Act
31%
16 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
29%
15 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
29%
15 controls mapped
Compare →+ 628 more: GDPR (27%), Turkey Personal Data Protection Law (KVKK — Law No. 6698) (27%)
See all 631 mapped frameworks ↓Maps to 631 other frameworks
Frequently Asked Questions
What is Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP?
Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP is a compliance framework from Costa Rica with 24 domains and 58 controls. Costa Rica's Law for the Protection of Persons Regarding the Processing of Their Personal Data (Law No. 8968 of 2011), as amended by Executive Decree No. 42089-MGP in 2023, establishes a comprehensive data protection framework. The Data Protection Agency (Agencia de Protección de Datos, APD) oversees compliance. The law establishes principles for lawful, fair, and transparent processing of personal data, including purpose limitation, data minimization, accuracy, storage limitation, and accountability. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP have?
Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP has 58 controls organised across 24 domains. The largest domains are Chapter III - Rights of Data Subjects (12 controls), Chapter IV - Obligations of Data Controllers (9 controls), Chapter I - General Provisions (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP map to?
Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP maps to 631 other compliance frameworks. The top mapping partners are EU AI Act (31% coverage), BS 65000:2014 — Guidance on Organizational Resilience (29% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP compliance?
Start your Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 58 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required