Uruguay Personal Data Protection Act (Law No. 18.331)
Uruguay's Personal Data Protection Act (Law No. 18.331 of 2008) establishes a comprehensive data protection framework. The Regulatory and Control Unit for Personal Data (URCDP) oversees compliance. Uruguay holds EU adequacy recognition (since 2012), making it one of only two Latin American countries with this status. The law establishes processing principles, data subject rights, database registration, and cross-border transfer provisions.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
Automated Processing
| Code | Title |
|---|---|
| URY-18331-17 | Automated Decisions and Profiling |
Breach Notification
| Code | Title |
|---|---|
| URY-18331-13 | Breach Notification to URCDP |
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — General Principles
| Code | Title |
|---|---|
| URY-3 | Principle of Lawfulness (Article 5) |
| URY-4 | Prior Informed Consent (Article 9) |
| URY-5 | Data Security (Article 10) |
| URY-6 | Duty of Confidentiality (Article 11) |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Special Categories of Data
| Code | Title |
|---|---|
| URY-10 | Sensitive Data (Article 18) |
| URY-11 | Health Data |
Chapter V — Supervisory Authority (URCDP)
| Code | Title |
|---|---|
| URY-12 | Regulatory and Control Body |
| URY-13 | Database Registration |
Chapter VI — Cross-Border Transfers
| Code | Title |
|---|---|
| URY-14 | International Transfers |
Chapter VII — Habeas Data
| Code | Title |
|---|---|
| URY-15 | Habeas Data Action (Article 38) |
| URY-16 | Penalties and Sanctions |
Confidentiality
| Code | Title |
|---|---|
| URY-18331-09 | Confidentiality Obligation |
Data Quality
| Code | Title |
|---|---|
| URY-18331-03 | Data Quality Principle |
Data Subject Rights
| Code | Title |
|---|---|
| URY-18331-06 | Data Subject Rights ARCO |
Enforcement
| Code | Title |
|---|---|
| URY-18331-20 | URCDP Inspections and Sanctions |
Governance
| Code | Title |
|---|---|
| URY-18331-12 | Data Protection Officer Appointment |
Impact Assessment
| Code | Title |
|---|---|
| URY-18331-14 | Privacy Impact Assessments |
International Transfers
| Code | Title |
|---|---|
| URY-18331-10 | Cross Border Data Transfers |
| URY-18331-11 | EU Adequacy Decision Compliance |
Lawful Basis
| Code | Title |
|---|---|
| URY-18331-02 | Lawful Basis and Consent |
Privacy by Design
| Code | Title |
|---|---|
| URY-18331-15 | Privacy by Design and by Default |
Public Sector
| Code | Title |
|---|---|
| URY-18331-18 | Public Sector Processing |
Purpose Limitation
| Code | Title |
|---|---|
| URY-18331-04 | Purpose Limitation |
Registration
| Code | Title |
|---|---|
| URY-18331-07 | Database Registration with URCDP |
Rights and Cross-Border
Data subject rights and international transfers
Scope
| Code | Title |
|---|---|
| URY-18331-01 | Scope and Territorial Application |
Sectoral
| Code | Title |
|---|---|
| URY-18331-19 | Credit Information Databases |
Security
| Code | Title |
|---|---|
| URY-18331-08 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| URY-18331-05 | Sensitive Data Processing |
Third Party Management
| Code | Title |
|---|---|
| URY-18331-16 | Processor Obligations and Contracts |
Your Compliance Coverage
If you comply with Uruguay Personal Data Protection Act (Law No. 18.331), you already cover:
Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
24%
14 controls mapped
Compare →EU AI Act
24%
14 controls mapped
Compare →Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
24%
14 controls mapped
Compare →+ 571 more: EU Network Code on Cybersecurity for the Electricity Sector (22%), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (22%)
See all 574 mapped frameworks ↓Maps to 574 other frameworks
Frequently Asked Questions
What is Uruguay Personal Data Protection Act (Law No. 18.331)?
Uruguay Personal Data Protection Act (Law No. 18.331) is a compliance framework from Uruguay with 27 domains and 58 controls. Uruguay's Personal Data Protection Act (Law No. 18.331 of 2008) establishes a comprehensive data protection framework. The Regulatory and Control Unit for Personal Data (URCDP) oversees compliance. Uruguay holds EU adequacy recognition (since 2012), making it one of only two Latin American countries with this status. The law establishes processing principles, data subject rights, database registration, and cross-border transfer provisions. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Uruguay Personal Data Protection Act (Law No. 18.331) have?
Uruguay Personal Data Protection Act (Law No. 18.331) has 58 controls organised across 27 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter II — General Principles (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Uruguay Personal Data Protection Act (Law No. 18.331) map to?
Uruguay Personal Data Protection Act (Law No. 18.331) maps to 574 other compliance frameworks. The top mapping partners are Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (24% coverage), EU AI Act (24% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Uruguay Personal Data Protection Act (Law No. 18.331) compliance?
Start your Uruguay Personal Data Protection Act (Law No. 18.331) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uruguay Personal Data Protection Act (Law No. 18.331) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 58 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required