Costa Rican Data Protection Law (Ley 8968)

Latin AmericaPrivacy2011
ByDecipherU Editorial

Costa Rica's data protection law (Ley 8968) establishes cybersecurity and privacy protections for personal data processing. The law created PRODHAB (Agencia de Protección de Datos de los Habitantes) as the enforcement agency. It requires consent-based processing, security measures for personal data, and registration of databases. Costa Rica also enacted a dedicated Cybersecurity Law (Ley 10482) in 2024.

Quick Reference

EnactedSeptember 5, 2011
Last AmendedRegulation published 2013; Cybersecurity Law (Ley 10482) enacted 2024
Enforcement BodyAgencia de Protección de Datos de los Habitantes (PRODHAB)
PenaltiesFines from 5 to 30 base salaries (approximately $2,000 to $14,000 USD); very serious: suspension of database operations for up to 6 months
Applicable ToAny individual or entity, public or private, processing personal data in Costa Rica

Key Requirements

Article 10 (Security of data)

Data controllers must adopt necessary technical and organizational measures to guarantee the security of personal data and prevent alteration, destruction, or unauthorized access

Article 12 (Data breach)

Data controllers must inform data subjects of security incidents that significantly affect their patrimonial or moral rights

Article 21 (Database registration)

Databases used for processing personal data must be registered with PRODHAB

How Does Costa Rica Ley 8968 Affect Cybersecurity Careers?

Costa Rica is a growing nearshore tech hub for US companies, making local cybersecurity compliance knowledge valuable. The 2024 Cybersecurity Law creates additional requirements for critical infrastructure. GRC analysts serving companies with Costa Rican operations must address Ley 8968 alongside the new Cybersecurity Law.

Cybersecurity Roles That Work With Costa Rica Ley 8968

Related Cybersecurity Certifications

Related Cybersecurity Laws

Frequently Asked Questions

Costa Rica's data protection law (Ley 8968) establishes cybersecurity and privacy protections for personal data processing. The law created PRODHAB (Agencia de Protección de Datos de los Habitantes) as the enforcement agency. It requires consent-based processing, security measures for personal data, and registration of databases. Costa Rica also enacted a dedicated Cybersecurity Law (Ley 10482) in 2024.

Costa Rica is a growing nearshore tech hub for US companies, making local cybersecurity compliance knowledge valuable. The 2024 Cybersecurity Law creates additional requirements for critical infrastructure. GRC analysts serving companies with Costa Rican operations must address Ley 8968 alongside the new Cybersecurity Law.

Fines from 5 to 30 base salaries (approximately $2,000 to $14,000 USD); very serious: suspension of database operations for up to 6 months

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?