Uruguay
Tier 3 Comprehensive law AmericasPrincipal framework: Law 18.331 on Personal Data Protection (2008). Regulator: URCDP. Adequacy holder since 2012; the 2018–20 reforms added GDPR-style breach notice, DPOs and impact assessments.
At a glance
- Principal law
- Law 18.331 on Personal Data Protection
- Regulator
- URCDP
- Breach notification
- 72 hours to the URCDP and affected persons
- Maximum penalty
- Fines up to 500,000 UI plus database suspension
- DPO required
- DPO required for large-scale or sensitive processing
- Digital consent age
- No statutory digital age
- Extraterritorial reach
- Extended by the 2018 accountability reforms
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- UY
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
- Holds EU adequacy
- Yes
- Granted
- 21 August 2012
- Review
- Confirmed Jan 2024 review
Uruguay; 1995 Directive (Dec. 2012/484/EU).
Instruments
No instrument profiled yet.
Sources
- Primary Adequacy decision
Never independently verified — seeded from the prototype.