Data Protection Atlas

Uruguay

Tier 3 Comprehensive law Americas

Principal framework: Law 18.331 on Personal Data Protection (2008). Regulator: URCDP. Adequacy holder since 2012; the 2018–20 reforms added GDPR-style breach notice, DPOs and impact assessments.

At a glance

Principal law
Law 18.331 on Personal Data Protection
Regulator
URCDP
Breach notification
72 hours to the URCDP and affected persons
Maximum penalty
Fines up to 500,000 UI plus database suspension
DPO required
DPO required for large-scale or sensitive processing
Digital consent age
No statutory digital age
Extraterritorial reach
Extended by the 2018 accountability reforms

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
UY

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
Yes
Granted
21 August 2012
Review
Confirmed Jan 2024 review

Uruguay; 1995 Directive (Dec. 2012/484/EU).

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.