Costa Rica Law 8968
Law 8968 on the Protection of Individuals with Regard to the Processing of Their Personal Data
Costa Rica's data protection law requiring database registration with PRODHAB and establishing comprehensive data subject rights.
Jurisdiction
Costa Rica
CR
Enacted
Jul 5, 2011
Effective
Jul 5, 2011
Enforcement
Agencia de Protección de Datos de los Habitantes (PRODHAB)
National AI Strategy 2024-2027 complements data protection framework
What It Requires
Who Must Comply
This law applies to:
- • Data controllers and processors in Costa Rica
- • Public and private entities maintaining personal databases
- • Cross-border data transfers from Costa Rica
Capability triggers:
Who bears obligations:
Safety Provisions
- • Database registration with PRODHAB mandatory
- • Right to access, rectification, and deletion
- • Security measures for personal data
- • Cross-border transfer restrictions
- • Habeas Data remedy available
Enforcement
Enforced by
Agencia de Protección de Datos de los Habitantes (PRODHAB)
Penalties
Fines and sanctions for violations
Quick Facts
- Binding
- Yes
- Mental Health Focus
- No
- Child Safety Focus
- No
- Algorithmic Scope
- No
Why It Matters
Costa Rica's mandatory database registration creates compliance step for AI chatbot services processing Costa Rican user data.
Recent Developments
National AI Strategy 2024-2027 establishes AI governance framework complementing data protection
Cite This
APA
Costa Rica. (2011). Law 8968 on the Protection of Individuals with Regard to the Processing of Their Personal Data. Retrieved from https://nope.net/regs/cr-law-8968
BibTeX
@misc{cr_law_8968,
title = {Law 8968 on the Protection of Individuals with Regard to the Processing of Their Personal Data},
author = {Costa Rica},
year = {2011},
url = {https://nope.net/regs/cr-law-8968}
} Related Regulations
CARICOM CCSCAP 2025
CARICOM's 2025 regional cyber security framework establishing digital safety culture and coordinated incident response across 18 member states.
Chile Cybersecurity Law
First cybersecurity framework law in Latin America (Law 21,663 promulgated Mar 26, 2024; published Apr 8, 2024). Creates National Cybersecurity Agency (ANCI), mandatory incident reporting, and encryption rights.
Puerto Rico Cybersecurity Act
Puerto Rico's comprehensive cybersecurity law establishing cybersecurity framework for public and private sectors, complementing Act 111-2005 breach notification.
Argentina AI Strategy
Non-binding AI governance guidelines establishing principles for responsible AI use. Argentina positioning as AI innovation hub with limited regulatory barriers. Emphasizes transparency, accountability, and human oversight. Multiple legislative proposals pending inspired by EU AI Act, aiming to establish formal regulatory authority.
AIDA
Would have regulated high-impact AI systems with potential penalties up to $25M or 5% global revenue. Part of Bill C-27 which died when Parliament ended.
Peru AI Regulations
Peru's first comprehensive AI regulatory framework, inspired by EU AI Act. Establishes three-tier risk-based approach: prohibited uses, high-risk systems (including healthcare), and low-risk/acceptable AI. First general AI regulation in Latin America. Requires human oversight, transparency, and risk assessments for high-risk AI including healthcare applications.