Puerto Rico Cybersecurity Act
Act 40-2024 Cybersecurity Act of Puerto Rico
Puerto Rico's comprehensive cybersecurity law establishing cybersecurity framework for public and private sectors, complementing Act 111-2005 breach notification.
Jurisdiction
Puerto Rico
Enacted
Jun 1, 2024
Effective
Jul 1, 2024
Enforcement
Puerto Rico Cybersecurity Bureau
Comprehensive cybersecurity framework complementing data breach law
Puerto Rico OGPWhy It Matters
Puerto Rico's 2024 Cybersecurity Act creates comprehensive security obligations for AI chatbot platforms processing Puerto Rican users' sensitive data.
Recent Developments
Enacted June 2024, effective July 2024
At a Glance
Applies to
Requires
Who Must Comply
- Public and private entities in Puerto Rico
- Critical infrastructure operators
- Entities processing sensitive data
Obligations fall on:
Safety Provisions
- Cybersecurity risk assessment requirements
- Incident response planning mandates
- Security controls for critical infrastructure
- Cybersecurity governance framework
Compliance & Enforcement
Penalties
Fines and enforcement actions
View on map
Puerto Rico
Focus Areas
Compliance Help
Cybersecurity risk assessments; incident response plans for sensitive data including mental health information
See how NOPE helpsCite This
APA
Puerto Rico. (2024). Act 40-2024 Cybersecurity Act of Puerto Rico.
Related Regulations
Puerto Rico Act 111-2005
Puerto Rico's medical information privacy law with breach notification requirement 'as expeditiously as possible' - stricter than federal standards.
CARICOM CCSCAP 2025
CARICOM's 2025 regional cyber security framework establishing digital safety culture and coordinated incident response across 18 member states.
Chile Cybersecurity Law
First cybersecurity framework law in Latin America (Law 21,663 promulgated Mar 26, 2024; published Apr 8, 2024). Creates National Cybersecurity Agency (ANCI), mandatory incident reporting, and encryption rights.
Argentina AI Strategy
Non-binding AI governance guidelines establishing principles for responsible AI use. Argentina positioning as AI innovation hub with limited regulatory barriers. Emphasizes transparency, accountability, and human oversight. Multiple legislative proposals pending inspired by EU AI Act, aiming to establish formal regulatory authority.
AIDA
Would have regulated high-impact AI systems with potential penalties up to $25M or 5% global revenue. Part of Bill C-27 which died when Parliament ended.
Peru AI Regulations
Peru's first comprehensive AI regulatory framework, inspired by EU AI Act. Establishes three-tier risk-based approach: prohibited uses, high-risk systems (including healthcare), and low-risk/acceptable AI. First general AI regulation in Latin America. Requires human oversight, transparency, and risk assessments for high-risk AI including healthcare applications.
Last updated January 22, 2026. Verify against primary sources before relying on this information.