Table of Contents
Data privacy is no longer optional for businesses operating in Puerto Rico
If you operate a business in Puerto Rico, handle customer information, or process personal data in any form, you face real legal obligations under Puerto Rico's data privacy framework. These laws impose specific requirements on how you collect, store, use, and protect personal information. Failure to comply exposes your business to regulatory penalties, civil liability, and reputational damage. Understanding what the law requires is the first step toward protecting your business and your customers.
Puerto Rico’s Primary Data Privacy Statute
Puerto Rico's main data privacy law is Act 37-2018, also known as the Personal Data Protection Act (Ley de Protección de Datos Personales). This statute establishes the legal framework governing how organizations must handle personal data. The law applies to any business that collects, processes, or maintains personal information about Puerto Rico residents, regardless of where the business is physically located.
Act 37-2018 defines personal data broadly to include any information that identifies or could identify an individual. This covers names, identification numbers, email addresses, phone numbers, financial information, health records, biometric data, and location information. The law also protects sensitive personal data, which includes information about race, ethnicity, political opinions, religious beliefs, union membership, genetic data, health information, and sexual orientation. Sensitive data receives heightened protection under the statute.
The law establishes several core principles that businesses must follow. First, data collection must be lawful, fair, and transparent. You cannot collect personal data without a legitimate legal basis. Second, you must collect data only for specified, explicit, and legitimate purposes. Third, you must limit data collection to what is necessary for those purposes. Fourth, you must keep personal data accurate and up to date. Fifth, you must not retain personal data longer than necessary. These principles form the foundation of Puerto Rico's data privacy regime.
Legal Bases for Processing Personal Data
Act 37-2018 requires that you have a legal basis before processing any personal data. The law recognizes several valid bases for processing. The most common is explicit consent from the individual. Consent must be freely given, specific, informed, and unambiguous. You cannot use pre-checked boxes, silence, or inactivity as consent. Consent must be as easy to withdraw as it is to give.
Beyond consent, you may process personal data when necessary to perform a contract with the individual. For example, if a customer purchases a product, you may process their address and payment information to fulfill that order. You may also process data when required by law, when necessary to protect vital interests, when necessary for tasks carried out in the public interest, and when necessary for legitimate interests pursued by the controller or a third party. Legitimate interests must be balanced against the individual's rights and freedoms.
Processing sensitive personal data requires even stricter justification. Generally, you cannot process sensitive data without explicit consent from the individual. Limited exceptions exist for employment purposes, health and safety obligations, legal claims, and data that individuals have made public themselves. If your business processes sensitive data, you must document your legal basis carefully and ensure you meet the statutory requirements.
Data Subject Rights Under Puerto Rico Law
Act 37-2018 grants individuals specific rights regarding their personal data. These rights create corresponding obligations for your business. Understanding these rights helps you build compliant data handling practices.
The right of access allows individuals to request confirmation of whether you process their personal data and to receive a copy of that data. You must respond to access requests within 30 days. The right to rectification allows individuals to correct inaccurate or incomplete personal data. You must make corrections without undue delay. The right to erasure, sometimes called the right to be forgotten, allows individuals to request deletion of their personal data under certain circumstances. You must delete data when it is no longer necessary for the purpose it was collected, when the individual withdraws consent, when they object to processing, or when processing is unlawful.
The right to restrict processing allows individuals to limit how you use their data. When an individual exercises this right, you may store the data but cannot actively process it except with their consent or for legal claims. The right to data portability allows individuals to receive their personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller. The right to object allows individuals to object to processing of their data for direct marketing, profiling, or legitimate interests. You must stop processing when an individual objects unless you can demonstrate compelling legitimate interests that override their rights.
Individuals also have the right not to be subject to automated decision-making that produces legal or similarly significant effects. If your business uses algorithms or automated systems to make decisions about individuals, you must provide transparency about how those systems work and allow individuals to request human review of automated decisions.
Data Security and Breach Notification Requirements
Act 37-2018 requires that you implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. The law does not prescribe specific security measures but requires that your security be appropriate to the risk level. Factors to consider include the nature of the data, the scope of processing, the state of technology, and the cost of implementation.
Your security measures should include encryption of sensitive data, access controls limiting who can view personal information, regular security assessments and penetration testing, employee training on data protection, and incident response procedures. You should maintain documentation of your security measures to demonstrate compliance if questioned by regulators.
If a data breach occurs, you must notify affected individuals without undue delay and in any case within 30 days of discovering the breach. The notification must describe the nature of the breach, the likely consequences, and the measures you are taking to address it. You must also notify the Puerto Rico Data Protection Authority if the breach poses a high risk to individuals' rights and freedoms. Failure to notify as required can result in significant penalties.
Data Protection Impact Assessments and Privacy by Design
For processing activities that pose high risk to individuals' rights and freedoms, Act 37-2018 requires that you conduct a Data Protection Impact Assessment (DPIA) before beginning processing. A DPIA is a systematic evaluation of the processing activity, the risks it creates, and the measures you will implement to mitigate those risks. High-risk processing includes large-scale processing of sensitive data, systematic monitoring of individuals, automated decision-making with legal effects, and processing of data about vulnerable populations.
The law also requires privacy by design and by default. This means you must build data protection into your systems and processes from the beginning, not as an afterthought. When designing new systems or processes that involve personal data, you must consider data protection at every stage. You should collect only the minimum data necessary, use the shortest retention periods possible, and implement strong security by default.
Data Protection Officer and Accountability
Certain organizations must appoint a Data Protection Officer (DPO). Organizations that must appoint a DPO include public authorities and organizations whose core activities involve large-scale systematic monitoring of individuals or large-scale processing of sensitive data. Even if your organization is not required to appoint a DPO, you should designate someone responsible for data protection compliance. This person should understand the law, monitor compliance, respond to data subject requests, and coordinate with regulators.
Act 37-2018 requires that you maintain records demonstrating your compliance with the law. These records should include your legal basis for processing, your data retention schedules, your security measures, your breach response procedures, and your responses to data subject requests. The Puerto Rico Data Protection Authority may request these records during an investigation. Maintaining thorough documentation protects your business by showing you took compliance seriously.
Penalties for Non-Compliance
Violations of Act 37-2018 can result in substantial penalties. The Puerto Rico Data Protection Authority has authority to impose administrative fines. Penalties vary based on the severity of the violation. Minor violations may result in fines up to $500 per violation. More serious violations can result in fines up to $5,000 per violation. Violations involving sensitive data or affecting large numbers of individuals typically result in higher penalties.
Beyond administrative penalties, individuals harmed by data protection violations may bring civil lawsuits seeking damages. If your business unlawfully processes personal data or fails to protect it adequately, affected individuals can sue for compensation. These lawsuits can be costly and damaging to your reputation. Additionally, regulatory investigations and enforcement actions consume management time and resources even before penalties are imposed.
Compliance for Specific Business Types
Certain industries face additional data privacy requirements beyond Act 37-2018. Financial institutions and businesses handling financial data must comply with banking and securities regulations that impose data protection requirements. Healthcare providers must protect health information under medical privacy laws. Businesses using blockchain technology or cryptocurrency must ensure their data handling complies with both Act 37-2018 and focused blockchain regulations. If your business operates in a regulated industry, you should review both general data privacy requirements and industry-specific rules.
Businesses that benefit from Puerto Rico's tax incentive programs under Act 60 should be aware that data protection compliance is part of operating responsibly in Puerto Rico. Tax incentive programs do not exempt businesses from data privacy obligations. If your business is considering relocating to Puerto Rico or establishing operations here, data protection compliance should be part of your planning.
International Data Transfers
If your business transfers personal data outside Puerto Rico, you must ensure the transfer complies with Act 37-2018. The law restricts transfers of personal data to countries that do not provide adequate data protection. Before transferring data internationally, you must verify that the destination country has adequate legal protections or that you have implemented appropriate safeguards such as standard contractual clauses or binding corporate rules.
This requirement affects many businesses. If you use cloud services hosted outside Puerto Rico, if you have employees or contractors in other countries who access personal data, or if you share customer information with international partners, you must ensure these transfers comply with the law. Failure to do so can result in enforcement action and penalties.
Practical Steps to Achieve Compliance
Achieving data privacy compliance requires systematic effort. Start by conducting an audit of what personal data your business collects, where it is stored, who has access to it, and how long you retain it. Document your findings. Next, review your legal basis for each type of data processing. Ensure you have valid consent, contractual necessity, legal obligation, or legitimate interest for each processing activity. If you lack a valid basis, stop that processing or obtain proper consent.
Implement privacy notices that clearly explain to individuals what data you collect, why you collect it, how you use it, how long you keep it, and what rights they have. Make these notices easily accessible. Update your data retention policies to ensure you do not keep personal data longer than necessary. Implement security measures appropriate to the sensitivity of your data. Establish procedures for responding to data subject requests within the required timeframes. Create an incident response plan for data breaches. Train your employees on data protection obligations.
Review your contracts with vendors and service providers who process personal data on your behalf. These contracts must include data protection obligations. If you use third-party service providers, you remain responsible for their compliance. Conduct regular compliance reviews to identify gaps and address them promptly.
Next Steps
Data privacy compliance is not a one-time project but an ongoing obligation. The requirements are detailed and the penalties for non-compliance are significant. If your business handles personal data in Puerto Rico, you should ensure your practices comply with Act 37-2018. Christian M. Frank Fas, Esq. has over 20 years of experience in Puerto Rico business law and can help you understand your obligations and implement compliant data handling practices. Schedule a free initial evaluation to discuss your specific situation and learn how to protect your business.
