Table of Contents
Data privacy is no longer optional for businesses operating in Puerto Rico
Puerto Rico has established a comprehensive legal framework governing how companies collect, store, process, and use personal data. Failure to comply with these laws exposes your business to significant fines, legal liability, and reputational damage. Whether you are a startup, an established corporation, or a financial services firm, understanding Puerto Rico's data privacy requirements is essential to lawful operations on the island.
This article explains the key data privacy laws applicable in Puerto Rico, the obligations they impose on businesses, and the practical steps you should take to ensure compliance.
Puerto Rico’s Primary Data Privacy Statute
Puerto Rico's main data privacy law is Act 115-2018, also known as the Personal Data Protection Act (Ley de Protección de Datos Personales). This statute establishes the rights of individuals regarding their personal information and the responsibilities of organizations that collect and process that data.
Act 115-2018 applies to any organization, whether public or private, that processes personal data of Puerto Rico residents. The law defines personal data broadly to include any information that identifies or can identify a natural person, including names, identification numbers, location data, online identifiers, and factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
The statute grants individuals several fundamental rights. These include the right to know what personal data is being collected, the right to access their own data, the right to correct inaccurate information, the right to request deletion of their data under certain circumstances, and the right to object to certain types of processing. Organizations must honor these requests within specified timeframes, typically 30 days from receipt.
Compliance with Act 115-2018 requires organizations to implement reasonable security measures to protect personal data from unauthorized access, alteration, or destruction. The law does not prescribe specific technical standards but requires that security measures be appropriate to the sensitivity of the data and the risks involved. This means your security obligations scale with the type of information you handle.
Data Processing Principles and Lawful Basis
Act 115-2018 establishes core principles that must guide all data processing activities. These principles require that data collection be lawful, fair, and transparent. You cannot collect personal data without a valid legal basis for doing so.
The law recognizes several lawful bases for processing personal data. The most common is explicit consent from the individual. Consent must be freely given, specific, informed, and unambiguous. Consent obtained through pre-checked boxes, silence, or inactivity does not satisfy this requirement. You must obtain affirmative consent before processing personal data for most purposes.
Other lawful bases include processing necessary to perform a contract with the individual, processing required by law, processing necessary to protect vital interests, processing necessary for legitimate interests pursued by the organization, and processing necessary for public tasks. However, even when using these alternative bases, you must still respect individual rights and implement appropriate safeguards.
Data minimization is another core principle. You should collect only the personal data that is necessary for the specific purpose you have identified. Collecting excessive data or retaining data longer than necessary violates this principle and increases your compliance burden and liability exposure.
Notification and Breach Reporting Requirements
When you collect personal data directly from an individual, you must provide specific information at the time of collection. This includes your identity and contact information, the purposes for which you will process the data, the legal basis for processing, information about data retention periods, and details about the individual's rights under the law.
If you collect personal data from sources other than the individual, you must provide this same information within a reasonable period, not to exceed 30 days from collection, unless you have already provided it or providing it would be impossible or involve disproportionate effort.
Puerto Rico law requires organizations to report data breaches to affected individuals and to the Puerto Rico Data Protection Authority without undue delay. A data breach occurs when there is unauthorized access to, disclosure of, or loss of personal data that compromises the security or privacy of that information. You must notify affected individuals unless the data was encrypted or otherwise rendered unintelligible to unauthorized parties.
The notification must describe the nature of the breach, the likely consequences, and the measures you have taken or will take to address the breach and mitigate harm. You must also provide contact information for your data protection officer or other point of contact. Failure to report breaches can result in substantial penalties and loss of public trust.
Data Protection Officers and Accountability
Organizations that process large volumes of personal data or engage in systematic monitoring of individuals must appoint a Data Protection Officer (DPO). The DPO serves as the point of contact between the organization and the Puerto Rico Data Protection Authority and is responsible for monitoring compliance with Act 115-2018.
Even if your organization is not required to appoint a DPO, you should designate someone responsible for data privacy compliance. This person should understand the law, oversee data handling practices, respond to individual requests, manage breach notifications, and maintain documentation of your compliance efforts.
Act 115-2018 requires organizations to maintain records demonstrating compliance with the law. This includes documentation of your lawful basis for processing, records of individual consents, breach notifications, and evidence of security measures implemented. These records must be available for inspection by the Puerto Rico Data Protection Authority.
International Data Transfers and Cross-Border Compliance
If your business transfers personal data of Puerto Rico residents to countries outside Puerto Rico, you must ensure that the recipient country provides an adequate level of data protection. Act 115-2018 restricts transfers to countries that do not meet this standard unless you have obtained explicit consent from the individual or have implemented appropriate safeguards such as standard contractual clauses.
This requirement is particularly important for businesses that use cloud services, outsource operations, or maintain operations in multiple jurisdictions. You should review your service agreements with vendors and ensure that any data processing by third parties complies with Puerto Rico law. Transferring data to a third party does not relieve you of your obligations under Act 115-2018.
If your organization is subject to both Puerto Rico law and other data privacy regimes such as the European Union's General Data Protection Regulation (GDPR), you must comply with the most stringent requirements. This often means implementing practices that satisfy both frameworks simultaneously.
Sector-Specific Data Privacy Requirements
Beyond Act 115-2018, certain industries in Puerto Rico are subject to additional data privacy and security requirements. Financial institutions, including banks and securities firms, must comply with federal banking regulations and Puerto Rico banking law that impose strict data security and customer information protection standards. These requirements often exceed the baseline protections in Act 115-2018.
Healthcare providers and organizations handling health information must comply with both Act 115-2018 and Puerto Rico health privacy laws. Health data is considered sensitive personal data and requires heightened protection measures.
Businesses operating under Puerto Rico's tax incentive programs, including those benefiting from Act 60, must ensure that their data privacy practices comply with all applicable laws. Tax incentive status does not exempt a business from data protection obligations.
Technology companies, particularly those involved in blockchain and cryptocurrency operations, face additional scrutiny regarding data security and customer information protection. These businesses should implement robust data governance frameworks that exceed minimum legal requirements.
Penalties for Non-Compliance
Violations of Act 115-2018 can result in significant financial penalties. The Puerto Rico Data Protection Authority has authority to impose fines for violations of the law. Penalties vary based on the severity of the violation, the number of individuals affected, and whether the violation was intentional or negligent.
Beyond administrative penalties, individuals harmed by data privacy violations can pursue civil claims against organizations. This creates potential liability for damages, attorney fees, and costs. A single data breach affecting thousands of individuals can generate substantial litigation exposure.
Data privacy violations can also trigger regulatory action by other agencies. Financial regulators may take enforcement action against banks and securities firms. Tax authorities may question the legitimacy of tax incentive claims if data security practices are inadequate. Reputational damage from privacy violations can harm customer relationships and business prospects.
Practical Compliance Steps for Your Business
Begin by conducting a data audit to identify all personal data your organization collects, where it is stored, how it is processed, and who has access to it. Document the lawful basis for each type of processing. This audit will reveal gaps in your current practices and help you prioritize compliance efforts.
Review and update your privacy policies and notices to ensure they comply with Act 115-2018. Your privacy policy should clearly explain what data you collect, why you collect it, how long you retain it, and what rights individuals have. Make this information easily accessible to customers and employees.
Implement technical and organizational security measures appropriate to the sensitivity of the data you process. This includes access controls, encryption, regular security assessments, employee training, and incident response procedures. Document these measures and maintain evidence of their implementation.
Establish procedures for responding to individual requests for access, correction, deletion, and objection. Train staff on these procedures and ensure requests are handled within required timeframes. Maintain records of all requests and responses.
Create a data breach response plan that identifies who will be notified, what information will be provided, and how quickly notifications will be sent. Test this plan regularly to ensure it can be executed effectively if a breach occurs.
If you use third-party service providers to process personal data, enter into written data processing agreements that clearly allocate responsibilities and require compliance with Act 115-2018. Audit these vendors periodically to ensure they are meeting their obligations.
Provide regular training to employees who handle personal data. They should understand the law, your organization's policies, and their individual responsibilities for protecting customer and employee information.
Next Steps
Data privacy compliance is not a one-time project but an ongoing responsibility. As your business grows and your data handling practices evolve, your compliance obligations will change. Regular review and updates are essential.
If you are uncertain about your current compliance status or need guidance on implementing data privacy practices, schedule a free initial evaluation with Christian M. Frank Fas, Esq. With over 20 years of experience in Puerto Rico business law, Mr. Frank Fas can assess your data handling practices, identify compliance gaps, and recommend practical solutions tailored to your business. Request your free initial evaluation today.
