Skip to content
Datos y confianza

Law 8968 in practice: what your company has to do

Almost everyone repeats that the database must be registered with PRODHAB. The law says something more precise than that.

Published 11 min read Navhera

Costa Rica has had a data protection law since 2011, and many companies in the country live alongside it without quite knowing what it requires of them. When the subject comes up — usually because someone is about to buy a new system — the conversation fills with repeated half-truths, and the one repeated most often is also the least accurate.

Before going further. This article explains how we read the law in order to make technical decisions, with the sources in plain view. It is not legal advice, and a company handling health data, high-volume data or data about minors should check it with a lawyer. What this text can do is make that conversation with the lawyer start better informed.

What Law 8968 is

Law No. 8968, Ley de Protección de la Persona frente al tratamiento de sus datos personales — Costa Rica's personal data protection act — was enacted on 7 July 2011 and published in La Gaceta on 5 September of that year. It governs what an organisation may do with information about identifiable people. It was implemented through Executive Decree 37554-JP and is supervised by PRODHAB, the national data protection agency.

Its premise is that the data belongs to the person, not to whoever collects it. Whoever collects it administers it under conditions, and those conditions do not end at the moment of asking.

The four obligations that reach almost any company

1 · Informed and express consent

Before collecting personal data you have to tell the person who is collecting it, what for, what will be done with it, whether it will be passed to anyone else and what rights they have. And you have to obtain their authorisation.

What gets broken most often is not asking permission: it is respecting the purpose. The phone number a customer gave you to arrange a delivery was given to arrange a delivery. Using it later for a promotional campaign is a different kind of processing, and it needs its own basis.

2 · The person's rights

Anyone can ask you to tell them what data of theirs you hold, to correct it if it is wrong, to delete it once it is no longer needed or was collected improperly, and to object to particular uses.

The practical implication is underestimated: you have to be able to find all of a person's data when they ask for it. If a customer's data is spread across one system, three spreadsheets and the WhatsApp accounts of two employees, that right cannot be honoured no matter how willing everyone is.

3 · Security measures

The law requires technical and organisational measures proportionate to the nature of the data and to the risk, protecting it from unauthorised access, loss, destruction or alteration.

«Proportionate» means a small company is not asked for what a bank is asked for, but it is asked for something: control over who has access to what, passwords that are not shared, backups that have actually been tested, and no complete databases sitting on personal devices.

4 · Care with transfers

Handing data to a third party is processing that needs its own basis. A software provider, an automation platform or an AI tool are third parties, however much they feel like «just a tool». The operating criterion for the AI case is in what data should not go into a model.

The point almost everyone gets wrong

The sentence going around is: «you have to register your database with PRODHAB». Put that way, it is incorrect.

Article 21 of the law says, literally, that «every database, public or private, administered for the purposes of distribution, dissemination or commercialisation, must be entered in the register maintained for that purpose by Prodhab». A database a company keeps for its own operations, and which it neither sells nor transfers nor disseminates, does not fall under that provision merely by existing.

With three qualifications that matter, and which are the reason not to stop at the short version of this article:

  • The implementing decree defined what commercialising, distributing, disseminating and transferring mean, and those definitions are broader than intuition suggests: they cover sharing or handing over data, whether for payment or free of charge. Many everyday practices fit there without anyone experiencing them as «selling data».
  • Registration carries an annual fee of two hundred US dollars. The agency does not set it at its own discretion: the figure is in the text of the law, in United States dollars. Even so, confirm the current amount and procedure with PRODHAB before budgeting for it.
  • Failing to register when required is a punishable infringement, not an administrative oversight. Doubt about whether you must register is not harmless doubt, and it is exactly the kind of question that justifies a short legal consultation.

So the honest formulation is: not every database has to be registered, but the boundary is drawn by use, not by size. If your company routinely shares customer data with third parties, that consultation should be made by a lawyer with the detail of your operation in front of them.

What happens if you do not comply

PRODHAB can act on a complaint or on its own initiative, request documentation, inspect databases, order that processing be suspended and that improperly collected data be deleted.

Infringements are graded as minor, serious and very serious, and fines are set in base salaries — the reference unit used across Costa Rican law, updated each year — as follows: up to five base salaries for minor infringements, five to twenty for serious ones and fifteen to thirty for very serious ones. The equivalent in colones changes annually because the base salary is revised; that is why this article gives the range in the law's own unit rather than a figure that would age badly.

The sanction that usually hurts most, however, is not the fine. For very serious infringements the law also provides for suspending operation of the database for one to six months. Translated into operations: six months without being able to use the database the business runs on.

What to do this week, before involving a lawyer

Four tasks that cost nothing and that put the later conversation in order:

  1. Take the inventory. What personal data you hold, where it lives, who can see it and since when. Two or three places nobody remembered almost always turn up.
  2. Write down the purpose of each one. What you asked for it. If you cannot write it, that is the first problem.
  3. Review who you are passing it to. Systems, platforms, agencies, accountants. Each one is a transfer.
  4. Decide who answers for it. One named person in charge of the subject. Without an owner there is no compliance, there are good intentions.

With those four things done, the legal consultation costs less and achieves more. How we apply these same rules to the data this site collects is written in the privacy policy.

A reform under discussion. Bill 23.097, «Ley de Protección de Datos Personales», has been before the Legislative Assembly since 9 May 2022, and proposes replacing the current framework with one closer to the European model. As of this edition it remains in progress: it has been neither approved nor shelved, and therefore changes nothing in this article. The law in force is the one described here. If the bill advances, this text will be updated.

Frequently asked questions

What does Law 8968 require of a company in Costa Rica?

Four main things: obtain informed, express consent before collecting personal data and respect the purpose it was asked for; be able to honour the person's rights to access, correct, delete and object; apply security measures proportionate to the risk; and have your own basis for transferring data to third parties, software providers included.

Does every database have to be registered with PRODHAB?

No. Article 21 of Law 8968 requires registration of databases, public or private, administered for the purposes of distribution, dissemination or commercialisation. A database a company keeps solely for its own operations, without selling, transferring or disseminating it, does not fall under that provision merely by existing. The important qualification is that the implementing decree defines those terms broadly and covers sharing data free of charge as well, so the boundary is drawn by the specific use and is worth reviewing with a lawyer. Registration carries an annual fee of two hundred US dollars.

What fines does Costa Rica's data protection law provide for?

Infringements are graded as minor, serious and very serious. Fines are expressed in base salaries: up to five for minor ones, five to twenty for serious ones and fifteen to thirty for very serious ones. The equivalent in colones varies each year because the base salary is revised. For very serious infringements the law also provides for suspending operation of the database for one to six months, which in practice usually weighs more than the fine. PRODHAB can also order that processing be suspended and that improperly collected data be deleted.

Does using a foreign AI or automation tool break the law?

Not in itself. What the law requires is that a basis exists for that transfer and that the person has been informed their data may be processed this way. The problem appears when personal data is passed to a third party for a purpose other than the one it was collected for, which is what happens almost every time without anyone noticing.

Is Costa Rica's data protection law going to change?

There is a bill in progress. Bill 23.097, «Ley de Protección de Datos Personales», was introduced on 9 May 2022 and proposes a framework closer to the European model. It has been neither approved nor shelved, so the law in force remains Law 8968 with its implementing decree. It is worth checking the bill's status before making a decision that depends on it.

Sources and notes

  1. Law No. 8968, Ley de Protección de la Persona frente al tratamiento de sus datos personales, enacted on 7 July 2011 and published in La Gaceta no. 170 of 5 September 2011. Text on the website of the Ministry of Science, Innovation, Technology and Telecommunications. Article 21, registration of databases; articles 28 to 31, the sanctions regime; the annual fee of US$200 is set in the text of the law itself.
  2. Executive Decree No. 37554-JP, Reglamento a la Ley N.º 8968, signed on 30 October 2012 and published in La Gaceta no. 45 of 5 March 2013, as later amended by Executive Decree No. 40008-JP.
  3. PRODHAB — Agencia de Protección de Datos de los Habitantes, the supervisory authority. The current fee and procedure are to be confirmed with the agency.
  4. Legislative Assembly of Costa Rica, bill 23.097, Ley de Protección de Datos Personales, introduced on 9 May 2022 and in progress as of this edition.
  5. This article does not constitute legal advice. It is marked perishable: it is reviewed every three months, and in particular if bill 23.097 changes status.

Written by the Navhera team and reviewed before publishing. If you spot an error, write to us and we will correct it with a note.