Browse by jurisdiction
Brazil's LGPD is modeled after the GDPR with extraterritorial scope. Requires explicit consent with separate authorization per processing purpose. Non-essential cookies require prior consent per ANPD guidance. Penalties include publicization of the infraction, creating reputational risk beyond fines.
Colombia's comprehensive data protection law with active SIC enforcement. Requires prior, express, and informed consent for all processing including cookies. The SIC has broad investigative powers including on-site inspections. Authorization logs are required for cookies, and a pop-up must inform users about privacy and cookie management.
Completely new data protection law enacted March 2025, replacing the 2010 version. The INAI was dissolved and replaced by Transparencia para el Pueblo. Introduces criminal penalties, specialized federal data protection courts, and doubled fines for sensitive data violations. Express consent required for sensitive data; implied consent available for non-sensitive.
A complete overhaul of Chile's data protection framework replacing the 1999 law. Creates a new dedicated Data Protection Agency, introduces tiered penalties, and explicitly prohibits pre-ticked consent boxes. The agency must issue cookie guidelines. Takes effect December 2026 after a 24-month implementation period.
Peru's data protection law was significantly strengthened in 2025 with updated regulations introducing phased DPO requirements, extraterritorial scope, and the tightest breach notification timeline in the region. Foreign companies serving Peruvian individuals must appoint local representatives. Maximum penalty is 10% of annual net income.
The most comprehensive data protection law in the Caribbean, with GDPR-level penalties (4% of worldwide turnover). Individual violators face both fines and up to 10 years imprisonment. The OIC operates independently with broad enforcement powers including assessment notices, information notices, and criminal prosecution.
One of the earliest comprehensive data protection laws in Latin America, granting Argentina EU adequacy since 2003. The law is increasingly outdated, and reform bills submitted in 2025 would introduce GDPR-aligned penalties of up to 4% of turnover. Current penalties under the original law are low.
Ecuador's LOPDP requires all organizations to implement a Comprehensive Personal Data Protection System (SPDP) by December 2025. After initially zero sanctions, recent fines against LigaPro (~$250K) and the Football Federation (~$200K) demonstrate increasing enforcement. DPO registration is required on the authority's digital platform.
Paraguay's first comprehensive data protection law (Ley 7593/2025), promulgated November 2025 with a two-year vacatio legis, becomes enforceable around November 2027. GDPR/LGPD-modeled with prior consent, implying opt-in for non-essential website cookies.
Uruguay's data protection law earned EU adequacy in 2012. Features mandatory database registration with quarterly updates and graduated enforcement from warning through database closure. Uruguay also ratified Convention 108+ for additional international alignment.
Costa Rica's data protection law requires informed and express consent for all processing including cookies and online tracking. Organizations must register databases with PRODHAB. PRODHAB can suspend data processing for up to 6 months for serious violations. Breach notification is required within 5 business days.
El Salvador's comprehensive data protection law (Decreto 144), in force since November 2024, requires prior consent to process personal data. For websites this implies opt-in consent before non-essential cookies load.
Barbados's data protection law requires mandatory breach notification within 72 hours (GDPR-aligned) and registration with the Data Protection Commissioner before processing. Penalties range widely from BD $10,000 to $500,000 with criminal sanctions including 2 months to 3 years imprisonment.
Bermuda's PIPA became fully effective January 2025 after phased implementation from 2016. Requires clear, free, and informed consent with mandatory privacy officer designation. Failure to notify breaches is a criminal offense. Court-ordered compensation is available for financial loss or emotional distress.
The Cayman Islands' data protection law was designed with EU adequacy in mind. The Ombudsman has substantial enforcement powers including information orders, enforcement orders, inspection and seizure powers, and monetary penalties. Data breach notification is required within 5 days.
Panama's data protection law establishes principles including loyalty, purpose limitation, proportionality, and transparency. ANTAI oversees enforcement with powers to conduct inspections and approve cross-border transfers. Violations are classified into minor (3-year expiry), serious (5-year expiry), and very serious (no prescription).
Belize's Data Protection Act 2021 is a GDPR-style consent-based law requiring prior consent to process personal data, implying opt-in for non-essential website cookies.
Cuba's Ley 149/2022, effective February 2023, is a consent-based data protection law. Processing personal data requires prior consent, implying opt-in for non-essential website cookies.
The Dominican Republic has a comprehensive data protection framework inspired by European standards, but lacks a dedicated supervisory authority, creating a significant enforcement gap. Criminal sanctions of 6 months to 2 years imprisonment are available. The Bank Superintendency handles only credit bureau violations.
Guyana's Data Protection Act 2023 was assented in August 2023 but has not been brought into force (no commencement order as of 2026). Once operative it is consent-based, implying opt-in for non-essential website cookies.
Nicaragua's Ley 787 is a consent-based data protection law requiring prior consent to process personal data, implying opt-in for non-essential website cookies.
Saint Lucia's Data Protection Act 2011 was brought into force in 2023. It is consent-based, requiring prior consent to process personal data, implying opt-in for non-essential website cookies.
Antigua and Barbuda's data protection law establishes a framework for personal data processing with the Information Commissioner as enforcement authority. Features both summary and indictable offense categories with escalating penalties, including up to 5 years imprisonment for serious violations.
The Bahamas' original data protection law is over 20 years old and increasingly outdated. It establishes basic principles for fair and lawful collection, accuracy, and secure storage. A comprehensive GDPR-inspired replacement bill (Data Protection Bill, 2025) is under public consultation covering AI, biometrics, and cloud computing.
The Wbp BES governs personal data in the Caribbean Netherlands (the special municipalities Bonaire, Sint Eustatius and Saba). It is consent-based, implying opt-in for non-essential website cookies.
Curaçao has its own personal data protection ordinance, separate from the Netherlands' GDPR implementation. The penalty ceiling is relatively low at NAf. 10,000. As an autonomous country within the Kingdom of the Netherlands, Curaçao maintains its own data protection framework.
Sint Maarten has its own personal data protection ordinance with substantially higher penalties than neighboring Curaçao: NAf. 500,000 versus NAf. 10,000 (50x higher). As an autonomous country within the Kingdom of the Netherlands, it maintains an independent framework.
The BVI's first comprehensive data protection law establishes an Information Commissioner role with penalties up to USD 500,000 for corporations. However, the Commissioner is not yet fully operational, creating an enforcement gap despite the law being in force.
Trinidad and Tobago's data protection law has been only partially in force since 2012 and remains not fully operational after more than 14 years. The delay stems from incomplete establishment of administrative frameworks. While comprehensive on paper, practical enforcement remains severely limited.
Aruba is an autonomous country within the Kingdom of the Netherlands with its own personal data protection ordinance, separate from the Netherlands' GDPR implementation. The framework is consent-based with data subject rights and registration requirements.