Skip to content
MiPRFácil
ESEN
Public Utilities

They threw out the files with your data: how the law requires destroying them

Last reviewed: August 24, 2026VerifiedDACO

In short

Act 234-2014 requires every commercial entity that owns, holds or controls files containing consumers’ personal information, before discarding them, to do so — or arrange for their disposal — through shredding, deletion or modification so that the personal information cannot be read or deciphered by any method. When the information is in digital rather than printed form, the entity must ensure its disposal meets this law’s parameters or those of any other applicable law or regulation. The duty expressly reaches every commercial entity that ceases operations, merges or consolidates with another. The procedure is recorded before a notary through a notarial act, and a certified copy of that act must be kept by the entity for inspection for a minimum term of ten (10) years; that notarial requirement does not apply to commercial entities with twenty-five (25) employees or fewer and gross income under three (3) million dollars. The Department of Consumer Affairs may issue regulations and impose fines under Act 5-1973, and those fines do not affect your right to bring actions or damage claims before a competent court.

External link

Go to the official site

You'll leave MiPRFácilOpens in a new tab

bvirtualogp.pr.gov

What is it?

It is the law regulating how files with consumers’ personal information are destroyed in Puerto Rico (10 L.P.R.A. §§ 4181-4188). It came from a concrete concern the statement of motives describes: the uncertainty about the fate of files with personal information when commercial entities abandon them, whether by ceasing operations or simply no longer needing them, and the identity-theft risk that creates. A "personal information file" is a tangible or intangible record containing a consumer’s personal information, and a "commercial entity" is a natural or juridical person normally or occasionally engaged in commerce.

Who can do it?

Any consumer whose personal information is in a commercial entity’s files in Puerto Rico. The law defines "personal information" broadly: any information that identifies, relates to, describes or can be associated with a particular person, including name or first initial and surname; Social Security number; physical characteristics or descriptions; residential or postal address; phone number; passport number; driver’s license or other official identification number; insurance policy number; education; employment; employment history; medical or health policy information; tax information; employment evaluations; biometric data; bank or financial account numbers of any kind, with or without access keys; credit or debit card numbers or other financial information; usernames and passwords to computer systems; and data from motor vehicle "black box" event data recorders. It does not include information disclosed to the general public under any state or federal law.

Requirements

Documents you need

This list describes what is usually requested. It has not yet been confirmed with the official agency.

Cost

This procedure has no cost.

Step by step

  1. Step 1: Know the method the law requires

    Throwing the papers out is not enough. Every commercial entity that owns, holds or controls files with personal information must, before discarding them, do so or arrange for their disposal through shredding, deletion or modification so that the personal information cannot be read or deciphered by any method. That last phrase is the standard: unreadable and undecipherable, not merely discarded.

  2. Step 2: Note that digital also counts

    Where consumers’ personal information is in digital rather than printed form, the commercial entity must ensure its disposal meets the parameters set in this law or in any other applicable law or regulation. A discarded hard drive, a sold computer or a decommissioned server falls under the same duty as a paper file.

  3. Step 3: Remember that closing the business does not erase the duty

    The law says it expressly: every commercial entity that ceases operations, merges or consolidates with another commercial entity must comply with this law when disposing of consumers’ personal information. That was precisely the concern that motivated the law — the files abandoned when a company closes.

  4. Step 4: Know the notarial act and who is exempt

    The destruction procedure must be recorded before a notary through a notarial act, and a certified copy of that act must be kept by the commercial entity for inspection for a minimum term of ten (10) years. But there is a size exception: that requirement does not apply to commercial entities with twenty-five (25) employees or fewer and gross income under three (3) million dollars. Mind the "and": those are two conditions at once, not one or the other.

  5. Step 5: Take the complaint to DACO and keep your damages action

    The Department of Consumer Affairs may issue a regulation to carry out this law’s purposes, though its adoption is not jurisdictional: the law has been in force since its approval, regulation or no regulation. The fines the DACO Secretary may impose under Act 5-1973 for each violation of this law or its regulation do not affect consumers’ rights to bring actions or damage claims before a competent court. That is, fining the business does not consume your claim.

Where to do it

The Department of Consumer Affairs is the agency empowered to regulate and fine under this law, relying on the powers of Act 5-1973. The damages route before a competent court remains open in parallel. If, beyond improper disposal, there was a breach with third-party access, that is a different law and a different clock: the breach notification of Act 111-2005, covered in its own guide.

How long it takes

Check the current processing time with the official agency.

What to do if something goes wrong

How this law relates to the other two on data: Act 111-2005 requires notifying you when there is a security breach; Act 39-2012 and DACO’s provisions regulate what can be asked of you at purchase; and this one, 234-2014, regulates destruction. They are distinct duties with distinct remedies, and they do not replace one another. A saving clause the law includes in favor of stricter policies: no provision of this law shall be interpreted to the detriment of institutional information and security policies a commercial entity had in force before its effective date and whose effect is equivalent or superior protection. What we did not read for this guide: DACO’s regulation under this law, if any, and Act 5-1973’s fine schedules — which is why we publish no amounts. And a substantive limit: this law regulates how the information is destroyed, not how long the entity may keep it or what it may do with it while it holds it.

Common mistakes

  • Believing it is enough to throw out or recycle the documents: the standard is that the information cannot be read or deciphered by any method.
  • Thinking it only applies to paper: the law expressly covers information in digital form.
  • Assuming the duty disappears when the business closes: ceasing operations, merging or consolidating is expressly covered.
  • Reading the notarial exemption as one condition: it is 25 employees or fewer AND under $3 million in gross income.
  • Not keeping the certified copy of the act: the minimum is ten (10) years for inspection.
  • Believing address or phone do not count: unlike Act 111-2005, here the definition of personal information includes them.
  • Thinking DACO’s fine replaces your claim: the law expressly says it does not affect your right to claim damages in court.
  • Confusing this law with the breach notification one: one regulates destruction, the other notice after a leak.

Frequently asked questions

How must they destroy my data?

Through shredding, deletion or modification so that the personal information cannot be read or deciphered by any method. If it is in digital form, the entity must ensure its disposal meets this law’s parameters or those of any other applicable law or regulation.

Does it apply when a business closes?

Yes, expressly: every commercial entity that ceases operations, merges or consolidates with another must comply with this law when disposing of consumers’ personal information.

What is the notarial act and who is exempt?

The destruction procedure is recorded before a notary through a notarial act, and a certified copy is kept for inspection for a minimum of ten (10) years. It does not apply to commercial entities with twenty-five (25) employees or fewer and gross income under three (3) million dollars — both conditions at once.

What information does it protect?

Nineteen types, among them name and surname, Social Security, physical descriptions, address, phone, passport, driver’s license, insurance policy, education, employment and history, medical and tax information, employment evaluations, biometric data, bank accounts and cards, usernames and passwords, and even motor vehicle "black box" data. It does not include information disclosed to the general public under state or federal law.

Where do I complain?

Before the Department of Consumer Affairs, which may regulate and impose fines under Act 5-1973. Those fines do not affect your right to bring actions or damage claims before a competent court.

Official sources

These are the government pages this guide is based on.

Last verified

August 24, 2026

MiPRFácil is an independent informational website and is not affiliated with, endorsed by, or operated by the Government of Puerto Rico or any government agency.

MiPRFácil does not submit applications on your behalf.

Was this guide helpful?

Did you find out-of-date information?

Did you find out-of-date information?

No account needed. We don't ask for personal data.