Skip to content
MiPRFácil
ESEN
Public Utilities

Your data was breached: what they must tell you, and how fast

Last reviewed: August 23, 2026VerifiedDACO

In short

Act 111-2005 requires every entity that owns or holds a data bank containing personal information of citizens residing in Puerto Rico to notify them of any breach of system security, when the breached data banks contained, in whole or in part, their personal information file and that information was not protected with cryptographic keys beyond a password. Notification to customers must be made as expeditiously as possible, taking into account law enforcement’s need to secure possible crime scenes and evidence, and to apply the measures needed to restore system security. And there are two concrete clocks: the responsible parties shall inform the Department of Consumer Affairs within a non-extendable term of ten (10) days from detecting the breach, and the Department shall make a public announcement about it within twenty-four (24) hours of receiving that information. The notice you receive must be delivered clearly and conspicuously, describe the breach in general terms and the type of sensitive information involved, and include a toll-free phone number or an Internet site you can use for more information or assistance.

External link

Go to the official site

You'll leave MiPRFácilOpens in a new tab

bvirtualogp.pr.gov

What is it?

This is Puerto Rico’s data breach notification law. It defines "breach of system security" broadly: any situation where it is detected that unauthorized persons or entities have been allowed access to the data files, such that the security, confidentiality or integrity of the information is compromised; or when that access is by normally authorized persons or entities and it is known or reasonably suspected that they violated professional confidentiality or obtained their authorization under false representations intending to make unlawful use of the information. It includes both access through the system and physical access to the recording media holding the data, and any improper removal or movement of those recordings. In other words: a "hack" is not required for the law to apply.

Who can do it?

Citizens residing in Puerto Rico whose data is in the breached data bank. What decides whether you are covered is the definition of "personal information file": a record containing at least your name or first initial and your paternal surname, combined with any of these data in such a way that they can be associated with one another, and in which the information is legible without needing a special cryptographic key: Social Security number; driver’s license, voter card or other official identification number; bank or financial account numbers of any kind, with or without their access keys; usernames and passwords to public or private computer systems; medical information protected by HIPAA; tax information; and employment evaluations. What the law expressly excludes from protected information: the postal or residential address, and any information that is a public document available to the general public.

Requirements

Documents you need

Cost

This procedure has no cost.

Step by step

  1. Step 1: Check whether your data falls within the definition

    The law does not protect just any data. It protects the record combining your name — or first initial — and your paternal surname with at least one of seven data types: Social Security; driver’s license, voter card or other official identification; bank or financial accounts; usernames and passwords; HIPAA-protected medical information; tax information; and employment evaluations. If all that leaked was your address, the law expressly says the postal or residential address is not within the protected information.

  2. Step 2: Know what the notice must say

    Article 4 sets the minimum content: the notice shall be delivered clearly and conspicuously, describe the security breach in general terms and the type of sensitive information involved, and include a toll-free phone number or an Internet site you can use for more information or assistance. A notice that does not say what type of information was affected, or that gives you no way to make contact, is incomplete under the text.

  3. Step 3: Understand why sometimes you hear it from the press

    The law gives the entity two routes. The first is direct written notice to those affected, by mail or by authenticated electronic means under the Digital Signatures Act. The second applies when the cost of notifying or identifying everyone would be excessively burdensome because of the number of people, the difficulty of locating them or the entity’s financial situation; or whenever the cost exceeds one hundred thousand ($100,000) dollars or the number of people exceeds one hundred thousand. In that case the entity must do two things: prominently display an announcement at its premises, on its website if it has one, and within any informational flyer it publishes and sends through postal and electronic mailing lists; and communicate it to the press, reporting the situation and how to contact the entity for follow-up.

  4. Step 4: Count the ten days and the twenty-four hours

    These are the law’s two measurable deadlines. The responsible parties shall inform the Department of Consumer Affairs within a non-extendable term of ten (10) days from detecting the breach of system security. And the Department shall make a public announcement about it within twenty-four (24) hours of receiving the information. Note the word non-extendable: it admits no extension. If you learned of a breach long before any announcement, those are the deadlines to cite when claiming.

  5. Step 5: If the breach was at a government body, the forum is different

    Article 7 separates it: where the breach or irregularity in data bank security systems occurs at a government agency or public corporation, it shall be notified to the Office of the Citizen’s Ombudsman, which shall assume jurisdiction, and for that the Ombudsman shall designate a Specialized Ombudsman to handle this type of case. The law also ordered it to create within its Office the position of Specialized Ombudsman for Government Data Bank Security Systems. We do not link that office because we could not load a working host: search for it by its full name rather than assuming an address.

  6. Step 6: Know what you have besides the fine

    The Secretary may impose fines from five hundred ($500) dollars up to a maximum of five thousand ($5,000) dollars for each violation of this law or its regulation. And the law closes with something worth reading slowly: the fines set in that article do not affect consumers’ rights to bring actions or damage claims before a competent court. That is, DACO fining the company does not consume your claim for the damages the breach caused you.

Where to do it

The Department of Consumer Affairs is the agency the law designates: it receives the entity’s report within ten days, makes the public announcement within the following twenty-four hours, and is the one that imposes the fines. The law also ordered it to design and issue a regulation for compliance with its provisions. If the breach occurred at a government agency or public corporation, jurisdiction belongs to the Office of the Citizen’s Ombudsman through a Specialized Ombudsman. And the damages route before a competent court remains open in any case.

How long it takes

The entity has a non-extendable 10 days from detecting the breach to inform DACO, and DACO shall make a public announcement within 24 hours of receiving that information. Notice to affected people goes "as expeditiously as possible".

Verified against the official source · August 23, 2026

What to do if something goes wrong

Who is bound, because the definition of "entity" is among the broadest there is: every agency, board, body, examining tribunal, corporation, public corporation, commission, independent office, division, administration, bureau, department, authority, officer, instrumentality or administrative organ of the three branches of government; every private corporation, partnership, association, company or organization authorized to do business or operate in Puerto Rico; and every public and private educational institution, whatever level of education it offers. Your children’s school is included. There is a chain obligation almost nobody mentions: every entity that as part of its functions resells or provides access to digital data banks containing personal information files must notify the owner, custodian or holder of that information of any breach that allowed access by unauthorized persons. And a saving clause the law includes in favor of stricter policies: no provision of this law shall be interpreted to the detriment of institutional information and security policies a company or entity had in force before its effective date and whose effect is equivalent or superior protection. What we do not publish: the regulation DACO had one hundred twenty days to issue, nor the Ombudsman’s, because we did not read them. And a substantive limitation: this law requires notice, not compensation. If what happened to you was fraudulent use of your identity after the breach, that is a different fight, and the law itself leaves the damages action before the court open to you.

Common mistakes

  • Assuming any leak counts: the law protects your name combined with one of seven data types, and excludes the postal or residential address.
  • Overlooking the encryption exception: the duty to notify arises when the information was not protected with cryptographic keys beyond a password.
  • Accepting a notice that does not say what type of sensitive information was affected.
  • Accepting a notice without a toll-free number or an Internet site for more information or assistance.
  • Believing the law only covers "hacks": it also covers physical access to the recording media and improper removal.
  • Thinking schools are outside it: the definition of entity includes every educational institution, public and private.
  • Taking to DACO a breach that occurred at a government agency, when that jurisdiction belongs to the Citizen’s Ombudsman.
  • Believing DACO’s fine replaces your claim: the law expressly says it does not affect your right to claim damages in court.

Frequently asked questions

Must they tell me if my data leaks?

Yes, if the breached data contained in whole or in part your personal information file and that information was not protected with cryptographic keys beyond a password. Notice must be given as expeditiously as possible, considering law enforcement’s need to secure crime scenes and evidence and to restore system security.

How long do they have?

To inform the Department of Consumer Affairs, a non-extendable term of ten (10) days from detecting the breach. The Department shall make a public announcement within twenty-four (24) hours of receiving that information. To notify you, the law sets no number of days: it says "as expeditiously as possible".

What data is protected?

Your name or first initial and paternal surname combined with: Social Security; driver’s license, voter card or other official identification; bank or financial accounts of any kind, with or without keys; usernames and passwords to computer systems; HIPAA-protected medical information; tax information; or employment evaluations. It does not include the postal or residential address or information that is a public document available to the general public.

Can they announce it in the press instead of writing to me?

Only under conditions. When the cost of notifying or identifying everyone would be excessively burdensome, or whenever the cost exceeds one hundred thousand dollars or the number of people exceeds one hundred thousand, the entity may notify through two combined steps: a prominent announcement at its premises, on its website and in its flyers and mailing lists; and a communication to the press explaining the situation and how to follow up.

What is the fine?

From five hundred ($500) up to a maximum of five thousand ($5,000) dollars per violation of the law or its regulation, imposed by the Secretary. Those fines do not affect your right as a consumer to bring actions or damage claims before a competent court.

Official sources

These are the government pages this guide is based on.

Last verified

August 23, 2026

MiPRFácil is an independent informational website and is not affiliated with, endorsed by, or operated by the Government of Puerto Rico or any government agency.

MiPRFácil does not submit applications on your behalf.

Was this guide helpful?

Did you find out-of-date information?

Did you find out-of-date information?

No account needed. We don't ask for personal data.