URUGUAY-1 | Scope, Lawful Basis, Consent | 42 |
URUGUAY-2 | Data Subject Rights (ARCO + Habeas Data) | 20 |
URUGUAY-3 | Sensitive Data, Health Data, Children | 61 |
URUGUAY-4 | Security and Cross-Border | 78 |
URUGUAY-5 | Database Registration with AGESIC URCDP | 109 |
URUGUAY-6 | DPO, Governance, Breach | 0 |
1-5 | Human right, scope, definitions and the value of database operators' actions | 0 |
10 | Principle of data security | 0 |
11 | Principle of confidentiality (reserva) and professional secrecy | 0 |
12 | Principle of proactive responsibility (as amended by Ley 19.670 article 39) and its documented measures | 0 |
13 | Right to information on collection | 0 |
14 | Right of access | 0 |
15 | Rights of rectification, updating, inclusion and suppression | 0 |
16 | Right to contest automated personal evaluations | 0 |
17 | Rights concerning the communication of data | 0 |
18 | Sensitive data and data on offences | 0 |
19 | Health data held by health establishments and professionals | 0 |
20 | Telecommunications operators | 0 |
21 | Databases for advertising and commercial prospecting | 0 |
22 | Commercial and credit data | 0 |
23 | International transfers | 0 |
24-28 | Public databases, security-force databases, exceptions to rights and to the Law, and private databases | 0 |
29 | Registration of databases | 0 |
30 | Outsourced processing of personal data | 0 |
31-34 | The Unidad Reguladora y de Control de Datos Personales (URCDP) | 0 |
35 | Sanctioning powers | 0 |
36 | Codes of conduct | 0 |
37-45 | Habeas data action | 0 |
46-49 | Transitional and final provisions | 0 |
6 | Principle of legality: registered databases with lawful purposes | 0 |
7 | Principle of veracity: accurate, adequate, fair and not excessive data, collected fairly | 0 |
8 | Principle of purpose: no incompatible use, deletion when no longer necessary, no communication without law or consent | 0 |
9 | Principle of prior informed consent, and the exceptions | 0 |
D64.10-15 | Decreto 64/020: the data protection officer (delegado de proteccion de datos) | 0 |
D64.3-4 | Decreto 64/020: security incidents and communication of security breaches within 72 hours | 0 |
D64.6-7 | Decreto 64/020: data protection impact assessment | 0 |
D64.8-9 | Decreto 64/020: privacy by design and by default | 0 |
L19670 | Ley 19.670 (2018) articles 37 to 40 and Decreto 64/020: territorial scope and the 2018 reform | 0 |
REGS | Decreto 414/009, Decreto 308/014, Decreto 64/020 and the EU adequacy decision | 0 |