Support & Education 12 questions · 10 minutes Nothing is submitted anywhere

Which Puerto Rico
rules might
apply to you?

Most businesses here answer that question by thinking about GDPR, or about whatever their US-based web agency mentioned once. Both miss the point: Puerto Rico has its own statutes, and they have been in force for years.

Twelve questions. Your answers stay in your browser: there is no submit, no email gate, and no lead capture. Our analytics receives the derived result: counts of how many items came back as gaps, open questions or possible triggers, and how many you answered. It does not receive your individual answer selections, any free text, your name, your email address or your organization name. At the end you get apparent gaps, open questions, and possible triggers, each naming the statute behind it, so you can hand a list to your lawyer instead of a vague worry. It is not a score and it cannot tell you whether you comply.

Start the check ↓
The question behind the question:
Not “do you have a privacy policy”, but are you a covered operator, and does the policy describe who your data may be shared with?

What actually
applies here.

↳ narrower than you fear, closer than you think

Two useful facts before you start. First, as of 15 August 2026 Puerto Rico has no enacted general omnibus consumer privacy statute: comprehensive bills have been introduced in recent sessions but none has been enacted. Second, and as of 15 August 2026, that does not mean nothing applies. Several older, narrower statutes bind an ordinary business with a website, and they are the ones people miss precisely because they are not called a privacy law.

Federal law is not somewhere else either: under 48 U.S.C. § 734, US statutory law has the same force in Puerto Rico. HIPAA’s definitions name the Commonwealth expressly, the TCPA and FTC Act §5 reach territories, and COPPA applies through its operator definition.

The one with teethLey 39-2012

Requires covered commercial operators to publish a privacy policy, in clear and conspicuous terms, describing what they collect and the persons or entities with whom information may be shared. Whether categories suffice or vendors need naming is fact-specific and a question for counsel. Mismatch between policy and practice carries a fine up to $50,000.

The one everyone misquotesLey 111-2005

Breach notification. The ten-day clock runs to DACO only and is improrrogable; there is no fixed deadline for telling the affected individuals, which must happen “de la manera más expedita posible.” Penalties run $500 to $5,000 per violation.

The recent onesLey 185-2024 & 163-2026

Minors’ cyber-privacy since March 2025, and AI-likeness protection since August 2026. Both are recent enough to be worth checking against deliberately.

The check.

↳ “not sure” is a real and useful answer

Answer as your site is today, not as you intend it to be. The first seven questions are about duties. The last five are about coverage: whether a statute plausibly reaches you at all, which is a different question and often the more important one. Uncertainty on any of them is itself the finding.

Privacy policy · Ley 39-2012Are you a covered operator, and if so does your website publish a privacy policy?
Privacy policy · Ley 39-2012Does it identify the persons or categories of entities your data may be shared with?
Privacy policy · Ley 39-2012If you maintain a way for people to review or change their information, does the policy explain it, and does it explain how policy changes are announced?
Privacy policy · Ley 39-2012Does the published policy actually match what your site does today?
Breach readiness · Ley 111-2005Is there a written breach plan that names who files with DACO, and who decides?
Breach readiness · Ley 111-2005Do the people who would handle a breach know that the ten-day clock runs to DACO, and not to your customers?
Advertising · Ley 5-1973Would every claim on your site survive a regulator reading it literally?
What you collectDo you collect email addresses or ZIP codes from Puerto Rico residents?
What you collectDo you collect any biometric feature: voice recordings, fingerprints, or retina images?
Social networks · Ley 185-2024Does your service meet Ley 185-2024’s definition of a social-network site or application, and allow Puerto Rico residents aged 18 or younger to register?
Government IT vendors · Ley 40-2024Are you a contracted information-technology or communications service provider to the Government of Puerto Rico?
AI & likeness · Ley 163-2026Do you make commercial or advertising use of an identifiable person’s AI-generated or cloned likeness, and do you have documented authorization?
0 of 12 answered
read this one ↳

This is education, not legal advice, and on this page especially. Mutiny Labs is a technology studio, not a law firm. This check is a plain-language summary of statutes as we understand them; it does not account for your sector, your contracts, your corporate structure, or any facts specific to you, and it cannot tell you whether you are compliant. Nothing here creates a lawyer-client relationship. Take the summary to a Puerto Rico attorney. That is exactly what it is designed for.

↳ if the answers surprised you

That’s a conversation.

Some of what this check surfaces is documentation that can be corrected quickly. Other parts, like consent architecture, a data inventory, deletion workflows or vendor changes, take technical, contractual or legal work. If it turns out to be architectural, a platform that collects things nobody chose to collect and cannot tell you who has the data, that part is our day job.