Which Puerto Rico
rules might
apply to you?
Most businesses here answer that question by thinking about GDPR, or about whatever their US-based web agency mentioned once. Both miss the point: Puerto Rico has its own statutes, and they have been in force for years.
Twelve questions. Your answers stay in your browser: there is no submit, no email gate, and no lead capture. Our analytics receives the derived result: counts of how many items came back as gaps, open questions or possible triggers, and how many you answered. It does not receive your individual answer selections, any free text, your name, your email address or your organization name. At the end you get apparent gaps, open questions, and possible triggers, each naming the statute behind it, so you can hand a list to your lawyer instead of a vague worry. It is not a score and it cannot tell you whether you comply.
What actually
applies here.
↳ narrower than you fear, closer than you think
Two useful facts before you start. First, as of 15 August 2026 Puerto Rico has no enacted general omnibus consumer privacy statute: comprehensive bills have been introduced in recent sessions but none has been enacted. Second, and as of 15 August 2026, that does not mean nothing applies. Several older, narrower statutes bind an ordinary business with a website, and they are the ones people miss precisely because they are not called a privacy law.
Federal law is not somewhere else either: under 48 U.S.C. § 734, US statutory law has the same force in Puerto Rico. HIPAA’s definitions name the Commonwealth expressly, the TCPA and FTC Act §5 reach territories, and COPPA applies through its operator definition.
The one with teethLey 39-2012
Requires covered commercial operators to publish a privacy policy, in clear and conspicuous terms, describing what they collect and the persons or entities with whom information may be shared. Whether categories suffice or vendors need naming is fact-specific and a question for counsel. Mismatch between policy and practice carries a fine up to $50,000.
The one everyone misquotesLey 111-2005
Breach notification. The ten-day clock runs to DACO only and is improrrogable; there is no fixed deadline for telling the affected individuals, which must happen “de la manera más expedita posible.” Penalties run $500 to $5,000 per violation.
The recent onesLey 185-2024 & 163-2026
Minors’ cyber-privacy since March 2025, and AI-likeness protection since August 2026. Both are recent enough to be worth checking against deliberately.
The check.
↳ “not sure” is a real and useful answerAnswer as your site is today, not as you intend it to be. The first seven questions are about duties. The last five are about coverage: whether a statute plausibly reaches you at all, which is a different question and often the more important one. Uncertainty on any of them is itself the finding.
This is education, not legal advice, and on this page especially. Mutiny Labs is a technology studio, not a law firm. This check is a plain-language summary of statutes as we understand them; it does not account for your sector, your contracts, your corporate structure, or any facts specific to you, and it cannot tell you whether you are compliant. Nothing here creates a lawyer-client relationship. Take the summary to a Puerto Rico attorney. That is exactly what it is designed for.
