Compliance

Cookies, GDPR and Ley 172-13: what your Dominican website actually needs

Not legal advice — a practical look at what a Dominican website needs for consent, what people forget, and the embeds that quietly load trackers anyway.

7 min read

The data protection conversation here has two parts, and most websites in this market only know about one of them. There is Ley 172-13, the Ley de Protección de Datos Personales, supervised by MEGAIP, which applies to everybody. And there is the GDPR, which additionally applies to the personal data of EU visitors — which, in a country whose tourists come from Germany, France, Italy, Canada and Russia, is a great many of them. Get the first one right and ignore the second and you are still exposed. We are not lawyers, and this is not legal advice, but it is the checklist we build to.

What the law actually asks for

Consent has to be informed, specific, unambiguous and freely given. In practice that means a banner that explains what is being stored and why, in a language the visitor understands, before anything non-essential loads. It also means the option to refuse has to be as easy to find and as easy to use as the option to accept.

  • No analytics, advertising or marketing tag loading before someone has agreed
  • A genuine 'reject all' that is as prominent as 'accept all', not a greyed-out link
  • Granular choices where people want them — cookies, measurement, marketing, third parties
  • A record of what was consented to and when, so you can answer a question later
  • A way to change the decision later, on every page, not just by clearing cookies

The embeds everyone forgets

This is where well-intentioned sites get into trouble. The cookie banner is fitted, the policy is written, and then somebody adds a booking widget, a map, a Facebook pixel, an Instagram feed, a YouTube video and a live chat tool — and every one of those arrives from a different company and sets its own storage. The visitor agreed to one thing and ended up with six. There is a Dominican addition to that list as well: a WhatsApp widget. A plain link to wa.me is harmless, and is what we would rather you had, but an embedded click-to-chat widget loads somebody else's script on every page.

  • Google Analytics, or the alternatives people install when the default one stops reporting on patchy mobile data
  • The Meta pixel, and any retargeting tag that follows a visitor around
  • Booking.com, reservation widgets for a restaurant, and vacation rental availability scripts
  • YouTube embeds, and the cookies they set before you press play
  • Google Maps embeds, which are not as harmless as they look
  • Fonts and scripts loaded from someone else's content delivery network

What we actually build

A consent layer that actually blocks. Not one that fires a message and then loads the script regardless — we have taken over sites where the 'reject' button did precisely that, which is worse than having no banner at all, because it looks compliant to everyone except the visitor. Blocking means the script does not execute until the decision has been made, and it stays blocked for anyone who declines.

On top of that: a privacy policy written around what your business genuinely does, with retention periods rather than vague promises; a page that identifies the business properly — name, address, and the cédula or RNC numbers where you have them; hosting in the Dominican Republic or close to your visitors wherever there is a choice; and analytics that stay switched off until the visitor agrees to them.

When the data is genuinely sensitive

Health information, identity documents, cédula and passport scans, legal and tax details — these belong to a different category under the GDPR, with a higher bar and shorter retention. A dental clinic enquiry form that asks for a medical history is collecting more than it needs. A property manager's site that takes a passport photograph over WhatsApp is doing something no amount of cookie policy makes acceptable, and the fact that WhatsApp is how everybody here communicates makes it easy to do by accident. Where documents are needed, we build a secure route with a defined deletion date, and say on the page when the file will be destroyed.

Newsletters and the messages you send

A newsletter needs its own consent, and it needs to be consent for that newsletter — not a vague 'by continuing to browse'. Every message needs a working unsubscribe that takes one click and does not ask for a reason. And if you email a list you bought rather than earned, you are inviting an administrative fine under Ley 172-13 that nobody needs. The same goes for a WhatsApp broadcast list: it still needs a real opt-in, and people need a way out that does not require a conversation.

The practical version: get the technical side right, then have a Dominican lawyer read the legal wording. We handle the first properly and we would always rather you did the second than took our word for it. Consumer protection is a separate question entirely — Ley 148-01, administered by Pro-Consumidor — and it is worth reading before you write a refund policy or a deposit clause. If you already have a site and are not sure what state it is in, ask for a free audit and we will tell you what is missing before you spend anything on it.

Free, no-obligation

Get a free website audit and quote

Tell us about your business and we’ll come back with honest, friendly advice — including a clear quote and what we’d improve first.

Trusted by businesses across the Dominican Republic