Skip to content
CorpshoreDominicana

Compliance

Outsourcing in regulated financial services: what Ley 172-13 requires

A close architectural detail of a modern building's steel and glass structure, clean intersecting lines against a navy sky.
The Corpshore Dominicana team·Published June 5, 2026

Law 172-13 governs the protection of personal data in the Dominican Republic. Financial institutions outsourcing functions that involve customer data must ensure their provider can demonstrate a documented compliance position, including lawful basis, access controls, retention rules and an auditable control environment.

This article is general information and not tax or legal advice. Specific tax and legal positions are confirmed with Dominican counsel.

Financial institutions in the Dominican Republic outsource more than they did five years ago, and the functions being outsourced have moved from peripheral to core. Contact centres, collections, onboarding, KYC support, back office processing and regulatory reporting support are all now routinely delivered by third parties.

Every one of those functions touches personal data, which puts Law 172-13 at the centre of the provider selection decision rather than at the edge of it.

In our experience the compliance question is also the most common reason an outsourcing proposal stalls inside a bank. Risk committees block arrangements they cannot examine. Understanding what they are actually looking for shortens the process considerably.

What the law establishes

Law 172-13 establishes the framework for the protection of personal data in the Dominican Republic. Its principles will be familiar to anyone who has worked with comparable regimes: personal data must be collected for legitimate purposes, processed lawfully, kept accurate, retained no longer than necessary and protected by appropriate security measures. Data subjects hold rights over their own information.

For an outsourcing arrangement the practical questions are narrower than the statute. Who is responsible for what, on what basis is the provider processing the data, what happens if something goes wrong, and can any of this be demonstrated to a supervisor or an auditor.

What a risk committee actually asks

Across the financial services engagements we have taken on, the questions cluster tightly.

Can we examine the control environment? Not whether controls exist, but whether the institution can inspect them. This is where many arrangements fail. A provider that will not accept a right-to-audit clause with on-site inspection is asking the institution to accept an unverifiable assurance.

Who has access, and how do we know? Role-based access restriction, session-level logging, periodic access recertification and a documented joiner-mover-leaver process. The recertification point is frequently the weakest link, because access granted for a project and never revoked is the most common finding in any access audit.

Where does the data physically go? Whether data leaves the country, what is stored versus accessed in session, what is retained on the provider's systems and for how long, and what happens at contract termination.

What is the incident process? Who is notified, within what window, by whom, and what the institution's own notification obligations are. This should be documented before an incident, not designed during one.

Is consent adequate, and is it recorded? Where the arrangement depends on data subject consent, the exact wording, the version and the timestamp must be reproducible. A consent record that cannot be reproduced is not a consent record.

The governance structure question

A distinct issue arises for institutions considering an international provider, and it is worth addressing directly because it cuts both ways.

A purely domestic provider is simple from a jurisdictional standpoint but may not have an audited control environment an institution's auditors can meaningfully examine. A purely foreign provider may have strong controls but introduces cross-border and contracting complexity that Dominican supervisory expectations do not accommodate easily.

The structure that resolves this is a domestic legal entity operating within an international group. The institution contracts with a Dominican entity, employing Dominican staff under Dominican labour law, subject to Dominican supervision. The control environment, information security framework and governance standards derive from the group. That structure is what allowed two risk committees who had previously blocked outsourcing to approve arrangements we now operate.

Practical requirements to specify

For any financial services outsourcing arrangement in the Dominican Republic, specify at minimum:

  • A named data protection lead within the provider's account team, reporting functionally to your own data protection officer
  • Right to audit with on-site inspection, exercisable on reasonable notice
  • Documented access control with periodic recertification and a defined recertification cycle
  • Physical segregation of the delivery area, with device restriction and clean-desk enforcement
  • Session-level access logging retained for a specified period
  • A documented incident response protocol with defined notification windows
  • Versioned consent records with reproducible text and timestamps
  • Defined data retention and a documented process at contract termination
  • Sub-processor disclosure and approval rights

None of this is exotic. It is the standard a competent provider should already meet, and a provider that treats these requirements as unusual is telling you where they sit.

Frequently asked questions

What is Ley 172-13?
Law 172-13 is the Dominican Republic's framework for the protection of personal data. It establishes principles for lawful processing, accuracy, retention limits and security, and it grants rights to data subjects over their own information.
Can Dominican banks outsource customer service?
Yes, provided the arrangement addresses data protection obligations under Law 172-13, including lawful basis, access controls, retention, incident response and an auditable control environment the institution can inspect.
What should a bank ask a BPO provider about data protection?
Whether the control environment can be audited on site, who has access and how it is recertified, where data physically resides, what the incident notification process is, and whether consent records are versioned and reproducible.
Is it better to use a Dominican or an international BPO provider for financial services?
A Dominican legal entity operating within an international group frequently resolves the tension. The institution contracts domestically under Dominican law and supervision while the control environment derives from group standards.

Related pages

Ready to evaluate a nearshore partner?

Book a discovery call or request a proposal. We respond to qualified enquiries within one business day.

Request a proposal

All engagements comply with Dominican Republic Law 172-13 on Personal Data Protection.

Looking for work?

Browse open roles across four Dominican cities, or join the talent community and we will reach out when a match opens.