Skip to content
ViperTech

Blog

CostaRica'sdataprotectionlawandyourwebsite:whatLey8968asksofforms,cookiesandmailinglists

  • 19 August 2026
  • 7 min read
  • Strategy
  • Web development

Almost every small business site has a contact form, and almost none knows where the data it collected over the last three years ended up. The law asks for no project and no in-house lawyer: it asks for four lines on the form, an unticked box, and knowing where things are. What falls to the website and what does not.

Almost every small business site has a contact form, and almost none knows what became of what that form received over the last three years. The data sits in an inbox, in a spreadsheet, in the WordPress dashboard, in the mailing platform someone tried once, and in a notebook. That — not the design, not the loading speed — is what Ley 8968 looks at the day somebody asks.

One clarification before going on, the same one we make about electronic invoicing: this is not legal advice. It is the part that falls to the website, which is the part we know. For everything else — and especially if you handle health, minors' or credit history data — the conversation is with a lawyer, not with your agency.

What counts as personal data

More than people assume. Personal data is anything that allows a person to be identified, directly or indirectly. On an ordinary website that includes:

  • Name, email and phone number from the contact form.
  • The national ID number, if you ask for it in order to invoice.
  • The delivery address on an order.
  • The mailing list you send promotions to.
  • The browsing records your analytics tools keep, when they can be tied to a person.

The law also sets aside a category with stricter rules, sensitive data: health, sex life, ethnic origin, political opinions, religious beliefs, union membership. A clinic's, a laboratory's or an association's form falls into that category almost without noticing, and there the standard is higher than for everything else.

The central rule: informed consent

The whole law rests on a simple idea: the data belongs to the person, not to whoever collects it. Processing it requires their consent, and that consent has to be informed — the person knows what for — express — they gave it, it was not inferred from their silence — and recorded in writing, which on a website is satisfied by electronic means.

In practice that means the form has to say four things before the person hits send: who will hold the data, what it will be used for, who else it will be passed to, and how to ask for it back. Four lines and one link. Hardly any form in the country has them.

The box that does not come pre-ticked

One detail is nearly always got wrong: the acceptance box cannot come ticked by default. If it comes ticked, the consent was not given by the person, it was given by the form, and that is not consent.

The other frequent mistake is putting two permissions in one box: "I accept the privacy policy and I want to receive news". They are two different things — one is needed in order to reply to you at all, the other is advertising — and they belong in two boxes, with the second one optional. It sounds like you will lose subscribers. You will lose the ones who were never going to open an email from you.

Cookies and analytics: local law is not the only thing in charge

Ley 8968 has no article devoted to cookies the way European rules do, and from that plenty of people conclude that nothing is needed in Costa Rica. It is a hasty conclusion, for two reasons.

The first is that the law does not talk about technologies, it talks about processing data: if your analytics tool stores something that lets a person's path be reconstructed, you are processing data, whether it is called a cookie or something else. The second is more immediate: if you use Google Analytics or Google Ads and your site gets European visits — and it does, even a hotel in Guanacaste — Google's own consent policy requires you to ask for it. That is the breach that shows up first, because Google is the one checking.

The reasonable point for a Costa Rican small business: a cookie policy that actually says what gets installed, and a notice where anything non-essential can be refused. You do not need the three-screen wall you see on European sites, and it is better not to build one: every extra screen before the content is people leaving.

The data that leaves the country

This one is hardly ever thought about and it is in the law: passing personal data to a third party, including a third party in another country, requires the person's consent. And you are already passing it. The hosting is in the United States, the email is run by Google or Microsoft, the form notifies an outside service, the mailing list lives on a foreign platform.

None of that is illegal and none of it has to be dismantled. What has to happen is that it gets said: the privacy policy has to name the categories of providers that receive the data and what they receive it for. It is one paragraph, and it is the whole difference between informed processing and processing that is not.

The right almost nobody is in a position to honour

A person can ask you for access to their data, correction of whatever is wrong, deletion, and withdrawal of consent they gave earlier. The uncomfortable question is not legal but operational: if someone writes tomorrow asking you to delete everything of theirs, can you? Do you know how many places it is in?

That is where the mess turns into a real risk. A site whose form submissions end up in four different places has no way of honouring a deletion request, and "we tried" is not an answer. Which is why it pays, from the start, to have the data land in one place and to have a written rule on how long it is kept. Keeping everything forever is not prudence: it is enlarging what gets lost the day there is a problem.

What happens if you do nothing

The likeliest scenario is not an inspection: it is a complaint. An annoyed customer who keeps getting emails they never asked for, a former employee, a competitor. Prodhab — the Agencia de Protección de Datos de los Habitantes — handles complaints, and penalties are calculated in base salaries, on top of the possibility of ordering use of the database suspended.

For a small business the amount is not the worst part. The worst part is having to explain in writing how every record in a five-thousand-address list built up over years without a single log was obtained.

There is also an obligation that gets little attention: the law requires databases intended for distribution, dissemination or commercial sale to be registered with Prodhab. If your list is only for your own mailings, the usual reading is that it does not apply, but that is exactly the kind of question worth putting to a lawyer rather than settling by reading a blog, this one included.

Where to start, in order

  • Take stock of where the data is today: forms, inbox, spreadsheets, mailing platform, store, WhatsApp. You cannot tidy what nobody has listed.
  • Put the purpose line and the link to the privacy policy on every form, with the box unticked.
  • Separate advertising consent from contact consent.
  • Write the privacy and cookie policies around what your site actually does, not around a template copied from another country.
  • Decide how long each thing is kept, and delete what no longer has a reason to be there.
  • Leave an email address where those rights can be exercised, and somebody who reads it.

Almost all of that is an afternoon of a developer's work plus half an hour of conversation about how your business runs. It is not a project. What is expensive is doing it after the complaint, when you also have to explain why it was missing.

If you like, we will go through your site and tell you what is missing: what data it collects today, what it asks for without needing it, and where your privacy policy contradicts what the site actually does. Write to us and we will look at your case with the details on the table.

Want us to review your site or build a new one?

Keep reading