es
A Costa Rican team exchanges records through a controlled workflow while one person oversees access with a key.
Privacy and data

Data privacy and AI in Costa Rica: what your SMB has to adjust under Law 8968 (2026 guide)

Pasting client information into an AI tool does not change who is responsible for it. Here is what Law 8968 asks of a Costa Rican service SMB, and where to start.

Author
VegasiO Team
Date published

Data privacy and AI in Costa Rica: what your SMB has to adjust under Law 8968 (2026 guide)

Is there any law that regulates AI use in your Costa Rican SMB? When that use involves processing personal data within its scope, Law 8968 and its Regulation 37554 apply. In practice it comes down to five points: on what basis you process the data, for what purpose, how much you share, how you protect it, and how you respond if someone files a claim. Pasting client information into an AI tool without reviewing that leaves an open risk, and it is worth sorting out before you grow.

Why did this become urgent?

Because the use is already inside. AI adoption by firms in the OECD reached 20.2% in 2025, and a good part of that use happens in public tools, from accounts the company does not administer. Without written rules, management loses sight of what information is going out. PRODHAB, which is the regulator, applies the law whenever personal data is involved, no matter which tool it ended up in.

What follows is for owners and managers of service SMBs in Costa Rica whose team is already using AI and who want to bring order to compliance without turning into a law firm on the inside.

What does Law 8968 say?

In one line: it regulates the protection of the individual with regard to the processing of their personal data, and PRODHAB is the body that enforces it. Changing tools does not change the obligations: if there is processing of personal data, the responsibility still belongs to the company.

Put in operational terms, the question you have to be able to answer is not whether you use AI or not. It is what data goes into each tool and for what purpose.

A six-stage path follows a data point from collection to a human-reviewed result.

Following the complete data journey helps identify access, transfers, and control points.


Which five rules affect you when you use AI?

1. On what basis you process the data

Law 8968 regulates informed consent and the quality of processing. Which basis applies, and how far the notice or the contract reaches, depends on the case, and it is best not to assume that a generic clause covers sending information to an outside provider.

In practice: review the processing clause in your current contracts, add a line where appropriate about the use of AI-assisted tools in delivering the service, and document consent from new clients from the start.

2. For what purpose you process it

The law requires processing to serve specified, explicit and legitimate purposes. Using real data to see how well a tool works is processing too, and it needs the same review of purpose and basis as any other. Testing is not a separate category.

3. How much you share

The principle of proportionality requires data to be adequate, relevant and not excessive for the purpose. Translated to daily work: if the task only needs the industry and the size of the company, take out the names, the ID numbers, the email addresses and the amounts before pasting anything.

4. How you protect it

When an outside provider processes personal data, you have to look at what role it plays, what the contract says, how long it retains the information, what security measures it applies and who it subcontracts to, in line with Law 8968 and Regulation 37554. The specific contractual form is validated with legal counsel case by case.

5. How you respond if someone files a claim

The law recognizes the right to access data, correct it or ask for it to be deleted, among other mechanisms. If a tool takes part in that processing, your company has to be able to find the data and handle the request. When it cannot, the problem does not belong to the client who complains: it belongs to the design, and it has to be fixed before you keep using real data.

A five-step path connects legal review, internal data rules, approved tools, vendor contracts, and responses to individual data requests.

In 90 days, a small business can establish five minimum controls for using AI with personal data under Law 8968.


Where do you start if you are not compliant today?

You start by sorting out five things, not by writing the full policy. That one takes time and it is not what exposes you today. What follows is the minimum any service SMB should have settled within ninety days.

The first is to review, with legal counsel, the notices and processing clauses you are already using. That is where you confirm on what basis and for what purpose you process the data, and without it the other four adjustments hang on an assumption.

Then come the written rules for AI use. A manual is not needed: it is enough to make clear which data is never shared and what review is required before an output reaches a deliverable or an email.

In parallel, put together a short list of authorized tools. Next to each one, write down who is accountable for it, what it is used for and under what conditions. Whatever is not on the list is not used with client data, and that way the decision stops being made case by case in the middle of the work.

The contractual part is still missing. Outside providers that process that data need proper contracts, ones that make clear the role of each party and the guarantees each one gives.

And last, a path for handling claims from individuals. Someone in the company has to be able to locate the data of whoever asks, correct it or delete it where appropriate, without the answer depending on improvisation.

None of the five needs a large firm or redoing your processes. They need a decision from management and someone in charge of making sure they are followed.

What is left out of this guide?

The European AI Regulation may apply to you if you operate in the European Union or if your use falls within its extraterritorial scope. If that is not your case, it is not your priority framework and it is not worth letting it distract you.

Regulated industries are a separate matter: in banking, healthcare or education there are additional rules worth confirming with legal counsel. This covers the general case of a service SMB.

A note for law and accounting firms: case files, financial information and trade secrets make a mistake far more expensive. In those cases it is worth validating these controls with legal and industry counsel before using real data in an AI tool.

Do you want to review where you stand?

VegasiO's Discovery web takes 5 minutes and reviews how your AI use stands today against these points. At the end it tells you whether the next step is a Diagnóstico de Adopción IA, a documentation fix with your legal counsel, or both in parallel.

Next step

Turn this into a clear next step

If this sounds like your operation, take the Discovery: five minutes and you leave with a read on your case, not a generic recommendation.