Uruguay Senate Reviews Critical Infrastructure Bill
The bill creates operators who must report incidents within 12 hours and requires security and response plans for critical infrastructure.
Uruguay’s Senate placed the bill "On the Protection of Critical Infrastructure" on the agenda for its ordinary session on Wednesday, Sept. 16. The measure would create public and private operators required to maintain security plans, coordinate responses to failures or attacks, and notify the state of incidents within 12 hours.
Uruguay’s Senate included the bill "On the Protection of Critical Infrastructure" on the agenda for its ordinary session on Wednesday, Sept. 16. The initiative creates the category of Critical Infrastructure Operators, requires public and private entities to maintain security and response plans, and sets a maximum of 12 hours to report incidents to the state.
What does the bill establish?
The text defines what counts as critical infrastructure and requires those who operate it to have security and response plans for failures or attacks. It also calls for a national register of categorized critical infrastructures, which would need incident detection and response systems, known as IDS and IPS.
The proposal also adds a requirement to adopt specific security protocols for operational technology and for the Internet of Things in infrastructure deemed critical. According to Última Hora, the bill seeks to establish a regulatory framework that covers both technical operations and institutional coordination during incidents.
Who would be covered, and what deadlines does it set?
The law would apply to public and private operators considered part of critical infrastructure under the new Critical Infrastructure Operator category. Those actors would have to notify cyber incidents to the state within 12 hours of occurrence and take part in drills organized by the authorities.
The bill also instructs the state to coordinate so that a problem in one critical sector does not spread to others, through an interagency framework for infrastructure security. That approach is meant to prevent cascading effects across essential services.
What international reference does it use, and how does it connect to Uruguay’s framework?
The draft is based on the 2004 Budapest Convention on Cybercrime as its international reference. At the same time, the legislative debate comes after Uruguay approved Law 20.327 on cybercrime in 2024, following decades of discussion since the first bill was introduced in 1987, with offenses such as computer fraud, unlawful access, and data breaches.
In a September 2026 interview, lawyer Nicolás Antúnez described that legislative path as part of the country’s progress in the field. With this new bill, the Senate is adding a piece focused on the resilience of services and operators that, because of their role, would face stricter security and reporting requirements.
What role does the URCDP appear to have?
The available information does not describe any specific role for the Personal Data Control and Regulatory Unit in this bill, but it does place the agency within Uruguay’s own data protection framework, according to its Resolution No. 283/026 database.
Within that framework, the critical infrastructure bill adds to a regulatory environment that already includes Law 18.331 and Law 20.327, while the Senate advances a tool aimed at operators that would need to record, protect, and report incidents under defined deadlines.
Sources
- De 2.000 a 30.000 denuncias: el ciberdelito crece, se profesionaliza y desafía a la justicialadiaria.com.uy· la diaria
- Senado tratará “infraestructura crítica” en su sesión ordinariaultimahora.com· Última Hora
- Resolución N° 283/026 base de datosgub.uy· Unidad Reguladora y de Control de Datos Personales (URCDP)



