Compliance Node Overview
Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP - Organic Personal Data Protection Law) - published in the Registro Oficial Suplemento No. 459 on 26 May 2021 - is Ecuador's comprehensive personal data protection legislation, enacted by the Asamblea Nacional (National Assembly) and entered into force on 26 May 2021 with a two-year transition period during which organisations were required to achieve full compliance (compliance deadline: 26 May 2023). The LOPDP is Ecuador's most advanced data protection instrument, repealing prior fragmented provisions and establishing a unified rights-based framework broadly aligned with the European Union's General Data Protection Regulation (GDPR - Regulation (EU) 2016/679). The supervisory authority is the Superintendencia de Protección de Datos Personales (SPDP - Personal Data Protection Superintendence), established under the LOPDP as a technically autonomous and independent public institution with regulatory, supervisory, and enforcement powers. The SPDP became operationally active following the enactment of the LOPDP and its implementing regulations. Key features of Ecuador's LOPDP: (1) Scope - applies to the processing of personal data of natural persons (titulares) located in Ecuador, regardless of where the responsible party (Responsable del Tratamiento) is located; also applies to processing carried out in Ecuador by entities located abroad; (2) Data processing principles - processing must comply with: lawfulness; consent; purpose limitation; proportionality; data quality; transparency; security; confidentiality; and accountability; (3) Sensitive personal data - ideología, afiliación política, filiación sindical, datos de salud, datos de vida sexual, datos genéticos, datos biométricos, datos de origen étnico o racial, creencias religiosas or filosóficas, origen étnico o racial, and datos relativos a condenas e infracciones penales; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests of the Responsable where not overriding data subject rights; (5) Data subject rights (Titular rights) - right of access; right to rectification; right to erasure; right to restriction; right to portability; right to oppose processing; and right not to be subject to automated decisions with legal or significantly similar effects; (6) Responsable del Tratamiento and Encargado del Tratamiento - data controller and processor distinction with processor contractual obligations; (7) Delegado de Protección de Datos (DPD/DPO) - mandatory appointment for certain controllers; (8) Evaluación de Impacto sobre Protección de Datos (EIPD/DPIA) - required for high-risk processing; (9) Breach notification - the Responsable must notify the SPDP within 72 hours of discovering a breach; affected data subjects notified where breach poses high risk; (10) Cross-border transfers - transfers outside Ecuador require equivalent protection or SPDP approval; (11) Administrative sanctions - infractions classified as minor, serious, and very serious; sanctions ranging from warnings to fines proportional to the severity of the violation. Ecuador's LOPDP incorporates the constitutional right to privacy and informational self-determination guaranteed by the Constitución de la República del Ecuador of 2008.
Pillar: Cybersecurity · Authority: Superintendencia de Protección de Datos Personales (SPDP, Ecuador) · Version: 1.0.0 · Last updated:
Primary source: https://www.finanzaspopulares.gob.ec/wp-content/uploads/2021/07/ley_organica_de_proteccion_de_datos_personales.pdf
SHA-256 integrity: 99faf509dfecf960738a555360904b02eb43dbb1f49992f2ac91da3bf6acd253
Primary Citations — 7 traced to source
- Ley Orgánica de Protección de Datos Personales (LOPDP, Ecuador) - published Registro Oficial Suplemento No. 459 on 26 May 2021; two-year transition period; compliance deadline 26 May 2023; nine processing principles: lawfulness, consent, purpose limitation, proportionality, data quality, transparency, security, confidentiality, accountability; sensitive personal data: ideología, afiliación política, filiación sindical, salud, vida sexual, datos genéticos, biométricos, étnico-racial, religiosas/filosóficas, condenas penales; data subject rights: access, rectification, erasure, restriction, portability, opposition, automated decision-making; DPD designation for large-scale or sensitive data processing; 72-hour SPDP breach notification; cross-border transfer restrictions
- Superintendencia de Protección de Datos Personales (SPDP, Ecuador) - independent supervisory authority established under the LOPDP; technically autonomous public institution; receives Responsable registrations; investigates complaints; conducts audits and inspections; issues corrective orders; imposes administrative sanctions; approves cross-border transfers; publishes LOPDP implementation guidance including on consent, sensitive data, DPD requirements, EIPD methodology, breach notification, and cross-border transfers at superprotecciondatos.gob.ec
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access