EnglishEspañol
Ecuador flag

Ecuador

Ecuador Data Privacy Laws: LOPDP Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 22 primary sources cited on this page. How we verify our legal content

Ecuador Data Privacy Laws: LOPDP Compliance Guide (2026)

Frequently Asked Questions

What is the LOPDP and when did it take full effect?

The LOPDP (Ley Orgánica de Protección de Datos Personales) is Ecuador's comprehensive data protection law, published in the Fifth Supplement to Official Registry No. 459 on May 26, 2021. A two-year transition period allowed organizations to prepare, and the sanctions regime became applicable on May 26, 2023. The implementing regulations came in Executive Decree No. 904, signed on November 6, 2023 and published in Official Registry Supplement No. 435 of November 13, 2023. In practice enforcement could not begin until the SPDP had a Superintendent, who took office on April 23, 2024.

What were Ecuador's first data protection enforcement actions?

The SPDP issued its first sanction resolutions on November 28, 2025 and announced them on December 1, 2025. LigaPro was fined USD 259,644.01 and ordered to notify 14,398 data subjects and delete their data. The FEF was fined USD 194,856.16 and faced similar corrective orders, and it has appealed. Both findings were serious infractions under Article 68(1), the failure to implement adequate administrative, technical, physical, organizational, and legal measures around fan applications built on invalid consent. A second round announced on January 20, 2026 added a minor-tier fine of USD 95,502.63 against LigaPro under Article 67(2) and a serious-tier fine of USD 194,469.85 against the FEF under Article 68(4), taking published sanctions to about USD 744,473.

What are the maximum fines under the LOPDP?

The LOPDP has two tiers, not three. For a private-law entity or public company, a serious infraction carries a fine of 0.7% to 1% of business volume for the immediately preceding financial year, and a minor infraction 0.1% to 0.7%. One percent is the ceiling. Public servants and officials are fined 1 to 10 unified basic salaries for a minor infraction and 10 to 20 for a serious one. Separately from any fine, the SPDP may order corrective measures under Article 65, including cessation of processing under stated conditions or time limits and deletion of the data.

Who must appoint a Data Protection Officer in Ecuador?

Article 48 of the LOPDP requires a DPO for the public sector as defined in Article 225 of the Constitution, for activities that require permanent and systematized control by volume, nature, scope, or purpose, and for large-scale processing of the special categories of data in Article 25, which are sensitive data, data of children and adolescents, health data, and disability data. Article 10 of Resolution No. SPDP-SPD-2025-0028-R then adds fourteen sectors that must appoint a DPO by virtue of their activity, with no scale test and even where they pursue no profit. They include schools and any entity processing minors' data, universities, financial firms, insurers and brokers, advertising and market research businesses, holders of clinical records, pharmacies, private security and gated-community administrators, professional sports bodies, professional guilds, telecoms providers, providers of mass video surveillance, geolocation and IT services including AI development, and public-service concessionaires. The MTGE scoring model issued in February 2026 provides a structured method for deciding whether processing is large-scale. Appointments must be registered with the SPDP within a fifteen-day term.

What qualifications must a DPO have in Ecuador?

Article 55 of the Reglamento General, restated in Resolution No. SPDP-SPD-2025-0028-R, requires a DPO to be in the enjoyment of political rights, to be of legal age, to hold a third-level degree in Law, Information Systems, Communications, or Technologies, and to have at least five years of professional experience. The degree list is closed, and the experience does not have to be in data protection. From January 1, 2029, DPOs must also complete the professionalizing program officialized by the SPDP.

How does Ecuador's LOPDP compare to the EU GDPR?

The LOPDP is modeled closely on the GDPR, but the differences are real. Article 7 gives eight conditions for legitimate processing rather than six, adding a judicial order and data held in publicly accessible databases. Article 10 lists thirteen principles, among them an in dubio pro titular rule under which officials must resolve doubt in the data subject's favor. Breach notification runs to two authorities, the SPDP and ARCOTEL, within a five business day term rather than 72 hours, while affected individuals must be told within a three business day term. Maximum fines are far lower, capped at 1% of business volume rather than 4% of global turnover. And the RIPD model clauses are recognized as a transfer safeguard for controller-to-controller transfers only.

Can personal data be transferred outside Ecuador?

Yes, under specific conditions, but there is no adequacy list to consult. The SPDP created the recognition procedure in Resolution No. SPDP-SPD-2026-0004-R on January 28, 2026 and has not yet declared any jurisdiction adequate, apart from Andean Community member states, which that resolution treats as adequate by community mandate unless serious deficiencies are verified in their compliance with the applicable community or national rules. Every other transfer needs approved safeguards such as standard contractual clauses, including the RIPD model clauses for controller-to-controller transfers, binding corporate rules, an approved code of conduct, or a certification mechanism. Failing that, one of the eleven exceptional grounds in Article 60 of the LOPDP may apply, or the transfer needs prior SPDP authorization under Article 59. International transfers must also be registered in the National Register.

What is the breach notification timeline in Ecuador?

Controllers must notify both the SPDP and ARCOTEL as soon as possible and within a five business day term of learning of a personal data breach, and a filing made after that term must state the reasons for the delay. Where the breach carries a risk to the fundamental rights and individual freedoms of data subjects, those individuals must also be notified directly without delay and within a three business day term, in clear and simple language, carrying the same information as the notice to the authorities: the nature and type of the breach, the affected data subjects, the initial detail of the systems breached, the presumed cause, the volume and types of data exposed, the measures adopted and planned, and the risk assessment. A processor has a two business day term to notify its controller.

Does Ecuador's data protection law apply to foreign companies?

Yes. The LOPDP applies to any processing directed at individuals located in Ecuador, regardless of where the controller or processor is established. A company based outside Ecuador that collects, processes, or stores personal data of Ecuadorian residents is subject to the LOPDP and the SPDP's jurisdiction.

What is a legitimate interest balancing test under Ecuador's LOPDP?

Since November 2025, Resolution No. SPDP-SPD-2025-0041-R requires organizations that rely on legitimate interest as their legal basis to prepare and document a prior written assessment. The assessment must demonstrate that the controller's interests do not override the data subject's fundamental rights and freedoms. This written balancing test must be maintained as part of the Record of Processing Activities and must be available to the SPDP on request.

Updates

SPDP issued Resolution No. SPDP-SPD-2025-0041-R establishing a formal framework for the legitimate interest legal basis. Controllers must complete and document a prior written balancing test before invoking this basis.

Executive Decree No. 904, signed November 6, 2023 and published in Official Registry Supplement No. 435 of November 13, 2023, promulgated the implementing regulations to the LOPDP, providing detailed guidance on breach notification, DPIA requirements, and DPO appointment. Its only transitional provision on the authority made the SPDP's implementation and operation contingent on budget availability.

SPDP issued Resolution No. SPDP-SPD-2025-0028-R, the General Regulation on Data Protection Officers. Article 10 adds fourteen sectors that must appoint a DPO regardless of scale or profit motive, and the resolution sets registration and functional independence rules while restating the qualification requirements already contained in Article 55 of the Reglamento General. The initial DPO registration window ran from November 1 to December 31, 2025.

SPDP issued Resolution No. SPDP-SPD-2026-0004-R, the General Rule on National and International Transfers or Communications of Personal Data, which takes effect on publication in the Official Registry. It formalizes safeguard mechanisms including the RIPD controller-to-controller model clauses and binding corporate rules, creates the procedure for recognizing an adequate level of protection, sets conditions for domestic transfers, requires three years of supporting documentation, and opens a twelve-month window to regularize pre-existing international transfers.

SPDP issued Resolution No. SPDP-SPD-2026-0005-R on Large-Scale Processing of Personal Data. The resolution introduced the Large-Scale Technical Model (MTGE), a six-variable scoring framework where a score of six or above triggers heightened compliance obligations including mandatory DPO appointment and DPIA requirements.

SPDP issued Resolution No. SPDP-SPD-2025-0004-R, the DPO Professionalization Regulation, establishing curriculum standards for SPDP-recognized DPO training programs. Completion of an accredited program becomes mandatory from January 1, 2029.

SPDP published its 2026 Institutional Regulatory Plan, announcing the regulatory priorities and rulemaking agenda for the coming year.

SPDP announced its first enforcement sanctions, both issued on November 28, 2025: USD 259,644.01 against LigaPro and USD 194,856.16 against the FEF, each a serious infraction under Article 68(1) for failing to implement adequate measures around fan data applications built on invalid consent. The FEF has appealed its resolution.

Corrected the penalty section: the LOPDP creates only minor and serious infractions, with 1% of business volume as the ceiling for a private entity, not a 10% maximum. Added ARCOTEL as a required co-recipient of breach notifications, the three-day term for telling affected individuals, the fifteen-day term for access and other rights requests, the fourteen sectors that must appoint a DPO under the SPDP's 2025 regulation, and the second round of SPDP fines announced in January 2026. Removed a supervisory delegation to the Superintendencia de Companias that the 2023 implementing decree does not contain, a scope carve-out for courts that Article 2 does not create, and an adequacy list the SPDP has never published. Corrected the sensitive-data rules to the seven exhaustive exceptions in Article 26 of the LOPDP (removing a GDPR exception Ecuador does not have), restated the automated-decision right as covering decisions based wholly or partly on automated assessments with the entitlements and carve-outs Article 20 attaches, rebuilt the breach-notification content requirements from Article 26 of the Reglamento General, corrected the description of Constitution Article 66(19), sourced the December 2025 fine amounts to the SPDP's 20 January 2026 bulletins, reconciled the international-transfer registration rules with Article 64 of Resolution SPDP-SPD-2026-0004-R, added the proviso on Andean Community adequacy, fixed the DPO independence and voluntary-appointment statements, and added the SPDP resolutions issued after February 2026.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Superintendencia de Protección de Datos Personales (SPDP) – Official Website(spdp.gob.ec).gov
  2. SPDP - Resoluciones emitidas por la Superintendencia de Proteccion de Datos Personales (official resolutions index, 2024-2026)(spdp.gob.ec).gov
  3. SPDP Press Releases – First Sanctions December 2025(spdp.gob.ec).gov
  4. National Assembly of Ecuador – Constitution of the Republic of Ecuador (2008)(asambleanacional.gob.ec).gov
  5. National Assembly of Ecuador – Official Website(asambleanacional.gob.ec).gov
  6. Government of Ecuador – Official Registry (Registro Oficial)(registroficial.gob.ec).gov
  7. Ecuador Government Services Portal – SPDP(gob.ec).gov
  8. RIPD – SPDP Issues First Sanctions for Serious LOPDP Violations(redipd.org)
  9. Ley Organica de Proteccion de Datos Personales (LOPDP), Quinto Suplemento del Registro Oficial 459, 26 May 2021 - full text (Arts. 2, 4, 7, 10, 13-16, 25, 43, 46, 48, 59-62, 65-74)(gob.ec).gov
  10. Reglamento General a la LOPDP, Decreto Ejecutivo 904 (signed 6 Nov 2023, Registro Oficial Suplemento 435 of 13 Nov 2023) - Arts. 24-28, 53-55 and transitional provisions(cosede.gob.ec).gov
  11. SPDP - Resolucion No. SPDP-SPD-2025-0028-R, Reglamento del Delegado de Proteccion de Datos Personales (Art. 10 lists the fourteen sectors with a mandatory DPO)(spdp.gob.ec).gov
  12. SPDP - Resolucion No. SPDP-SPD-2026-0004-R, Norma general de transferencias o comunicaciones nacionales e internacionales de datos personales (28 Jan 2026)(spdp.gob.ec).gov
  13. SPDP - Resolucion No. SPDP-SPD-2026-0005-R, Norma general sobre el tratamiento de datos personales a gran escala (2 Feb 2026)(spdp.gob.ec).gov
  14. SPDP - Resolucion No. SPDP-SPD-2026-0009-R, Norma general para la garantia del derecho de proteccion de datos personales en el uso de sistemas de inteligencia artificial (12 Feb 2026)(spdp.gob.ec).gov
  15. SPDP - Resolucion No. SPDP-SPD-2025-0022-R, metodologia para el calculo de las multas aplicables a infracciones leves y graves(spdp.gob.ec).gov
  16. SPDP - Resolucion No. SPDP-SPD-2025-0041-R, normativa general para la aplicacion del interes legitimo(spdp.gob.ec).gov
  17. SPDP - Sanciones (official index of the four sanction resolutions against LigaPro and the FEF)(spdp.gob.ec).gov
  18. SPDP - Resolucion No. RES-SPDP-ICS-2025-0002, LigaPro, 28 Nov 2025 (Art. 68(1), USD 259,644.01)(spdp.gob.ec).gov
  19. SPDP - Resolucion No. RES-SPDP-ICS-PASN-2025-0003, Federacion Ecuatoriana de Futbol, 28 Nov 2025 (Art. 68(1), USD 194,856.16)(spdp.gob.ec).gov
  20. SPDP - Resolucion No. RES-SPDP-ICS-2025-0005, LigaPro, 19 Dec 2025 (Art. 67(2); the posted PDF is truncated before the operative part, so the USD 95,502.63 amount comes from the SPDP bulletin of 20 Jan 2026)(spdp.gob.ec).gov
  21. SPDP - Resolucion No. RES-SPDP-ICS-2025-0006, Federacion Ecuatoriana de Futbol, 31 Dec 2025 (Art. 68(4); records the appeal against RES-SPDP-ICS-2025-0003; the posted PDF is truncated before the operative part, so the USD 194,469.85 amount comes from the SPDP bulletin of 20 Jan 2026)(spdp.gob.ec).gov
  22. Asamblea Nacional del Ecuador - Fabrizio Peralta Diaz se posesiono ante el Pleno como Superintendente de Proteccion de Datos, 23 April 2024(asambleanacional.gob.ec).gov
  23. Asamblea Nacional del Ecuador - Dina Farinango presents the Ley Organica Reformatoria a la LOPDP, 16 July 2026 (bill, not law)(asambleanacional.gob.ec).gov
Share: