Ecuador
Ecuador Data Privacy Laws: LOPDP Compliance Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 22 primary sources cited on this page. How we verify our legal content

Ecuador's personal data protection is governed by the Ley Orgánica de Protección de Datos Personales (LOPDP), enacted in May 2021 and fully enforceable since May 2023. The SPDP supervises compliance and announced its first sanctions on December 1, 2025, fining LigaPro and the FEF under Article 68(1) of the LOPDP for failing to implement adequate measures around fan applications that had not obtained valid consent. A second round of fines against both bodies followed on January 20, 2026.
Ecuador occupies a distinctive place in Latin American data protection. Its 2021 Ley Orgánica de Protección de Datos Personales (LOPDP) drew its architecture directly from the EU General Data Protection Regulation (GDPR). After a two-year implementation period, the law became fully enforceable in May 2023. The supervisory authority, the Superintendencia de Protección de Datos Personales (SPDP), had no head at all until its first Superintendent, Fabrizio Peralta Díaz, was sworn in before the National Assembly on April 23, 2024. It then worked through a dense regulatory agenda in 2025 and announced its first enforcement actions against two Ecuadorian football organizations on December 1, 2025.
This guide covers every layer of Ecuador's data protection framework: the constitutional foundation, the LOPDP's core provisions, data subject rights, legal bases, DPO requirements, breach notification, cross-border transfer rules, the penalty structure, and the wave of regulatory development that continues through 2026. For context on recording consent law in Ecuador, see Ecuador recording laws.
Quick Answer
Ecuador's data protection law is the LOPDP, published in the Official Registry on May 26, 2021. The law is fully in force as of May 2023. The SPDP enforces it with fines of up to 1% of annual business volume, which is the statutory ceiling for a private entity. Its first administrative sanctions, issued on November 28, 2025 and announced on December 1, 2025, were USD 259,644.01 on LigaPro and USD 194,856.16 on the FEF for failing to implement adequate measures around fan applications built on invalid consent. A second round announced on January 20, 2026 added USD 95,502.63 against LigaPro and USD 194,469.85 against the FEF. Organizations processing personal data of Ecuadorian residents must maintain a record of processing activities, designate a DPO in the cases the law and the SPDP's DPO regulation list, conduct impact assessments for high-risk processing, notify breaches to both the SPDP and ARCOTEL within a five business day term, and comply with specific safeguards for cross-border transfers.
Constitutional Foundation
Ecuador's data protection framework begins not with a statute but with the constitution. The 2008 Constitution provides one of the strongest constitutional bases for data protection in the hemisphere.
Article 66(19) recognizes the right to protection of personal data, which it defines as access to and decision over information and data of that character, together with its corresponding protection. Its second sentence is the operative half: the collection, archiving, processing, distribution, or dissemination of that data requires the data subject's authorization or a mandate of the law. That is the constitutional root of the LOPDP's rule that every processing activity needs consent or another legal basis.
Article 66(21) is a separate guarantee: the inviolability and secrecy of physical and virtual correspondence, which may not be retained, opened, or examined except in the cases the law provides, with prior judicial intervention. Informational self-determination in Ecuador rests on Article 66(19) itself and on the habeas data action, not on a separate numeral.
Article 66(20) establishes a distinct right to personal and family privacy. Article 92 creates the constitutional action of habeas data. It lets any person learn of the existence of and obtain access to the documents, genetic data, data banks, and reports held about them or their property by any public or private entity, know the use made of that information, its purpose, origin, and destination, and how long the file is kept, and petition a judge to order access, updating, rectification, deletion, or annulment.
Because the LOPDP was enacted as an organic law: a category requiring a qualified legislative majority under Article 133 of the Constitution: it occupies a higher tier in Ecuador's legal hierarchy than ordinary legislation. Ordinary laws cannot override or narrow its protections.
The LOPDP at a Glance
The LOPDP was published in the Fifth Supplement to Official Registry No. 459 on May 26, 2021. It established a two-year implementation window that expired on May 26, 2023. Executive Decree No. 904, signed on November 6, 2023 and published in Official Registry Supplement No. 435 of November 13, 2023, promulgated the implementing regulations (Reglamento General a la LOPDP) that added procedural detail on breach notification, DPO appointment, and data protection impact assessments.
Scope and Territorial Reach
The law applies to any processing of personal data carried out in Ecuadorian territory or directed at individuals located in Ecuador, regardless of where the controller or processor is established. This mirrors the GDPR's extraterritorial logic: a business operating from outside Ecuador that targets Ecuadorian residents is subject to the LOPDP.
The law covers processing in both the public and private sectors. Article 2 sets out the exclusions, and courts acting in a judicial capacity are not among them. The LOPDP does not apply to natural persons using data in family or domestic activities, to deceased persons, to anonymized data while the subject cannot be identified, to journalistic activities and other editorial content, to data governed by specialized norms of equal or higher rank on natural-disaster risk management and on State security and defense, to databases held by the competent State bodies for preventing, investigating, detecting, or prosecuting criminal offences and executing criminal penalties, or to data identifying legal persons.
Core Principles
Article 10 of the LOPDP lists thirteen principles, lettered (a) to (m). These are the ones that shape day-to-day compliance:
Juridicidad (lawfulness): Data must be processed in strict compliance with the Constitution, international instruments, the LOPDP, its Reglamento, and the applicable case law. That is a broader duty than simply holding a legal basis.
Loyalty and transparency: Data must be collected through fair means, and data subjects must be informed about how their data is used.
Purpose limitation: Data may only be used for the specific, explicit, and legitimate purposes stated at the time of collection.
Proportionality and data minimization: Only data that is adequate, relevant, and limited to what is necessary may be processed.
Data quality: Personal data must be accurate, complete, and current.
Retention limitation: Data must not be retained beyond what is necessary to fulfill the stated purpose.
Security: Appropriate technical and organizational measures must be implemented to protect data against unauthorized access, loss, or disclosure.
Confidentiality: Processing rests on a duty of secrecy. Data may not be processed or communicated for a purpose other than the one it was collected for unless another lawful-processing condition applies.
Accountability and proactive responsibility: Controllers must be able to demonstrate that they comply with these principles, not merely assert compliance.
Favorable application to the data subject: Where there is doubt about the scope of a legal or contractual provision on data protection, judicial and administrative officials must interpret and apply it in the sense most favorable to the data subject. This in dubio pro titular rule has no GDPR counterpart and can decide a close case.
Independence of supervision: The supervisory authority must exercise independent, impartial, and autonomous control, including prevention, investigation, and sanction.
Key Definitions
Personal data (datos personales): Any information relating to an identified or identifiable natural person.
Sensitive data (datos sensibles): Article 4 defines these as data on ethnicity, gender identity, cultural identity, religion, ideology, political affiliation, judicial record, migration status, sexual orientation, health, biometric data, and genetic data, plus any data whose improper processing could give rise to discrimination or could harm fundamental rights and freedoms. That open clause is the operative part of the definition. Trade union membership, a GDPR category, does not appear in the Ecuadorian list.
Special categories (categorías especiales): Article 25 defines a broader set made up of sensitive data, data of children and adolescents, health data, and data of persons with disabilities and their substitutes. The DPO and impact assessment triggers key off these special categories, not off sensitive data alone.
Controller (responsable del tratamiento): The person or entity that determines the purposes and means of processing.
Processor (encargado del tratamiento): The person or entity that processes data on behalf of the controller.
Data subject (titular): The natural person to whom the data relates.
Legal Bases for Processing
The LOPDP follows the GDPR's approach of requiring a valid legal basis for every processing activity. Article 7 sets out eight conditions for legitimate processing, two of which have no GDPR analogue.
Consent: The data subject has given free, specific, informed, and unambiguous consent for one or more defined purposes. Consent may be withdrawn at any time without negative consequences.
Contractual necessity: Processing is necessary to perform a contract to which the data subject is a party or to take pre-contractual steps at the data subject's request.
Legal obligation: Processing is required to comply with a legal duty imposed on the controller by Ecuadorian law.
Vital interests: Processing is necessary to protect the life or physical integrity of the data subject or another person when the data subject is incapable of consenting.
Public interest or official authority: Processing is necessary for a task performed in the public interest or in the exercise of official authority.
Judicial order: Processing is carried out by the controller under a judicial order, observing the principles of the law. This condition has no GDPR equivalent.
Publicly accessible databases: Processing concerns personal data held in publicly accessible databases, a term defined in Article 4. This condition also has no GDPR equivalent.
Legitimate interests: Processing is necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the data subject's rights and freedoms.
In November 2025, the SPDP issued Resolution No. SPDP-SPD-2025-0041-R, establishing detailed requirements for organizations that invoke legitimate interest. Controllers must conduct and document a prior written balancing test demonstrating that their interests do not override individuals' fundamental rights. The resolution adds a layer of procedural rigor that makes the legitimate interest basis more demanding in Ecuador than in some other GDPR-aligned regimes.
Sensitive data is different. Article 26 prohibits processing it unless one of seven circumstances applies, and that list is exhaustive.
Processing is permitted where the data subject has given explicit consent with the purposes clearly specified; where it is necessary to meet obligations and exercise specific rights of the controller or the data subject in labor law and in social security and protection; where it is necessary to protect the vital interests of the data subject or another person who cannot consent, physically or legally; where the data subject has manifestly made the data public; where it is carried out by order of a judicial authority; where it serves archiving in the public interest, scientific or historical research, or statistical purposes, proportionate to the aim, respecting the essence of the right and subject to specific safeguards; and where health data is processed under the LOPDP's own provisions.
Ecuador has no exception for a non-profit body processing the data of its own members. That one is GDPR Article 9(2)(d), it has no counterpart in the LOPDP, and it is not a basis an Ecuadorian controller can rely on.
Data Subject Rights
The LOPDP grants data subjects a comprehensive set of rights that parallel the GDPR framework.
Right of information: Before or at the time data is collected, controllers must inform subjects of the controller's identity, the purpose of processing, the legal basis, the categories of data collected, potential recipients, retention periods, and the existence of data subject rights.
Right of access: A data subject may request confirmation of whether their data is being processed and, if so, receive a copy. Article 13 gives the controller a plazo of fifteen (15) days to answer, and the same fifteen-day plazo governs rectification and updating (Article 14), erasure (Article 15), and objection (Article 16). A separate ten (10) business day término under Article 62 applies to a general requirement, petition, complaint, or claim brought directly to the controller. If that goes unanswered or is refused, Article 64 opens the administrative claim route to the SPDP.
Right of rectification: Individuals may request correction of inaccurate or incomplete personal data.
Right of deletion (erasure): Data subjects may request erasure when the data is no longer necessary, consent has been withdrawn, the processing was unlawful, or a legal obligation requires deletion. Exceptions apply for legal obligations and matters of public interest.
Right to object: Data subjects may object to processing based on legitimate interests or public interest grounds. The controller must suspend processing unless it demonstrates compelling legitimate grounds that override the data subject's interests.
Right to restrict processing: Individuals may request that processing be limited in defined circumstances, such as when the accuracy of the data is contested pending verification.
Right to data portability: Data subjects may receive their data in a structured, commonly used, and machine-readable format and may transmit it to another controller without obstruction.
Right not to be subject to automated decisions: Article 20 gives individuals the right not to be subjected to a decision based wholly or partly on automated assessments, including profiling, that produces legal effects or harms their fundamental rights and freedoms. Both the article heading and its operative sentence read unica o parcialmente, so a decision that is only partly automated is covered, and Article 4 of the SPDP's February 2026 artificial intelligence resolution restates the right in the same words. Article 21 gives children and adolescents the same right.
Article 20 attaches five entitlements to it. The data subject may ask the controller for a reasoned explanation of the decision, submit observations, ask for the valuation criteria used by the automated program, ask what types of data were used and where they came from, and challenge the decision before the controller or processor.
The right does not apply where the decision is necessary to conclude or perform a contract between the data subject and the controller or processor, where it is authorized by the applicable rules or by a judicial order or a reasoned order of a competent technical authority with safeguards in place, where it rests on the data subject's explicit consent, or where the decision carries no serious impact or verifiable risk. It cannot be waived in advance through mass adhesion contracts, and the controller must tell the data subject about the right no later than the first communication.
Right to be informed of breaches: When a breach carries a risk to a data subject's fundamental rights and individual freedoms, Article 46 requires that person to be notified without delay and within a three (3) business day term of the controller learning of the risk.
Data Breach Notification
The LOPDP and its implementing regulations establish a tiered breach notification obligation.
When a personal data breach occurs, Article 43 requires the controller to notify two authorities, not one: the SPDP and ARCOTEL, the Agencia de Regulación y Control de las Telecomunicaciones. Notification must go out as soon as possible and at the latest within a five (5) business day term of the controller learning of the breach, unless the breach is unlikely to pose a risk to people's rights and freedoms. A notification filed after that term must state the reasons for the delay. A processor, in turn, must notify its controller within a two (2) business day term.
Article 26 of the Reglamento General sets what the notification has to contain: the nature and type of the breach; identification of the affected data subjects; the initial detail of the systems breached; the presumed cause; the volume and types of data exposed or compromised; the measures adopted and planned to respond to and remedy it and to mitigate its presumed consequences; an assessment of the risk the breach poses to the rights and freedoms of the data subjects; and anything further the SPDP determines. Under Article 27 the processor's notice to its controller carries the same content except the risk assessment.
When the breach carries a risk to the fundamental rights and individual freedoms of affected individuals, Article 46 requires the controller to notify those individuals directly without delay and within a three (3) business day term of learning of the risk. Article 28 of the Reglamento General requires that notice to carry the same information as the notice to the authorities, written in clear and simple language and respecting the rights of the data subject.
Article 46 sets out three exceptions to individual notification: where the controller had already applied protective measures to the affected data that can be shown to be effective; where the controller has taken measures guaranteeing that the risk will not materialize; and where individual notification would take disproportionate effort, in which case the controller must issue a public communication instead. The first two exceptions have to be qualified by the SPDP, which must be informed within the Article 43 deadlines.
Ecuador's five business day window to the authorities is more lenient than the GDPR's 72-hour clock, but the three business day term to affected individuals is tighter than the GDPR's open-ended standard. Controllers should not wait until either deadline if the information is available sooner.
Data Protection Officer Requirements
The LOPDP requires certain organizations to appoint a Data Protection Officer (DPO). Article 48 sets four statutory triggers:
- Processing carried out by the public sector as defined in Article 225 of the Constitution, with no exception for courts
- Activities of the controller or processor that require permanent and systematized control by reason of the volume, nature, scope, or purposes of the processing, judged against the criteria in Article 53 of the Reglamento General
- Large-scale processing of special categories of data, which Article 25 defines as sensitive data, data of children and adolescents, health data, and disability data
- Processing that does not concern reserved or secret national security and defense data
In July 2025, the SPDP issued Resolution No. SPDP-SPD-2025-0028-R, the General Regulation on Data Protection Officers. Article 10 of that resolution is the part most organizations miss. It adds fourteen categories of controller and processor that must appoint a DPO by virtue of their habitual activity, expressly even where they pursue no profit, and with no scale or monitoring test to satisfy:
- Initial, basic, and secondary education institutions, and any entity that processes the data of minors even outside an educational setting
- Higher education institutions, public or private
- Any activity involving special categories of data relating to minors
- Legal persons carrying on financial activities that access or process personal data
- Insurers, reinsurance companies and intermediaries, and insurance brokers, agents, and other providers in the insurance sector
- Advertising, commercial prospecting, and market research businesses that process data based on preferences, interests, or behavior, or that build profiles
- Actors in the health system legally obliged to keep clinical records, except health professionals in solo private practice
- Pharmaceutical producers, distributors, laboratories, medicine representation houses, and pharmacies
- Private security companies, and administrators of gated developments, residential complexes, and horizontal property that process access-control data
- Professional sports federations and associations, sporting corporations, professional clubs, and sports academies
- Professional colleges and guilds
- Private telecommunications providers
- Providers of mass video surveillance, geolocation, or information technology services, expressly including the development, implementation, or deployment of artificial intelligence
- Public and private concessionaires of public services, and public-private partnerships that distribute or supply public services
So a pharmacy, an insurance broker, an advertising agency, a private school, or a gated-community administrator has a DPO obligation regardless of how much data it handles.
Qualification Standards
The qualification requirements come from Article 55 of the Reglamento General, which Resolution No. SPDP-SPD-2025-0028-R restates rather than creates. A DPO must:
- Be in the enjoyment of political rights
- Be of legal age
- Hold a third-level degree in Law, Information Systems, Communications, or Technologies. The list is closed, so a degree in another field does not qualify
- Have at least five years of professional experience. The norm does not require that experience to be in data protection
Beginning January 1, 2029, DPOs must also complete a professional training program officially recognized by the SPDP, offered by a higher education institution whose curriculum meets the minimum content standards in Resolution No. SPDP-SPD-2025-0004-R (the DPO Professionalization Regulation issued earlier in 2025).
Registration and Functional Independence
Organizations required to appoint a DPO must register the appointment with the SPDP through its web portal within a fifteen (15) day term of the designation. The SPDP still accepts a late filing, but treats late registration as a failure to implement a legal security measure. The initial registration window for obligated entities ran from November 1 to December 31, 2025.
The DPO must operate with functional independence. Article 51 of the Reglamento General bars the controller and the processor from sanctioning the DPO for doing the job, and a DPO who is sanctioned or removed for that reason may take it to the SPDP. Since Resolution No. SPDP-SPD-2026-0022-R of May 14, 2026 there is a formal complaint procedure for exactly that situation.
Article 15 of Resolution No. SPDP-SPD-2025-0028-R adds that the DPO may never receive instructions from the controller, the controller's staff, or the processor on the exercise of their functions, and may not suffer reprisals for acting technically and autonomously. Neither norm sets a reporting line to senior management. Article 16 runs the other way on hierarchy, barring information security officers, compliance officers, special attorneys of foreign controllers and processors, and holders of senior-hierarchy posts in the public sector from serving as DPO.
Core DPO functions include advising on data protection obligations, monitoring internal compliance, assisting with data protection impact assessments, cooperating with the SPDP, and serving as the principal contact point for data subjects and the supervisory authority.
Article 52 of the Reglamento General lets an organization that falls outside the mandatory categories appoint a DPO voluntarily, as a good practice and as part of its proactive responsibility measures, and lets any organization name a substitute delegate to act when the DPO is absent or impeded.
Data Protection Impact Assessments
The LOPDP and its regulations require data protection impact assessments (DPIAs) for high-risk processing activities. A DPIA is mandatory when processing is likely to result in high risk to the rights and freedoms of data subjects given the nature, context, or purposes of the processing.
Specific triggers include:
- Systematic and exhaustive evaluation of personal aspects of individuals based on automated processing, including profiling, where decisions producing legal or similarly significant effects are made
- Large-scale processing of sensitive data or data relating to criminal convictions and offences
- Systematic large-scale monitoring of publicly accessible areas
In February 2026, the SPDP issued Resolution No. SPDP-SPD-2026-0005-R, the General Rule on Large-Scale Processing of Personal Data. This resolution introduced the Large-Scale Technical Model (Modelo Técnico de Gran Escala, MTGE), which provides a structured scoring framework. The MTGE evaluates six variables:
- Number of data subjects affected
- Volume of data processed
- Categories of data involved (with sensitive data weighted higher)
- Frequency of processing
- Duration of processing
- Geographic scope of processing
A total score equal to or greater than six points means the processing qualifies as large-scale, triggering the heightened requirements including mandatory DPO appointment and DPIA obligations. This objective scoring methodology reduces ambiguity and gives organizations a clearer compliance roadmap than a purely qualitative test.
Cross-Border Data Transfers
The LOPDP restricts the transfer of personal data outside Ecuador to protect the rights of data subjects against erosion through weaker foreign frameworks.
Adequacy Determinations
Article 61 of the LOPDP contemplates a published list of countries, organizations, companies, and economic groups with adequate levels of protection, and Resolution No. SPDP-SPD-2026-0004-R of January 28, 2026 created the procedure for granting that recognition. Its Articles 11 to 17 allow recognition on application or on the SPDP's own initiative, by reasoned resolution valid for up to four years and subject to annual review and revocation.
As of September 10, 2026 the SPDP has not declared any country, international organization, legal person, or economic territory adequate, and it publishes no adequacy list. Do not plan a transfer around one. The single exception is regional: under Articles 59 to 63 of the same resolution, transfers to Andean Community member states count as cross-border flows and those States are recognized as having an adequate level of protection by community mandate, with no separate SPDP evaluation, unless serious deficiencies are verified in their compliance with the applicable community or national rules. Article 63 then lets the SPDP open a country-adequacy verification against a member State that falls short of the guarantees in Andean Decision 897, recommend corrective measures to the Andean Council of Foreign Ministers, and exercise ex post control inside Ecuador. Every other international transfer must currently rest on adequate safeguards, on one of the exceptional grounds in Article 60 of the LOPDP, or on prior SPDP authorization under Article 59.
Transfer Safeguards
For transfers to countries without adequacy status, a controller or processor must put appropriate safeguards in place. On January 28, 2026 the SPDP issued Resolution No. SPDP-SPD-2026-0004-R, the General Rule on National and International Transfers or Communications of Personal Data, which takes effect on publication in the Official Registry. Article 20 formalizes the available safeguard mechanisms:
- Standard contractual clauses adopted by the SPDP or the Ibero-American Data Protection Network (RIPD): the RIPD model clauses are recognized specifically for controller-to-controller transfers
- Binding corporate rules applicable within a corporate group
- Codes of conduct with binding commitments by the recipient
- Certification mechanisms approved by the SPDP
Article 4 of the resolution requires the controller or processor to keep the supporting documentation for at least three years and to make it available to the SPDP on request.
Two features of the resolution are easy to miss. Title II imposes free-standing conditions on purely domestic transfers to a third party: a lawful, legitimate, and determined purpose linked to the parties' functions, a legitimizing basis, informed consent unless an exception applies, security measures including encryption and a written undertaking from the recipient, limits on onward transfers, and the rule that the recipient takes on the status of controller.
The First and Second Transitional Provisions then open a twelve-month regularization window running from the resolution's entry into force. Controllers and processors with pre-existing international transfers must notify the SPDP of the destination country or entity, the categories of data, the purpose, and the legal instrument relied on, and must file an adecuación plan. No sanctions are imposed for failure to regularize during that window provided the notification and the plan are filed and carried out. Once it closes, legacy transfers that were never regularized are exposed to sanctions and corrective measures.
Article 64 of that same resolution also requires international transfers to be entered in the National Register of Personal Data Protection. Transfers made under an exceptional authorization or the Andean Community regime are registered case by case, at least ten days before the operation, while transfers under recognized adequacy or adequate safeguards are covered by a consolidated annual report filed in the first quarter of each year.
Derogations for Specific Situations
Article 60 of the LOPDP lists eleven exceptional grounds, and it opens by saying that they apply without prejudice to the preceding articles. They stand alongside the adequacy and safeguards routes rather than sitting behind them as a last resort. A transfer may proceed where:
- The data is required to fulfill institutional competences under the applicable rules
- The data subject has given explicit consent after being told of the risks arising from the absence of an adequacy decision and of adequate safeguards
- The transfer serves compliance with a legal or regulatory obligation
- The transfer is necessary to perform a contract between the data subject and the controller, or precontractual measures at the data subject's request
- The transfer is necessary for reasons of public interest
- The transfer is necessary for international judicial cooperation
- The transfer is necessary for cooperation in the investigation of offences
- The transfer is necessary to meet commitments taken on in inter-State international cooperation
- The transfer is made in banking and stock exchange operations
- The transfer is necessary to formulate, exercise, or defend claims, administrative or judicial actions, and appeals
- The transfer is necessary to protect the vital interests of the data subject or another person when that person is physically or legally incapable of consenting
Several of these are routine commercial situations rather than rare ones. For anything outside adequacy, the safeguards articles, and these grounds, Article 59 of the LOPDP requires prior SPDP authorization.
Article 59 also states a general duty to register international transfer information in advance in the National Register, and Article 64 of Resolution No. SPDP-SPD-2026-0004-R is what tells a controller how that duty runs in practice. Transfers made under an exceptional authorization and Intra-CAN flows are inscribed case by case, at least ten days before the operation. Transfers to destinations recognized as adequate, or made under adequate safeguards, expressly do not require individual inscription and are covered instead by a consolidated annual report filed in the first quarter of each year.
Supervisory Authority: The SPDP
The LOPDP created the Superintendencia de Protección de Datos Personales (SPDP) as Ecuador's independent data protection authority. The SPDP operates with administrative and financial autonomy. Its official website is spdp.gob.ec.
Powers and Functions
The SPDP's mandate encompasses both regulatory and enforcement functions:
- Issue binding regulations, guidelines, and model clauses
- Investigate complaints filed by data subjects
- Conduct ex officio inspections of controllers and processors
- Impose administrative sanctions for LOPDP violations
- Approve standard contractual clauses for cross-border transfers
- Maintain the registry of data processing activities and DPO registrations
- Recognize an adequate level of protection for international transfers and publish the resulting list
- Promote public awareness and data protection culture
Establishment and Operational Status
The SPDP was created by the LOPDP but faced long operational delays. The Reglamento General promulgated by Executive Decree No. 904 said only that the SPDP's implementation and operation would depend on budget availability, subject to a favorable opinion from the public finance authority. It delegated no supervisory function to any other body.
The authority had no head until Fabrizio Peralta Díaz, selected through the Council of Citizen Participation process, was sworn in before the plenary of the National Assembly on April 23, 2024 for a five-year term. That was almost eleven months after the sanctions grace period ended on May 26, 2023, which is why no enforcement was possible before 2024.
By 2025, the SPDP was fully operational and had shifted from institution-building to active regulatory output and enforcement. The authority published multiple binding resolutions during 2025, covering DPO qualifications, legitimate interest, and cross-border transfers, and followed these with additional resolutions in early 2026. In December 2025, the SPDP announced its 2026 Institutional Regulatory Plan, signaling continued rulemaking activity.
Penalties and Enforcement
The LOPDP establishes a turnover-based penalty structure that scales fines to the economic capacity of the violator.
Violation Categories and Fine Ranges
| Infraction Category | Private entity or public company | Public servant or official |
|---|---|---|
| Minor (leve), Arts. 67 and 69 | 0.1% to 0.7% of business volume | 1 to 10 unified basic salaries |
| Serious (grave), Arts. 68 and 70 | 0.7% to 1% of business volume | 10 to 20 unified basic salaries |
There is no third tier and no percentage above 1%. Articles 71 and 72 set the percentage penalties for a private-law entity or public company and the salary-multiple penalties for public servants and officials who caused the infraction by act or omission, the latter without prejudice to the State's extra-contractual liability. Article 73 defines business volume as revenue from sales of products and provision of services in the immediately preceding financial year, net of VAT and other taxes directly tied to the transaction. In the LigaPro case the SPDP obtained that figure from the tax authority. Resolution No. SPDP-SPD-2025-0022-R sets the methodology the SPDP uses to place a fine inside each band, and its own subject is limited to minor and serious infractions.
What Constitutes Each Category
The law runs two separate catalogues. Articles 67 and 68 typify the minor and serious infractions of the controller (responsable), while Articles 69 and 70 do the same for the processor (encargado), in different words.
Minor infractions of a controller are an exhaustive list of five in Article 67: not processing, processing out of time, or unjustifiably denying a data subject's petitions or complaints; not implementing data protection by design and by default; not keeping data protection policies available; choosing a processor that does not offer sufficient guarantees; and failing to comply with corrective measures ordered by the SPDP.
Serious infractions of a controller are the fourteen items in Article 68. They include failing to implement sufficient administrative, technical, physical, organizational, and legal measures, which is Article 68(1) and the basis of the first LigaPro and FEF fines; using data for purposes other than those declared; transferring or communicating data without meeting the statutory requirements; failing to use risk-analysis and risk-management methodologies adapted to the data and the processing, which is Article 68(4) and the basis of the second FEF fine; failing to carry out a required impact assessment; failing to implement measures to prevent and mitigate identified security risks; failing to notify a breach; failing to keep the National Register updated or to record in it what the law requires; and failing to designate a DPO when the obligation applies.
Infractions of a processor sit in Articles 69 and 70. Processing without observing the principles and rights in the law is Article 70(1), which binds the processor rather than the controller. A processor's other serious infractions include failing to process in line with its contract, failing to delete transferred data once the engagement ends, and failing to notify the controller of a breach or doing so with unjustified delay.
Additional Enforcement Powers
Beyond fines, Article 65 of the LOPDP lets the SPDP order corrective measures. The list is non-exhaustive and names three: cessation of processing under stated conditions or time limits, deletion of the data, and imposition of technical, legal, organizational, or administrative measures to guarantee adequate processing. Deletion is the measure the authority has actually used, ordering LigaPro to erase the records of 14,398 data subjects and the FEF to erase everything processed through its fan application. Article 74 additionally allows provisional protective and precautionary measures.
The sequencing in Article 66 matters. Where a serious infraction is suspected, the SPDP must apply corrective measures first, and may open the sanctioning procedure only if those measures are complied with late, partially, or defectively. That is the route the SPDP describes taking in the football cases.
SPDP Enforcement: Four Sanction Resolutions
The SPDP has published four sanction resolutions, all of them against the same two organizations in Ecuadorian football. The cases arose from two mobile applications, LigaPro's Fan ID app and the FEF's Fan FEF app, which collected personal data from fans on consent that had not been validly obtained.
First round, issued November 28, 2025 and announced December 1, 2025
LigaPro (Liga Profesional de Fútbol del Ecuador): In Resolution No. RES-SPDP-ICS-2025-0002 the SPDP found a serious infraction under Article 68(1) of the LOPDP, the failure to implement sufficient administrative, technical, physical, organizational, and legal measures. The fine was USD 259,644.01. LigaPro was also ordered to notify 14,398 affected data subjects that their consent had not been validly obtained, and to delete that personal data from all databases it administers.
FEF (Federación Ecuatoriana de Fútbol): Resolution No. RES-SPDP-ICS-PASN-2025-0003 made a comparable Article 68(1) finding. The fine was USD 194,856.16. The FEF was ordered to delete personal data processed through the Fan FEF application, update its Record of Processing Activities, implement a compliant Data Protection Policy, and notify affected data subjects that the consent originally obtained was invalid. The FEF has appealed this resolution, so it has not become final, and the SPDP declined to count it as a prior sanction when setting the next fine.
Second round, announced January 20, 2026
LigaPro: Resolution No. RES-SPDP-ICS-2025-0005 of December 19, 2025 found a minor infraction under Article 67(2), the failure to implement data protection by design and by default in the biometric processing behind Fan ID. The fine was USD 95,502.63, set inside the 0.1% to 0.7% minor band, and the SPDP ordered a redesign of the Fan ID solution within one month. The SPDP published that amount in its bulletin of January 20, 2026. The resolution itself, as posted on the SPDP site, stops at the fine-calculation table and does not reach its operative part.
FEF: Resolution No. RES-SPDP-ICS-2025-0006 of December 31, 2025 found a serious infraction under Article 68(4), the failure to use risk-analysis and risk-management methodologies adapted to the nature of the data, the particulars of the processing, and the parties involved. The fine was USD 194,469.85, again taken from the SPDP's bulletin of January 20, 2026 because the posted resolution likewise stops before its operative part, and the SPDP ordered the FEF to reformulate its risk methodology and its impact assessment, which had wrongly returned a result of zero.
Across the four resolutions, published sanctions come to roughly USD 744,473. The cases show that the SPDP will use its enforcement powers, that app-based collection with flawed consent flows is a priority, and that the minor tier is in active use alongside the serious one.
Recent Regulatory Developments (2025-2026)
The pace of regulatory activity since the SPDP became fully operational has been substantial. The following are the most significant developments.
Artificial intelligence: Resolution No. SPDP-SPD-2026-0009-R
Signed on February 12, 2026, the General Rule on Guaranteeing the Right to Personal Data Protection in the Use of Artificial Intelligence Systems binds any controller or processor that develops, trains, implements, deploys, or supplies an AI system processing the personal data of Ecuadorian data subjects, and it says so regardless of where the system or the supplier is located. It defines four roles, developer, deployer, distributor, and implementer, and requires security measures proportionate to the risks the processing produces. It does not reach AI systems that process no personal data within the LOPDP's material and territorial scope.
Other resolutions worth knowing
Resolution No. SPDP-SPD-2026-0003-R, announced on February 3, 2026, sets out when processing stops counting as a family or domestic activity, which matters as soon as content leaves a closed circle. Resolution No. SPDP-SPD-2025-0006-R requires data protection clauses in contracts concluded within Ecuadorian territory, a direct drafting obligation. Resolution No. SPDP-SPD-2025-0022-R contains the fine-calculation methodology used to set both rounds of football fines, and Resolution No. SPDP-SPD-2025-0030-R governs pseudonymization, anonymization, blocking, and deletion.
Rulemaking did not stop in February 2026. The SPDP's resolutions index also carries Resolution No. SPDP-SPD-2026-0007-R, the policy for developing and using artificial intelligence inside the SPDP's own administrative processes, Resolutions No. SPDP-SPD-2026-0020-R and No. SPDP-SPD-2026-0021-R reforming the consultations regulation and the annual audit plan regulation, and Resolution No. SPDP-SPD-2026-0022-R of May 14, 2026, which creates the procedure for a data protection officer to complain to the SPDP after being removed, dismissed, or sanctioned for carrying out the role.
Pending: a reform bill, not law
On July 16, 2026, Assembly member Dina Farinango presented a Ley Orgánica Reformatoria a la LOPDP. It would tighten the conditions for valid consent, limit the treatment of publicly accessible sources, strengthen protections for children and adolescents, make the adequacy procedure more rigorous and require publication of an updated list of qualifying jurisdictions, and refine the definition of business volume for penalties. It is a bill. None of it is in force.
Business Compliance Checklist
Organizations processing personal data of individuals in Ecuador should verify the following elements of their compliance program.
Legal basis documentation: Every processing activity in the Record of Processing Activities must identify a specific legal basis under the LOPDP. For organizations relying on legitimate interest, a written balancing test is now required per the November 2025 resolution.
Record of Processing Activities: Controllers must maintain a register documenting the purposes, legal bases, data categories, retention periods, recipients, and security measures for each processing activity.
Data subject rights procedures: Response workflows must be capable of meeting the fifteen-day plazo for access, rectification, erasure, and objection requests, and the separate ten business day término for a general requirement, petition, or complaint brought directly to the controller.
DPO appointment and registration: Organizations meeting the mandatory thresholds must have appointed and registered a qualified DPO with the SPDP. The DPO must meet the professional qualifications established in the 2025 regulation.
Breach notification protocol: Internal procedures must allow the organization to assess a breach and notify both the SPDP and ARCOTEL within a five business day term. Where the breach carries a risk to individuals' fundamental rights, direct notification to those individuals must follow without delay and within a three business day term. A processor has a two business day term to alert its controller.
Data Protection Impact Assessments: Any processing that qualifies as large-scale under the MTGE scoring model or that presents a high risk based on nature, context, or purpose requires a DPIA before the processing begins.
Cross-border transfer safeguards: Because the SPDP has recognized no jurisdiction as adequate outside the Andean Community, transfers must rest on approved standard contractual clauses or another recognized safeguard, on an Article 60 exceptional ground, or on prior SPDP authorization, and they must be entered in the National Register. Pre-existing transfers should be notified to the SPDP with an adecuación plan inside the twelve-month regularization window in Resolution No. SPDP-SPD-2026-0004-R.
Consent mechanisms: For processing based on consent, collection flows must be capable of demonstrating free, specific, informed, and unambiguous consent. The LigaPro and FEF cases confirm that collecting consent through an app does not satisfy the LOPDP if the process is deficient.
Sensitive data controls: Heightened controls, including explicit consent or a statutory exception, must be in place for any processing of sensitive data categories.
Vendor contracts: Data processing agreements must be in place with all processors, including the clauses required by the LOPDP. Resolution No. SPDP-SPD-2025-0006-R separately requires data protection clauses in contracts concluded within Ecuadorian territory.
Frequently Asked Questions
What is the LOPDP and when did it take full effect?
The LOPDP (Ley Orgánica de Protección de Datos Personales) is Ecuador's comprehensive data protection law, published in the Fifth Supplement to Official Registry No. 459 on May 26, 2021. A two-year transition period allowed organizations to prepare, and the sanctions regime became applicable on May 26, 2023. The implementing regulations came in Executive Decree No. 904, signed on November 6, 2023 and published in Official Registry Supplement No. 435 of November 13, 2023. In practice enforcement could not begin until the SPDP had a Superintendent, who took office on April 23, 2024.
What were Ecuador's first data protection enforcement actions?
The SPDP issued its first sanction resolutions on November 28, 2025 and announced them on December 1, 2025. LigaPro was fined USD 259,644.01 and ordered to notify 14,398 data subjects and delete their data. The FEF was fined USD 194,856.16 and faced similar corrective orders, and it has appealed. Both findings were serious infractions under Article 68(1), the failure to implement adequate administrative, technical, physical, organizational, and legal measures around fan applications built on invalid consent. A second round announced on January 20, 2026 added a minor-tier fine of USD 95,502.63 against LigaPro under Article 67(2) and a serious-tier fine of USD 194,469.85 against the FEF under Article 68(4), taking published sanctions to about USD 744,473.
What are the maximum fines under the LOPDP?
The LOPDP has two tiers, not three. For a private-law entity or public company, a serious infraction carries a fine of 0.7% to 1% of business volume for the immediately preceding financial year, and a minor infraction 0.1% to 0.7%. One percent is the ceiling. Public servants and officials are fined 1 to 10 unified basic salaries for a minor infraction and 10 to 20 for a serious one. Separately from any fine, the SPDP may order corrective measures under Article 65, including cessation of processing under stated conditions or time limits and deletion of the data.
Who must appoint a Data Protection Officer in Ecuador?
Article 48 of the LOPDP requires a DPO for the public sector as defined in Article 225 of the Constitution, for activities that require permanent and systematized control by volume, nature, scope, or purpose, and for large-scale processing of the special categories of data in Article 25, which are sensitive data, data of children and adolescents, health data, and disability data. Article 10 of Resolution No. SPDP-SPD-2025-0028-R then adds fourteen sectors that must appoint a DPO by virtue of their activity, with no scale test and even where they pursue no profit. They include schools and any entity processing minors' data, universities, financial firms, insurers and brokers, advertising and market research businesses, holders of clinical records, pharmacies, private security and gated-community administrators, professional sports bodies, professional guilds, telecoms providers, providers of mass video surveillance, geolocation and IT services including AI development, and public-service concessionaires. The MTGE scoring model issued in February 2026 provides a structured method for deciding whether processing is large-scale. Appointments must be registered with the SPDP within a fifteen-day term.
What qualifications must a DPO have in Ecuador?
Article 55 of the Reglamento General, restated in Resolution No. SPDP-SPD-2025-0028-R, requires a DPO to be in the enjoyment of political rights, to be of legal age, to hold a third-level degree in Law, Information Systems, Communications, or Technologies, and to have at least five years of professional experience. The degree list is closed, and the experience does not have to be in data protection. From January 1, 2029, DPOs must also complete the professionalizing program officialized by the SPDP.
How does Ecuador's LOPDP compare to the EU GDPR?
The LOPDP is modeled closely on the GDPR, but the differences are real. Article 7 gives eight conditions for legitimate processing rather than six, adding a judicial order and data held in publicly accessible databases. Article 10 lists thirteen principles, among them an in dubio pro titular rule under which officials must resolve doubt in the data subject's favor. Breach notification runs to two authorities, the SPDP and ARCOTEL, within a five business day term rather than 72 hours, while affected individuals must be told within a three business day term. Maximum fines are far lower, capped at 1% of business volume rather than 4% of global turnover. And the RIPD model clauses are recognized as a transfer safeguard for controller-to-controller transfers only.
Can personal data be transferred outside Ecuador?
Yes, under specific conditions, but there is no adequacy list to consult. The SPDP created the recognition procedure in Resolution No. SPDP-SPD-2026-0004-R on January 28, 2026 and has not yet declared any jurisdiction adequate, apart from Andean Community member states, which that resolution treats as adequate by community mandate unless serious deficiencies are verified in their compliance with the applicable community or national rules. Every other transfer needs approved safeguards such as standard contractual clauses, including the RIPD model clauses for controller-to-controller transfers, binding corporate rules, an approved code of conduct, or a certification mechanism. Failing that, one of the eleven exceptional grounds in Article 60 of the LOPDP may apply, or the transfer needs prior SPDP authorization under Article 59. International transfers must also be registered in the National Register.
What is the breach notification timeline in Ecuador?
Controllers must notify both the SPDP and ARCOTEL as soon as possible and within a five business day term of learning of a personal data breach, and a filing made after that term must state the reasons for the delay. Where the breach carries a risk to the fundamental rights and individual freedoms of data subjects, those individuals must also be notified directly without delay and within a three business day term, in clear and simple language, carrying the same information as the notice to the authorities: the nature and type of the breach, the affected data subjects, the initial detail of the systems breached, the presumed cause, the volume and types of data exposed, the measures adopted and planned, and the risk assessment. A processor has a two business day term to notify its controller.
Does Ecuador's data protection law apply to foreign companies?
Yes. The LOPDP applies to any processing directed at individuals located in Ecuador, regardless of where the controller or processor is established. A company based outside Ecuador that collects, processes, or stores personal data of Ecuadorian residents is subject to the LOPDP and the SPDP's jurisdiction.
What is a legitimate interest balancing test under Ecuador's LOPDP?
Since November 2025, Resolution No. SPDP-SPD-2025-0041-R requires organizations that rely on legitimate interest as their legal basis to prepare and document a prior written assessment. The assessment must demonstrate that the controller's interests do not override the data subject's fundamental rights and freedoms. This written balancing test must be maintained as part of the Record of Processing Activities and must be available to the SPDP on request.
Updates
SPDP issued Resolution No. SPDP-SPD-2025-0041-R establishing a formal framework for the legitimate interest legal basis. Controllers must complete and document a prior written balancing test before invoking this basis.
Executive Decree No. 904, signed November 6, 2023 and published in Official Registry Supplement No. 435 of November 13, 2023, promulgated the implementing regulations to the LOPDP, providing detailed guidance on breach notification, DPIA requirements, and DPO appointment. Its only transitional provision on the authority made the SPDP's implementation and operation contingent on budget availability.
SPDP issued Resolution No. SPDP-SPD-2025-0028-R, the General Regulation on Data Protection Officers. Article 10 adds fourteen sectors that must appoint a DPO regardless of scale or profit motive, and the resolution sets registration and functional independence rules while restating the qualification requirements already contained in Article 55 of the Reglamento General. The initial DPO registration window ran from November 1 to December 31, 2025.
SPDP issued Resolution No. SPDP-SPD-2026-0004-R, the General Rule on National and International Transfers or Communications of Personal Data, which takes effect on publication in the Official Registry. It formalizes safeguard mechanisms including the RIPD controller-to-controller model clauses and binding corporate rules, creates the procedure for recognizing an adequate level of protection, sets conditions for domestic transfers, requires three years of supporting documentation, and opens a twelve-month window to regularize pre-existing international transfers.
SPDP issued Resolution No. SPDP-SPD-2026-0005-R on Large-Scale Processing of Personal Data. The resolution introduced the Large-Scale Technical Model (MTGE), a six-variable scoring framework where a score of six or above triggers heightened compliance obligations including mandatory DPO appointment and DPIA requirements.
SPDP issued Resolution No. SPDP-SPD-2025-0004-R, the DPO Professionalization Regulation, establishing curriculum standards for SPDP-recognized DPO training programs. Completion of an accredited program becomes mandatory from January 1, 2029.
SPDP published its 2026 Institutional Regulatory Plan, announcing the regulatory priorities and rulemaking agenda for the coming year.
SPDP announced its first enforcement sanctions, both issued on November 28, 2025: USD 259,644.01 against LigaPro and USD 194,856.16 against the FEF, each a serious infraction under Article 68(1) for failing to implement adequate measures around fan data applications built on invalid consent. The FEF has appealed its resolution.
Corrected the penalty section: the LOPDP creates only minor and serious infractions, with 1% of business volume as the ceiling for a private entity, not a 10% maximum. Added ARCOTEL as a required co-recipient of breach notifications, the three-day term for telling affected individuals, the fifteen-day term for access and other rights requests, the fourteen sectors that must appoint a DPO under the SPDP's 2025 regulation, and the second round of SPDP fines announced in January 2026. Removed a supervisory delegation to the Superintendencia de Companias that the 2023 implementing decree does not contain, a scope carve-out for courts that Article 2 does not create, and an adequacy list the SPDP has never published. Corrected the sensitive-data rules to the seven exhaustive exceptions in Article 26 of the LOPDP (removing a GDPR exception Ecuador does not have), restated the automated-decision right as covering decisions based wholly or partly on automated assessments with the entitlements and carve-outs Article 20 attaches, rebuilt the breach-notification content requirements from Article 26 of the Reglamento General, corrected the description of Constitution Article 66(19), sourced the December 2025 fine amounts to the SPDP's 20 January 2026 bulletins, reconciled the international-transfer registration rules with Article 64 of Resolution SPDP-SPD-2026-0004-R, added the proviso on Andean Community adequacy, fixed the DPO independence and voluntary-appointment statements, and added the SPDP resolutions issued after February 2026.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- Superintendencia de Protección de Datos Personales (SPDP) – Official Website(spdp.gob.ec).gov
- SPDP - Resoluciones emitidas por la Superintendencia de Proteccion de Datos Personales (official resolutions index, 2024-2026)(spdp.gob.ec).gov
- SPDP Press Releases – First Sanctions December 2025(spdp.gob.ec).gov
- National Assembly of Ecuador – Constitution of the Republic of Ecuador (2008)(asambleanacional.gob.ec).gov
- National Assembly of Ecuador – Official Website(asambleanacional.gob.ec).gov
- Government of Ecuador – Official Registry (Registro Oficial)(registroficial.gob.ec).gov
- Ecuador Government Services Portal – SPDP(gob.ec).gov
- RIPD – SPDP Issues First Sanctions for Serious LOPDP Violations(redipd.org)
- Ley Organica de Proteccion de Datos Personales (LOPDP), Quinto Suplemento del Registro Oficial 459, 26 May 2021 - full text (Arts. 2, 4, 7, 10, 13-16, 25, 43, 46, 48, 59-62, 65-74)(gob.ec).gov
- Reglamento General a la LOPDP, Decreto Ejecutivo 904 (signed 6 Nov 2023, Registro Oficial Suplemento 435 of 13 Nov 2023) - Arts. 24-28, 53-55 and transitional provisions(cosede.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2025-0028-R, Reglamento del Delegado de Proteccion de Datos Personales (Art. 10 lists the fourteen sectors with a mandatory DPO)(spdp.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2026-0004-R, Norma general de transferencias o comunicaciones nacionales e internacionales de datos personales (28 Jan 2026)(spdp.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2026-0005-R, Norma general sobre el tratamiento de datos personales a gran escala (2 Feb 2026)(spdp.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2026-0009-R, Norma general para la garantia del derecho de proteccion de datos personales en el uso de sistemas de inteligencia artificial (12 Feb 2026)(spdp.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2025-0022-R, metodologia para el calculo de las multas aplicables a infracciones leves y graves(spdp.gob.ec).gov
- SPDP - Resolucion No. SPDP-SPD-2025-0041-R, normativa general para la aplicacion del interes legitimo(spdp.gob.ec).gov
- SPDP - Sanciones (official index of the four sanction resolutions against LigaPro and the FEF)(spdp.gob.ec).gov
- SPDP - Resolucion No. RES-SPDP-ICS-2025-0002, LigaPro, 28 Nov 2025 (Art. 68(1), USD 259,644.01)(spdp.gob.ec).gov
- SPDP - Resolucion No. RES-SPDP-ICS-PASN-2025-0003, Federacion Ecuatoriana de Futbol, 28 Nov 2025 (Art. 68(1), USD 194,856.16)(spdp.gob.ec).gov
- SPDP - Resolucion No. RES-SPDP-ICS-2025-0005, LigaPro, 19 Dec 2025 (Art. 67(2); the posted PDF is truncated before the operative part, so the USD 95,502.63 amount comes from the SPDP bulletin of 20 Jan 2026)(spdp.gob.ec).gov
- SPDP - Resolucion No. RES-SPDP-ICS-2025-0006, Federacion Ecuatoriana de Futbol, 31 Dec 2025 (Art. 68(4); records the appeal against RES-SPDP-ICS-2025-0003; the posted PDF is truncated before the operative part, so the USD 194,469.85 amount comes from the SPDP bulletin of 20 Jan 2026)(spdp.gob.ec).gov
- Asamblea Nacional del Ecuador - Fabrizio Peralta Diaz se posesiono ante el Pleno como Superintendente de Proteccion de Datos, 23 April 2024(asambleanacional.gob.ec).gov
- Asamblea Nacional del Ecuador - Dina Farinango presents the Ley Organica Reformatoria a la LOPDP, 16 July 2026 (bill, not law)(asambleanacional.gob.ec).gov