WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Ecuador Privacy & Data Protection Laws

Every regime below can apply to a business handling Ecuador residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

May 26, 2021; sanctions regime in force since May 26, 2023
Organic Law on Personal Data Protection (Ley Organica de Proteccion de Datos Personales)
Ecuador LOPDP
Verify details

A GDPR-modeled statute. Article 5 applies it to processing carried out in Ecuadorian territory, to controllers or processors established in Ecuador, and — extraterritorially — to those outside Ecuador that offer goods or services to people in Ecuador or monitor their behavior there. It carries GDPR-style rights (access, rectification, erasure, portability, objection to automated decisions), breach notification, DPO requirements for larger or higher-risk processing, and fines calibrated to turnover. The two-year transition ended May 26, 2023, at which point the sanctions regime became enforceable; the supervisory authority (the Superintendencia de Proteccion de Datos Personales) was stood up later than the law itself, so enforcement practice is still maturing — a reason to confirm current regulator guidance rather than assume the statute is being applied exactly as written.

Registro Oficial Suplemento 459, May 26, 2021, Art. 5 (territorial scope)Read regulation →

Cross-Border Data Transfer · 1

May 26, 2021; enforcement from May 26, 2023; the SPDP transfer rule from January 2026
Ley Organica de Proteccion de Datos Personales — international transfers and communications of personal data
Ecuador LOPDP transfer rules
Verify details

Ecuador built a full GDPR-shaped transfer chapter: transfer is permitted to countries the Superintendencia de Proteccion de Datos Personales has declared adequate (Art. 56); failing that, on adequate safeguards such as contractual clauses (Art. 57) or binding corporate rules (Art. 58); failing that, on prior authorisation from the SPDP for cases the chapter does not contemplate (Art. 59) or on the exceptional grounds in Art. 60, with the SPDP retaining power to review and withdraw an adequacy finding (Art. 61). The operative detail arrived late: the SPDP issued its General Rule on national and international transfers by Resolution SPDP-SPD-2026-0004-R in January 2026, which is the document that sets the actual conditions and requirements. Marked 'check': the operative texts are Spanish-language, the article numbering was triangulated rather than read in the original, and the 2026 Resolution is new enough that practice around it is unformed.

Ley Organica de Proteccion de Datos Personales, Arts. 55-61; SPDP Resolution No. SPDP-SPD-2026-0004-R (General Rule on national and international transfers)Read regulation →

Data Security & Breach Notification · 1

May 26, 2021; the sanctions regime became enforceable May 26, 2023 after a two-year transition
Ley Organica de Proteccion de Datos Personales — notification of personal data security breaches
Ecuador LOPDP breach duty
Verify details

Ecuador runs one of the shortest and most unusual notification schemes in this dataset. The controller must notify the data protection authority within three days of detecting a breach — and, distinctively, must also notify the telecommunications regulator ARCOTEL, a dual-notification requirement with no close analogue elsewhere here. Affected individuals must be told as soon as possible and no later than five days. A processor must notify its controller as soon as possible and within two days of becoming aware. Businesses reusing a GDPR runbook will miss both the second regulator and the fact that the outer limits are counted in days rather than hours. Marked 'check': the operative texts are Spanish-language, the day-counts were triangulated across independent sources rather than read in the original, and Ecuador's supervisory authority was stood up only after the law's transition period — confirm current reporting channels with the Superintendencia de Proteccion de Datos Personales.

Ley Organica de Proteccion de Datos Personales (Registro Oficial Suplemento 459, May 26, 2021); Reglamento General (2023)Read regulation →

Other Americas jurisdictions