WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Ley Organica de Proteccion de Datos Personales — notification of personal data security breaches

Ecuador LOPDP breach duty

Ecuador · May 26, 2021; the sanctions regime became enforceable May 26, 2023 after a two-year transition

Verify details

Ecuador runs one of the shortest and most unusual notification schemes in this dataset. The controller must notify the data protection authority within three days of detecting a breach — and, distinctively, must also notify the telecommunications regulator ARCOTEL, a dual-notification requirement with no close analogue elsewhere here. Affected individuals must be told as soon as possible and no later than five days. A processor must notify its controller as soon as possible and within two days of becoming aware. Businesses reusing a GDPR runbook will miss both the second regulator and the fact that the outer limits are counted in days rather than hours. Marked 'check': the operative texts are Spanish-language, the day-counts were triangulated across independent sources rather than read in the original, and Ecuador's supervisory authority was stood up only after the law's transition period — confirm current reporting channels with the Superintendencia de Proteccion de Datos Personales.

Ley Organica de Proteccion de Datos Personales (Registro Oficial Suplemento 459, May 26, 2021); Reglamento General (2023)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.