Data Security & Breach Notification
Ley Organica de Proteccion de Datos Personales — notification of personal data security breaches
Ecuador · May 26, 2021; the sanctions regime became enforceable May 26, 2023 after a two-year transition
Verify detailsEcuador runs one of the shortest and most unusual notification schemes in this dataset. The controller must notify the data protection authority within three days of detecting a breach — and, distinctively, must also notify the telecommunications regulator ARCOTEL, a dual-notification requirement with no close analogue elsewhere here. Affected individuals must be told as soon as possible and no later than five days. A processor must notify its controller as soon as possible and within two days of becoming aware. Businesses reusing a GDPR runbook will miss both the second regulator and the fact that the outer limits are counted in days rather than hours. Marked 'check': the operative texts are Spanish-language, the day-counts were triangulated across independent sources rather than read in the original, and Ecuador's supervisory authority was stood up only after the law's transition period — confirm current reporting channels with the Superintendencia de Proteccion de Datos Personales.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.