Skip to the content
Global Data RulesData governance rules, country by country

Ecuador

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Ecuador — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Ecuador lets personal data leave the country, but only with paperwork. You need one of a short list of approved routes. You must also register each transfer with the regulator at least ten days before it happens. No country has yet been declared safe to send data to. The privacy regulator opened in 2024, is fully staffed, and issued its first six-figure fines in December 2025.

Data governance in Ecuador

The eight things that decide how you handle data about people in Ecuador. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches you even with no office in Ecuador. It applies if you offer goods or services to people living in Ecuador, or watch what they do there. There is no size or revenue threshold to hide behind. A foreign company caught this way must appoint a special attorney who actually lives in Ecuador. You must register that person with the regulator.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with conditions. This works like the European system, not an open one. Data may only go abroad through an approved route. You must tell the regulator before it goes. We looked hard for industries that force data to stay inside Ecuador and found none. Banking, payments, insurance, securities, health, telecoms, government cloud and mapping all lack a rule about where data must sit. The one real limit is credit-reference data. Only the banking regulator may hold it.

What you have to do here:
Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Ecuador.

Sending data out of the country

You can only send data abroad through an approved route. A transfer is not allowed unless you can name the route you are using. There are five routes. An official finding that the destination is safe. A set of approved standard contract clauses. Approved group-wide rules. An approved industry code. Or a one-off permission. No country has been declared safe yet. So almost everyone uses the standard clauses. You must also register the transfer with the regulator at least ten days before it happens.

What you have to do here:
Register or notify
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Government sign-off needed

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The Superintendency of Personal Data Protection, and it is really working. It opened in April 2024 under Superintendent Fabrizio Peralta Diaz. It finished hiring its roughly thirty-three staff by October 2024. It published a formula for calculating fines in July 2025. In December 2025 and January 2026 it fined Ecuador's football federation and its professional football league six-figure sums. The case was about a biometric fan identification app. Telecoms and banking regulators enforce in their own lanes.

How long you must keep it — and when to delete it

There is a maximum and a minimum, set in different places. The maximum: keep personal data no longer than you need it for the purpose you collected it for. Delete it within fifteen days when someone validly asks. The minimum: tax books and supporting documents must be kept for as long as the tax authority can still assess you. That is three years from filing. It is six years if you filed late or not at all. Where a law says keep it, keeping it wins.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Let people delete their data · Allowed because the law requires it

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are two clocks, and the shorter one points at your customers, not the regulator. You have five working days to tell the privacy regulator about a security breach. You have only three working days to tell the people affected, if the breach puts their rights at risk. Telecoms companies must tell their industry regulator as well. A third clock is being built. The new cybersecurity law is in force, but its reporting deadlines have not been set yet.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things will cost you a weekend. One: you have less time to warn customers than to warn the regulator. Two: you must file what you do with data with the regulator within ten days of starting. You must file each transfer abroad ten days before it happens. Three: whether you need a data protection officer is decided by employee count, at one hundred employees. It is not decided by how risky your use of data is. Four: a foreign company with no registered local attorney can find that whoever seems to act for it locally carries the blame. Five: fines are a slice of your Ecuadorian turnover. Ecuador uses the US dollar, so there is no currency cushion.

What you have to do here:
Register or notify · Appoint a data protection officer · Tell affected people
What it costs if you get it wrong:
Percentage of global turnover

What's changing next

Three things to watch in the next twelve months. The cybersecurity law passed in May 2026 still needs its detailed rules. The national incident response team must exist by May 2027. The twelve-month grace period for transfers already running ends in early 2027. And the privacy regulator has draft rules out on breach reporting and on biometric data. The biggest single unknown is the list of approved destination countries. It is empty, and it can be filled at any time.

What to do: Diarise 22 May 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking rules

Official name: Registro de Datos Crediticios · Codigo Organico Monetario y Financiero, article 357, as reformed by the Ley para la Reactivacion Economica · Act of parliament

In forceNo — it stays put

Private credit bureaux were abolished in Ecuador. The Superintendency of Banks runs the Credit Data Registry. It is the only body allowed to keep and hand out credit information, though it may hire a supplier to run the service. A foreign credit-scoring business cannot lawfully assemble this data set.

Enforced by Superintendency of Banks

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Ley Organica de Telecomunicaciones · Articles 24.13, 24.14 and 24.25 · Act of parliament

In forceYes, with paperwork

Telecom operators must protect subscriber data and guarantee the secrecy of communications. They must keep service records for whatever period the industry rules set. The regulator inspects where subscriber data is stored. It does not require it to be stored in Ecuador.

Enforced by Telecommunications Regulation and Control Agency

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Not fully verified — see “What we're not sure about” below.

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley Organica de Proteccion de Datos Personales · Registro Oficial Suplemento 459, 26 May 2021 · Act of parliament

In forceYes, with paperwork

Ecuador's general privacy law, closely modelled on the European approach. It reaches foreign companies that target or watch people in Ecuador. It requires an approved route before data goes abroad. Real fines have backed it since December 2025. Penalties are a percentage of Ecuadorian turnover, paid in US dollars.

In force since 26 May 2021Enforced from 26 May 2023

Enforced by Superintendency of Personal Data Protection

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

General data protection law (2023)

Official name: Reglamento General a la Ley Organica de Proteccion de Datos Personales · Decreto Ejecutivo 904, Registro Oficial Suplemento 435, 13 November 2023 · Directly binding regulation

In forceYes, with paperwork

The regulation that turns the privacy law into day-to-day duties. It creates the local-representative requirement for foreign companies. It creates the ten-day registration duty. And it sets a test of one hundred employees for appointing a data protection officer.

In force since 13 November 2023

Enforced by Superintendency of Personal Data Protection

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Government sign-off needed

Rules for sending data abroad

Official name: Norma general para la transferencia y comunicacion nacional e internacional de datos personales · Resolucion SPDP-SPD-2026-0004-R · Government rules

In forceYes, with paperwork

The rulebook for sending personal data out of Ecuador. There are four safe routes, plus one at the regulator's discretion. There is a list of approved countries, but it is empty. And there is a hard day-to-day duty to register each transfer ten days in advance. Transfers already running have twelve months to be brought into line.

In force since 28 January 2026In force now, but not enforced until 28 January 2027

It is already law, so plan for it — but nobody can be penalised under it until 28 January 2027. A contract you sign may still hold you to it sooner.

Enforced by Superintendency of Personal Data Protection

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed

Who you would hear from

  • Superintendencia de Proteccion de Datos Personales

    General privacy law, all sectors

    Fully operational. Superintendent Fabrizio Peralta Diaz took office on 23 April 2024. Staffing was complete by 1 October 2024, with about 33 people. It published a fine-calculation method in July 2025. It issued its first four sanctioning resolutions in December 2025 and January 2026, with fines from roughly 95,500 to 259,600 US dollars. It also ordered them to delete data and notify affected individuals. Its rule-making output is high: a dozen general rules in 2025 and at least nine in 2026.

  • Agencia de Regulacion y Control de las Telecomunicaciones

    Telecoms operators, subscriber data, secrecy of communications

  • Superintendencia de Bancos

    Banks, operational risk, the Credit Data Registry

  • Ministerio de Telecomunicaciones y de la Sociedad de la Informacion

    Digital transformation, government information security, lead body for cybersecurity

  • Superintendencia de Companias, Valores y Seguros

    Companies, securities markets and insurance

    Active as an industry supervisor. We found no securities or insurance rule requiring data to stay in the country. See the unconfirmed list.

  • Agencia de Aseguramiento de la Calidad de los Servicios de Salud

    Health providers, telehealth, clinical records

  • Instituto Geografico Militar

    Cartographic and geospatial activity authorisations

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the sanctions regime under the privacy law began on 26 May 2023, two years after publication

    Ecuadorian law firms consistently report this date. We could not open a government copy of the law's transitional text to quote it. The regulator's own fine-calculation rule and its 2025 sanctions confirm that fines are live. Only the exact start date lacks a government source.

  • The exact Registro Oficial publication date of Resolutions SPDP-SPD-2026-0004-R and SPDP-SPD-2026-0005-R

    The signed resolutions are dated 28 January 2026. They say they take effect on publication in the Official Register. Secondary sources report that as early February 2026. We have fixed the end of the twelve-month window for existing transfers conservatively at 28 January 2027. Check the Official Register for the exact date.

  • Whether the Superintendency has declared any country to have an adequate level of protection

    The 2026 transfers rule creates the public list of safe countries, but names none. We found no such decision on the regulator's site as at 19 August 2026. We are recording an empty list. That is not proof that no decision exists.

  • Whether any securities, insurance or pension rule imposes where data has to be stored in Ecuador

    We searched the Superintendency of Companies, Securities and Insurance and the Financial Policy Board. We found no rule requiring data to stay in Ecuador. But we could not open a combined rulebook. If you work in securities, insurance or pensions, check before you rely on this.

  • Whether the banking operational risk rule (Resolution SB-2021-2126) restricts offshore processing or requires prior notice to the Superintendency of Banks

    The Superintendency of Banks' own document server blocked automated retrieval. We could not reach older archived chapters on third-party services. If you are an Ecuadorian bank using offshore cloud, treat this as an open question and take local advice.

  • The statutory retention period for clinical records in Ecuador

    We could not retrieve the Ministry of Public Health's archive manual. The 2025 telehealth standard requires custody and preservation, but sets no period. Ask the Ministry if you hold clinical records.

  • Whether 'termino de cinco dias' in the breach article is counted in working days

    Ecuadorian practice treats 'termino' as working days and 'plazo' as calendar days, and we have applied that. We could not find a government statement confirming it for the breach clock specifically. If in doubt, plan to the calendar-day reading.

  • Incident reporting deadlines under the 2026 cybersecurity law

    The law leaves response times to later rules, which had not been issued as at 19 August 2026. So there is no live reporting clock under this law today. Watch for those later rules before you build to a deadline.

  • Whether Ecuador's public sector cloud policy of 2023 restricts hosting abroad

    Legal databases refer to the ministerial agreement on cloud services for the public sector. We could not open a government-hosted copy. The Government Information Security Scheme of February 2024, which we did open, has no rule about keeping data in the country.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 30 days. Next check due 18 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.