Ecuador
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Ecuador — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Ecuador lets personal data leave the country, but only with paperwork. You need one of a short list of approved routes. You must also register each transfer with the regulator at least ten days before it happens. No country has yet been declared safe to send data to. The privacy regulator opened in 2024, is fully staffed, and issued its first six-figure fines in December 2025.
Data governance in Ecuador
The eight things that decide how you handle data about people in Ecuador. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches you even with no office in Ecuador. It applies if you offer goods or services to people living in Ecuador, or watch what they do there. There is no size or revenue threshold to hide behind. A foreign company caught this way must appoint a special attorney who actually lives in Ecuador. You must register that person with the regulator.
- What you have to do here:
- Appoint a representative
The Organic Law on Personal Data Protection sets four triggers. Data handled inside Ecuadorian territory. A company based in Ecuador. Data about people living in Ecuador, handled by a company outside Ecuador. That applies where you offer them goods or services, or track what they do in Ecuador. And cases where a treaty makes Ecuadorian law apply. The 2023 General Regulation adds the local-representative duty: 'Los responsables y encargados del tratamiento de datos personales no establecidos en el Ecuador deberan designar un apoderado especial en el Ecuador con residencia en el pais.' The only exception is occasional use of data that does not involve large amounts of special-category data. The Superintendency issued a binding technical guide for registering that representative on 6 September 2024 (Resolution SPDP-SPDP-2024-0002-R). It set a six-month deadline running from publication in the Official Register. Here is the sting. If you register no representative, anyone who appears to act on your behalf in Ecuador can be held responsible for your use of data.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, article 3 (ambito de aplicacion)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceCorporacion del Seguro de Depositos (COSEDE)Reglamento General a la LOPDP (Decreto Ejecutivo 904), article 3 — duty to appoint a resident special attorney
cosede.gob.ec
“Los responsables y encargados del tratamiento de datos personales no establecidos en el Ecuador deberan designar un apoderado especial en el Ecuador con residencia en el pais”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPDP-2024-0002-R, 6 September 2024 — technical guide for registering special attorneys of foreign controllers
spdp.gob.ec
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions. This works like the European system, not an open one. Data may only go abroad through an approved route. You must tell the regulator before it goes. We looked hard for industries that force data to stay inside Ecuador and found none. Banking, payments, insurance, securities, health, telecoms, government cloud and mapping all lack a rule about where data must sit. The one real limit is credit-reference data. Only the banking regulator may hold it.
- What you have to do here:
- Put a transfer safeguard in place
The general answer is that it depends. The Organic Law on Personal Data Protection allows a transfer abroad in three cases. The destination has been officially declared to protect data well enough. Or you put adequate safeguards in place. Or you use approved group-wide rules. The Superintendency's General Rule on national and international transfers, Resolution SPDP-SPD-2026-0004-R of 28 January 2026, fills this out. It adds approved codes of conduct, and individual permission for exceptional cases. Industry by industry, checked on 19 August 2026: - Banking and payments: we found no rule about where data must sit. The Superintendency of Banks regulates operational risk and third-party services. The Financial Policy Board's fintech rules (Resolution JPRF-F-2023-076) expressly allow cloud computing, with no limit on location. Conditions apply. - Credit reference data: closed. Private credit bureaux were abolished. The Superintendency of Banks runs the Credit Data Registry, and is the only body allowed to hold and hand out that information. - Insurance and securities: we found no rule about where data must sit. The Superintendency of Companies, Securities and Insurance supervises. Conditions apply, but our confidence is low. See the unconfirmed list. - Health: we found no rule about where data must sit. The Telehealth Technical Standard of 28 October 2025 requires custody, confidentiality and availability of records, and points back to the general privacy law. It does not say where the data must sit. Conditions apply. - Telecoms: we found no rule about where data must sit. Operators must guarantee the secrecy of communications, protect subscriber data, and keep service information for as long as the rules require. The regulator inspects where subscriber data is stored, but does not require it to be in Ecuador. Conditions apply. - Government cloud: we found no rule about where data must sit. The Government Information Security Scheme of 8 February 2024 sets security controls for public bodies, with no rule about the country. - Mapping and geospatial: we found no storage or export rule. But doing any cartographic work in Ecuador needs a permit from the Military Geographic Institute. - Online gambling: we found no data rule. None of these say 'there is no rule'. They say 'we found no rule as at 19 August 2026'.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, articles 55-58 (transferencia o comunicacion internacional)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R, 28 January 2026 — General Rule on national and international transfers
spdp.gob.ec
Link checked 19 August 2026
- Official sourceAgencia de Aseguramiento de la Calidad de los Servicios de Salud (ACESS)Norma Tecnica de Telesalud, Registro Oficial Segundo Suplemento 153, 28 October 2025 — health records, no residency rule
acess.gob.ec
Link checked 19 August 2026
- Official sourceAgencia de Regulacion y Control de las Telecomunicaciones (ARCOTEL)Ley Organica de Telecomunicaciones, article 24 — operator duties on secrecy, subscriber data and record keeping
arcotel.gob.ec
“Conservar la informacion relacionada con la prestacion de servicios de telecomunicaciones, en las condiciones y por el tiempo que se disponga en las regulaciones respectivas”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / gob.ecRegistro de Datos Crediticios — the Superintendency of Banks is the only body authorised to hold and deliver credit data
gob.ec
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Ecuador.
Sending data out of the country
You can only send data abroad through an approved route. A transfer is not allowed unless you can name the route you are using. There are five routes. An official finding that the destination is safe. A set of approved standard contract clauses. Approved group-wide rules. An approved industry code. Or a one-off permission. No country has been declared safe yet. So almost everyone uses the standard clauses. You must also register the transfer with the regulator at least ten days before it happens.
- What you have to do here:
- Register or notify
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Government sign-off needed
Resolution SPDP-SPD-2026-0004-R sets out how this works. The Superintendency decides which countries protect data well enough. It publishes those decisions in the Official Register and lists them in the National Register of Personal Data Protection: 'Se inscribira, ademas, en el Registro Nacional de Proteccion de Datos Personales, que contendra el listado publico de paises, organizaciones internacionales...'. As at 19 August 2026 that public list is empty. We found no decision naming a country. The rule expressly accepts the Ibero-American Data Protection Network model contract clauses as 'validas y suficientes para legitimar las transferencias o comunicaciones internacionales', with no prior approval needed. That is the route most companies use. Group-wide rules and codes of conduct are approved by the Superintendency. They last four years, with annual monitoring. Individual permission is kept for exceptional cases, and needs a full risk and impact analysis. Registration is the real day-to-day burden. Individual transfers must go into the National Register at least ten days before they happen. If you rely on a safe-country finding or on safeguards, you also file one combined annual report. A transitional rule gives you twelve months to declare transfers that were already running, and to submit a plan to bring them into line. There are no penalties during that window if you file the plan and carry it out.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R — transfer mechanisms, public country list, ten-day registration, twelve-month transition
spdp.gob.ec
“la inscripcion debera realizarse con un termino minimo de diez (10) dias previo a la operacion”
Link checked 19 August 2026
- Official sourceCOSEDEReglamento General a la LOPDP, articles 71-78 and 86 — adequacy criteria, binding corporate rules, contractual safeguards and registration
cosede.gob.ec
Link checked 19 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The Superintendency of Personal Data Protection, and it is really working. It opened in April 2024 under Superintendent Fabrizio Peralta Diaz. It finished hiring its roughly thirty-three staff by October 2024. It published a formula for calculating fines in July 2025. In December 2025 and January 2026 it fined Ecuador's football federation and its professional football league six-figure sums. The case was about a biometric fan identification app. Telecoms and banking regulators enforce in their own lanes.
The Superintendency was created by the 2021 privacy law. It was staffed through the Council for Citizen Participation and Social Control's appointment process, which ended in April 2024. Here is the enforcement evidence, from the regulator's own site. It published four sanctioning resolutions against the Federacion Ecuatoriana de Futbol and the Liga Profesional de Futbol del Ecuador (RES-SPDP-ICS-2025-0002, -0003, -0005 and -0006). The announced amounts include about 259,600 US dollars and about 194,900 US dollars in December 2025. Then about 95,500 US dollars and about 194,500 US dollars in January 2026. It also ordered them to notify 14,398 affected people, and to delete consent records obtained unlawfully. The regulator publishes general rules steadily: more than a dozen in 2025 and at least nine in 2026. It also issues public alerts. So this is an active regulator, not a sleeping one. It is not an aggressive one yet either. The caseload so far is small and concentrated. Other enforcers exist. The Telecommunications Regulation and Control Agency inspects how operators handle subscriber data. The Superintendency of Banks runs the Credit Data Registry. The Ministry of Telecommunications is the lead body for the new cybersecurity law.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP press room — December 2025 and January 2026 sanctions against the football federation and professional league
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP register of sanctioning administrative procedures (RES-SPDP-ICS-2025-0002, -0003, -0005, -0006)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceFuncion de Transparencia y Control SocialFunction of Transparency and Social Control — the SPDP is fully staffed; Superintendent Fabrizio Peralta Diaz took office on 23 April 2024
ftcs.gob.ec
Link checked 19 August 2026
- Official sourceConsejo de Participacion Ciudadana y Control SocialCouncil for Citizen Participation and Social Control — appointment process for the Superintendent, concluded April 2024
cpccs.gob.ec
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is a maximum and a minimum, set in different places. The maximum: keep personal data no longer than you need it for the purpose you collected it for. Delete it within fifteen days when someone validly asks. The minimum: tax books and supporting documents must be kept for as long as the tax authority can still assess you. That is three years from filing. It is six years if you filed late or not at all. Where a law says keep it, keeping it wins.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Let people delete their data · Allowed because the law requires it
The maximum. The privacy law says data must not be kept longer than the purpose needs: 'Los datos personales seran conservados durante un tiempo no mayor al necesario para cumplir con la finalidad.' It also gives a right to deletion. You must act on that within fifteen days in four cases. The use of the data was unlawful. The purpose is spent. Consent was withdrawn. Or the keeping period has ended. The minimum. The Tax Code requires taxpayers to keep books and accounting records 'mientras la obligacion tributaria no este prescrita'. The tax authority can assess you for three years from the date of the return. That becomes six years where you filed no return, or an incomplete one. It has one year to re-check an assessment already made. Telecom operators must keep service-related information for the period set in the industry rules, not in the law itself. Health records are governed by the Ministry of Public Health's clinical-record rules. We could not open the manual to confirm the exact period, so it is listed as unconfirmed. When they clash. The privacy rule against keeping data too long gives way to a legal duty to keep it. Keeping data because a law requires it is a lawful reason in its own right. So the tax minimum beats the privacy maximum for the documents it covers. The safe pattern is simple. Keep the tax-relevant documents for the period the law sets. Delete everything else on the shorter privacy clock.
Sources
- Official sourceConsejo de Regulacion y Desarrollo de la Informacion y ComunicacionLey Organica de Proteccion de Datos Personales, articles 10 and 15 — storage limitation and fifteen-day deletion
consejodecomunicacion.gob.ec
“Los datos personales seran conservados durante un tiempo no mayor al necesario para cumplir con la finalidad”
Link checked 19 August 2026
- Official sourceServicio de Rentas InternasCodigo Tributario, articles 94 and 96 — assessment time limits and the duty to keep books while the tax obligation is not time-barred
sri.gob.ec
“conservar tales libros y registros, mientras la obligacion tributaria no este prescrita”
Link checked 19 August 2026
- Official sourceACESSNorma Tecnica de Telesalud, 28 October 2025 — custody and preservation duties for electronic clinical records
acess.gob.ec
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are two clocks, and the shorter one points at your customers, not the regulator. You have five working days to tell the privacy regulator about a security breach. You have only three working days to tell the people affected, if the breach puts their rights at risk. Telecoms companies must tell their industry regulator as well. A third clock is being built. The new cybersecurity law is in force, but its reporting deadlines have not been set yet.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The privacy law says you must notify 'tan pronto sea posible, y a mas tardar en el termino de cinco (5) dias despues de que haya tenido constancia'. In Ecuador 'termino' means working days. So that is five working days, not five calendar days. The same rule sends the notification to the telecommunications regulator too, where a telecom provider is involved. A separate rule requires you to tell the affected individual without delay, and within three days of learning of the risk. So the customer clock is shorter than the regulator clock. A draft general rule on breach notification was published for comment in May 2026. It would move notifications onto the National Personal Data Protection System. It would sort incidents by severity automatically before a human review. And it would require telling the public through at least two mass-media channels. It is a draft with no legal effect. The Organic Law for the Strengthening of Cybersecurity was published in the Official Register on 22 May 2026. It applies to public bodies, digital service providers and private operators of critical digital infrastructure. It leaves response times, coordination protocols and reporting formats to later rules. It gives twelve months to set up the national incident response team. So its clock has not started yet.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, articles 43 and 46 — five-day and three-day breach clocks
finanzaspopulares.gob.ec
“notificar... tan pronto sea posible, y a mas tardar en el termino de cinco (5) dias despues de que haya tenido constancia”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesDraft general rule on notification of personal data security breaches, May 2026 (proyecto — no legal effect)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceAsamblea Nacional del EcuadorLey Organica para el Fortalecimiento de la Ciberseguridad, Registro Oficial Quinto Suplemento 290, 22 May 2026
asambleanacional.gob.ec
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things will cost you a weekend. One: you have less time to warn customers than to warn the regulator. Two: you must file what you do with data with the regulator within ten days of starting. You must file each transfer abroad ten days before it happens. Three: whether you need a data protection officer is decided by employee count, at one hundred employees. It is not decided by how risky your use of data is. Four: a foreign company with no registered local attorney can find that whoever seems to act for it locally carries the blame. Five: fines are a slice of your Ecuadorian turnover. Ecuador uses the US dollar, so there is no currency cushion.
- What you have to do here:
- Register or notify · Appoint a data protection officer · Tell affected people
- What it costs if you get it wrong:
- Percentage of global turnover
1. You get three days to tell affected people, and five days to tell the regulator. Both are counted in working days. 2. The 2023 General Regulation requires you to register in the National Register of Personal Data Protection within ten days of starting to use the data. The 2026 transfers rule requires each international transfer to be registered at least ten days before it happens. You also file one combined annual report if you rely on a safe-country finding or on safeguards. So a routine engineering decision to move a workload to a new region can be unlawful, just for want of a filing. 3. The General Regulation makes a data protection delegate compulsory for any company with one hundred or more employees. It is also compulsory for smaller ones whose use of data is risky, regular, or involves special categories. A twelve-person Ecuadorian subsidiary of a global group can be caught by that second test. 4. The 2024 technical guide on registering a special attorney is blunt. Where a foreign company has not registered one, 'todas las personas naturales o juridicas que, segun las circunstancias, aparentaren actuar u obrar por cuenta de los sujetos regulados' answer for the use of the data. Local distributors and staff become the target. 5. Fines are a percentage of the previous financial year's turnover. That is 0.1% to 0.7% for minor breaches, and 0.7% to 1% for serious ones. 'Volumen de negocio' means revenue from sales and services in the last financial year, after value added tax and related direct taxes. Public officials are fined in multiples of the unified basic salary instead. That is one to ten for minor breaches, and ten to twenty for serious ones. The Superintendency published its calculation method on 16 July 2025. So the numbers are formulaic, not negotiable. 6. A bonus trap for anyone doing survey, drone or mapping work. Cartographic activity in Ecuador needs registration and authorisation from the Military Geographic Institute. That includes foreign companies. It comes from a 1978 cartography law that predates everything else here.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2025-0022-R, 16 July 2025 — methodology for calculating fines, citing LOPDP articles 71, 72 and 73
spdp.gob.ec
“la cuantia resultante de la venta de productos y de la prestacion de servicios realizados por operadores economicos, durante el ultimo ejercicio”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPDP-2024-0002-R — liability of those who appear to act for an unregistered foreign controller
spdp.gob.ec
“por las actividades de tratamiento responderan, administrativamente, todas las personas naturales o juridicas que, segun las circunstancias, aparentaren actuar u obrar por cuenta de los sujetos regulados”
Link checked 19 August 2026
- Official sourceCOSEDEReglamento General a la LOPDP, articles 39 and 86 — hundred-employee delegate threshold and ten-day registration
cosede.gob.ec
Link checked 19 August 2026
- Official sourceInstituto Geografico Militar / gob.ecRegistration and authorisation to carry out cartographic activities — Military Geographic Institute
gob.ec
Link checked 19 August 2026
What's changing next
Three things to watch in the next twelve months. The cybersecurity law passed in May 2026 still needs its detailed rules. The national incident response team must exist by May 2027. The twelve-month grace period for transfers already running ends in early 2027. And the privacy regulator has draft rules out on breach reporting and on biometric data. The biggest single unknown is the list of approved destination countries. It is empty, and it can be filled at any time.
Dated items: - By 22 May 2027: the national computer security incident response team must be organised under the Organic Law for the Strengthening of Cybersecurity. The later rules setting response times, coordination protocols and reporting formats are due then too. Until that happens the law is in force, but its day-to-day duties are not. - Early 2027: the twelve-month transitional window in the 2026 transfers rule closes. Organisations that declared existing transfers and filed a plan are protected from penalties during that window. After it, they are not. - Undated: a draft general rule on personal data breach notification was published in May 2026. A draft general rule on biometric data was published in March 2026. Both are out for comment. Both would add duties if adopted. Neither is binding. - The Superintendency has also issued a rule on reviewing and evaluating the privacy law itself. That points at proposals to reform the law, but does not change the law by itself. Powers the regulator already holds, which could change things with no consultation: 1. The safe-country list. The Superintendency can declare a country safe enough, or decline to, by resolution alone. Today the list is empty, so everyone is on contractual safeguards. A single decision could reroute a whole market. 2. Refusing or revoking individual transfer permissions. The exceptional-case route is discretionary, and the regulator has already shown it will impose corrective measures. 3. Corrective measures short of a fine. The privacy law lets the regulator order you to change how you use data. In the football cases it ordered deletion of consent records and mass notification of individuals. That costs more commercially than the fines. 4. The cybersecurity regulator's power to set incident reporting deadlines by later rules, with no minimum fixed in the law.
Sources
- Official sourceAsamblea Nacional del EcuadorLey Organica para el Fortalecimiento de la Ciberseguridad, Registro Oficial Quinto Suplemento 290, 22 May 2026 — twelve months to organise the national CSIRT
asambleanacional.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesDraft general rule on the processing of biometric data, March 2026 (proyecto — no legal effect)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP list of resolutions — 2024, 2025 and 2026 rule-making, including the review and evaluation of the LOPDP
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R — first transitional provision, twelve months to regularise existing transfers
spdp.gob.ec
Link checked 19 August 2026
What to do: Diarise 22 May 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking rules
Official name: Registro de Datos Crediticios · Codigo Organico Monetario y Financiero, article 357, as reformed by the Ley para la Reactivacion Economica · Act of parliament
Private credit bureaux were abolished in Ecuador. The Superintendency of Banks runs the Credit Data Registry. It is the only body allowed to keep and hand out credit information, though it may hire a supplier to run the service. A foreign credit-scoring business cannot lawfully assemble this data set.
Enforced by Superintendency of Banks
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis is not a storage-location rule on its face, but that is the result. Only the Superintendency of Banks may hold and hand out Ecuadorian credit-reference data. So no private or offshore credit bureau can hold it.
- Register or notify
Sources
- Official sourceSuperintendencia de Bancos / gob.ecRegistro de Datos Crediticios — official service description citing article 357
gob.ec
Link checked 19 August 2026
Telecoms rules
Official name: Ley Organica de Telecomunicaciones · Articles 24.13, 24.14 and 24.25 · Act of parliament
Telecom operators must protect subscriber data and guarantee the secrecy of communications. They must keep service records for whatever period the industry rules set. The regulator inspects where subscriber data is stored. It does not require it to be stored in Ecuador.
Enforced by Telecommunications Regulation and Control Agency
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Secure the dataGuarantee the secrecy and inviolability of communications carried on the network.
- Keep logsKeep service-related information for the period set by the industry rules. The law itself fixes no period.
- Report breaches to the regulator — within 120 hoursThe privacy law routes breach notifications to the telecoms regulator as well as the privacy regulator.
Sources
- Official sourceARCOTELLey Organica de Telecomunicaciones, article 24 — operator obligations
arcotel.gob.ec
“Adoptar las medidas necesarias para la proteccion de los datos personales de sus usuarios”
Link checked 19 August 2026
- Official sourceARCOTELARCOTEL — control of procedures for disclosing subscriber personal data, including identifying where data is stored
arcotel.gob.ec
Link checked 19 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley Organica de Proteccion de Datos Personales · Registro Oficial Suplemento 459, 26 May 2021 · Act of parliament
Ecuador's general privacy law, closely modelled on the European approach. It reaches foreign companies that target or watch people in Ecuador. It requires an approved route before data goes abroad. Real fines have backed it since December 2025. Penalties are a percentage of Ecuadorian turnover, paid in US dollars.
Enforced by Superintendency of Personal Data Protection
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Get consent
- Document a legitimate interestThe regulator issued a dedicated rule on legitimate interest as a lawful basis in 2025.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their dataAction within fifteen days.
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 120 hoursFive working days. Telecom providers notify the telecoms regulator as well.
- Tell affected people — within 72 hoursThree working days where the breach puts rights at risk. Shorter than the regulator clock.
- Delete data after a period
- Put a transfer safeguard in place
- Written vendor contract
- Assess high-risk projects
- Appoint a data protection officerCompulsory for all public bodies. The threshold for private companies is set in the General Regulation.
What it costs if you get it wrong
- Percentage of global turnover: 0.7% of the previous year's Ecuadorian turnoverMinor infringement (range 0.1% to 0.7%)
- Percentage of global turnover: 1% of the previous year's Ecuadorian turnoverSerious infringement (range 0.7% to 1%)
- Fixed maximum fine: 20 unified basic salariesPublic officials, serious infringement (range 10 to 20 salaries)
- Order to stopCorrective measures, including orders to delete data and to notify affected individuals
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales (full text)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2025-0022-R — fine bands under LOPDP articles 71 to 73
spdp.gob.ec
Link checked 19 August 2026
General data protection law (2023)
Official name: Reglamento General a la Ley Organica de Proteccion de Datos Personales · Decreto Ejecutivo 904, Registro Oficial Suplemento 435, 13 November 2023 · Directly binding regulation
The regulation that turns the privacy law into day-to-day duties. It creates the local-representative requirement for foreign companies. It creates the ten-day registration duty. And it sets a test of one hundred employees for appointing a data protection officer.
Enforced by Superintendency of Personal Data Protection
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Government sign-off needed
What you have to do
- Appoint a representativeForeign companies must appoint a special attorney living in Ecuador. The exception is where you use data only occasionally, and not large amounts of special-category data.
- Register or notifyYou must register in the National Register of Personal Data Protection within ten days of starting to use the data.
- Appoint a data protection officer — applies at: 100 or more employees, or fewer where processing is risky, non-occasional or involves special categories
- Keep records of how you use data
- Put a transfer safeguard in place
Sources
- Official sourceCOSEDEReglamento General a la LOPDP (Decreto Ejecutivo 904)
cosede.gob.ec
Link checked 19 August 2026
- Official sourceLink may be brokenMinisterio de Telecomunicaciones y de la Sociedad de la InformacionDecreto Ejecutivo No. 904 as published by the Ministry of Telecommunications
telecomunicaciones.gob.ec
Link checked 19 August 2026
Rules for sending data abroad
Official name: Norma general para la transferencia y comunicacion nacional e internacional de datos personales · Resolucion SPDP-SPD-2026-0004-R · Government rules
The rulebook for sending personal data out of Ecuador. There are four safe routes, plus one at the regulator's discretion. There is a list of approved countries, but it is empty. And there is a hard day-to-day duty to register each transfer ten days in advance. Transfers already running have twelve months to be brought into line.
It is already law, so plan for it — but nobody can be penalised under it until 28 January 2027. A contract you sign may still hold you to it sooner.
Enforced by Superintendency of Personal Data Protection
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed
What you have to do
- Register or notifyEach international transfer must be entered in the National Register at least ten days before it happens.
- Keep records of how you use dataYou file one combined annual report where the transfer relies on a safe-country finding, or on safeguards.
- Put a transfer safeguard in placeIbero-American Data Protection Network model clauses are accepted as valid and sufficient without prior approval.
- Assess high-risk projectsFull risk and impact analysis required for the exceptional individual-authorisation route.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R, 28 January 2026
spdp.gob.ec
“Se inscribira, ademas, en el Registro Nacional de Proteccion de Datos Personales, que contendra el listado publico de paises, organizaciones internacionales”
Link checked 19 August 2026
General data protection law (Resolucion SPDP-SPD-2026-0005-R)
Official name: Norma general para el tratamiento de datos personales a gran escala · Resolucion SPDP-SPD-2026-0005-R · Government rules
A 2026 rule that defines when handling data counts as large scale. That matters, because the large-scale label switches on three things. The duty to have a data protection officer. Risk assessments. And the local-representative requirement for foreign companies.
Enforced by Superintendency of Personal Data Protection
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Assess high-risk projectsHandling data on a large scale triggers a risk assessment and a data protection delegate under the General Regulation.
- Appoint a data protection officer
- Register or notify
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP resolutions index — Resolution SPDP-SPD-2026-0005-R, large-scale processing
spdp.gob.ec
Link checked 19 August 2026
Cyber security rules
Official name: Ley Organica para el Fortalecimiento de la Ciberseguridad · Registro Oficial Quinto Suplemento 290, 22 May 2026 · Act of parliament
Ecuador's cybersecurity law, in force since 22 May 2026, but not yet doing anything. It covers private operators of critical digital infrastructure and digital service providers. It gives twelve months to set up the national incident response team. It contains no requirement to keep data or systems inside Ecuador.
It is already law, so plan for it — but nobody can be penalised under it until 22 May 2027. A contract you sign may still hold you to it sooner.
Enforced by Ministry of Telecommunications and the Information Society
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — from 22 May 2027Reporting deadlines, coordination protocols and formats are left to secondary regulation and had not been issued as at 19 August 2026.
- Secure the dataApplies to public bodies, digital service providers and private operators of critical digital infrastructure.
Sources
- Official sourceAsamblea Nacional del EcuadorRegistro Oficial Quinto Suplemento 290, 22 May 2026 — Ley Organica para el Fortalecimiento de la Ciberseguridad
asambleanacional.gob.ec
Link checked 19 August 2026
- Official sourceMinisterio de Telecomunicaciones y de la Sociedad de la InformacionMinistry of Telecommunications — approval of the cybersecurity bill
telecomunicaciones.gob.ec
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the sanctions regime under the privacy law began on 26 May 2023, two years after publication
Ecuadorian law firms consistently report this date. We could not open a government copy of the law's transitional text to quote it. The regulator's own fine-calculation rule and its 2025 sanctions confirm that fines are live. Only the exact start date lacks a government source.
The exact Registro Oficial publication date of Resolutions SPDP-SPD-2026-0004-R and SPDP-SPD-2026-0005-R
The signed resolutions are dated 28 January 2026. They say they take effect on publication in the Official Register. Secondary sources report that as early February 2026. We have fixed the end of the twelve-month window for existing transfers conservatively at 28 January 2027. Check the Official Register for the exact date.
Whether the Superintendency has declared any country to have an adequate level of protection
The 2026 transfers rule creates the public list of safe countries, but names none. We found no such decision on the regulator's site as at 19 August 2026. We are recording an empty list. That is not proof that no decision exists.
Whether any securities, insurance or pension rule imposes where data has to be stored in Ecuador
We searched the Superintendency of Companies, Securities and Insurance and the Financial Policy Board. We found no rule requiring data to stay in Ecuador. But we could not open a combined rulebook. If you work in securities, insurance or pensions, check before you rely on this.
Whether the banking operational risk rule (Resolution SB-2021-2126) restricts offshore processing or requires prior notice to the Superintendency of Banks
The Superintendency of Banks' own document server blocked automated retrieval. We could not reach older archived chapters on third-party services. If you are an Ecuadorian bank using offshore cloud, treat this as an open question and take local advice.
The statutory retention period for clinical records in Ecuador
We could not retrieve the Ministry of Public Health's archive manual. The 2025 telehealth standard requires custody and preservation, but sets no period. Ask the Ministry if you hold clinical records.
Whether 'termino de cinco dias' in the breach article is counted in working days
Ecuadorian practice treats 'termino' as working days and 'plazo' as calendar days, and we have applied that. We could not find a government statement confirming it for the breach clock specifically. If in doubt, plan to the calendar-day reading.
Incident reporting deadlines under the 2026 cybersecurity law
The law leaves response times to later rules, which had not been issued as at 19 August 2026. So there is no live reporting clock under this law today. Watch for those later rules before you build to a deadline.
Whether Ecuador's public sector cloud policy of 2023 restricts hosting abroad
Legal databases refer to the ministerial agreement on cloud services for the public sector. We could not open a government-hosted copy. The Government Information Security Scheme of February 2024, which we did open, has no rule about keeping data in the country.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 30 days. Next check due 18 September 2026.