Ecuador
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Ecuador lets personal data leave the country, but only with paperwork. You need one of a short list of approved routes, and you must register each transfer with the regulator at least ten days before it happens. No country has yet been declared safe to send data to. The privacy regulator opened in 2024, is fully staffed, and issued its first six-figure fines in December 2025.
Data governance in Ecuador
The eight things that decide how you handle data about people in Ecuador. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in Ecuador if it offers goods or services to people living in Ecuador, or watches what they do there. There is no size or revenue threshold to hide behind. A foreign company caught this way must appoint a special attorney who actually lives in Ecuador and register that person with the regulator.
Article 3 of the Organic Law on Personal Data Protection sets four triggers: processing carried out in Ecuadorian territory; a controller or processor established in Ecuador; processing of data belonging to people resident in Ecuador by a controller or processor outside Ecuador where the activity is offering goods or services to them or monitoring their behaviour in Ecuador; and where a treaty makes Ecuadorian law apply. Article 3 of the 2023 General Regulation adds the local-representative duty: 'Los responsables y encargados del tratamiento de datos personales no establecidos en el Ecuador deberan designar un apoderado especial en el Ecuador con residencia en el pais.' The only carve-out is occasional processing that does not involve large-scale processing of special-category data. The Superintendency issued a binding technical guide for registering that representative on 6 September 2024 (Resolution SPDP-SPDP-2024-0002-R) with a six-month deadline running from publication in the Official Register. The guide's sting is that where no representative is registered, anyone who appears to be acting on the foreign company's behalf in Ecuador can be held administratively responsible for the processing.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, article 3 (ambito de aplicacion)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceCorporacion del Seguro de Depositos (COSEDE)Reglamento General a la LOPDP (Decreto Ejecutivo 904), article 3 — duty to appoint a resident special attorney
cosede.gob.ec
“Los responsables y encargados del tratamiento de datos personales no establecidos en el Ecuador deberan designar un apoderado especial en el Ecuador con residencia en el pais”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPDP-2024-0002-R, 6 September 2024 — technical guide for registering special attorneys of foreign controllers
spdp.gob.ec
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions — this is a European-style regime, not an open one. Data may only go abroad through an approved route, and you must tell the regulator before it goes. We looked hard for industries that force data to stay inside Ecuador and found none: banking, payments, insurance, securities, health, telecoms, government cloud and mapping all lack a storage-location rule. The one real wall is credit-reference data, which only the banking regulator may hold.
General rating: conditional. Articles 55 to 58 of the Organic Law on Personal Data Protection allow an international transfer where the destination has been declared to have an adequate level of protection, or where the exporter puts adequate safeguards in place, or under approved binding corporate rules. The Superintendency's General Rule on national and international transfers, Resolution SPDP-SPD-2026-0004-R of 28 January 2026, fleshes this out and adds approved codes of conduct and individual authorisation for exceptional cases. Sector by sector, checked on 19 August 2026: - Banking and payments: no storage-location rule found. The Superintendency of Banks regulates operational risk and third-party services, and the Financial Policy Board's fintech rules (Resolution JPRF-F-2023-076) expressly contemplate cloud computing without any territorial limit. Rating: conditional. - Credit reference data: closed. Private credit bureaux were abolished; the Superintendency of Banks runs the Credit Data Registry and is the only body authorised to hold and deliver that information. - Insurance and securities: no storage-location rule found; supervised by the Superintendency of Companies, Securities and Insurance. Rating: conditional, low confidence — see the unconfirmed list. - Health: no storage-location rule found. The Telehealth Technical Standard of 28 October 2025 requires custody, confidentiality and availability of records and points back to the general privacy law, but does not say where the data must sit. Rating: conditional. - Telecoms: no storage-location rule found. Operators must guarantee the secrecy of communications, protect subscriber data, and keep service information for as long as the regulations require. The regulator inspects where subscriber data is stored, but does not require it to be in Ecuador. Rating: conditional. - Government cloud: no storage-location rule found. The Government Information Security Scheme of 8 February 2024 sets security controls for public bodies with no residency requirement. - Mapping and geospatial: no storage or export rule found, but doing cartographic work in Ecuador at all needs a permit from the Military Geographic Institute. - Online gambling: no data rule found. None of these are 'there is no rule' statements. They are 'no rule found as at 19 August 2026'.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, articles 55-58 (transferencia o comunicacion internacional)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R, 28 January 2026 — General Rule on national and international transfers
spdp.gob.ec
Link checked 19 August 2026
- Official sourceAgencia de Aseguramiento de la Calidad de los Servicios de Salud (ACESS)Norma Tecnica de Telesalud, Registro Oficial Segundo Suplemento 153, 28 October 2025 — health records, no residency rule
acess.gob.ec
Link checked 19 August 2026
- Official sourceAgencia de Regulacion y Control de las Telecomunicaciones (ARCOTEL)Ley Organica de Telecomunicaciones, article 24 — operator duties on secrecy, subscriber data and record keeping
arcotel.gob.ec
“Conservar la informacion relacionada con la prestacion de servicios de telecomunicaciones, en las condiciones y por el tiempo que se disponga en las regulaciones respectivas”
Link checked 19 August 2026
- Official sourceSuperintendencia de Bancos / gob.ecRegistro de Datos Crediticios — the Superintendency of Banks is the only body authorised to hold and deliver credit data
gob.ec
Link checked 19 August 2026
Sending data out of the country
Think allowlist, not blocklist: a transfer is not allowed unless you can name the route you are using. The routes are an official finding that the destination is safe, a set of approved standard contract clauses, approved group-wide rules, an approved industry code, or a one-off permission. No country has been declared safe yet, so in practice almost everyone uses the standard clauses. You must also register the transfer with the regulator at least ten days before it happens.
Resolution SPDP-SPD-2026-0004-R sets the machinery. Adequacy findings are made by the Superintendency, published in the Official Register and listed in the National Register of Personal Data Protection: 'Se inscribira, ademas, en el Registro Nacional de Proteccion de Datos Personales, que contendra el listado publico de paises, organizaciones internacionales...'. As at 19 August 2026 that public list is empty — no adequacy decision has been located. The rule expressly accepts the Ibero-American Data Protection Network model contract clauses as 'validas y suficientes para legitimar las transferencias o comunicaciones internacionales' without prior approval, which is the practical route for most companies. Binding corporate rules and codes of conduct are approved by the Superintendency and last four years with annual monitoring. Individual authorisation is reserved for exceptional cases and requires a full risk and impact analysis. Registration is the real operational burden: individual transfers must be entered in the National Register at least ten days before the operation, and organisations relying on adequacy or safeguards must file a consolidated annual report. A first transitional provision gives twelve months to declare transfers that were already running and to submit an adaptation plan, with no sanctions during that window if the plan is filed and implemented.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R — transfer mechanisms, public country list, ten-day registration, twelve-month transition
spdp.gob.ec
“la inscripcion debera realizarse con un termino minimo de diez (10) dias previo a la operacion”
Link checked 19 August 2026
- Official sourceCOSEDEReglamento General a la LOPDP, articles 71-78 and 86 — adequacy criteria, binding corporate rules, contractual safeguards and registration
cosede.gob.ec
Link checked 19 August 2026
The regulator, and whether it actually acts
The Superintendency of Personal Data Protection, and yes, it is genuinely working. It opened in April 2024 under Superintendent Fabrizio Peralta Diaz, finished hiring its roughly thirty-three staff by October 2024, published a formula for calculating fines in July 2025, and in December 2025 and January 2026 fined Ecuador's football federation and its professional football league six-figure sums over a biometric fan identification app. Telecoms and banking regulators enforce in their own lanes.
The Superintendency was created by the 2021 privacy law and staffed through the Council for Citizen Participation and Social Control's appointment process, which concluded in April 2024. Enforcement evidence, from the regulator's own site: four sanctioning resolutions published against the Federacion Ecuatoriana de Futbol and the Liga Profesional de Futbol del Ecuador (RES-SPDP-ICS-2025-0002, -0003, -0005 and -0006). Announced amounts include about 259,600 US dollars and about 194,900 US dollars in December 2025, and about 95,500 US dollars and about 194,500 US dollars in January 2026, with orders to notify 14,398 affected people and to delete unlawfully obtained consent records. The regulator also publishes general rules at a steady clip — more than a dozen in 2025 and at least nine in 2026 — and issues public alerts. That is an active regulator, not a dormant one, though not yet an aggressive one: the caseload so far is small and concentrated. Other enforcers: the Telecommunications Regulation and Control Agency inspects operators' handling of subscriber data; the Superintendency of Banks runs the Credit Data Registry; the Ministry of Telecommunications is the lead body for the new cybersecurity law.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP press room — December 2025 and January 2026 sanctions against the football federation and professional league
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP register of sanctioning administrative procedures (RES-SPDP-ICS-2025-0002, -0003, -0005, -0006)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceFuncion de Transparencia y Control SocialFunction of Transparency and Social Control — the SPDP is fully staffed; Superintendent Fabrizio Peralta Diaz took office on 23 April 2024
ftcs.gob.ec
Link checked 19 August 2026
- Official sourceConsejo de Participacion Ciudadana y Control SocialCouncil for Citizen Participation and Social Control — appointment process for the Superintendent, concluded April 2024
cpccs.gob.ec
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is a ceiling and a floor, and they are set in different places. The ceiling: keep personal data no longer than you need it for the purpose you collected it for, and delete it within fifteen days when someone validly asks. The floor: tax books and supporting documents must be kept for as long as the tax authority can still assess you, which is three years from filing or six years if you filed late or not at all. Where a law says keep it, keeping it wins.
Ceiling. Article 10 of the privacy law states the storage-limitation principle: 'Los datos personales seran conservados durante un tiempo no mayor al necesario para cumplir con la finalidad.' Article 15 gives a right to deletion which the controller must action within fifteen days where the processing was unlawful, the purpose is spent, consent was withdrawn or the retention period has ended. Floor. Article 96(1)(c) of the Tax Code requires taxpayers to keep books and accounting records 'mientras la obligacion tributaria no este prescrita'. Article 94 fixes the assessment window at three years from the date of the return, six years where no return or an incomplete return was filed, and one year to re-check an assessment already made. Telecom operators must keep service-related information for the period set in the sector regulations rather than a period fixed in the statute. Health records are governed by the Ministry of Public Health's clinical-record rules; we could not open the governing manual to confirm the exact period, so it is listed as unconfirmed. Conflict. The privacy law's storage-limitation principle bends to a legal obligation to retain: retention required by another law is a lawful basis in its own right, so the tax floor beats the privacy ceiling for the documents it covers. The safe pattern is to retain the tax-relevant document set for the statutory window and delete everything else on the shorter privacy clock.
Sources
- Official sourceConsejo de Regulacion y Desarrollo de la Informacion y ComunicacionLey Organica de Proteccion de Datos Personales, articles 10 and 15 — storage limitation and fifteen-day deletion
consejodecomunicacion.gob.ec
“Los datos personales seran conservados durante un tiempo no mayor al necesario para cumplir con la finalidad”
Link checked 19 August 2026
- Official sourceServicio de Rentas InternasCodigo Tributario, articles 94 and 96 — assessment time limits and the duty to keep books while the tax obligation is not time-barred
sri.gob.ec
“conservar tales libros y registros, mientras la obligacion tributaria no este prescrita”
Link checked 19 August 2026
- Official sourceACESSNorma Tecnica de Telesalud, 28 October 2025 — custody and preservation duties for electronic clinical records
acess.gob.ec
Link checked 19 August 2026
If something goes wrong
Two clocks, and the shorter one points at your customers, not the regulator. You have five working days to tell the privacy regulator about a security breach. You have only three working days to tell the people affected, if the breach puts their rights at risk. Telecoms companies must tell their sector regulator as well. A third clock is being built: the new cybersecurity law is in force but its reporting deadlines have not been set yet.
Article 43 of the privacy law: notify 'tan pronto sea posible, y a mas tardar en el termino de cinco (5) dias despues de que haya tenido constancia' — 'termino' means working days in Ecuadorian practice, so five working days, not five calendar days. The same article routes the notification to the telecommunications regulator as well where a telecom provider is involved. Article 46 requires notification to the affected individual without delay and within three days of learning of the risk. Getting these the wrong way round is the classic Ecuadorian mistake: most global playbooks assume the regulator clock is the tight one. A draft general rule on breach notification was published for consultation in May 2026. It would move notifications onto the National Personal Data Protection System, run an automated severity triage before human review, and require notification to the public through at least two mass-media channels. It is a draft with no legal effect. The Organic Law for the Strengthening of Cybersecurity was published in the Official Register on 22 May 2026 and applies to public bodies, digital service providers and private operators of critical digital infrastructure. It leaves response times, coordination protocols and reporting formats to secondary regulation, and gives twelve months to stand up the national incident response team. Treat it as a clock that has not started ticking yet.
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales, articles 43 and 46 — five-day and three-day breach clocks
finanzaspopulares.gob.ec
“notificar... tan pronto sea posible, y a mas tardar en el termino de cinco (5) dias despues de que haya tenido constancia”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesDraft general rule on notification of personal data security breaches, May 2026 (proyecto — no legal effect)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceAsamblea Nacional del EcuadorLey Organica para el Fortalecimiento de la Ciberseguridad, Registro Oficial Quinto Suplemento 290, 22 May 2026
asambleanacional.gob.ec
Link checked 19 August 2026
What catches people out
Five things that will cost you a weekend. One: you have less time to warn customers than to warn the regulator. Two: you must file your processing with the regulator within ten days of starting it, and file each transfer abroad ten days before it happens. Three: whether you need a data protection officer is decided by headcount — one hundred employees — not by how risky your processing is. Four: a foreign company with no registered local attorney can find that whoever seems to act for it locally carries the blame. Five: fines are a slice of your Ecuadorian turnover, and because Ecuador uses the US dollar there is no currency cushion.
1. Article 46 gives three days to tell affected people; article 43 gives five to tell the regulator. Both are counted in working days. 2. Article 86 of the 2023 General Regulation requires registration in the National Register of Personal Data Protection within ten days of starting the processing. Article 64 of the 2026 transfers rule requires each international transfer to be registered at least ten days before it happens, plus a consolidated annual report where you rely on adequacy or safeguards. A routine engineering decision to move a workload to a new region can therefore be unlawful for want of a filing. 3. Article 39 of the General Regulation makes a data protection delegate compulsory for any controller or processor with one hundred or more employees, and for smaller ones whose processing is risky, non-occasional or involves special categories. A twelve-person Ecuadorian subsidiary of a global group can be caught by the second limb. 4. The 2024 technical guide on registering a special attorney states that where a foreign controller has not registered one, 'todas las personas naturales o juridicas que, segun las circunstancias, aparentaren actuar u obrar por cuenta de los sujetos regulados' answer administratively for the processing. Local distributors and staff become the target. 5. Fines are set as a percentage of the previous financial year's turnover: 0.1% to 0.7% for minor infringements and 0.7% to 1% for serious ones, with 'volumen de negocio' defined as revenue from sales and services in the last financial year net of value added tax and related direct taxes. Public officials are fined in multiples of the unified basic salary instead — one to ten for minor breaches, ten to twenty for serious ones. The Superintendency published its calculation methodology on 16 July 2025, so the numbers are formulaic rather than negotiable. 6. Bonus trap for anyone doing survey, drone or mapping work: cartographic activity in Ecuador needs a registration and authorisation from the Military Geographic Institute, including for foreign entities, under a 1978 cartography law that predates everything else here.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2025-0022-R, 16 July 2025 — methodology for calculating fines, citing LOPDP articles 71, 72 and 73
spdp.gob.ec
“la cuantia resultante de la venta de productos y de la prestacion de servicios realizados por operadores economicos, durante el ultimo ejercicio”
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPDP-2024-0002-R — liability of those who appear to act for an unregistered foreign controller
spdp.gob.ec
“por las actividades de tratamiento responderan, administrativamente, todas las personas naturales o juridicas que, segun las circunstancias, aparentaren actuar u obrar por cuenta de los sujetos regulados”
Link checked 19 August 2026
- Official sourceCOSEDEReglamento General a la LOPDP, articles 39 and 86 — hundred-employee delegate threshold and ten-day registration
cosede.gob.ec
Link checked 19 August 2026
- Official sourceInstituto Geografico Militar / gob.ecRegistration and authorisation to carry out cartographic activities — Military Geographic Institute
gob.ec
Link checked 19 August 2026
What's changing next
Three things to watch in the next twelve months. The cybersecurity law passed in May 2026 still needs its detailed rules, and the national incident response team must exist by May 2027. The twelve-month grace period for transfers already running ends in early 2027. And the privacy regulator has draft rules out on breach reporting and on biometric data. The biggest single unknown is that the list of approved destination countries is empty and can be filled at any time.
Dated items: - By 22 May 2027: the national computer security incident response team must be organised under the Organic Law for the Strengthening of Cybersecurity, and the secondary regulation setting response times, coordination protocols and reporting formats is due. Until then the law is in force but its operational duties are not. - Early 2027: the twelve-month transitional window in the 2026 transfers rule closes. Organisations that declared existing transfers and filed an adaptation plan are protected from sanctions during that window; after it, they are not. - Undated: a draft general rule on personal data breach notification (published May 2026) and a draft general rule on biometric data (published March 2026) are both out for comment and would add duties if adopted. Neither is binding. - The Superintendency has also issued a rule on reviewing and evaluating the privacy law itself, which points at statutory reform proposals but does not itself change the law. Dormant switches — powers already held that can change the picture with no consultation: 1. The adequacy list. The Superintendency can declare a country adequate, or decline to, purely by resolution. Today it is empty, which means everyone is on contractual safeguards; a single decision could reroute an entire market's compliance. 2. Refusal or revocation of individual transfer authorisations. The exceptional-case route is discretionary and the regulator has already shown it will impose corrective measures. 3. Corrective measures short of a fine. The privacy law lets the regulator order changes to processing; in the football cases it ordered deletion of consent records and mass notification of individuals, which is commercially heavier than the fines. 4. The cybersecurity regulator's power to set incident reporting deadlines by secondary regulation, with no fixed floor in the statute.
Sources
- Official sourceAsamblea Nacional del EcuadorLey Organica para el Fortalecimiento de la Ciberseguridad, Registro Oficial Quinto Suplemento 290, 22 May 2026 — twelve months to organise the national CSIRT
asambleanacional.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesDraft general rule on the processing of biometric data, March 2026 (proyecto — no legal effect)
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP list of resolutions — 2024, 2025 and 2026 rule-making, including the review and evaluation of the LOPDP
spdp.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R — first transitional provision, twelve months to regularise existing transfers
spdp.gob.ec
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Registro de Datos Crediticios
Act of parliament · Codigo Organico Monetario y Financiero, article 357, as reformed by the Ley para la Reactivacion Economica
Private credit bureaux were abolished in Ecuador. The Superintendency of Banks runs the Credit Data Registry and is the only body authorised to keep and hand out credit information, though it may contract a supplier to run the service. A foreign credit-scoring business cannot lawfully assemble this data set.
Enforced by Superintendency of Banks
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNot a storage-location rule in form, but in effect: only the Superintendency of Banks may hold and deliver Ecuadorian credit-reference data, so no private or offshore credit bureau can hold it.
- Register or notify
Sources
- Official sourceSuperintendencia de Bancos / gob.ecRegistro de Datos Crediticios — official service description citing article 357
gob.ec
Link checked 19 August 2026
Ley Organica de Telecomunicaciones
Act of parliament · Articles 24.13, 24.14 and 24.25
Telecom operators must protect subscriber data, guarantee the secrecy of communications, and keep service records for whatever period the sector rules set. The regulator inspects where subscriber data is stored but does not require it to be stored in Ecuador.
Enforced by Telecommunications Regulation and Control Agency
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Secure the dataGuarantee the secrecy and inviolability of communications carried on the network.
- Keep logsKeep service-related information for the period set by sector regulation; the statute fixes no period.
- Report breaches to the regulator — within 120 hoursThe privacy law routes breach notifications to the telecoms regulator as well as the privacy regulator.
Sources
- Official sourceARCOTELLey Organica de Telecomunicaciones, article 24 — operator obligations
arcotel.gob.ec
“Adoptar las medidas necesarias para la proteccion de los datos personales de sus usuarios”
Link checked 19 August 2026
- Official sourceARCOTELARCOTEL — control of procedures for disclosing subscriber personal data, including identifying where data is stored
arcotel.gob.ec
Link checked 19 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley Organica de Proteccion de Datos Personales
Act of parliament · Registro Oficial Suplemento 459, 26 May 2021
Ecuador's general privacy law, closely modelled on the European approach. It reaches foreign companies that target or monitor people in Ecuador, requires an approved route before data goes abroad, and has been backed by real fines since December 2025. Penalties are a percentage of Ecuadorian turnover, paid in US dollars.
Enforced by Superintendency of Personal Data Protection
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Get consent
- Document a legitimate interestThe regulator issued a dedicated rule on legitimate interest as a lawful basis in 2025.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their dataAction within fifteen days.
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 120 hoursFive working days. Telecom providers notify the telecoms regulator as well.
- Tell affected people — within 72 hoursThree working days where the breach puts rights at risk. Shorter than the regulator clock.
- Delete data after a period
- Put a transfer safeguard in place
- Written vendor contract
- Assess high-risk projects
- Appoint a data protection officerCompulsory for all public bodies; private sector threshold set in the General Regulation.
What it costs if you get it wrong
- Percentage of global turnover: 0.7% of the previous year's Ecuadorian turnoverMinor infringement (range 0.1% to 0.7%)
- Percentage of global turnover: 1% of the previous year's Ecuadorian turnoverSerious infringement (range 0.7% to 1%)
- Fixed maximum fine: 20 unified basic salariesPublic officials, serious infringement (range 10 to 20 salaries)
- Order to stopCorrective measures, including orders to delete data and to notify affected individuals
Sources
- Official sourceCorporacion Nacional de Finanzas Populares y SolidariasLey Organica de Proteccion de Datos Personales (full text)
finanzaspopulares.gob.ec
Link checked 19 August 2026
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2025-0022-R — fine bands under LOPDP articles 71 to 73
spdp.gob.ec
Link checked 19 August 2026
Reglamento General a la Ley Organica de Proteccion de Datos Personales
Directly binding regulation · Decreto Ejecutivo 904, Registro Oficial Suplemento 435, 13 November 2023
The regulation that turns the privacy law into day-to-day duties. It creates the local-representative requirement for foreign companies, the ten-day registration duty, and a headcount test of one hundred employees for appointing a data protection officer.
Enforced by Superintendency of Personal Data Protection
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Government sign-off needed
What it makes you do
- Appoint a local representativeForeign controllers and processors must appoint a special attorney resident in Ecuador, unless processing is occasional and does not involve large-scale special-category data.
- Register or notifyRegistration in the National Register of Personal Data Protection within ten days of starting the processing.
- Appoint a data protection officer — applies at: 100 or more employees, or fewer where processing is risky, non-occasional or involves special categories
- Keep records of processing
- Put a transfer safeguard in place
Sources
- Official sourceCOSEDEReglamento General a la LOPDP (Decreto Ejecutivo 904)
cosede.gob.ec
Link checked 19 August 2026
- Official sourceLink may be brokenMinisterio de Telecomunicaciones y de la Sociedad de la InformacionDecreto Ejecutivo No. 904 as published by the Ministry of Telecommunications
telecomunicaciones.gob.ec
Link checked 19 August 2026
Norma general para la transferencia y comunicacion nacional e internacional de datos personales
Government rules · Resolucion SPDP-SPD-2026-0004-R
The rulebook for sending personal data out of Ecuador. Four safe routes plus a discretionary one, an adequate-country list that exists but is empty, and a hard operational duty to register each transfer ten days in advance. Transfers already running have twelve months to be regularised.
Enforced by Superintendency of Personal Data Protection
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed
What it makes you do
- Register or notifyEach international transfer must be entered in the National Register at least ten days before it happens.
- Keep records of processingAnnual consolidated report where the transfer relies on adequacy or on safeguards.
- Put a transfer safeguard in placeIbero-American Data Protection Network model clauses are accepted as valid and sufficient without prior approval.
- Assess high-risk projectsFull risk and impact analysis required for the exceptional individual-authorisation route.
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesResolution SPDP-SPD-2026-0004-R, 28 January 2026
spdp.gob.ec
“Se inscribira, ademas, en el Registro Nacional de Proteccion de Datos Personales, que contendra el listado publico de paises, organizaciones internacionales”
Link checked 19 August 2026
Norma general para el tratamiento de datos personales a gran escala
Government rules · Resolucion SPDP-SPD-2026-0005-R
A 2026 rule that defines when processing counts as large scale. It matters because the large-scale label is what switches on the data protection officer duty, risk assessments and the local-representative requirement for foreign companies.
Enforced by Superintendency of Personal Data Protection
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Assess high-risk projectsLarge-scale processing triggers risk assessment and a data protection delegate under the General Regulation.
- Appoint a data protection officer
- Register or notify
Sources
- Official sourceSuperintendencia de Proteccion de Datos PersonalesSPDP resolutions index — Resolution SPDP-SPD-2026-0005-R, large-scale processing
spdp.gob.ec
Link checked 19 August 2026
Ley Organica para el Fortalecimiento de la Ciberseguridad
Act of parliament · Registro Oficial Quinto Suplemento 290, 22 May 2026
Ecuador's cybersecurity law, in force since 22 May 2026 but not yet biting. It covers private operators of critical digital infrastructure and digital service providers, and gives twelve months to set up the national incident response team. It contains no requirement to keep data or systems inside Ecuador.
Enforced by Ministry of Telecommunications and the Information Society
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — from 22 May 2027Reporting deadlines, coordination protocols and formats are left to secondary regulation and had not been issued as at 19 August 2026.
- Secure the dataApplies to public bodies, digital service providers and private operators of critical digital infrastructure.
Sources
- Official sourceAsamblea Nacional del EcuadorRegistro Oficial Quinto Suplemento 290, 22 May 2026 — Ley Organica para el Fortalecimiento de la Ciberseguridad
asambleanacional.gob.ec
Link checked 19 August 2026
- Official sourceMinisterio de Telecomunicaciones y de la Sociedad de la InformacionMinistry of Telecommunications — approval of the cybersecurity bill
telecomunicaciones.gob.ec
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the sanctions regime under the privacy law began on 26 May 2023, two years after publication
The date is consistently reported by Ecuadorian law firms, but we could not open a government copy of the law's transitional provisions to quote it. The regulator's own fine-calculation rule and its 2025 sanctions confirm the regime is live; only the precise start date lacks a government backlink.
The exact Registro Oficial publication date of Resolutions SPDP-SPD-2026-0004-R and SPDP-SPD-2026-0005-R
The signed resolutions are dated 28 January 2026 and state they take effect on publication in the Official Register, reported by secondary sources as early February 2026. The twelve-month transitional window for existing transfers therefore ends on a date we have fixed conservatively at 28 January 2027.
Whether the Superintendency has declared any country to have an adequate level of protection
The 2026 transfers rule creates the public list but names no country, and we found no adequacy resolution on the regulator's site as at 19 August 2026. We are recording an empty list, not proving that none exists.
Whether any securities, insurance or pension rule imposes data residency in Ecuador
We searched the Superintendency of Companies, Securities and Insurance and the Financial Policy Board and found no such rule, but we could not open a consolidated rulebook. Rated conditional with low confidence rather than asserted as absent.
Whether the banking operational risk rule (Resolution SB-2021-2126) restricts offshore processing or requires prior notice to the Superintendency of Banks
The Superintendency of Banks' own document server blocked automated retrieval. Older archived chapters on third-party services were unreachable. Treat offshore cloud use by Ecuadorian banks as an open question needing local advice.
The statutory retention period for clinical records in Ecuador
The Ministry of Public Health's archive manual could not be retrieved. The 2025 telehealth standard requires custody and preservation but sets no period.
Whether 'termino de cinco dias' in the breach article is counted in working days
Ecuadorian administrative practice treats 'termino' as working days and 'plazo' as calendar days, which we have applied. We could not find a government statement confirming this specifically for the breach clock, so plan to the calendar-day reading if in doubt.
Incident reporting deadlines under the 2026 cybersecurity law
The law defers response times to secondary regulation which had not been issued as at 19 August 2026. Anyone treating this law as imposing a live reporting clock today is reading it wrong.
Whether Ecuador's public sector cloud policy of 2023 restricts hosting abroad
The ministerial agreement on cloud services for the public sector is referenced in legal databases but we could not open a government-hosted copy. The Government Information Security Scheme of February 2024, which we did open, contains no residency requirement.
30-day cadence. Ecuador is in active rule-making: the Superintendency has issued nine general rules in 2026 alone, has drafts pending on breach notification and biometric data, the adequacy list can be populated by a single resolution, and the cybersecurity law's secondary regulation is due within twelve months of 22 May 2026. A 90-day cadence would let this record assert an empty adequacy list and an unset incident clock long after both had changed.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 30 days. Next check due 18 September 2026.
Put this next to another country
Ecuador versus
Compare