Skip to the content
Global Data RulesData governance rules, country by country

Ecuador

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Ecuador lets personal data leave the country, but only with paperwork. You need one of a short list of approved routes, and you must register each transfer with the regulator at least ten days before it happens. No country has yet been declared safe to send data to. The privacy regulator opened in 2024, is fully staffed, and issued its first six-figure fines in December 2025.

Data governance in Ecuador

The eight things that decide how you handle data about people in Ecuador. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Ecuador if it offers goods or services to people living in Ecuador, or watches what they do there. There is no size or revenue threshold to hide behind. A foreign company caught this way must appoint a special attorney who actually lives in Ecuador and register that person with the regulator.

High confidenceNational rulesAppoint a local representativeLocal representative

Where the data is allowed to live

Yes, with conditions — this is a European-style regime, not an open one. Data may only go abroad through an approved route, and you must tell the regulator before it goes. We looked hard for industries that force data to stay inside Ecuador and found none: banking, payments, insurance, securities, health, telecoms, government cloud and mapping all lack a storage-location rule. The one real wall is credit-reference data, which only the banking regulator may hold.

High confidenceYes, with paperworkAllowlistPut a transfer safeguard in place

Sending data out of the country

Think allowlist, not blocklist: a transfer is not allowed unless you can name the route you are using. The routes are an official finding that the destination is safe, a set of approved standard contract clauses, approved group-wide rules, an approved industry code, or a one-off permission. No country has been declared safe yet, so in practice almost everyone uses the standard clauses. You must also register the transfer with the regulator at least ten days before it happens.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesApproved code of conductGovernment sign-off neededRegister or notify

The regulator, and whether it actually acts

The Superintendency of Personal Data Protection, and yes, it is genuinely working. It opened in April 2024 under Superintendent Fabrizio Peralta Diaz, finished hiring its roughly thirty-three staff by October 2024, published a formula for calculating fines in July 2025, and in December 2025 and January 2026 fined Ecuador's football federation and its professional football league six-figure sums over a biometric fan identification app. Telecoms and banking regulators enforce in their own lanes.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

There is a ceiling and a floor, and they are set in different places. The ceiling: keep personal data no longer than you need it for the purpose you collected it for, and delete it within fifteen days when someone validly asks. The floor: tax books and supporting documents must be kept for as long as the tax authority can still assess you, which is three years from filing or six years if you filed late or not at all. Where a law says keep it, keeping it wins.

Medium confidenceDelete data after a periodKeep data for a minimum periodLet people delete their dataAllowed because the law requires it

If something goes wrong

Two clocks, and the shorter one points at your customers, not the regulator. You have five working days to tell the privacy regulator about a security breach. You have only three working days to tell the people affected, if the breach puts their rights at risk. Telecoms companies must tell their sector regulator as well. A third clock is being built: the new cybersecurity law is in force but its reporting deadlines have not been set yet.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that will cost you a weekend. One: you have less time to warn customers than to warn the regulator. Two: you must file your processing with the regulator within ten days of starting it, and file each transfer abroad ten days before it happens. Three: whether you need a data protection officer is decided by headcount — one hundred employees — not by how risky your processing is. Four: a foreign company with no registered local attorney can find that whoever seems to act for it locally carries the blame. Five: fines are a slice of your Ecuadorian turnover, and because Ecuador uses the US dollar there is no currency cushion.

High confidenceRegister or notifyAppoint a data protection officerAppoint a local representativePercentage of global turnoverTell affected people

What's changing next

Three things to watch in the next twelve months. The cybersecurity law passed in May 2026 still needs its detailed rules, and the national incident response team must exist by May 2027. The twelve-month grace period for transfers already running ends in early 2027. And the privacy regulator has draft rules out on breach reporting and on biometric data. The biggest single unknown is that the list of approved destination countries is empty and can be filled at any time.

Medium confidencePartly in forceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Registro de Datos Crediticios

Act of parliament · Codigo Organico Monetario y Financiero, article 357, as reformed by the Ley para la Reactivacion Economica

In forceNo — it stays put

Private credit bureaux were abolished in Ecuador. The Superintendency of Banks runs the Credit Data Registry and is the only body authorised to keep and hand out credit information, though it may contract a supplier to run the service. A foreign credit-scoring business cannot lawfully assemble this data set.

Enforced by Superintendency of Banks

Transfer model: Not allowed

Medium confidence
Telecoms

Ley Organica de Telecomunicaciones

Act of parliament · Articles 24.13, 24.14 and 24.25

In forceYes, with paperwork

Telecom operators must protect subscriber data, guarantee the secrecy of communications, and keep service records for whatever period the sector rules set. The regulator inspects where subscriber data is stored but does not require it to be stored in Ecuador.

Enforced by Telecommunications Regulation and Control Agency

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Medium confidence

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley Organica de Proteccion de Datos Personales

Act of parliament · Registro Oficial Suplemento 459, 26 May 2021

In forceYes, with paperwork

Ecuador's general privacy law, closely modelled on the European approach. It reaches foreign companies that target or monitor people in Ecuador, requires an approved route before data goes abroad, and has been backed by real fines since December 2025. Penalties are a percentage of Ecuadorian turnover, paid in US dollars.

In force since 26 May 2021But only enforceable from 26 May 2023

Enforced by Superintendency of Personal Data Protection

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Reglamento General a la Ley Organica de Proteccion de Datos Personales

Directly binding regulation · Decreto Ejecutivo 904, Registro Oficial Suplemento 435, 13 November 2023

In forceYes, with paperwork

The regulation that turns the privacy law into day-to-day duties. It creates the local-representative requirement for foreign companies, the ten-day registration duty, and a headcount test of one hundred employees for appointing a data protection officer.

In force since 13 November 2023

Enforced by Superintendency of Personal Data Protection

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Standard contract clauses, Government sign-off needed

High confidence

Norma general para la transferencia y comunicacion nacional e internacional de datos personales

Government rules · Resolucion SPDP-SPD-2026-0004-R

In forceYes, with paperwork

The rulebook for sending personal data out of Ecuador. Four safe routes plus a discretionary one, an adequate-country list that exists but is empty, and a hard operational duty to register each transfer ten days in advance. Transfers already running have twelve months to be regularised.

In force since 28 January 2026But only enforceable from 28 January 2027

Enforced by Superintendency of Personal Data Protection

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Government sign-off needed

High confidence

Who you would hear from

  • Superintendencia de Proteccion de Datos Personales

    General privacy law, all sectors

    Fully operational. Superintendent Fabrizio Peralta Diaz took office on 23 April 2024; staffing completed by 1 October 2024 with about 33 people. Published a fine-calculation methodology in July 2025 and issued its first four sanctioning resolutions in December 2025 and January 2026, with fines from roughly 95,500 to 259,600 US dollars, plus orders to delete data and notify affected individuals. Rule-making output is high: a dozen general rules in 2025 and at least nine in 2026.

  • Agencia de Regulacion y Control de las Telecomunicaciones

    Telecoms operators, subscriber data, secrecy of communications

  • Superintendencia de Bancos

    Banks, operational risk, the Credit Data Registry

  • Ministerio de Telecomunicaciones y de la Sociedad de la Informacion

    Digital transformation, government information security, lead body for cybersecurity

  • Superintendencia de Companias, Valores y Seguros

    Companies, securities markets and insurance

    Active as a sector supervisor. We found no securities or insurance rule imposing data residency; see the unconfirmed list.

  • Agencia de Aseguramiento de la Calidad de los Servicios de Salud

    Health providers, telehealth, clinical records

  • Instituto Geografico Militar

    Cartographic and geospatial activity authorisations

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the sanctions regime under the privacy law began on 26 May 2023, two years after publication

    The date is consistently reported by Ecuadorian law firms, but we could not open a government copy of the law's transitional provisions to quote it. The regulator's own fine-calculation rule and its 2025 sanctions confirm the regime is live; only the precise start date lacks a government backlink.

  • The exact Registro Oficial publication date of Resolutions SPDP-SPD-2026-0004-R and SPDP-SPD-2026-0005-R

    The signed resolutions are dated 28 January 2026 and state they take effect on publication in the Official Register, reported by secondary sources as early February 2026. The twelve-month transitional window for existing transfers therefore ends on a date we have fixed conservatively at 28 January 2027.

  • Whether the Superintendency has declared any country to have an adequate level of protection

    The 2026 transfers rule creates the public list but names no country, and we found no adequacy resolution on the regulator's site as at 19 August 2026. We are recording an empty list, not proving that none exists.

  • Whether any securities, insurance or pension rule imposes data residency in Ecuador

    We searched the Superintendency of Companies, Securities and Insurance and the Financial Policy Board and found no such rule, but we could not open a consolidated rulebook. Rated conditional with low confidence rather than asserted as absent.

  • Whether the banking operational risk rule (Resolution SB-2021-2126) restricts offshore processing or requires prior notice to the Superintendency of Banks

    The Superintendency of Banks' own document server blocked automated retrieval. Older archived chapters on third-party services were unreachable. Treat offshore cloud use by Ecuadorian banks as an open question needing local advice.

  • The statutory retention period for clinical records in Ecuador

    The Ministry of Public Health's archive manual could not be retrieved. The 2025 telehealth standard requires custody and preservation but sets no period.

  • Whether 'termino de cinco dias' in the breach article is counted in working days

    Ecuadorian administrative practice treats 'termino' as working days and 'plazo' as calendar days, which we have applied. We could not find a government statement confirming this specifically for the breach clock, so plan to the calendar-day reading if in doubt.

  • Incident reporting deadlines under the 2026 cybersecurity law

    The law defers response times to secondary regulation which had not been issued as at 19 August 2026. Anyone treating this law as imposing a live reporting clock today is reading it wrong.

  • Whether Ecuador's public sector cloud policy of 2023 restricts hosting abroad

    The ministerial agreement on cloud services for the public sector is referenced in legal databases but we could not open a government-hosted copy. The Government Information Security Scheme of February 2024, which we did open, contains no residency requirement.

30-day cadence. Ecuador is in active rule-making: the Superintendency has issued nine general rules in 2026 alone, has drafts pending on breach notification and biometric data, the adequacy list can be populated by a single resolution, and the cybersecurity law's secondary regulation is due within twelve months of 22 May 2026. A 90-day cadence would let this record assert an empty adequacy list and an unset incident clock long after both had changed.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 30 days. Next check due 18 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Ecuador versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.