Organic Law on Protection of Personal Data
Ecuador’s Organic Law on Protection of Personal Data (Ley Orgánica de Protección de Datos Personales or LOPDP) establishes the country’s framework for protecting personal data and regulating its processing by public and private organisations.
The LOPDP was enacted in 2021 and is supplemented by the General Regulation to the LOPDP, issued through Executive Decree No. 904 and published on 13 November 2023. The regulatory framework establishes requirements covering consent, data subject rights, security, international transfers, accountability, and other aspects of personal data processing.
Ecuador’s LOPDP requires organisations to identify an appropriate lawful basis before processing personal data. Where consent is used, it must be free, specific, informed, and unequivocal. Certain categories of sensitive personal data are subject to enhanced requirements.
The framework also gives individuals rights over their personal data and establishes obligations relating to security, transparency, international transfers, data protection impact assessments, and compliance governance.
Ecuador
Enacted in 2021
The LOPDP was enacted in 2021, with its implementing General Regulation issued in 2023. Ecuador’s data protection framework is currently administered and supervised by the Superintendencia de Protección de Datos Personales (SPDP).
Americas
The LOPDP and its Regulation apply to natural and legal persons, public and private entities, and organisations that process personal data within the scope of Ecuador’s framework.
The General Regulation expressly covers national and foreign controllers and processors where their processing activities fall within the applicable territorial scope. It can also apply to organisations processing the personal data of non-residents when the relevant processing takes place in Ecuador.
Organisations should therefore assess:
The LOPDP establishes administrative sanctions for violations of Ecuador’s personal data protection framework.
Penalties vary according to the type and seriousness of the infringement and, for certain organisations, can be calculated by reference to income or turnover.
The applicable sanction depends on the specific violation, the organisation involved, and the circumstances established by the competent authority.
Organisations should therefore treat privacy compliance as an ongoing governance obligation rather than relying only on a privacy policy or consent banner.
Organisations processing personal data in Ecuador should:
Consent is one of the lawful bases available under Ecuador’s LOPDP.
Where consent is used, it must be:
The LOPDP defines consent as a manifestation of free, specific, informed, and unequivocal will through which the data subject authorises the controller to process their personal data.
However, organisations should not assume that consent is required for every processing activity.
The LOPDP recognises multiple lawful bases for processing personal data. Organisations should therefore determine the appropriate legal basis for each processing purpose before implementing their consent strategy.
For websites, this distinction is particularly important when managing analytics, advertising, personalisation, and other tracking technologies.
The LOPDP provides enhanced protection for special categories of personal data.
Organisations processing sensitive information should assess the applicable legal basis and additional requirements before processing begins.
Consent mechanisms should clearly identify relevant sensitive data processing where consent is required and should not bundle sensitive-data consent into unclear or overly broad permissions.
The LOPDP provides individuals with rights concerning their personal data.
These include:
Individuals can request information about their personal data and relevant processing activities.
Individuals can request correction or updating of inaccurate, incomplete, or outdated personal data.
Individuals may request deletion of their personal data where the applicable legal requirements are satisfied.
Individuals can object to certain processing activities where the conditions established by the law apply.
Under applicable conditions, individuals may request their personal data in a structured format and exercise their right to data portability.
The LOPDP also provides additional rights and protections, including rights relating to automated decision-making and the processing of personal data.
Organisations should maintain a documented process for receiving, authenticating, tracking, and responding to these requests.
Organisations should provide individuals with clear and understandable information about how their personal data is processed.
A privacy notice should explain relevant information such as:
Transparency should be maintained throughout the data lifecycle and not limited to the initial collection stage.
The LOPDP requires controllers and processors to implement appropriate security measures for protecting personal data.
The law specifically requires security measures to take into account factors such as the nature of the personal data, the processing context, risks, threats, and vulnerabilities.
Security measures can include:
Organisations should periodically assess whether their safeguards remain appropriate as processing activities and risks change.
The Ecuadorian framework includes data protection impact assessments (DPIAs) for processing activities that may create significant risks to individuals.
A DPIA can help organisations identify:
Organisations carrying out high-risk processing should assess whether a DPIA is required before processing begins.
The Ecuadorian framework establishes requirements concerning the appointment of a Data Protection Officer (DPO) for certain organisations and processing activities.
The DPO function can include responsibilities such as:
Organisations should assess whether their size, activities, data categories, or processing operations trigger a DPO requirement.
The LOPDP framework establishes obligations relating to personal data security breaches.
Organisations should maintain procedures to:
A privacy programme should therefore connect security incident management with data protection compliance.
Ecuador’s framework regulates the transfer and communication of personal data, including international transfers.
The SPDP issued specific 2025 regulations addressing national and international transfers or communications of personal data. The rules require organisations to apply the relevant provisions of the LOPDP and its General Regulation when conducting international data transfers.
Organisations should assess:
International data flows should be documented as part of the organisation’s broader data mapping programme.
Personal data should not be retained indefinitely without an appropriate purpose.
Organisations should establish retention periods based on:
When personal data is no longer required, organisations should apply appropriate deletion, anonymisation, or other legally required measures.
Ecuador’s SPDP has also issued a specific regulation concerning the anonymisation, blocking, suspension, and elimination of personal data, further developing this aspect of the framework.
Cookies, pixels, advertising trackers, analytics tools, and other technologies can involve the processing of personal data.
Organisations operating websites in Ecuador should therefore identify:
Where consent is the applicable lawful basis, ConsentX can help organisations obtain valid consent before applicable tracking technologies are activated.
ConsentX helps organisations operationalise key privacy and consent requirements across websites and digital experiences.
Create consent experiences designed to capture the characteristics required when consent is the applicable legal basis.
Clearly explain the purposes associated with cookies, trackers, analytics, advertising, and other processing activities.
Support separate handling of sensitive categories where enhanced consent or other legal requirements apply.
Scan websites to identify cookies and trackers and prevent applicable non-essential technologies from activating before consent.
Maintain auditable records of users’ consent choices and relevant contextual information.
Support workflows for access, rectification, deletion, opposition, portability, and other applicable privacy requests.
Use ConsentX’s region rule engine to configure consent experiences according to the applicable jurisdiction.
Scan your website → Identify trackers → Map purposes → Configure consent → Block applicable trackers → Record consent → Manage privacy requests
Build a more transparent and auditable privacy experience for users in Ecuador.
Scan your website to identify cookies, trackers, pixels, scripts, and third-party technologies.
Identify why each technology processes personal data and determine the appropriate lawful basis.
Where consent is the applicable legal basis, configure a banner that provides clear information and captures free, specific, informed, and unequivocal consent.
Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.
Maintain consent receipts containing relevant information about the user’s choice and the consent event.
Centralise requests for access, rectification, deletion, opposition, portability, and other applicable rights.
Regularly rescan your website to detect new trackers, scripts, vendors, or changes in processing activities.
This page provides a plain-English summary of Ecuador’s personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Ecuadorian legal counsel where necessary.