DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Ecuador

LOPDP

Organic Law on Protection of Personal Data

Ecuador’s Organic Law on Protection of Personal Data (Ley Orgánica de Protección de Datos Personales or LOPDP) establishes the country’s framework for protecting personal data and regulating its processing by public and private organisations.

The LOPDP was enacted in 2021 and is supplemented by the General Regulation to the LOPDP, issued through Executive Decree No. 904 and published on 13 November 2023. The regulatory framework establishes requirements covering consent, data subject rights, security, international transfers, accountability, and other aspects of personal data processing.

Ecuador’s LOPDP requires organisations to identify an appropriate lawful basis before processing personal data. Where consent is used, it must be free, specific, informed, and unequivocal. Certain categories of sensitive personal data are subject to enhanced requirements.

The framework also gives individuals rights over their personal data and establishes obligations relating to security, transparency, international transfers, data protection impact assessments, and compliance governance.

ภูมิภาค

Ecuador

สถานะ

Enacted in 2021

The LOPDP was enacted in 2021, with its implementing General Regulation issued in 2023. Ecuador’s data protection framework is currently administered and supervised by the Superintendencia de Protección de Datos Personales (SPDP).

กลุ่ม

ทวีปอเมริกา

Who must comply with the LOPDP?

The LOPDP and its Regulation apply to natural and legal persons, public and private entities, and organisations that process personal data within the scope of Ecuador’s framework.

The General Regulation expressly covers national and foreign controllers and processors where their processing activities fall within the applicable territorial scope. It can also apply to organisations processing the personal data of non-residents when the relevant processing takes place in Ecuador.

Organisations should therefore assess:

  • Where their processing takes place
  • Where the relevant individuals are located
  • Whether they act as a controller or processor
  • Whether they offer goods or services involving individuals in Ecuador
  • Whether they monitor or otherwise process personal data within Ecuador
  • Whether an Ecuadorian representative is required

Penalties under the LOPDP

The LOPDP establishes administrative sanctions for violations of Ecuador’s personal data protection framework.

Penalties vary according to the type and seriousness of the infringement and, for certain organisations, can be calculated by reference to income or turnover.

The applicable sanction depends on the specific violation, the organisation involved, and the circumstances established by the competent authority.

Organisations should therefore treat privacy compliance as an ongoing governance obligation rather than relying only on a privacy policy or consent banner.

Key obligations under the LOPDP

Organisations processing personal data in Ecuador should:

  • Identify an appropriate lawful basis for each processing purpose.
  • Obtain valid consent where consent is the applicable legal basis.
  • Ensure consent is free, specific, informed, and unequivocal.
  • Apply additional requirements when processing sensitive personal data.
  • Provide transparent information about processing activities.
  • Respect data subject rights.
  • Implement appropriate technical and organisational security measures.
  • Maintain appropriate documentation and evidence of compliance.
  • Conduct data protection impact assessments where required.
  • Manage international transfers in accordance with applicable requirements.
  • Notify qualifying personal data security incidents.
  • Appoint a Data Protection Officer where required.
  • Maintain appropriate procedures for responding to data subject requests.

Lawful basis and consent requirements

Consent is one of the lawful bases available under Ecuador’s LOPDP.

Where consent is used, it must be:

  • Free
  • Specific
  • Informed
  • Unequivocal

The LOPDP defines consent as a manifestation of free, specific, informed, and unequivocal will through which the data subject authorises the controller to process their personal data.

However, organisations should not assume that consent is required for every processing activity.

The LOPDP recognises multiple lawful bases for processing personal data. Organisations should therefore determine the appropriate legal basis for each processing purpose before implementing their consent strategy.

For websites, this distinction is particularly important when managing analytics, advertising, personalisation, and other tracking technologies.

Sensitive personal data

The LOPDP provides enhanced protection for special categories of personal data.

Organisations processing sensitive information should assess the applicable legal basis and additional requirements before processing begins.

Consent mechanisms should clearly identify relevant sensitive data processing where consent is required and should not bundle sensitive-data consent into unclear or overly broad permissions.

Data subject rights

The LOPDP provides individuals with rights concerning their personal data.

These include:

Right of access

Individuals can request information about their personal data and relevant processing activities.

Right of rectification and updating

Individuals can request correction or updating of inaccurate, incomplete, or outdated personal data.

Right of deletion

Individuals may request deletion of their personal data where the applicable legal requirements are satisfied.

Right of opposition

Individuals can object to certain processing activities where the conditions established by the law apply.

Right to portability

Under applicable conditions, individuals may request their personal data in a structured format and exercise their right to data portability.

Other rights

The LOPDP also provides additional rights and protections, including rights relating to automated decision-making and the processing of personal data.

Organisations should maintain a documented process for receiving, authenticating, tracking, and responding to these requests.

Privacy notices and transparency

Organisations should provide individuals with clear and understandable information about how their personal data is processed.

A privacy notice should explain relevant information such as:

  • Identity of the controller
  • Categories of personal data collected
  • Purposes of processing
  • Applicable legal basis
  • Recipients or categories of recipients
  • International transfers, where applicable
  • Data retention information
  • Data subject rights
  • How individuals can exercise their rights
  • Contact information for privacy-related requests

Transparency should be maintained throughout the data lifecycle and not limited to the initial collection stage.

Data security

The LOPDP requires controllers and processors to implement appropriate security measures for protecting personal data.

The law specifically requires security measures to take into account factors such as the nature of the personal data, the processing context, risks, threats, and vulnerabilities.

Security measures can include:

  • Technical safeguards
  • Organisational controls
  • Access management
  • Encryption where appropriate
  • Monitoring
  • Data minimisation
  • Incident response
  • Business continuity measures
  • Employee awareness and training

Organisations should periodically assess whether their safeguards remain appropriate as processing activities and risks change.

Data protection impact assessments

The Ecuadorian framework includes data protection impact assessments (DPIAs) for processing activities that may create significant risks to individuals.

A DPIA can help organisations identify:

  • The nature and purpose of processing
  • Potential risks to individuals
  • Security and privacy controls
  • Necessity and proportionality of processing
  • Measures for reducing identified risks

Organisations carrying out high-risk processing should assess whether a DPIA is required before processing begins.

Data Protection Officer

The Ecuadorian framework establishes requirements concerning the appointment of a Data Protection Officer (DPO) for certain organisations and processing activities.

The DPO function can include responsibilities such as:

  • Advising on data protection obligations
  • Monitoring compliance
  • Supporting DPIAs
  • Cooperating with the supervisory authority
  • Providing guidance on data subject rights
  • Promoting privacy governance within the organisation

Organisations should assess whether their size, activities, data categories, or processing operations trigger a DPO requirement.

Data breach notification

The LOPDP framework establishes obligations relating to personal data security breaches.

Organisations should maintain procedures to:

  1. Detect security incidents.
  2. Assess whether personal data is affected.
  3. Document the incident.
  4. Determine applicable notification requirements.
  5. Notify the competent authority where required.
  6. Communicate with affected individuals where applicable.
  7. Implement corrective measures.

A privacy programme should therefore connect security incident management with data protection compliance.

International data transfers

Ecuador’s framework regulates the transfer and communication of personal data, including international transfers.

The SPDP issued specific 2025 regulations addressing national and international transfers or communications of personal data. The rules require organisations to apply the relevant provisions of the LOPDP and its General Regulation when conducting international data transfers.

Organisations should assess:

  • Where personal data is being transferred
  • Who receives the data
  • The purpose of the transfer
  • The categories of data involved
  • The destination country
  • Applicable safeguards
  • Contractual requirements
  • The legal basis for the transfer

International data flows should be documented as part of the organisation’s broader data mapping programme.

Data retention and deletion

Personal data should not be retained indefinitely without an appropriate purpose.

Organisations should establish retention periods based on:

  • Purpose of processing
  • Applicable legal obligations
  • Contractual requirements
  • Security considerations
  • Data subject rights
  • Regulatory requirements

When personal data is no longer required, organisations should apply appropriate deletion, anonymisation, or other legally required measures.

Ecuador’s SPDP has also issued a specific regulation concerning the anonymisation, blocking, suspension, and elimination of personal data, further developing this aspect of the framework.

Cookies and online tracking

Cookies, pixels, advertising trackers, analytics tools, and other technologies can involve the processing of personal data.

Organisations operating websites in Ecuador should therefore identify:

  • Cookies and trackers deployed
  • Data collected by each technology
  • Processing purposes
  • Third-party recipients
  • International transfers
  • Applicable lawful bases
  • Whether consent is required
  • Whether trackers should be blocked before consent

Where consent is the applicable lawful basis, ConsentX can help organisations obtain valid consent before applicable tracking technologies are activated.

How ConsentX helps with LOPDP compliance

ConsentX helps organisations operationalise key privacy and consent requirements across websites and digital experiences.

Free, specific and informed consent

Create consent experiences designed to capture the characteristics required when consent is the applicable legal basis.

Purpose-based consent

Clearly explain the purposes associated with cookies, trackers, analytics, advertising, and other processing activities.

Sensitive-data consent

Support separate handling of sensitive categories where enhanced consent or other legal requirements apply.

Cookie and tracker management

Scan websites to identify cookies and trackers and prevent applicable non-essential technologies from activating before consent.

Consent receipts

Maintain auditable records of users’ consent choices and relevant contextual information.

Data subject request management

Support workflows for access, rectification, deletion, opposition, portability, and other applicable privacy requests.

Regional compliance

Use ConsentX’s region rule engine to configure consent experiences according to the applicable jurisdiction.

Get LOPDP ready with ConsentX

Scan your website → Identify trackers → Map purposes → Configure consent → Block applicable trackers → Record consent → Manage privacy requests

Build a more transparent and auditable privacy experience for users in Ecuador.

วิธีปฏิบัติตาม LOPDP ด้วย ConsentX

  1. 1

    Scan your website

    Scan your website to identify cookies, trackers, pixels, scripts, and third-party technologies.

  2. 2

    Map processing purposes

    Identify why each technology processes personal data and determine the appropriate lawful basis.

  3. 3

    Configure an Ecuador-ready consent banner

    Where consent is the applicable legal basis, configure a banner that provides clear information and captures free, specific, informed, and unequivocal consent.

  4. 4

    Block applicable trackers before consent

    Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.

  5. 5

    Record consent evidence

    Maintain consent receipts containing relevant information about the user’s choice and the consent event.

  6. 6

    Manage data subject requests

    Centralise requests for access, rectification, deletion, opposition, portability, and other applicable rights.

  7. 7

    Monitor your website

    Regularly rescan your website to detect new trackers, scripts, vendors, or changes in processing activities.

คำถามที่พบบ่อย

Country under LOPDP

Legal disclaimer

This page provides a plain-English summary of Ecuador’s personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Ecuadorian legal counsel where necessary.