Skip to content
World Watch/Ecuador/Data & Privacy

Data & Privacy · Ecuador

Data protection & privacy law in Ecuador (2026)

Comprehensive lawCountry index 79 · B+

Ecuador shaded by its data & privacy status

Data protection in Ecuador: comprehensive law.

FrameworkLey Orgánica de Protección de Datos Personales (LOPDP), Official Gazette Supplement 459, 26 May 2021; supervised by the Superintendencia de Protección de Datos Personales (SPDP, spdp.gob.ec)

Ecuador enacted the LOPDP on 26 May 2021, its first comprehensive, GDPR-aligned personal data protection statute, which entered full legal effect, including its sanctioning regime, on 26 May 2023. The Superintendencia de Protección de Datos Personales (SPDP) is the independent supervisory authority empowered to issue binding resolutions, investigate complaints, and impose financial penalties. Active enforcement is underway, with the SPDP having issued its first significant published sanctions and multiple secondary regulations through early 2026.

Key points

Primary legislation

The LOPDP (Ley Orgánica de Protección de Datos Personales), published in Official Gazette Supplement 459 on 26 May 2021, is Ecuador's first standalone, comprehensive data protection law. A General Implementing Regulation was issued in late 2023 and the law was last updated in April 2026 per the official consolidated text.

Supervisory authority

The Superintendencia de Protección de Datos Personales (SPDP) is the independent control authority created by the LOPDP. It issues binding technical standards and resolutions, handles complaints, conducts audits, and imposes sanctions; its official portal is spdp.gob.ec.

Data subject rights

The LOPDP grants data subjects rights of access, rectification, erasure, restriction of processing, data portability, opposition, and the right not to be subject to solely automated decisions, substantially equivalent to EU GDPR Chapter III rights.

Controller & processor obligations

Controllers must establish a lawful basis for processing (explicit consent required for sensitive data), maintain a Record of Processing Activities (RAT), implement proportionate security measures, notify data breaches, and register a Data Protection Officer (DPO) with the SPDP's digital platform, a deadline that fell on 31 December 2025 for private-sector entities.

Sanctions regime

The sanctioning regime entered into force on 26 May 2023 (the law's two-year transition period). Fines range from 0.1%, 0.7% of annual business volume for minor infractions to 0.7%, 1% for serious infractions. Concrete sanctions already issued include USD 259,644 against LigaPro and USD 194,856 against the Ecuadorian Football Federation (FEF).

International data transfers

In February 2026 the SPDP issued Resolution SPDP-SPD-2026-0004-R establishing General Rules on National and International Personal Data Transfers, creating a binding adequacy/safeguards framework for cross-border data flows analogous to GDPR Chapter V mechanisms.

Timeline - major decisions & events

Jan 1, 2026guidanceofficial
SPDP Issues AI Data-Processing Norm and General Transfers Regulation

The Superintendencia published Resolution SPDP-SPD-2026-0004-R establishing the general norm for cross-border personal data transfers, and Resolution SPDP-SPD-2026-0009-R requiring any organization using AI systems to process Ecuadorian personal data to adopt a risk-based compliance approach under the LOPDP — extending the framework explicitly to automated decision-making.

SPDP — Superintendencia de Protección de Datos Personales
Dec 1, 2025enforcement
First Major LOPDP Sanctions: LigaPro Fined $259 K, FEF Fined $195 K

The SPDP imposed its first significant administrative fines — USD 259,644 on professional football league LigaPro and USD 194,856 on the Ecuadorian Football Federation — for processing spectators' personal data via digital event-registration platforms without valid informed consent, establishing precedent and signalling active enforcement.

Moncayo y Almeida Abogados
Nov 1, 2025guidance
Mandatory DPO Registration Window Opens (Nov 1 – Dec 31, 2025)

Per Resolution SPDP-SPD-2025-0028-R, private-sector entities in designated sectors (financial, insurance, education) were required to formally appoint and register their Data Protection Delegate (Delegado de Protección de Datos) with the SPDP during this 60-day window; failure constitutes a legal-security violation under the LOPDP.

NMS Law Ecuador
Aug 1, 2025guidanceofficial
SPDP Issues Technical Norms on Pseudonymisation, Anonymisation, Blocking and Deletion

Resolution SPDP-SPD-2025-0030-R defined technical standards for data pseudonymisation, anonymisation, blocking, and deletion, providing controllers with concrete operational requirements to satisfy data-minimisation and retention obligations under the LOPDP.

SPDP — Superintendencia de Protección de Datos Personales
Jul 30, 2025guidanceofficial
SPDP Issues Formal Data Protection Officer (DPO) Regulation

Resolution SPDP-SPD-2025-0028-R established the complete regulatory framework for Delegados de Protección de Datos, covering which entities must appoint one, required qualifications, functional independence, duties, and the SPDP registration process — mirroring GDPR Art. 37-39 obligations in the Ecuadorian context.

SPDP — Superintendencia de Protección de Datos Personales
Aug 19, 2024decision
SPDP Issues First Resolution — Regulator Formally Operational

Resolution SPDP-SPDP-2024-0001-R approved the Superintendencia's provisional Organic Statute of Organisational Management, marking the regulator's first formal act and the start of its operational existence — more than three years after the LOPDP created it on paper.

NMS Law Ecuador
Nov 13, 2023lawofficial
Executive Decree 904 — General Regulation to the LOPDP Issued

President Noboa signed Decreto Ejecutivo No. 904, issuing the Reglamento General de la LOPDP. The 14-chapter regulation detailed procedures for exercising data-subject rights (access, rectification, deletion, portability, opposition), breach notification timelines, SPDP procedural rules, and the public data-processing register — operationalising the law's skeleton into enforceable obligations.

COSEDE (hosts official Decreto 904 text)
May 26, 2023lawofficial
LOPDP Enters Full Force — Sanctions Regime Activates

The two-year compliance transition period granted by the LOPDP expired, making all obligations — including administrative fines reaching up to 1% (minor), 2% (serious), or 5% (very serious) of the liable entity's annual turnover — immediately applicable to controllers and processors throughout Ecuador.

Registro Oficial Suplemento 459 — LOPDP (Official text)
Sep 11, 2019incident
Novaestrat Mega-Breach: Records of ~20 Million Ecuadorians Exposed

Researchers at vpnMentor discovered an unsecured Elasticsearch server run by analytics firm Novaestrat, exposing detailed civil-registry, financial, vehicle, and employment records on virtually the entire Ecuadorian population — including ~7 million minors. Authorities arrested Novaestrat's manager; the incident became the direct legislative catalyst for drafting and expediting the LOPDP.

CNN
Sep 28, 2008lawofficial
2008 Constitution Enshrines Autonomous Right to Personal Data Protection and Habeas Data

Ecuador's Constitution of Montecristi, approved by national referendum, embedded an autonomous constitutional right to personal data protection (Art. 66.19) and created the habeas data guarantee (Art. 92), following the European model of data protection as an independent fundamental right. Any person could invoke habeas data before any court to access, correct, or delete their data held by public or private entities — the constitutional foundation on which all subsequent statute law was built.

Dirección Nacional de Registros Públicos (DINARDAP) — official government body

Ecuador - other topics

Data & Privacy in other countries

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →