LOPDP, comprehensive personal-data protection regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 26 May 2021.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies.
- Do not make a decision based solely or partly on automated processing, including profiling, that produces legal or similarly significant effects for a data subject, and give heightened protection where the data subject is a child or adolescent.
- Notify the Authority and the telecommunications regulator of a personal-data security breach as soon as possible and no later than five days after becoming aware of it.
- Before transferring personal data outside Ecuador, obtain an Authority adequacy resolution, put appropriate safeguards in place, or obtain the Authority's case-by-case authorization.
If you get it wrong
Private right of actionNo
Penalty structure
For a private-law entity, or a public enterprise, found to have committed a grave infraction: a fine of between 0.7% and 1% of business turnover for the immediately preceding fiscal year. A public servant whose act or omission caused the infraction is instead fined 10 to 20 unified basic salaries (salarios básicos unificados).
- Rule
- Turnover pct only
- As of
- 5 September 2026
- Turnover percentage cap
- 1
Who enforces it
Enforcement body
Superintendencia (Autoridad) de Protección de Datos Personales
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 guarantees the right to protection of personal data, including access to and decision over one's own data, and article 2 applies the Act to the processing of personal data in any medium, automated or not, by any public or private controller or processor, with narrow exclusions for purely personal or household use and for the personal data of deceased persons.
Article 25 lists sensitive data, children's and adolescents' data, health data, and disability data as special categories, and article 26 prohibits processing sensitive data absent the data subject's explicit consent or another enumerated ground.
Article 20 gives every data subject the right not to be the object of a decision based solely or partly on automated processing, including profiling, that produces legal or similarly significant effects, unless a narrow exception applies, and article 21 extends heightened protection to children's and adolescents' data in that same context.
Article 43 requires a controller to notify a personal-data security breach to the Authority and to the telecommunications regulator as soon as possible and no later than five days after becoming aware of it, and a processor must notify the controller within two days. International transfers require an Authority adequacy resolution, appropriate safeguards meeting a stated standard, or, for other cases, the Authority's prior authorization.
The Authority, the Autoridad de Protección de Datos Personales headed by the Superintendente de Protección de Datos, may impose corrective measures and, for private-law entities and public enterprises, administrative fines of between 0.7% and 1% of the prior fiscal year's business turnover for grave infractions; the corrective-measures and sanctions regime, unlike the rest of the Act, did not begin to apply until two years after the Act's publication in the Official Registry.
When LexLint raises it
automated_outreachhigh_risk_decisionsprocesses_biometrics