Law / Ecuador

Ecuador

10 of 16 named instruments researched to a stage, across four of the six areas of law we track: 8 in force, 1 enacted but not yet in force and 1 proposed. As of 5 September 2026.

When they take effect8 of 10 carry a date, 2 do not.
2014: 4 instruments (4 in force) ’14 2015: 0 instruments 2016: 3 instruments (3 in force) 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 2
  3. Scraping law 6
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (158 words)

No AI-transparency, AI-risk-obligations, AI-training-data, AI-prohibited-practices, AI-governance, or AI-sector-rules statute is in force in Ecuador. A national-level organic AI bill (Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial, Trámite No. 450889) was presented in the National Assembly on 20 June 2024 and qualified for processing by the Consejo de Administración Legislativa on 26 July 2024; it had not passed either chamber as of 5 September 2026.

The Ministerio de Telecomunicaciones y de la Sociedad de la Información has separately adopted a non-binding national AI strategy (Acuerdo Ministerial MINTEL-MINTEL-2025-0030, 19 January 2026) and announced, on 24 March 2026, a voluntary regulatory sandbox for AI testing; neither creates an enforceable obligation on a private party.

Ecuador's data-protection authority has separately extended personal-data-protection rights and duties specifically to AI systems that process personal data; because that duty attaches to the data rather than to the AI system as such, it is a privacy finding, not an AI-topic one.

AI risk obligations

Unified Organic AI Bill (Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial)

Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial en Ecuador (Trámite No. 450889, As. Patricia Núñez) presentado 20 de junio de 2024Official Asamblea Nacional del Ecuador legislative-bill record

Proposed: draft date not recorded.

What this law does

Proposed; not yet in force, so it currently binds no one. This bill, presented in the National Assembly on 20 June 2024, was qualified for processing by the Consejo de Administración Legislativa (CAL) on 26 July 2024, following the Unidad Técnica Legislativa's report of 15 July 2024. The Assembly's own record shows only the bill's presentation and qualification as of 5 September 2026; it has not passed a first or second debate.

What it requires

Privacy law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (119 words)

Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP), in force since its publication in the Fifth Supplement of Registro Oficial No. 459 of 26 May 2021, is a comprehensive, General Data Protection Regulation (GDPR)-modeled regime binding any public or private processor of personal data, enforced by the Superintendente de Protección de Datos heading the Autoridad de Protección de Datos Personales (SPDP); its corrective-measures and sanctions regime did not begin to apply until two years after publication.

The SPDP has since issued a binding resolution, in force since 12 February 2026, extending the LOPDP's automated-decision, information and opposition rights specifically to personal data processed through artificial-intelligence systems and imposing risk-management, impact-assessment and audit duties on any developer or deployer of such a system.

Comprehensive regime

LOPDP, comprehensive personal-data protection regime

Ley Orgánica de Protección de Datos Personales (LOPDP), Quinto Suplemento del Registro Oficial No. 459, 26 de mayo de 2021Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 1 guarantees the right to protection of personal data, including access to and decision over one's own data, and article 2 applies the Act to the processing of personal data in any medium, automated or not, by any public or private controller or processor, with narrow exclusions for purely personal or household use and for the personal data of deceased persons.

Article 25 lists sensitive data, children's and adolescents' data, health data, and disability data as special categories, and article 26 prohibits processing sensitive data absent the data subject's explicit consent or another enumerated ground.

Article 20 gives every data subject the right not to be the object of a decision based solely or partly on automated processing, including profiling, that produces legal or similarly significant effects, unless a narrow exception applies, and article 21 extends heightened protection to children's and adolescents' data in that same context.

Article 43 requires a controller to notify a personal-data security breach to the Authority and to the telecommunications regulator as soon as possible and no later than five days after becoming aware of it, and a processor must notify the controller within two days. International transfers require an Authority adequacy resolution, appropriate safeguards meeting a stated standard, or, for other cases, the Authority's prior authorization.

The Authority, the Autoridad de Protección de Datos Personales headed by the Superintendente de Protección de Datos, may impose corrective measures and, for private-law entities and public enterprises, administrative fines of between 0.7% and 1% of the prior fiscal year's business turnover for grave infractions; the corrective-measures and sanctions regime, unlike the rest of the Act, did not begin to apply until two years after the Act's publication in the Official Registry.

What it requires

Data subject rights

SPDP Norma General guaranteeing personal-data protection in the use of AI systems

Resolución No. SPDP-SPD-2026-0009-R, Superintendencia de Protección de Datos Personales, 12 de febrero de 2026Official text of Resolución No. SPDP-SPD-2026-0009-R

Commencement not set. Binds public and private bodies.

What this law does

This resolution binds any controller or processor that develops, trains, implements, deploys, or provides an artificial-intelligence system that processes personal data, whenever that system falls within the LOPDP's material and territorial scope. Article 4 guarantees, at all times, the data subject's right not to be the object of a decision based solely or partly on automated valuations, together with the right to information and the right to object.

Article 5 requires the controller or processor to inform the data subject clearly and specifically about the AI-based processing, and article 6 requires a prior risk-management process and impact assessment before developing an AI system that will process personal data. The resolution states that it takes effect upon its publication in the Registro Oficial; the signed text itself does not independently confirm that publication has occurred.

What it requires

Scraping law6 instruments, 6 in force

Research summary (261 words)

Ecuador has no scraping-specific statute, so general law governs each dimension separately.

The Código Orgánico Integral Penal (COIP), in force since 10 February 2014, criminalises unconsented access to, and interception of and attacks on, a computer or telematic system, but each offence turns on defeating an access control, intercepting without judicial order, or damaging a system, so reading a public, unauthenticated page does not fit a plain reading of any of them, and no reported case located tests the point.

No Ecuadorian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), in force since 9 December 2016, ties any use of a protected work to a closed list of acts that do not require authorization, tested against a four-factor fair-use-style standard, and that list includes text mining, but only as one purpose a library, archive, or museum may reproduce a work in its collection for, not a general-purpose text-and-data-mining exception.

The same Code gives a compilation-style protection to a database's original selection or arrangement, not to the underlying data, and does not extend that protection to software. The LOPDP applies its full lawful-basis and purpose-limitation regime to personal data drawn from a publicly accessible source; it supplies only a lawful-processing ground for that data, not a carve-out from the Act's other duties.

No Ecuadorian statute or case law located establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigns legal weight to a robots.txt directive or an AI-training-specific rule.

Computer misuse

COIP, acceso no consentido a un sistema informático

Código Orgánico Integral Penal (COIP), art. 234 (acceso no consentido a un sistema informático)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 234 punishes, with three to five years' imprisonment, a person who, without authorization, accesses all or part of a computer, telematic, or telecommunications system, or remains inside it against the will of the person with the legitimate right, in order to unlawfully exploit the access obtained, modify a web portal, divert or redirect data or voice traffic, or offer the services those systems provide to third parties without paying the legitimate service providers.

Because the offence's trigger is unauthorized access exploited for one of those listed purposes, reading a public, unauthenticated page without defeating an access control and without one of the listed purposes falls outside a plain reading of the provision.

What it requires

COIP, ataque a la integridad de sistemas informáticos

Código Orgánico Integral Penal (COIP), art. 232 (ataque a la integridad de sistemas informáticos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 232 punishes, with three to five years' imprisonment, a person who destroys, damages, deletes, deteriorates, alters, suspends, obstructs, causes malfunction or unwanted behaviour of, or suppresses computer data, e-mail messages, or an information, telematic, or telecommunications processing system or its logical components.

The same penalty reaches designing, developing, programming, acquiring, sending, introducing, executing, selling, or distributing malicious software or programs meant to cause those effects, and destroying or altering, without authorization, the technological infrastructure needed to transmit, receive, or process information. The penalty rises to five to seven years where the target is infrastructure for a public service or linked to public safety.

What it requires

COIP, interceptación ilegal de datos

Código Orgánico Integral Penal (COIP), art. 230 (interceptación ilegal de datos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 230(1) punishes, with three to five years' imprisonment, a person who, without prior judicial order and for their own benefit or a third party's, intercepts, listens to, diverts, records, or observes, in any form, a computer datum at its origin, destination, or inside a computer system, or a signal or data transmission, with the aim of obtaining registered or available information.

Reading a public, unauthenticated page does not fit a plain reading of an offence built around a judicial-order requirement and an interception of a transmission.

What it requires

COIP, revelación ilegal de base de datos

Código Orgánico Integral Penal (COIP), art. 229 (revelación ilegal de base de datos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 229 punishes, with one to three years' imprisonment, a person who, for their own benefit or a third party's, reveals information registered or contained in files, archives, databases, or similar media, through or directed at an electronic, computer, telematic, or telecommunications system, deliberately and intentionally breaching the secrecy, privacy, and intimacy of persons.

The penalty rises to three to five years where a public servant, or a bank or savings-and-credit-cooperative employee carrying out financial intermediation, or a contractor commits the same act.

What it requires

Copyright and text and data mining (TDM)

Código Ingenios, uso justo y minería de textos

Arts. 211-212 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), uso justo y actos que no requieren autorizaciónOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 211 states that using or exploiting a protected work or performance in the cases the next article lists is not a violation of patrimonial rights, provided it does not conflict with the work's normal exploitation and does not cause unjustified prejudice to the rights holder's legitimate interests, tested against a four-factor standard (the purpose and nature of the use, the nature of the work, the amount used relative to the whole, and the effect on the work's market value).

Article 212 then lists the acts that do not require authorization, including brief quotation for analysis, comment, or criticism with attribution, and, at item 9, an enumerated set of purposes for which a library, archive, or museum may reproduce a single copy of a work already in its collection, the eighth of which is text mining.

The exception is therefore not a general-purpose text-and-data-mining allowance: it is available only to a library, archive, or museum reproducing a work already in its own collection, not to a commercial or research entity scraping or mining text from the open web at large.

What it requires

Database right

Código Ingenios, protección de bases de datos

Art. 140 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), materia protegible por las bases de datosOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 140 protects a compilation of data or other material, in any form, as such, only where the originality of the selection or arrangement of its contents constitutes an intellectual creation; that protection does not extend to the underlying data or information compiled, and does not affect any copyright or related right subsisting in the works or performances the compilation contains. The article also states that the protection it recognizes for databases does not apply to software.

Ecuador therefore has no sui generis database right of the European kind, protecting a producer's investment in obtaining, verifying, or presenting the contents regardless of originality; only a compilation-copyright model tied to originality of selection or arrangement.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (180 words)

Ecuador has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), in force since 9 December 2016, article 212(1) of which treats a periodic compilation made in the form of a press review or press digest as a form of quotation, exempt from the rights holder's authorization, provided the underlying work has already been disclosed, the use is for citation, analysis, comment, or criticism, with teaching or research purposes, and the source and author are credited.

Whether that exception reaches a systematic online news aggregator's reproduction of headlines and snippets, as opposed to a traditional press review, has not been tested in a located Ecuadorian decision, and the Code predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Código Ingenios, reseñas y revista de prensa como forma de cita

Art. 212 numeral 1 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), reseñas y revista de prensa como citaOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 212(1) permits, without the rights holder's authorization, including brief fragments of an already-disclosed written, sound, audiovisual, artistic, photographic, or figurative work in one's own work, provided the inclusion is by way of quotation or for analysis, comment, or critical judgment, with teaching or research purposes, to the extent justified by that purpose, and provided the source and author's name are indicated and the use is not a disguised exploitation of the work.

The same provision states that periodic compilations made in the form of press reviews or a press digest are considered quotations for this purpose. That treatment is not capped at a headline-length or short-extract threshold in the article's text, and article 211 additionally requires that the use not conflict with the work's normal exploitation and not cause unjustified prejudice to the rights holder, tested against a four-factor standard.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.