Skip to content

Evidence request lists

Ley Orgánica de Protección de Datos Personales (LOPDP)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border + Articles 59-65 + Andean Community

LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community
Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm

Ecuador LOPDP Articles 59-65 Cross-Border Data Transfers (Transferencias Internacionales). Transfer of personal data outside Ecuador permitted only where: (1) destination jurisdiction provides adequate level of protection (Article 59 SPDP assessment + adequacy decisions automatic recognition of EU/EEA + UK + Switzerland + Argentina + Canada + Israel + Japan + Korea + Uruguay + New Zealand + Convention 108 parties); (2) appropriate safeguards (Article 60) including SPDP-approved Standard Contractual Clauses (SCCs - Clausulas Contractuales Tipo) + Binding Corporate Rules (BCRs - Reglas Corporativas Vinculantes) for intra-group transfers + SPDP-approved Codes of Conduct + Certification Mechanisms + international agreements; (3) derogations (Article 61) - explicit informed consent + performance of contract + public interest + legal claims + vital interests + register-based + limited transfer

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • Adequacy reliance documentation
  • SCC executed copies
  • SPDP-approved BCRs
  • Transfer Impact Assessment per Schrems II
  • RIPD + Andean Community cooperation evidence
  • Onward transfer documentation
Where this commonly fails
  • Transfer without lawful basis
  • Old SCCs not SPDP-approved
  • No TIA
  • No BCR approval procedure
  • No Andean Community coordination

Enforcement + Sanctions + Articles 66-76 + Habeas Data

LOPDP-EC-Enforcement-Sanctions-Articles-66-76-SPDP-Investigation-Administrative-Fines-Tiered-Penalty-Habeas-Data
Ecuador LOPDP Enforcement + Sanctions + Articles 66-76 + SPDP + Habeas Data

Ecuador LOPDP Articles 66-76 Enforcement and Sanctions. Article 66 SPDP Powers - investigative + corrective + authorisation + advisory powers: (a) Investigations + audits + on-site inspection + access to premises + production of records + interviews + sworn officials; (b) Reprimands + warnings + Article 67 corrective measures including temporary or definitive bans on processing + suspension of cross-border transfers + processing rectification orders; (c) Article 68 Administrative Fines - tiered structure: minor infringements (Infracciones Leves) USD 1-10 monthly basic salary + medium infringements (Infracciones Medianas) USD 10-50 monthly basic salary + serious infringements (Infracciones Graves) USD 50-100 monthly basic salary + maximum 1% to 7% of annual turnover for serious infringements + cumulative + criteria GDPR Article 83 + reduced for SMEs; (d) Article 69 Criminal sanctions - Pe

Artefacts an auditor will ask for
  • SPDP investigation response plan
  • Sanctions exposure register (USD 1-100 MBS + 1-7% turnover)
  • Cooperation with SPDP audit records
  • Habeas Data response procedure
  • Certification or Code of Conduct adoption
  • Administrative Court + Constitutional Court review procedure
  • Penal Code Articles 178-179 awareness
Where this commonly fails
  • No SPDP response plan
  • No sanctions exposure analysis
  • No Habeas Data procedure
  • No certification
  • No constitutional review procedure

Governance + DPO + ROPA + DPIA + Articles 46-58

LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring
Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training

Ecuador LOPDP Articles 46-58 Governance + Accountability. Article 46 Data Protection Officer (DPO - Delegado de Proteccion de Datos) - mandatory designation where: (a) public bodies; (b) core activities consisting of systematic monitoring on large scale; (c) core activities involving processing of sensitive categories on large scale; (d) controllers with 5000+ data subjects records. DPO qualifications + independence + reporting to highest management + sufficient resources + SPDP notification + public DPO contact. Article 47 Records of Processing Activities (ROPA - Registro de Actividades de Tratamiento) - controllers and processors must maintain detailed records including categories + purposes + recipients + Cross-Border transfers + retention + security + provided to SPDP on request. Article 48 Data Protection Impact Assessment (DPIA - Evaluacion de Impacto en la Proteccion de Datos) - m

Artefacts an auditor will ask for
  • DPO designation + SPDP notification
  • ROPA per processing operation
  • DPIA reports for high-risk
  • Privacy by Design embedded in SDLC
  • Annual training records + role-based
  • Prior consultation with SPDP for residual high-risk
  • Codes of Conduct adoption
Where this commonly fails
  • No DPO
  • ROPA incomplete
  • No DPIA for high-risk
  • No PbD in development
  • No annual training
  • No prior consultation

Lawful Basis + Consent + Notice + Articles 7-15

LOPDP-EC-Lawful-Basis-Consent-Notice-Information-Duty-Principles-Article-7-15-Purpose-Limitation-Minimisation
Ecuador LOPDP Lawful Basis + Consent + Notice + Principles + Articles 7-15

Ecuador LOPDP Articles 7-15 Principles and Lawful Basis. Article 7 8 principles: (a) Lawfulness (Juridicidad); (b) Loyalty (Lealtad); (c) Transparency (Transparencia); (d) Purpose Specification (Finalidad); (e) Relevance and Data Minimisation (Pertinencia y Minimizacion); (f) Proportionality (Proporcionalidad); (g) Confidentiality (Confidencialidad); (h) Quality and Accuracy (Calidad y Exactitud); (i) Responsibility (Responsabilidad). Article 8 Lawful Bases: (1) Consent of data subject; (2) Compliance with legal obligation; (3) Performance of contract; (4) Vital interests; (5) Public interest task or exercise of public authority; (6) Legitimate interests of controller. Article 9 Consent (Consentimiento) - explicit + specific + informed + free + unambiguous + revocable + special form for minors via legal guardian + verifiable. Article 10 Withdrawal of Consent - as easily as given. Article

Artefacts an auditor will ask for
  • Lawful basis register
  • Consent records (explicit + verifiable + withdrawable)
  • Spanish privacy notices
  • 8-principle compliance evidence
  • Withdrawal mechanism as easy as giving
  • Direct marketing opt-in evidence
Where this commonly fails
  • Bundled consent
  • Spanish notices missing
  • No 8-principle compliance
  • No withdrawal mechanism
  • Marketing without opt-in

Scope + Asamblea Nacional 2021 + SPDP + Habeas Data

LOPDP-EC-Scope-Application-Asamblea-Nacional-10-May-2021-Effective-26-May-2023-SPDP-Constitution-Article-66-Habeas-Data
Ecuador LOPDP Scope + Asamblea Nacional + 10 May 2021 + Effective 26 May 2023 + SPDP

Ecuador Ley Organica de Proteccion de Datos Personales (LOPDP) approved by Asamblea Nacional 10 May 2021 + published Suplemento Registro Oficial Quinto Suplemento No. 459 of 26 May 2021 + 2-year transition period + fully effective 26 May 2023. Foundational Ecuador comprehensive personal data protection statute. Constitutional anchor Ecuador Constitution Article 66 numerals 19 (right to protection of personal data) + 20 (right to personal and family intimacy) + 21 (inviolability of correspondence) + Article 92 Habeas Data action (constitutional remedy for personal data protection). 76 articles in 7 chapters: Chapter I General Provisions + Chapter II Principles and Subject Rights + Chapter III Legitimacy of Processing and Information Duties + Chapter IV Categories of Personal Data + Chapter V Cross-Border Transfers + Chapter VI Supervisory Authority + Chapter VII Sanctions. Superintendenci

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • SPDP engagement records
  • Spanish privacy notices
  • Constitutional Articles 66 + 92 compliance memo
  • RIPD coordination evidence
  • Andean Community alignment evidence
Where this commonly fails
  • No SPDP engagement
  • Notices not in Spanish
  • No Constitutional compliance review
  • Treating LOPDP same as GDPR without Ecuador provisions

Security + Processor + Breach + Articles 37-45

LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT
Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

Ecuador LOPDP Articles 37-45 Security + Processor + Breach Notification. Article 37 Security of Processing (Seguridad del Tratamiento) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + nature of data + state-of-the-art + including: (a) pseudonymisation + encryption (at rest AES-256 + in transit TLS 1.3 minimum); (b) confidentiality + integrity + availability + resilience of systems; (c) timely restoration of availability and access after incident; (d) regular testing + assessment + evaluation. Article 38 Documented Security Measures. Article 39 Processor Agreements - written contract specifying categories + purposes + duration + obligations including: process only on documented instructions + confidentiality + security + sub-processing prior authorisation + Data Subject Rights support + breach notification + return or de

Artefacts an auditor will ask for
  • Encryption + pseudonymisation evidence
  • Processor contracts (Article 39 compliant)
  • SPDP breach notification log + 72-hour evidence
  • Data subject breach notification when high-risk
  • EcuCERT + CECIBER coordination records
  • Incident response playbook
  • Tabletop exercise records
Where this commonly fails
  • No encryption
  • No processor contracts
  • Late SPDP notification
  • No data subject breach notification
  • No EcuCERT liaison
  • No tabletop exercises

Sensitive Data + Children + Articles 28-32

LOPDP-EC-Sensitive-Personal-Data-Children-Adolescents-Healthcare-Articles-28-32-Codigo-Ninez-Adolescencia
Ecuador LOPDP Sensitive Data + Children + Adolescents + Articles 28-32

Ecuador LOPDP Articles 28-32 Sensitive Personal Data and Children Special Categories. Article 28 Sensitive Personal Data (Datos Personales Sensibles) categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + genetic data + biometric data + health data + sexual life + sexual orientation + criminal record + administrative sanctions + immigration status. Article 29 Sensitive Data processing prohibited except: (1) explicit informed written consent of data subject; (2) vital interest of data subject incapable of consenting; (3) compelling public interest authorised by specific law; (4) processing by non-profit body for members; (5) data manifestly made public by data subject; (6) legal claims; (7) substantial public interest authorised by Asamblea Nacional law; (8) preventive or occupational medicine + medical diagn

Artefacts an auditor will ask for
  • Sensitive data inventory + Article 28 categories
  • Explicit consent records for sensitive
  • Children parental consent + age verification (under 15)
  • Codigo de la Ninez y Adolescencia coordination
  • CNNA + UNICEF coordination evidence
  • Healthcare data Codigo de la Salud compliance
  • Professional secrecy attestations
Where this commonly fails
  • Sensitive without explicit consent
  • Children without parental consent
  • No CNNA coordination
  • Healthcare without Codigo de la Salud alignment
  • No best interests of child analysis

Subject Rights + Access + Rectification + Articles 16-27

LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27
Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27

Ecuador LOPDP Articles 16-27 Data Subject Rights (Derechos del Titular - LatAm ARCO tradition adapted to GDPR alignment). Article 16 Right of Information + Right of Access (Derecho de Informacion + Derecho de Acceso) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + retention + free first request + reasonable subsequent fee + 15-day response standard (faster than typical 30-day). Article 17 Right of Rectification (Derecho de Rectificacion) - to correct inaccurate + incomplete + outdated data + 15-day response + propagation to recipients. Article 18 Right of Erasure (Derecho de Eliminacion / Derecho al Olvido) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing. Article 19 Right to Object (Derecho de Oposicion) - to processing on legitimate grounds + absolute right to object to direct marketing. Ar

Artefacts an auditor will ask for
  • Rights request handling SLAs (15-day) + log
  • Spanish response templates
  • Portability format documentation
  • Habeas Data procedural response
  • Administrative Court review path
  • Identity verification policy
Where this commonly fails
  • Slow rights response (>15 days)
  • No Habeas Data procedure
  • No portability format
  • No automated-decision opt-out
  • No appeals path
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.