Ley Orgánica de Protección de Datos Personales (LOPDP)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + Articles 59-65 + Andean Community
Ecuador LOPDP Articles 59-65 Cross-Border Data Transfers (Transferencias Internacionales). Transfer of personal data outside Ecuador permitted only where: (1) destination jurisdiction provides adequate level of protection (Article 59 SPDP assessment + adequacy decisions automatic recognition of EU/EEA + UK + Switzerland + Argentina + Canada + Israel + Japan + Korea + Uruguay + New Zealand + Convention 108 parties); (2) appropriate safeguards (Article 60) including SPDP-approved Standard Contractual Clauses (SCCs - Clausulas Contractuales Tipo) + Binding Corporate Rules (BCRs - Reglas Corporativas Vinculantes) for intra-group transfers + SPDP-approved Codes of Conduct + Certification Mechanisms + international agreements; (3) derogations (Article 61) - explicit informed consent + performance of contract + public interest + legal claims + vital interests + register-based + limited transfer
- Cross-border transfer inventory
- Adequacy reliance documentation
- SCC executed copies
- SPDP-approved BCRs
- Transfer Impact Assessment per Schrems II
- RIPD + Andean Community cooperation evidence
- Onward transfer documentation
- Transfer without lawful basis
- Old SCCs not SPDP-approved
- No TIA
- No BCR approval procedure
- No Andean Community coordination
Enforcement + Sanctions + Articles 66-76 + Habeas Data
Ecuador LOPDP Articles 66-76 Enforcement and Sanctions. Article 66 SPDP Powers - investigative + corrective + authorisation + advisory powers: (a) Investigations + audits + on-site inspection + access to premises + production of records + interviews + sworn officials; (b) Reprimands + warnings + Article 67 corrective measures including temporary or definitive bans on processing + suspension of cross-border transfers + processing rectification orders; (c) Article 68 Administrative Fines - tiered structure: minor infringements (Infracciones Leves) USD 1-10 monthly basic salary + medium infringements (Infracciones Medianas) USD 10-50 monthly basic salary + serious infringements (Infracciones Graves) USD 50-100 monthly basic salary + maximum 1% to 7% of annual turnover for serious infringements + cumulative + criteria GDPR Article 83 + reduced for SMEs; (d) Article 69 Criminal sanctions - Pe
- SPDP investigation response plan
- Sanctions exposure register (USD 1-100 MBS + 1-7% turnover)
- Cooperation with SPDP audit records
- Habeas Data response procedure
- Certification or Code of Conduct adoption
- Administrative Court + Constitutional Court review procedure
- Penal Code Articles 178-179 awareness
- No SPDP response plan
- No sanctions exposure analysis
- No Habeas Data procedure
- No certification
- No constitutional review procedure
Governance + DPO + ROPA + DPIA + Articles 46-58
Ecuador LOPDP Articles 46-58 Governance + Accountability. Article 46 Data Protection Officer (DPO - Delegado de Proteccion de Datos) - mandatory designation where: (a) public bodies; (b) core activities consisting of systematic monitoring on large scale; (c) core activities involving processing of sensitive categories on large scale; (d) controllers with 5000+ data subjects records. DPO qualifications + independence + reporting to highest management + sufficient resources + SPDP notification + public DPO contact. Article 47 Records of Processing Activities (ROPA - Registro de Actividades de Tratamiento) - controllers and processors must maintain detailed records including categories + purposes + recipients + Cross-Border transfers + retention + security + provided to SPDP on request. Article 48 Data Protection Impact Assessment (DPIA - Evaluacion de Impacto en la Proteccion de Datos) - m
- DPO designation + SPDP notification
- ROPA per processing operation
- DPIA reports for high-risk
- Privacy by Design embedded in SDLC
- Annual training records + role-based
- Prior consultation with SPDP for residual high-risk
- Codes of Conduct adoption
- No DPO
- ROPA incomplete
- No DPIA for high-risk
- No PbD in development
- No annual training
- No prior consultation
Lawful Basis + Consent + Notice + Articles 7-15
Ecuador LOPDP Articles 7-15 Principles and Lawful Basis. Article 7 8 principles: (a) Lawfulness (Juridicidad); (b) Loyalty (Lealtad); (c) Transparency (Transparencia); (d) Purpose Specification (Finalidad); (e) Relevance and Data Minimisation (Pertinencia y Minimizacion); (f) Proportionality (Proporcionalidad); (g) Confidentiality (Confidencialidad); (h) Quality and Accuracy (Calidad y Exactitud); (i) Responsibility (Responsabilidad). Article 8 Lawful Bases: (1) Consent of data subject; (2) Compliance with legal obligation; (3) Performance of contract; (4) Vital interests; (5) Public interest task or exercise of public authority; (6) Legitimate interests of controller. Article 9 Consent (Consentimiento) - explicit + specific + informed + free + unambiguous + revocable + special form for minors via legal guardian + verifiable. Article 10 Withdrawal of Consent - as easily as given. Article
- Lawful basis register
- Consent records (explicit + verifiable + withdrawable)
- Spanish privacy notices
- 8-principle compliance evidence
- Withdrawal mechanism as easy as giving
- Direct marketing opt-in evidence
- Bundled consent
- Spanish notices missing
- No 8-principle compliance
- No withdrawal mechanism
- Marketing without opt-in
Scope + Asamblea Nacional 2021 + SPDP + Habeas Data
Ecuador Ley Organica de Proteccion de Datos Personales (LOPDP) approved by Asamblea Nacional 10 May 2021 + published Suplemento Registro Oficial Quinto Suplemento No. 459 of 26 May 2021 + 2-year transition period + fully effective 26 May 2023. Foundational Ecuador comprehensive personal data protection statute. Constitutional anchor Ecuador Constitution Article 66 numerals 19 (right to protection of personal data) + 20 (right to personal and family intimacy) + 21 (inviolability of correspondence) + Article 92 Habeas Data action (constitutional remedy for personal data protection). 76 articles in 7 chapters: Chapter I General Provisions + Chapter II Principles and Subject Rights + Chapter III Legitimacy of Processing and Information Duties + Chapter IV Categories of Personal Data + Chapter V Cross-Border Transfers + Chapter VI Supervisory Authority + Chapter VII Sanctions. Superintendenci
- Applicability assessment
- Personal data inventory
- SPDP engagement records
- Spanish privacy notices
- Constitutional Articles 66 + 92 compliance memo
- RIPD coordination evidence
- Andean Community alignment evidence
- No SPDP engagement
- Notices not in Spanish
- No Constitutional compliance review
- Treating LOPDP same as GDPR without Ecuador provisions
Security + Processor + Breach + Articles 37-45
Ecuador LOPDP Articles 37-45 Security + Processor + Breach Notification. Article 37 Security of Processing (Seguridad del Tratamiento) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + nature of data + state-of-the-art + including: (a) pseudonymisation + encryption (at rest AES-256 + in transit TLS 1.3 minimum); (b) confidentiality + integrity + availability + resilience of systems; (c) timely restoration of availability and access after incident; (d) regular testing + assessment + evaluation. Article 38 Documented Security Measures. Article 39 Processor Agreements - written contract specifying categories + purposes + duration + obligations including: process only on documented instructions + confidentiality + security + sub-processing prior authorisation + Data Subject Rights support + breach notification + return or de
- Encryption + pseudonymisation evidence
- Processor contracts (Article 39 compliant)
- SPDP breach notification log + 72-hour evidence
- Data subject breach notification when high-risk
- EcuCERT + CECIBER coordination records
- Incident response playbook
- Tabletop exercise records
- No encryption
- No processor contracts
- Late SPDP notification
- No data subject breach notification
- No EcuCERT liaison
- No tabletop exercises
Sensitive Data + Children + Articles 28-32
Ecuador LOPDP Articles 28-32 Sensitive Personal Data and Children Special Categories. Article 28 Sensitive Personal Data (Datos Personales Sensibles) categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + genetic data + biometric data + health data + sexual life + sexual orientation + criminal record + administrative sanctions + immigration status. Article 29 Sensitive Data processing prohibited except: (1) explicit informed written consent of data subject; (2) vital interest of data subject incapable of consenting; (3) compelling public interest authorised by specific law; (4) processing by non-profit body for members; (5) data manifestly made public by data subject; (6) legal claims; (7) substantial public interest authorised by Asamblea Nacional law; (8) preventive or occupational medicine + medical diagn
- Sensitive data inventory + Article 28 categories
- Explicit consent records for sensitive
- Children parental consent + age verification (under 15)
- Codigo de la Ninez y Adolescencia coordination
- CNNA + UNICEF coordination evidence
- Healthcare data Codigo de la Salud compliance
- Professional secrecy attestations
- Sensitive without explicit consent
- Children without parental consent
- No CNNA coordination
- Healthcare without Codigo de la Salud alignment
- No best interests of child analysis
Subject Rights + Access + Rectification + Articles 16-27
Ecuador LOPDP Articles 16-27 Data Subject Rights (Derechos del Titular - LatAm ARCO tradition adapted to GDPR alignment). Article 16 Right of Information + Right of Access (Derecho de Informacion + Derecho de Acceso) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + retention + free first request + reasonable subsequent fee + 15-day response standard (faster than typical 30-day). Article 17 Right of Rectification (Derecho de Rectificacion) - to correct inaccurate + incomplete + outdated data + 15-day response + propagation to recipients. Article 18 Right of Erasure (Derecho de Eliminacion / Derecho al Olvido) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing. Article 19 Right to Object (Derecho de Oposicion) - to processing on legitimate grounds + absolute right to object to direct marketing. Ar
- Rights request handling SLAs (15-day) + log
- Spanish response templates
- Portability format documentation
- Habeas Data procedural response
- Administrative Court review path
- Identity verification policy
- Slow rights response (>15 days)
- No Habeas Data procedure
- No portability format
- No automated-decision opt-out
- No appeals path
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.