Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
Arts. 33 to 36: communication to third parties and processors – Ley Orgánica de Protección de Datos Personales (LOPDP)

Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) 34: Arts. 34 and 35 and RGLOPDP Arts. 40 to 47: processors and service providers

Access by a processor or other third party to provide a service to the controller is not a communication, but must be governed by a contract stating that the data are processed only on the controller's instructions, not used for other purposes and not transferred or communicated to others even for storage; when the service ends the data are destroyed or returned under the Authority's supervision, and the processor or third party answers for its own breaches. The Reglamento requires processors to offer sufficient guarantees; a written contract setting out the object, duration, nature, purpose, data categories, data subjects and the processor's obligations; measures comparable to the controller's in place before service starts; assistance to the controller with data subjects' rights; notice to the controller without undue delay of instructions it considers unlawful; subcontracting only where the contract allows it or with the controller's written authorisation, the subcontractor assuming the processor's obligations; return or deletion of all data and copies at the end unless the law requires retention; a record of processing activities where the controller must keep one; and review of its records and processes by the controller on request. A processor that determines purposes and means becomes a controller.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Arts. 33 to 36: communication to third parties and processors – Ley Orgánica de Protección de Datos Personales (LOPDP)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.