Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) 37: Art. 37: security of personal data, continuously verified

Controllers and processors must apply the security principle taking into account the categories and volume of data, the state of the art, integrated security good practice and costs according to the nature, scope, context and purposes, and identify the likelihood of risks; implement a continuous process for verifying, assessing and valuing the efficiency, efficacy and effectiveness of their technical, organisational and other measures; and show that the measures adequately mitigate the risks identified. Measures may include anonymisation, pseudonymisation or encryption; measures keeping systems and services permanently confidential, intact and available and restoring access quickly after incidents; measures improving technical, physical, administrative and legal resilience; and adherence to international risk-management and information security standards or codes of conduct authorised by the Authority.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.