Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) 42: Art. 42 and RGLOPDP Arts. 29 to 32: data protection impact assessment

The controller must carry out an impact assessment, before processing starts, where processing is likely to present a high risk to data subjects' rights and freedoms or the Authority requires it, and always for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal effects are based; large-scale processing of special categories or of criminal convictions and offences data; and large-scale systematic monitoring of a publicly accessible area; the Authority may add further cases. The Reglamento defines the assessment as a preventive technical analysis identifying and mitigating risks; mandatory assessments are submitted to the Authority and contain at least a systematic description of the operations and purposes, the necessity and proportionality justification, the assessment of risks to rights and freedoms, and the measures, safeguards and security mechanisms planned, without confidential security details; in case of doubt the controller may consult the Authority, which answers within 5 days.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.