Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) 43: Art. 43 and RGLOPDP Arts. 24 to 27: breach notification to the Authority and the telecommunications regulator within 5 days

The controller must notify a security breach to the Personal Data Protection Authority and the Agencia de Regulacion y Control de las Telecomunicaciones as soon as possible and at the latest within 5 working days (termino) of becoming aware of it, unless it is unlikely to create a risk to people's rights and freedoms; a later notification must give the reasons for the delay. The processor must notify the controller as soon as possible and within 2 working days. The Reglamento treats a breach as risky where data are destroyed or unusable, altered, corrupted or incomplete, out of the controller's control or possession, or processed without authorisation or unlawfully (including disclosure or access by unauthorised recipients); the notification states the nature and type of breach, the affected data subjects, the systems affected, the presumed cause, the volume and types of data, the measures taken and planned, the risk assessment and anything else the Authority requires (the processor's notice omits the risk assessment).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.