International transfers are allowed to countries, organisations and legal persons the Authority has declared adequate by reasoned resolution (reviewed annually, published in the Registro Oficial, with general effect so no prior authorisation is needed), judged on their data protection, security and criminal legislation (especially authorities' access to data), onward transfer rules, case law, rights and remedies, controller duties, an independent authority and international commitments. Otherwise the controller or processor must offer appropriate safeguards ensuring principles, rights and obligations at least equal to Ecuador's, effective administrative or judicial remedies and full reparation, in a binding legal instrument: binding instruments between public bodies, approved binding corporate rules, standard clauses of international data protection bodies endorsed by the Authority, codes of conduct or certification mechanisms with binding commitments, or contractual clauses authorised by the Authority. Without adequacy or safeguards, transfers may still take place for institutional competences, with the explicit consent of a data subject informed of the risks, for legal or regulatory obligations, contracts or pre-contractual steps at the data subject's request, public interest, international judicial cooperation or cooperation in investigating offences, commitments between States, banking and stock-market operations, legal claims, or vital interests of a person unable to consent.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.