Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
Ecuador's comprehensive personal data protection law (LOPDP, Registro Oficial 459 of 26 May 2021, sanctions from 26 May 2023) with its Reglamento General of 2023 and the Superintendencia's 2025 rules on data protection officers: lawful bases and consent, rights answered within 15 days, children from 15, sensitive, credit and health data, processor contracts, risk-based security and privacy by design, impact assessments, breach notice within 5 working days to the Superintendencia and the telecommunications regulator and 3 to data subjects, records of processing, mandatory officers in listed sectors, registration of databases and transfers, international transfer safeguards, and fines up to 1% of turnover. Built from the law's own text.
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) is a compliance framework from Ecuador with 9 domains and 48 controls that map to 116 other frameworks. The largest domains are Arts. 7 to 10: lawful processing, consent and principles – Ley Orgánica de Protección de Datos Personales (LOPDP) (11 controls), Arts. 12 to 24 and 62: rights of the data subject and their exercise – Ley Orgánica de Protección de Datos Personales (LOPDP) (10 controls), Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP) (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Arts. 1 to 6 and 11: object, scope, definitions and the protection system – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::3 | Art. 3 and RGLOPDP Arts. 2 and 3: territorial scope and the special representative of non-resident controllers |
Arts. 12 to 24 and 62: rights of the data subject and their exercise – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::12 | Art. 12: right to information and its timing |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::13 | Art. 13: right of access within 15 days, free of charge |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::14 | Art. 14: rectification and updating within 15 days, with recipients informed |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::15 | Art. 15: deletion (eliminacion) within 15 days |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::16 | Art. 16: objection, including to direct marketing and profiling, within 15 days |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::17 | Art. 17: data portability |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::19 | Art. 19: suspension (restriction) of processing |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::20 | Art. 20: decisions based solely or partly on automated assessment |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::21 | Arts. 21 and 24 and RGLOPDP Arts. 19 and 20: children and adolescents |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::62 | Art. 62 and RGLOPDP Arts. 12 to 16: handling requests, the 10-day term and complaints |
Arts. 25 to 32: special categories of data – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::25-26 | Arts. 25 and 26: special categories and the prohibition on processing sensitive data |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::27 | Art. 27 and RGLOPDP Art. 17: data of deceased persons |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::28-29 | Arts. 28 and 29 and RGLOPDP Art. 18: credit data and the rights of credit data subjects |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::30-31 | Arts. 30 and 31: health data |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::32 | Art. 32: health data for scientific research |
Arts. 33 to 36: communication to third parties and processors – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::33 | Arts. 33 and 36 and RGLOPDP Arts. 21 to 23: communication to third parties |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::34 | Arts. 34 and 35 and RGLOPDP Arts. 40 to 47: processors and service providers |
Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::37 | Art. 37: security of personal data, continuously verified |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::38 | Art. 38: security measures in the public sector |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::39 | Art. 39 and RGLOPDP Arts. 59 and 60: data protection by design and by default |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::40-41 | Arts. 40 and 41: risk analysis methodology and choice of security measures |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::42 | Art. 42 and RGLOPDP Arts. 29 to 32: data protection impact assessment |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::43 | Art. 43 and RGLOPDP Arts. 24 to 27: breach notification to the Authority and the telecommunications regulator within 5 days |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::45 | Art. 45 and the amended Arts. 78, 81, 82 and 83 of the Ley Organica de Telecomunicaciones: secrecy of communications and telecommunications providers' duties |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::46 | Art. 46 and RGLOPDP Art. 28: breach notification to data subjects within 3 days |
Arts. 47 to 51: controller, processor and data protection officer – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::47 | Art. 47: general obligations of controllers and processors |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::48 | Art. 48, RGLOPDP Arts. 53 and 54 and resolution 0028-R Arts. 9 and 10: when a data protection officer must be designated |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::49-50 | Arts. 49 and 50, RGLOPDP Arts. 48 to 52 and resolution 0028-R Arts. 12 to 23: officer's functions, resources and independence |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::51 | Art. 51 and RGLOPDP Arts. 84 to 86: reporting to the National Register of Personal Data Protection |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::RG-37 | RGLOPDP Art. 37: joint controllers |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::RG-38 | RGLOPDP Arts. 38, 39 and 44: record of processing activities |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::RG-55 | RGLOPDP Arts. 55 to 57 and resolution 0028-R Arts. 3 to 8, 11 and 15 to 18: officer qualifications, conflicts, appointment and registration |
Arts. 55 to 61: international transfers – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::56-57 | Arts. 55 to 57 and 60 and RGLOPDP Arts. 71 to 74: transfers to adequate countries, with appropriate safeguards or under exceptions |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::58 | Art. 58 and RGLOPDP Arts. 75 and 76: binding corporate rules |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::59 | Art. 59 and RGLOPDP Arts. 77 and 78: authorisation of other transfers and registration of all transfers |
Arts. 7 to 10: lawful processing, consent and principles – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(a)-(c) | Art. 10(a) to (c): lawfulness (juridicidad), loyalty and transparency |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(d) | Art. 10(d): purpose limitation and compatible further processing |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(e)-(f) | Art. 10(e) and (f): relevance, minimisation and proportionality |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(g) | Art. 10(g): confidentiality |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(h) | Art. 10(h): quality and accuracy |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(i) | Art. 10(i) and RGLOPDP Arts. 8 to 11: retention limits, periodic review and secure deletion |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(j) | Art. 10(j): security principle |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::10(k) | Art. 10(k) and RGLOPDP Arts. 33 to 36 and 58: proactive and demonstrated responsibility |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::7 | Art. 7 and RGLOPDP Art. 7: lawful bases for processing |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::8 | Art. 8 and RGLOPDP Arts. 5 and 6: valid, provable and revocable consent |
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::9 | Art. 9: conditions for processing on legitimate interest |
General, transitional, amending and repealing provisions – Ley Orgánica de Protección de Datos Personales (LOPDP)
| Code | Title |
|---|---|
| ley-org-nica-de-protecci-n-de-datos-personales-lopdp::DG-8 | Octava and Novena Disposiciones Generales: no charge for information based on the requester's own data; indigenous languages |
Your Compliance Coverage
If you comply with Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP), you already cover:
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
9%
5 controls mapped
Compare →Privacy Act 1988 (Australia)
9%
5 controls mapped
Compare →Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
9%
5 controls mapped
Compare →+ 113 more: Kentucky Consumer Data Protection Act (9%), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (9%)
See all 116 mapped frameworks ↓Maps to 116 other frameworks
Coverage is not the same as your position
This page shows what Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) and who does it apply to?
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) is a compliance framework from Ecuador with 9 domains and 48 controls. Ecuador's comprehensive personal data protection law (LOPDP, Registro Oficial 459 of 26 May 2021, sanctions from 26 May 2023) with its Reglamento General of 2023 and the Superintendencia's 2025 rules on data protection officers: lawful bases and consent, rights answered within 15 days, children from 15, sensitive, credit and health data, processor contracts, risk-based security and privacy by design, impact assessments, breach notice within 5 working days to the Superintendencia and the telecommunications regulator and 3 to data subjects, records of processing, mandatory officers in listed sectors, registration of databases and transfers, international transfer safeguards, and fines up to 1% of turnover. Built from the law's own text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) actually require?
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) has 48 controls organised across 9 domains. The largest domains are Arts. 7 to 10: lawful processing, consent and principles – Ley Orgánica de Protección de Datos Personales (LOPDP) (11 controls), Arts. 12 to 24 and 62: rights of the data subject and their exercise – Ley Orgánica de Protección de Datos Personales (LOPDP) (10 controls), Arts. 37 to 46: security, impact assessment and breach notification – Ley Orgánica de Protección de Datos Personales (LOPDP) (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) do I already cover?
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) maps to 116 other compliance frameworks. The top mapping partners are Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) (9% coverage), Privacy Act 1988 (Australia) (9% coverage), Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)?
Start your Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.
Get Started Free →Free forever — no credit card required