Skip to main content

Ecuador LOPDP

Organic Law on the Protection of Personal Data (LOPDP)

Ecuador's GDPR-inspired data protection law with 5-day breach notification (stricter than GDPR's 72 hours) and DPIA requirements for high-risk processing.

Jurisdiction

Ecuador

EC

Enacted

May 26, 2021

Effective

May 26, 2023

Enforcement

Superintendencia de Protección de Datos Personales

5-day breach notification - stricter than GDPR

Who Must Comply

This law applies to:

  • Data controllers and processors in Ecuador
  • Entities processing data of Ecuadorian residents
  • High-risk automated decision-making systems

Capability triggers:

dataProcessing (required)
Required Increases applicability

Who bears obligations:

Safety Provisions

  • 5-day breach notification to data subjects (stricter than GDPR)
  • Data Protection Impact Assessment for high-risk processing
  • Right to object to automated decisions
  • Data Protection Officer for certain controllers
  • Cross-border transfer restrictions

Enforcement

Enforced by

Superintendencia de Protección de Datos Personales

Penalties

Fines for violations

Quick Facts

Binding
Yes
Mental Health Focus
Yes
Child Safety Focus
No
Algorithmic Scope
Yes

Why It Matters

Ecuador's 5-day breach notification is stricter than GDPR's 72 hours, creating tightest incident response timeline globally for AI chatbot security incidents.

Cite This

APA

Ecuador. (2021). Organic Law on the Protection of Personal Data (LOPDP). Retrieved from https://nope.net/regs/ec-lopdp

BibTeX

@misc{ec_lopdp,
  title = {Organic Law on the Protection of Personal Data (LOPDP)},
  author = {Ecuador},
  year = {2021},
  url = {https://nope.net/regs/ec-lopdp}
}

Related Regulations

In Effect CARICOM Data Protection

CARICOM CCSCAP 2025

CARICOM's 2025 regional cyber security framework establishing digital safety culture and coordinated incident response across 18 member states.

In Effect CL Data Protection

Chile Cybersecurity Law

First cybersecurity framework law in Latin America (Law 21,663 promulgated Mar 26, 2024; published Apr 8, 2024). Creates National Cybersecurity Agency (ANCI), mandatory incident reporting, and encryption rights.

In Effect PR Data Protection

Puerto Rico Cybersecurity Act

Puerto Rico's comprehensive cybersecurity law establishing cybersecurity framework for public and private sectors, complementing Act 111-2005 breach notification.

In Effect AR AI Safety

Argentina AI Strategy

Non-binding AI governance guidelines establishing principles for responsible AI use. Argentina positioning as AI innovation hub with limited regulatory barriers. Emphasizes transparency, accountability, and human oversight. Multiple legislative proposals pending inspired by EU AI Act, aiming to establish formal regulatory authority.

Failed CA AI Safety

AIDA

Would have regulated high-impact AI systems with potential penalties up to $25M or 5% global revenue. Part of Bill C-27 which died when Parliament ended.

In Effect PE AI Safety

Peru AI Regulations

Peru's first comprehensive AI regulatory framework, inspired by EU AI Act. Establishes three-tier risk-based approach: prohibited uses, high-risk systems (including healthcare), and low-risk/acceptable AI. First general AI regulation in Latin America. Requires human oversight, transparency, and risk assessments for high-risk AI including healthcare applications.