Data Protection Atlas

Ecuador

Tier 3 Comprehensive law Americas

Principal framework: LOPDP (2021). Regulator: Superintendencia de Protección de Datos. The 2021 LOPDP is GDPR-modelled; the Superintendencia became operational in 2023 and sanctioning powers applied from mid-2023.

At a glance

Principal law
LOPDP
Regulator
Superintendencia de Protección de Datos
Breach notification
3 days to the Superintendencia; affected persons where high risk
Maximum penalty
Serious infringements up to 1% of prior-year turnover
DPO required
Required for public bodies, large-scale or sensitive processing
Digital consent age
Parental consent for minors (best-interests rule)
Extraterritorial reach
Yes — GDPR-style scope

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
EC

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.