On November 6, 2023, by executive decree 904, it is defined as the date on which, after more than 2 long years, the decree was issued Regulation to the Organic Law on the Protection of Personal Datathe same that is fully in force, and that caused a great movement of legal regulation, over the last few months, in national companies of all kinds and foreign branches established in Ecuador.
Below are the 10 relevant points of this Regulation:
- The person responsible and/or responsible for the processing of personal data shall be domiciled in Ecuador; otherwise, he shall have an A-Power representing him in this jurisdiction. The obligation to subject to this requirement shall be subject to the technical guide to be issued by the competent Authority.
- New definitions are included not previously provided for in the Act, such as the processing of large-scale data, data related to family or domestic activities, health data, among others, which is directly associated with the levels of responsibility and applicability of certain provisions contained in the Regulations.
- In certain cases, the obligation to perform an impact assessment of the processing of personal data is established, which will have a "preventive" character, evaluating the actual impacts of the processing of personal data, in order to identify and mitigate possible risks. This assessment shall be submitted to the competent Authority.
- It is stipulated that the inability to assume the costs of applying a data protection system will not be considered as an excuse for non-compliance with the law and regulations; by obliging companies, to protect themselves in the principle of proportionality between the volume of data processing and their economic capacity.
- Those companies responsible for the processing, which have 100 or more workers, must keep a record of all personal data activities that are within their competence. Without prejudice to that, companies with fewer workers still have the obligations inherent to those responsible and/or responsible for processing personal data.
- The data protection delegate may be recruited under the dependency ratio or through a professional service contract. Business groups may designate a single delegate.
- The Competent Authority shall issue certifications in order to determine the degree of compliance with a self-regulation mechanism with respect to the obligations of the Organic Law on the Protection of Personal Data and its Regulations, for a maximum duration of 3 years.
- International data transfer and/or communication is regulated.
- Any corporate regulations or codes of conduct aimed at regulating the processing of Personal Data within a corporate entity shall be approved by the Competent Authority.
- The Personal Data Protection Authority is defined as a Personal Data Protection Superintendent. Its implementation is subject to budgetary availability.
Contact iURISRED Legal Expert for more information for both the data protection system and the anti-corruption compliance system. We're at your command! This article is merely informative, not a legal opinion.







