Law / Ecuador

Ecuador

15 of 21 named instruments researched to a stage, across four of the six areas of law we track: 13 in force, 1 enacted but not yet in force and 1 proposed. As of 19 September 2026.

When they take effect13 of 15 carry a date, 2 do not.
2014: 4 instruments (4 in force) ’14 2015: 0 instruments 2016: 3 instruments (3 in force) 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 6 instruments (6 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 6
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (158 words)

No AI-transparency, AI-risk-obligations, AI-training-data, AI-prohibited-practices, AI-governance, or AI-sector-rules statute is in force in Ecuador. A national-level organic AI bill (Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial, Trámite No. 450889) was presented in the National Assembly on 20 June 2024 and qualified for processing by the Consejo de Administración Legislativa on 26 July 2024; it had not passed either chamber as of 5 September 2026.

The Ministerio de Telecomunicaciones y de la Sociedad de la Información has separately adopted a non-binding national AI strategy (Acuerdo Ministerial MINTEL-MINTEL-2025-0030, 19 January 2026) and announced, on 24 March 2026, a voluntary regulatory sandbox for AI testing; neither creates an enforceable obligation on a private party.

Ecuador's data-protection authority has separately extended personal-data-protection rights and duties specifically to AI systems that process personal data; because that duty attaches to the data rather than to the AI system as such, it is a privacy finding, not an AI-topic one.

AI risk obligations

Unified Organic AI Bill (Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial)

Proyecto de Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial en Ecuador (Trámite No. 450889, As. Patricia Núñez) presentado 20 de junio de 2024Official Asamblea Nacional del Ecuador legislative-bill record

Proposed: draft date not recorded.

What this law does

Proposed; not yet in force, so it currently binds no one. This bill, presented in the National Assembly on 20 June 2024, was qualified for processing by the Consejo de Administración Legislativa (CAL) on 26 July 2024, following the Unidad Técnica Legislativa's report of 15 July 2024. The Assembly's own record shows only the bill's presentation and qualification as of 5 September 2026; it has not passed a first or second debate.

What it requires

Privacy law7 instruments, 6 in force, 1 enacted but not yet in force

Research summary (119 words)

Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP), in force since its publication in the Fifth Supplement of Registro Oficial No. 459 of 26 May 2021, is a comprehensive, General Data Protection Regulation (GDPR)-modeled regime binding any public or private processor of personal data, enforced by the Superintendente de Protección de Datos heading the Autoridad de Protección de Datos Personales (SPDP); its corrective-measures and sanctions regime did not begin to apply until two years after publication.

The SPDP has since issued a binding resolution, in force since 12 February 2026, extending the LOPDP's automated-decision, information and opposition rights specifically to personal data processed through artificial-intelligence systems and imposing risk-management, impact-assessment and audit duties on any developer or deployer of such a system.

Breach notification

LOPDP, notificación de vulneración de seguridad

LOPDP, arts. 43 y 46 (notificacion de vulneracion de seguridad)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 43 requires the controller to notify a personal-data security breach to the Personal Data Protection Authority and to the telecommunications regulator as soon as possible and no later than five days after becoming aware of it, unless the breach is unlikely to pose a risk to the rights and freedoms of natural persons, and to give the reasons for any delay where the notification is later than that.

The same article requires the processor to notify the controller of any personal-data security breach as soon as possible and no later than two days from the date it learns of it.

Article 46 requires the controller to notify the data subject without delay where the breach carries a risk to their fundamental rights and individual freedoms, within three days from the date it learned of the risk, and excuses that notice only where the controller had applied demonstrably effective protection measures to the affected data, where it has taken measures ensuring the risk will not occur, or where notice would take a disproportionate effort, in which case it must make a public communication instead.

The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

Comprehensive regime

LOPDP, comprehensive personal-data protection regime

Ley Orgánica de Protección de Datos Personales (LOPDP), arts. 1-11 y 33-54 (ámbito, principios, seguridad y obligaciones del responsable)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 2 applies the law to the processing of personal data in any medium, automated or not, by any public or private controller or processor, with narrow exclusions for purely personal or household use and for the personal data of deceased persons, and article 3 sets its territorial reach. Article 7 makes processing legitimate only on one of the grounds it lists, article 8 governs consent and article 9 legitimate interest. Article 10 carries the principles.

Articles 33 to 36 govern the transfer or communication of personal data to another controller, access by a processor and access by third parties, and the exceptions to consent for those. Article 37 requires the controller or processor to secure personal data, article 39 requires data protection by design and by default, article 40 a risk, threat and vulnerability analysis, article 41 the determination of the applicable security measures and article 42 an impact assessment.

Article 47 lists the obligations of the controller and processor, articles 48 to 50 the designation, functions and special position of the data protection delegate, article 51 the national register, and articles 52 to 54 self-regulation, codes of conduct and certification entities. The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

Cross border transfer

LOPDP, transferencia internacional de datos personales

LOPDP, arts. 55-60 (transferencia internacional de datos personales)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Articles 55 and 56 govern the international transfer or communication of personal data, article 57 transfer on adequate safeguards, article 58 binding corporate rules, article 59 the Authority's authorisation for every other transfer, and article 60 the exceptional cases in which a transfer or communication may proceed without one.

A transfer therefore rests on an Authority adequacy resolution, on safeguards meeting the standard the law states, or on the Authority's prior authorisation case by case. The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

Data subject rights

LOPDP, derechos del titular

LOPDP, arts. 12-24 (derechos del titular)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 12 gives the data subject a right to information, article 13 a right of access, article 14 a right of rectification and updating, article 15 a right of erasure, article 16 a right to object, article 17 a right to portability and article 19 a right to suspension of the processing, with article 18 setting the exceptions to rectification, updating and erasure.

Article 20 gives every data subject the right not to be the object of a decision based solely or partly on automated processing, including profiling, that produces legal or similarly significant effects, unless a narrow exception applies, and article 21 gives children and adolescents that right in a heightened form. Article 22 gives a right of consultation, article 23 a right to digital education, and article 24 fixes how the rights are exercised.

The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

SPDP Norma General guaranteeing personal-data protection in the use of AI systems

Resolución No. SPDP-SPD-2026-0009-R, Superintendencia de Protección de Datos Personales, 12 de febrero de 2026Official text of Resolución No. SPDP-SPD-2026-0009-R

Commencement not set. Binds public and private bodies.

What this law does

This resolution binds any controller or processor that develops, trains, implements, deploys, or provides an artificial-intelligence system that processes personal data, whenever that system falls within the LOPDP's material and territorial scope. Article 4 guarantees, at all times, the data subject's right not to be the object of a decision based solely or partly on automated valuations, together with the right to information and the right to object.

Article 5 requires the controller or processor to inform the data subject clearly and specifically about the AI-based processing, and article 6 requires a prior risk-management process and impact assessment before developing an AI system that will process personal data. The resolution states that it takes effect upon its publication in the Registro Oficial; the signed text itself does not independently confirm that publication has occurred.

What it requires

Enforcement supervision

LOPDP, control, infracciones, sanciones y la Autoridad

LOPDP, arts. 61-77 (control, infracciones, sanciones y la Autoridad)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 61 gives the Personal Data Protection Authority continuous control, article 62 lets a data subject address it directly, articles 63 and 64 set the preliminary actions and the administrative procedure, and articles 65 and 66 the corrective measures and their application. Articles 67 to 70 list the minor and grave infractions of the controller and of the processor, articles 71 and 72 the sanctions for each, and article 73 defines the business turnover the sanctions regime is calculated on.

Article 74 provides for provisional or precautionary measures. Articles 75 to 77 establish the Personal Data Protection Authority and its functions, powers and head. The corrective-measures and sanctions regime, unlike the rest of the Act, did not begin to apply until two years after the Act's publication in the Official Registry. The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

Sensitive categories

LOPDP, categorías especiales de datos personales

LOPDP, arts. 25-32 (categorias especiales de datos personales)Official text of the LOPDP as published by Ecuador's Ministerio de Inclusión Económica y Social (finanzaspopulares.gob.ec)

In force since 26 May 2021. Binds public and private bodies.

What this law does

Article 25 makes sensitive data, the data of children and adolescents, health data and disability data special categories of personal data. Article 26 prohibits the processing of sensitive data unless the data subject gives explicit consent or one of the other enumerated grounds applies.

Article 27 governs the personal data of deceased persons, articles 28 and 29 credit data and the rights of credit data subjects, and articles 30 to 32 health data, its processing, and its processing by private and public bodies. Article 21 separately gives children and adolescents a heightened right not to be the object of a decision based solely or partly on automated processing.

The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.

What it requires

Scraping law6 instruments, 6 in force

Research summary (261 words)

Ecuador has no scraping-specific statute, so general law governs each dimension separately.

The Código Orgánico Integral Penal (COIP), in force since 10 February 2014, criminalises unconsented access to, and interception of and attacks on, a computer or telematic system, but each offence turns on defeating an access control, intercepting without judicial order, or damaging a system, so reading a public, unauthenticated page does not fit a plain reading of any of them, and no reported case located tests the point.

No Ecuadorian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), in force since 9 December 2016, ties any use of a protected work to a closed list of acts that do not require authorization, tested against a four-factor fair-use-style standard, and that list includes text mining, but only as one purpose a library, archive, or museum may reproduce a work in its collection for, not a general-purpose text-and-data-mining exception.

The same Code gives a compilation-style protection to a database's original selection or arrangement, not to the underlying data, and does not extend that protection to software. The LOPDP applies its full lawful-basis and purpose-limitation regime to personal data drawn from a publicly accessible source; it supplies only a lawful-processing ground for that data, not a carve-out from the Act's other duties.

No Ecuadorian statute or case law located establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigns legal weight to a robots.txt directive or an AI-training-specific rule.

Computer misuse

COIP, acceso no consentido a un sistema informático

Código Orgánico Integral Penal (COIP), art. 234 (acceso no consentido a un sistema informático)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 234 punishes, with three to five years' imprisonment, a person who, without authorization, accesses all or part of a computer, telematic, or telecommunications system, or remains inside it against the will of the person with the legitimate right, in order to unlawfully exploit the access obtained, modify a web portal, divert or redirect data or voice traffic, or offer the services those systems provide to third parties without paying the legitimate service providers.

Because the offence's trigger is unauthorized access exploited for one of those listed purposes, reading a public, unauthenticated page without defeating an access control and without one of the listed purposes falls outside a plain reading of the provision.

What it requires

COIP, ataque a la integridad de sistemas informáticos

Código Orgánico Integral Penal (COIP), art. 232 (ataque a la integridad de sistemas informáticos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 232 punishes, with three to five years' imprisonment, a person who destroys, damages, deletes, deteriorates, alters, suspends, obstructs, causes malfunction or unwanted behaviour of, or suppresses computer data, e-mail messages, or an information, telematic, or telecommunications processing system or its logical components.

The same penalty reaches designing, developing, programming, acquiring, sending, introducing, executing, selling, or distributing malicious software or programs meant to cause those effects, and destroying or altering, without authorization, the technological infrastructure needed to transmit, receive, or process information. The penalty rises to five to seven years where the target is infrastructure for a public service or linked to public safety.

What it requires

COIP, interceptación ilegal de datos

Código Orgánico Integral Penal (COIP), art. 230 (interceptación ilegal de datos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 230(1) punishes, with three to five years' imprisonment, a person who, without prior judicial order and for their own benefit or a third party's, intercepts, listens to, diverts, records, or observes, in any form, a computer datum at its origin, destination, or inside a computer system, or a signal or data transmission, with the aim of obtaining registered or available information.

Reading a public, unauthenticated page does not fit a plain reading of an offence built around a judicial-order requirement and an interception of a transmission.

What it requires

COIP, revelación ilegal de base de datos

Código Orgánico Integral Penal (COIP), art. 229 (revelación ilegal de base de datos)Official COIP text (Registro Oficial Suplemento 180, 10 de febrero de 2014)

In force since 10 February 2014. Binds public and private bodies.

What this law does

Article 229 punishes, with one to three years' imprisonment, a person who, for their own benefit or a third party's, reveals information registered or contained in files, archives, databases, or similar media, through or directed at an electronic, computer, telematic, or telecommunications system, deliberately and intentionally breaching the secrecy, privacy, and intimacy of persons.

The penalty rises to three to five years where a public servant, or a bank or savings-and-credit-cooperative employee carrying out financial intermediation, or a contractor commits the same act.

What it requires

Copyright and text and data mining (TDM)

Código Ingenios, uso justo y minería de textos

Arts. 211-212 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), uso justo y actos que no requieren autorizaciónOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 211 states that using or exploiting a protected work or performance in the cases the next article lists is not a violation of patrimonial rights, provided it does not conflict with the work's normal exploitation and does not cause unjustified prejudice to the rights holder's legitimate interests, tested against a four-factor standard (the purpose and nature of the use, the nature of the work, the amount used relative to the whole, and the effect on the work's market value).

Article 212 then lists the acts that do not require authorization, including brief quotation for analysis, comment, or criticism with attribution, and, at item 9, an enumerated set of purposes for which a library, archive, or museum may reproduce a single copy of a work already in its collection, the eighth of which is text mining.

The exception is therefore not a general-purpose text-and-data-mining allowance: it is available only to a library, archive, or museum reproducing a work already in its own collection, not to a commercial or research entity scraping or mining text from the open web at large.

What it requires

Database right

Código Ingenios, protección de bases de datos

Art. 140 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), materia protegible por las bases de datosOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 140 protects a compilation of data or other material, in any form, as such, only where the originality of the selection or arrangement of its contents constitutes an intellectual creation; that protection does not extend to the underlying data or information compiled, and does not affect any copyright or related right subsisting in the works or performances the compilation contains. The article also states that the protection it recognizes for databases does not apply to software.

Ecuador therefore has no sui generis database right of the European kind, protecting a producer's investment in obtaining, verifying, or presenting the contents regardless of originality; only a compilation-copyright model tied to originality of selection or arrangement.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (180 words)

Ecuador has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), in force since 9 December 2016, article 212(1) of which treats a periodic compilation made in the form of a press review or press digest as a form of quotation, exempt from the rights holder's authorization, provided the underlying work has already been disclosed, the use is for citation, analysis, comment, or criticism, with teaching or research purposes, and the source and author are credited.

Whether that exception reaches a systematic online news aggregator's reproduction of headlines and snippets, as opposed to a traditional press review, has not been tested in a located Ecuadorian decision, and the Code predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Código Ingenios, reseñas y revista de prensa como forma de cita

Art. 212 numeral 1 Código Ingenios (Código Orgánico de la Economía Social de los Conocimientos, Creatividad e Innovación), reseñas y revista de prensa como citaOfficial Código Ingenios text (Registro Oficial Suplemento 899, 9 de diciembre de 2016)

In force since 9 December 2016. Binds public and private bodies.

What this law does

Article 212(1) permits, without the rights holder's authorization, including brief fragments of an already-disclosed written, sound, audiovisual, artistic, photographic, or figurative work in one's own work, provided the inclusion is by way of quotation or for analysis, comment, or critical judgment, with teaching or research purposes, to the extent justified by that purpose, and provided the source and author's name are indicated and the use is not a disguised exploitation of the work.

The same provision states that periodic compilations made in the form of press reviews or a press digest are considered quotations for this purpose. That treatment is not capped at a headline-length or short-extract threshold in the article's text, and article 211 additionally requires that the use not conflict with the work's normal exploitation and not cause unjustified prejudice to the rights holder, tested against a four-factor standard.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.