The corrective measures and sanctions provisions of Ecuador’s Organic Law on Personal Data Protection (LOPDP) take effect today, two years after the law was published, so the law is now fully in force.
Key points
- A GDPR-style law regulated by the Superintendency of Personal Data Protection.
- Security measures are required.
- A DPO is required in specified cases.
- Breaches must be notified to the authority within 5 days.
UK organisations with Ecuadorian operations, customers or processors should ensure compliance now that the regulator can take enforcement action.
Source: Ley Orgánica de Protección de Datos Personales, Registro Oficial 459 (Government of Ecuador)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.