AI LAW RADAR · Daily Last verified 29 Aug 2026

Jurisdiction dossier

Ecuador: AI regulation & deadlines

Ecuador has one binding automated-decision right in force since 26 May 2021 and, since 10 March 2026, a regulator-made AI rulebook in force alongside it. Art. 20 of the Ley Orgánica de Protección de Datos Personales is the only rule in the atlas that drops the «solely» limb of the GDPR art. 22 family: its title and its operative sentence both read «una decisión basada única o parcialmente en valoraciones automatizadas» — wholly OR PARTLY automated — so the human-rubber-stamp argument that runs through the rest of the family has no purchase on the text. The effects threshold is widened alongside it, to decisions producing legal effects or infringing fundamental rights and freedoms, and the right is drafted as five active entitlements — reasoned explanation, observations, the valuation criteria bearing on the automated program, the types of data used and their source, and challenge — rather than as an abstention. Against that breadth sit four exits rather than the GDPR's three, the fourth being a de minimis exit for decisions carrying no serious impact or verifiable risk; and two clauses with no GDPR counterpart, a bar on advance waiver through mass adhesion contracts and a duty to state the right by the first communication. Art. 21 gives children and adolescents their own automated-decision article. The penalty structure has a quirk of its own: the infraction lists never name art. 20, so a controller refusing the right falls into the light band at 0.1%–0.7% of turnover while a processor doing the same falls into the serious band at 0.7%–1% through a catch-all. Ecuador has no AI statute — the Superintendencia de Protección de Datos Personales instead issued Resolución SPDP-SPD-2026-0009-R, a general norm binding developers, deployers, distributors and implementers of AI systems that process Ecuadorian subjects' data wherever the system or supplier sits, with information, impact-assessment, security, register and audit duties and no risk tiers; signed on 12 February 2026 and in force since its publication in Registro Oficial Nº 240 of 10 March 2026. 2 obligations tracked — 2 in force.

Binding — Binding sectoral Flagship law: LOPDP art. 20

Ecuador has one binding automated-decision right in force since 26 May 2021 and, since 10 March 2026, a regulator-made AI rulebook in force alongside it. Art. 20 of the Ley Orgánica de Protección de Datos Personales is the only rule in the atlas that drops the «solely» limb of the GDPR art. 22 family: its title and its operative sentence both read «una decisión basada única o parcialmente en valoraciones automatizadas» — wholly OR PARTLY automated — so the human-rubber-stamp argument that runs through the rest of the family has no purchase on the text. The effects threshold is widened alongside it, to decisions producing legal effects or infringing fundamental rights and freedoms, and the right is drafted as five active entitlements — reasoned explanation, observations, the valuation criteria bearing on the automated program, the types of data used and their source, and challenge — rather than as an abstention. Against that breadth sit four exits rather than the GDPR's three, the fourth being a de minimis exit for decisions carrying no serious impact or verifiable risk; and two clauses with no GDPR counterpart, a bar on advance waiver through mass adhesion contracts and a duty to state the right by the first communication. Art. 21 gives children and adolescents their own automated-decision article. The penalty structure has a quirk of its own: the infraction lists never name art. 20, so a controller refusing the right falls into the light band at 0.1%–0.7% of turnover while a processor doing the same falls into the serious band at 0.7%–1% through a catch-all. Ecuador has no AI statute — the Superintendencia de Protección de Datos Personales instead issued Resolución SPDP-SPD-2026-0009-R, a general norm binding developers, deployers, distributors and implementers of AI systems that process Ecuadorian subjects' data wherever the system or supplier sits, with information, impact-assessment, security, register and audit duties and no risk tiers; signed on 12 February 2026 and in force since its publication in Registro Oficial Nº 240 of 10 March 2026.

checked 29 Aug 2026 primary source ↗

The Register

2 obligations
Ecuador Binding

LOPDP art. 20 — the automated-decision right that drops «solely»: «única o parcialmente»

Binds Responsables and encargados del tratamiento — controllers and processors. Art. 3 reaches processing carried out anywhere in national territory, controllers or processors domiciled in Ecuador, and controllers or processors not established in Ecuador that process the data of subjects residing in Ecuador where the activity relates to offering goods or services to them, payment required or not, or to monitoring their behaviour in Ecuador; a fourth limb picks up cases where Ecuadorian law applies by contract or by public international law. Art. 20 covers administrative acts and private decisions alike, so there is no public-sector carve-out — the sanctions articles instead split the tariff between public servants and private or state-owned entities. Impact tier: all entities.. Art. 20 of the Ley Orgánica de Protección de Datos Personales (Quinto Suplemento del Registro Oficial Nº 459 of 26 May 2021, adopted 10 May 2021) is titled «Derecho a no ser objeto de una decisión basada única o parcialmente en valoraciones automatizadas» — a right not to be subject to a decision based wholly OR PARTLY on automated valuations. The two words «o parcialmente» are the finding. Every other transposition in the atlas of the GDPR art. 22 family keeps the «solely» limb, and the argument that partial automation with a human rubber-stamp escapes the rule is the most contested question in that family; Ecuador removed the question from the text in 2021. The effects threshold is widened in the same sentence: the decision has to «produzcan efectos jurídicos en él o que atenten contra sus derechos y libertades fundamentales» — produce legal effects in the subject OR infringe their fundamental rights and freedoms — where GDPR art. 22(1) asks for a similarly significant effect. The right is also built as a bundle of five active entitlements rather than an abstention: a reasoned explanation of the decision taken (a), the filing of observations (b), «los criterios de valoración sobre el programa automatizado» — the valuation criteria bearing on the automated program itself (c), the types of data used and the source they were obtained from (d), and challenge of the decision before the controller or processor (e). There are four exceptions, one more than the GDPR has: contract, authorising law (widened to include a judicial order or the reasoned mandate of a competent technical authority, with adequate safeguards established), explicit consent, and — with no counterpart in the GDPR — «la decisión no conlleve impactos graves o riesgos verificables para el titular», a de minimis exit for decisions carrying no serious impact or verifiable risk for the subject. Two closing sentences have no GDPR counterpart either: advance waiver of the right through mass adhesion contracts cannot be required, and the right is stated explicitly to the subject, by any suitable medium, no later than the first communication. That last sentence reverts to «basada únicamente en valoraciones automatizadas» — the notification duty is drawn back to solely-automated decisions while the right itself covers partly-automated ones, an internal inconsistency present in the gazette text. Art. 21 carries a dedicated companion right for children and adolescents: on top of art. 20, sensitive data and the data of children and adolescents are not processed this way absent the express authorisation of the subject or their legal representative, or an essential public interest assessed against international human-rights standards satisfying legality, proportionality and necessity and including specific safeguards; adolescents from 15 may consent as subjects in their own right. Arts. 12(14) and 12(17) make the transparency proactive — the existence of automated valuations and decisions, profiling included, forms part of the information given at collection.

In force since 26 May 2021: the Disposición Final states «La presente Ley entrará en vigencia una vez publicada en el Registro Oficial», and publication was in the Quinto Suplemento del Registro Oficial Nº 459 of that date. The corrective-measures and sanctions regime is the exception — Disposición Transitoria Primera delayed it by two years from publication, so fines became available on 26 May 2023, and Disposición General Séptima states in terms that the rights «podrá ser exigido por el titular independientemente de la entrada en vigor del régimen sancionatorio», an explicitly enforceable-but-unfineable interval that no other instrument in the atlas spells out. Art. 20 was verified against the scanned gazette itself — page 23 of the Asamblea Nacional's copy of the Quinto Suplemento — and that reading corrected the commercial rendering: the gazette lists five lettered entitlements a) to e), where the widely circulated Lexis-typeset edition folds «e. Impugnar la decisión» into item d) by reading the letter «e» as the conjunction. Ecuador's data-protection authority, the Superintendencia de Protección de Datos Personales, has been operating since 2023 and issues general norms under art. 76(5) of the Law. No amendment: the government-hosted consolidated editions of November 2024 and July 2025 both carry «Estado: Vigente / Fecha de última reforma: No aplica», and no reforming law was found through August 2026.

Stated maximum penalty — Split by the identity of the offender, not by the article breached. Art. 71 sets the light tariff — 1 to 10 unified basic salaries for a public servant, or 0.1% to 0.7% of the previous financial year's turnover for a private entity or state-owned enterprise. Art. 72 sets the serious tariff — 10 to 20 unified basic salaries, or 0.7% to 1% of turnover. Art. 73 defines turnover as sales of goods and services net of VAT and directly related taxes. There is a finding in the lists themselves. Neither art. 67 nor art. 68 names art. 20, so a controller that denies the right lands in art. 67(1) — failing to process, processing out of time or unjustifiably refusing a subject's petition — which is a LIGHT infraction; art. 70(1), the processor's list, is a catch-all reaching any processing «sin observar los principios y derechos desarrollados en la presente Ley», which is a SERIOUS one. The same refusal is therefore fined an order of magnitude apart depending on whether the entity acted as controller or as processor. Art. 72 also carries a cross-border enforcement fallback: where the offender has no domicile or legal representation in Ecuador, the resolution is notified to the data-protection authority of its principal place of business to carry the measures through.

In force · 26 May 2021 checked 29 Aug 2026 LOPDP art. 20 ↗ high confidence
Ecuador Binding

SPDP Norma General on personal data in AI systems — a regulator-made AI rulebook with a four-role supply chain

Binds Controllers and processors that develop, train, implement, deploy or supply AI systems processing the personal data of Ecuadorian data subjects, wherever the system or the supplier is located (art. 1), in the four capacities defined by art. 2 — developer, deployer, distributor, implementer. Art. 1 excludes AI systems that do not process personal data within the material and territorial scope of the LOPDP, so the norm has no reach over models trained only on non-personal data. Impact tier: all entities.. Resolución Nº SPDP-SPD-2026-0009-R of the Superintendente de Protección de Datos Personales, signed in Quito on 12 February 2026, issues the «Norma General para la Garantía del Derecho de Protección de Datos Personales en el Uso de Sistemas de Inteligencia Artificial». It is secondary legislation made under art. 76(5) of the LOPDP rather than a statute, and it is the closest thing Ecuador has to an AI act. Art. 1 fixes the scope: the principles, rights and obligations of the LOPDP, its General Regulation and SPDP secondary norms are of obligatory compliance for controllers and processors that develop, train, implement, deploy and/or provide AI systems processing the data of Ecuadorian subjects, «con independencia de la ubicación del sistema o del proveedor» — regardless of where the system or the supplier sits. Art. 2 adds a four-role supply-chain taxonomy layered onto the controller/processor pair: desarrollador (generates or creates the system), desplegador (uses a system to deliver a service, excluding non-professional personal activity), distribuidor (a supply-chain party other than the developer, deployer or implementer that markets or supplies the system), and implementador (commissions development or embeds a system into internal procedures). Art. 4 states that where personal data are processed directly in AI systems, the art. 20 right not to be subject to a wholly or partly automated decision, the right to information and the right to object are guaranteed at all times. Art. 5 lists the standing obligations: clear, specific and transparent information to the subject about processing carried out through AI systems, including the purposes and the automated character of the processing; risk management and data-protection impact assessment; administrative, technical, physical, organisational and legal security measures scaled to the categories and volume of data, the state of the art, best practice and cost, with identification of probable risks; entry of AI-mediated processing in the register of processing activities (RAT); and audit of the general functioning of the system by reference to its risk level. Art. 6 places the risk management and impact assessment before development begins. Art. 7 makes security continuous and adds that automated decisions of AI systems producing legal impacts or affecting the rights and freedoms of subjects are entered in the RAT, which is made available to the SPDP. Art. 10 gives the SPDP power to audit AI systems and to impose corrective measures under the LOPDP or precautionary measures under the Código Orgánico Administrativo. Art. 8 routes non-compliance to the LOPDP's existing sanctions regime rather than creating a tariff of its own. The norm does not classify systems by risk tier, has no prohibited-practices list and no conformity assessment — it is a data-protection overlay on AI, not a product-safety regime.

In force since 10 March 2026, the date the Registro Oficial published it. The Disposición Final states «Esta resolución entrará en vigencia a partir de su publicación en el Registro Oficial», and the resolution was «dada y firmada en Quito, D. M., el 12 de febrero del 2026» by Superintendente Fabrizio Peralta-Díaz; the gazette citation is Registro Oficial Año I Nº 240 of Tuesday 10 March 2026, an ordinary edition rather than a supplement, where the norm runs from page 49 to page 56 under the heading FUNCIÓN DE TRANSPARENCIA Y CONTROL SOCIAL / SUPERINTENDENCIA DE PROTECCIÓN DE DATOS PERSONALES. The gazette text was read in full against the signed copy the SPDP publishes at https://spdp.gob.ec/wp-content/uploads/2026/02/ResolIA.pdf and is the same instrument: same ten articles, same four-role taxonomy in art. 2, same Disposición Final, same signature block. Between 29 August 2026, when the entry was first drafted, and this verification the citation could not be produced — the SPDP's own publication page carries no gazette stamp and none of its later 2026 resolutions (0020-R, 0021-R and 0022-R of May 2026, all checked) recites this one — so the row was held at lifecycle proposed with an empty date rather than asserting an in-force date that could not be sourced. The citation was found through the gazette's own site search at registroficial.gob.ec, which returns the edition's SUMARIO and a download link for the full PDF.

Stated maximum penalty — No tariff of its own. Art. 8 states that controllers and processors breaching the LOPDP, its General Regulation or this general norm through the use of AI systems are sanctioned under the sanctions regime already provided by law, which is arts. 67 to 73 of the LOPDP: 1 to 10 unified basic salaries or 0.1% to 0.7% of turnover for light infractions, 10 to 20 unified basic salaries or 0.7% to 1% of turnover for serious ones. The obligations this norm creates — impact assessment, security measures, the RAT entry — map onto art. 68's serious-infraction list for controllers, where failure to run an impact assessment when one was required (68(5)) and failure to keep the national register current (68(10)) already appear, so the practical exposure of an AI-specific breach is the serious band. Art. 10's audit and corrective or precautionary measures operate independently of any fine.

In force · 10 Mar 2026 checked 29 Aug 2026 SPDP-SPD-2026-0009-R ↗ high confidence

Questions & answers

From the data

When does LOPDP art. 20 take effect in Ecuador?

LOPDP art. 20 is already in force, with obligations live since May 26, 2021. Ecuador has one binding automated-decision right in force since 26 May 2021 and, since 10 March 2026, a regulator-made AI rulebook in force alongside it. Art. 20 of the Ley Orgánica de Protección de Datos Personales is the only rule in the atlas that drops the «solely» limb of the GDPR art. 22 family: its title and its operative sentence both read «una decisión basada única o parcialmente en valoraciones automatizadas» — wholly OR PARTLY automated — so the human-rubber-stamp argument that runs through the rest of the family has no purchase on the text. The effects threshold is widened alongside it, to decisions producing legal effects or infringing fundamental rights and freedoms, and the right is drafted as five active entitlements — reasoned explanation, observations, the valuation criteria bearing on the automated program, the types of data used and their source, and challenge — rather than as an abstention. Against that breadth sit four exits rather than the GDPR's three, the fourth being a de minimis exit for decisions carrying no serious impact or verifiable risk; and two clauses with no GDPR counterpart, a bar on advance waiver through mass adhesion contracts and a duty to state the right by the first communication. Art. 21 gives children and adolescents their own automated-decision article. The penalty structure has a quirk of its own: the infraction lists never name art. 20, so a controller refusing the right falls into the light band at 0.1%–0.7% of turnover while a processor doing the same falls into the serious band at 0.7%–1% through a catch-all. Ecuador has no AI statute — the Superintendencia de Protección de Datos Personales instead issued Resolución SPDP-SPD-2026-0009-R, a general norm binding developers, deployers, distributors and implementers of AI systems that process Ecuadorian subjects' data wherever the system or supplier sits, with information, impact-assessment, security, register and audit duties and no risk tiers; signed on 12 February 2026 and in force since its publication in Registro Oficial Nº 240 of 10 March 2026.

Who must comply with AI rules in Ecuador?

Current obligations bind, among others, Responsables and encargados del tratamiento — controllers and processors. Art. 3 reaches processing carried out anywhere in national territory, controllers or processors domiciled in Ecuador, and controllers or processors not established in Ecuador that process the data of subjects residing in Ecuador where the activity relates to offering goods or services to them, payment required or not, or to monitoring their behaviour in Ecuador; a fourth limb picks up cases where Ecuadorian law applies by contract or by public international law. Art. 20 covers administrative acts and private decisions alike, so there is no public-sector carve-out — the sanctions articles instead split the tariff between public servants and private or state-owned entities. Impact tier: all entities.; Controllers and processors that develop, train, implement, deploy or supply AI systems processing the personal data of Ecuadorian data subjects, wherever the system or the supplier is located (art. 1), in the four capacities defined by art. 2 — developer, deployer, distributor, implementer. Art. 1 excludes AI systems that do not process personal data within the material and territorial scope of the LOPDP, so the norm has no reach over models trained only on non-personal data. Impact tier: all entities.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Ecuador?

Stated statutory maxima include: LOPDP art. 20 — Split by the identity of the offender, not by the article breached. Art. 71 sets the light tariff — 1 to 10 unified basic salaries for a public servant, or 0.1% to 0.7% of the previous financial year's turnover for a private entity or state-owned enterprise. Art. 72 sets the serious tariff — 10 to 20 unified basic salaries, or 0.7% to 1% of turnover. Art. 73 defines turnover as sales of goods and services net of VAT and directly related taxes. There is a finding in the lists themselves. Neither art. 67 nor art. 68 names art. 20, so a controller that denies the right lands in art. 67(1) — failing to process, processing out of time or unjustifiably refusing a subject's petition — which is a LIGHT infraction; art. 70(1), the processor's list, is a catch-all reaching any processing «sin observar los principios y derechos desarrollados en la presente Ley», which is a SERIOUS one. The same refusal is therefore fined an order of magnitude apart depending on whether the entity acted as controller or as processor. Art. 72 also carries a cross-border enforcement fallback: where the offender has no domicile or legal representation in Ecuador, the resolution is notified to the data-protection authority of its principal place of business to carry the measures through.; SPDP-SPD-2026-0009-R — No tariff of its own. Art. 8 states that controllers and processors breaching the LOPDP, its General Regulation or this general norm through the use of AI systems are sanctioned under the sanctions regime already provided by law, which is arts. 67 to 73 of the LOPDP: 1 to 10 unified basic salaries or 0.1% to 0.7% of turnover for light infractions, 10 to 20 unified basic salaries or 0.7% to 1% of turnover for serious ones. The obligations this norm creates — impact assessment, security measures, the RAT entry — map onto art. 68's serious-infraction list for controllers, where failure to run an impact assessment when one was required (68(5)) and failure to keep the national register current (68(10)) already appear, so the practical exposure of an AI-specific breach is the serious band. Art. 10's audit and corrective or precautionary measures operate independently of any fine.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.