Most companies discover a breach weeks or months after it happened. Do you know where yours stands?
Compliance

LOPDP: what it requires and how to comply without slowing the business

Ecuador's Organic Law on Personal Data Protection is no longer a theoretical threat. Administrative penalties are already in force, and already being applied.

What the law requires

The LOPDP was published in 2021 and sets out the principles every Ecuadorian company must follow when processing personal data: data subject consent, a defined purpose, and security measures proportional to the risk. It also requires notifying the authority and affected data subjects when a security breach occurs, within the deadlines the law sets, and obligates companies that handle large volumes of data or sensitive data to designate a Data Protection Officer.

It’s worth pinning down two terms that come up constantly. A security breach is any incident that exposes, alters, or destroys personal data without authorization — from an attack to an email sent to the wrong recipient. A Data Protection Officer is the person charged with overseeing the company’s compliance with the law: a role, not necessarily a new full-time position.

What happens if you don’t comply

The law’s administrative penalties took effect in May 2023, and the Superintendencia de Protección de Datos Personales (SPDP) is already applying them: serious infractions can reach up to 1% of the prior year’s revenue, plus corrective measures such as suspending data processing or publishing the sanction.

Missing the deadline to respond to a data subject’s rights request — like access or deletion — already counts as an infraction on its own, without a breach ever having to occur. It’s the point that surprises companies most: you don’t need an attack to be sanctioned; failing to answer in time is enough.

How managed security helps you comply

Complying with the LOPDP isn’t just a legal exercise: much of what it requires is technical, and that’s where an orderly security operation becomes evidence. These are the controls an auditor asks to see, and the layer that delivers each:

  • Encryption of sensitive data and verified backups — the data protection that proves information is safeguarded and recoverable.
  • Control over who accesses what — the identity layer, which turns “we trust the team” into a verifiable access record.
  • A record of what’s monitored and acted on — the continuous log of a managed SOC, which gives your legal team something concrete to show instead of a written policy no one can verify in practice.

The difference between complying and saying you comply is exactly that: technical evidence, dated and logged, versus a document that describes good intentions.

Does this sound familiar?

If your company has a published privacy policy but no one could explain how it’s actually followed, if you handle customer data without knowing for sure where it’s backed up, or if an audit makes you more nervous than confident, you’re not alone — it’s the situation most mid-sized companies in Ecuador are in today.

Certified in ISO 27001, we help our clients translate these legal requirements into concrete, documented technical controls. We don’t replace your legal counsel, but we do give that counsel the technical evidence they need.

FAQ

Since when have LOPDP penalties applied?

The law was published in 2021, and its administrative penalty regime took effect in May 2023. The Superintendency for Personal Data Protection is already applying it.

How much can non-compliance cost?

Serious infractions can reach up to 1% of the prior year's revenue, on top of corrective measures such as suspending data processing or publishing the sanction.

What is a Data Protection Officer, and who needs one?

It's the person responsible for overseeing compliance with the law inside the company. The LOPDP requires one for organizations that process large volumes of data or sensitive data.

Is the LOPDP a legal matter or a technical one?

Both. The principles are legal, but much of what it requires — encryption, access control, verified backups, activity logging — is technical and has to be implemented and documented.

See how ready your company is for an audit.

The security assessment also reviews the compliance evidence you already have and what's missing.

Request a free assessment
WhatsApp