Ecuador strengthens its data protection framework

ecuador strengthens its data protection
On September 9, 2026, Ecuador’s Superintendency for Personal Data Protection (SPDP) issued four resolutions that strengthen the regulatory framework applicable to the use of artificial intelligence, biometric data, and the management of personal data security breaches.

Resolution 0037-R updates the rules for AI systems, now also applicable to data processors; Resolution 0038-R allows the SPDP itself to rely on AI to manage complaints, always under human oversight; Resolution 0039-R sets out specific rules for the processing of biometric data; and Resolution 0040-R closes the loop with clear rules for reporting security breaches affecting personal data.

The new rules require prior impact assessments for biometric systems, establish reinforced requirements where processing is based on consent, restrict mass and indiscriminate biometric identification in public spaces, and set specific rules for reporting security incidents.

What does this mean for companies? Organizations subject to these provisions will need to assess the impact of the new rules on their AI and biometric systems, their consent mechanisms, and their incident response and notification protocols.

18 Sep, 2026

Categorías

Archivo

Archives

Categorías

Archivo

Archives