Introduction
The protection of personal data is a fundamental right that has gained relevance in the digital age. The Organic Law on Personal Data Protection aims to guarantee the exercise of the right to personal data protection in Ecuador, including access, decision-making, and protection of this data. Below, a comprehensive analysis of the regulations is presented.
What is the main purpose of the law in question?
Article 1 establishes that the purpose and aim of the law is to guarantee the exercise of the right to personal data protection, including access to and decision-making on information and data of this nature, as well as its corresponding protection. The law regulates, provides for, and develops principles, rights, obligations, and protection mechanisms.
What type of data does this law apply to and on what media?
According to Article 2, the law will apply to the processing of personal data contained in any type of medium, whether automated or not, and to any subsequent use.
Are there exceptions to the application of this law?
Yes, Article 2 also details a series of exceptions, including data used in family or domestic activities, data of deceased persons, anonymized data, journalistic activities, among others.
What data is accessible to the public and subject to processing under this law?
Article 2 specifies that personal data relating to the contact of professionals, traders, representatives, partners, shareholders of legal entities, and public servants are accessible to the public and subject to processing, provided they relate to the exercise of their profession, trade, business, competencies, powers, attributions, or position.
What is the territorial scope of application of this law?
Article 3 establishes that the law will apply in the national territory, including the processing of personal data carried out within the territory, by those responsible or in charge domiciled in the country, and in certain cases, by those responsible or in charge not domiciled in Ecuador, but whose processing activities are related to the country.
When is the processing of personal data considered legitimate and lawful?
According to Article 7, the processing of personal data will be legitimate and lawful if it meets any of the following conditions: consent of the holder, compliance with a legal obligation, court order, fulfillment of a public interest mission, execution of pre-contractual measures or fulfillment of contractual obligations, protection of vital interests, processing of data in public access databases, or satisfaction of a legitimate interest of the responsible party or a third party, provided that the interests or fundamental rights of the holders do not prevail.
What characteristics must the holder’s consent have for the processing of their personal data?
According to Article 8, the holder’s consent must be free, specific, informed, and unequivocal. It must be free from defects, specifically determine the means and purposes of the processing, comply with the principle of transparency, and leave no doubts about the scope of the authorization granted.
Can the holder revoke their consent? What effect does this revocation have?
Yes, the holder may revoke their consent at any time without justification, according to Article 8. The revocation does not have retroactive effects, and the processing carried out before the revocation remains lawful.
What is understood by legitimate interest in the processing of personal data?
Article 9 establishes that legitimate interest as a basis for the processing of personal data implies that only the data strictly necessary for the purpose can be processed. The responsible party must ensure transparency, and the Data Protection Authority may require a risk report to verify that there are no threats to the legitimate expectations of the holders and their fundamental rights.
What happens if the processing of data is based on the consent of the affected party for multiple purposes?
Article 8 establishes that if the processing of data is based on the consent of the affected party for several purposes, it must be stated that such consent is granted for all of them.
What are the rights of the holder of personal data regarding the information they must receive?
Article 12 establishes that the holder has the right to be informed about various aspects of the processing of their personal data, including the purposes of the processing, the legal basis, types of processing, retention time, existence of a database, origin of the data, identity and contact details of the responsible party, possibility of revoking consent, mechanisms to enforce their rights, among others. The information must be clear, simple, and accessible.
How should the right of access to personal data by the holder be handled?
According to Article 13, the holder has the right to know and obtain access to all their personal data and the detailed information in the preceding article, without justification. The responsible party must establish reasonable methods for exercising this right and attend to it within fifteen (15) days. It must not constitute an abuse of the right.
What rights does the holder have regarding the rectification and updating of their personal data?
Article 14 grants the holder the right to obtain the rectification and updating of their inaccurate or incomplete personal data. The responsible party must attend to the request within fifteen (15) days and, if applicable, inform the recipient of the data about the rectification.
Under what circumstances can the holder request the deletion of their personal data?
Article 15 establishes that the holder may request the deletion of their personal data when they do not comply with the principles of the law, are not necessary or relevant, have fulfilled the purpose, have expired the retention period, affect fundamental rights, consent is revoked, or there is a legal obligation.
What is the right of opposition and when can it be exercised?
Article 16 defines the right of opposition as the power of the holder to object or refuse the processing of their personal data in certain cases, such as when third-party rights are not affected, in the case of direct marketing, or when their consent is not necessary due to a legitimate interest. The request must be attended to within fifteen (15) days.
How is the right to data portability defined and applied?
Article 17 establishes the right to portability as the power of the holder to receive their personal data in a compatible format or transmit them to other responsible parties. The transfer must be economical, efficient, and without hindrance, and may proceed under certain conditions such as the holder’s consent, automated processing, a relevant volume of data, or compliance with obligations in the labor field.
What duties does the person responsible for processing have regarding the deletion of personal data?
According to Article 15, the person responsible for processing must implement methods and techniques to permanently and securely delete, render illegible, or make unrecognizable personal data. This obligation must be fulfilled within fifteen (15) days of receiving the request from the holder and will be free of charge.
What obligations do those responsible and in charge of personal data processing have regarding data security?
According to Article 37, they must adhere to the principle of personal data security, considering factors such as categories and volume of data, state of the art, and application costs. They must implement a continuous verification, evaluation, and assessment process of security measures, including measures such as anonymization, encryption, and improvement of technical, physical, and legal resilience.
How is the analysis of risk, threats, and vulnerabilities in personal data processing carried out?
Article 40 establishes that the responsible party and the person in charge must use a methodology that considers the particularities of the processing, the parties involved, and the categories and volume of personal data subject to processing.
When is an impact assessment of personal data processing mandatory?
According to Article 42, the impact assessment is mandatory when the processing entails a high risk to the rights and freedoms of the holder, in cases such as profiling, large-scale processing of special categories of data, or large-scale systematic observation of a publicly accessible area.
How should a personal data security breach be notified?
Articles 43 and 46 establish that the responsible party must notify the Personal Data Protection Authority and the Telecommunications Regulation and Control Agency within five (5) days. The person in charge must notify the responsible party within two (2) days. If there is a risk to the fundamental rights and individual freedoms of the holder, the responsible party must notify the holder within three days.
What guarantees must telecommunications service providers offer regarding the secrecy of communications and personal data security?
Article 45 establishes that telecommunications service providers must guarantee the secrecy of communications and the security of personal data. The recording of communications can only be carried out by court order, and any unauthorized processing will be sanctioned according to the law.
What corrective measures can the Personal Data Protection Authority dictate in case of non-compliance with the law?
The Personal Data Protection Authority may dictate measures such as the cessation of data processing under certain conditions or deadlines, the deletion of data, and the imposition of technical, legal, organizational, or administrative measures to ensure proper data processing.
How are corrective measures applied in the case of different degrees of infringement?
The application of corrective measures varies according to the severity of the infringement. For minor infringements, the administrative sanctioning procedure ill be activated directly. In the case of serious infringements, corrective measures ill first be applied, and if not properly complied with, sanctions ill be applied. For very serious infringements, the sanctioning procedure ill be activated directly.
What are the minor and serious infringements that the Responsible and the Data Protection Officer can commit?
Minor and serious infringements vary depending on the role of the Responsible or Data Protection Officer. Minor infringements include not processing requests from the holder, not implementing data protection from the design, among others. Serious infringements may include not implementing adequate security measures, using data for purposes other than those declared, not notifying security breaches, among others.
What sanctions are applied in the case of minor and serious infringements?
Sanctions vary according to the nature of the infringement and the offender. For minor infringements, sanctions may include fines of one to ten unified basic salaries or a percentage of the olumen of business. For serious infringements, fines may be between 10 to 20 unified basic salaries or between 0.7% and 1% of the olumen of business.
How is the olumen of business defined in the context of this law?
The volume of business refers to the amount resulting from the sale of products and the provision of services carried out by economic operators during the last fiscal year, after deducting Value Added Tax and other taxes directly related to the economic operation.
Conclusion
Ecuador’s personal data protection law is a robust legal framework that seeks to guarantee the rights of data holders. Understanding and complying with this law are essential for any entity that handles personal data within Ecuadorian territory.
If your organization needs expert advice on implementing personal data protection measures, we invite you to contact us. Our team of specialists in data protection law is committed to helping you comply with all legal obligations and ensuring that your business operates within the legal framework. Please do not hesitate to contact us for a detailed and personalized consultation.
EXPLANATORY NOTE: The text contained in this entry is for informational purposes only. Lince – Saltos & Associates is not and will not be responsible for any loss or damage caused as a result of having acted or failed to act based on the content of any of the notes in this document.