Boletines
2026-09-16
Resolution No. SPDP-SPD-2026-0040-R – New Technical Standard on the Notification of Personal Data Security Breaches
The Superintendency for the Protection of Personal Data (SPDP) issued a technical standard establishing the procedure for notifying personal data security breaches. It applies to data controllers and processors subject to the Organic Law on the Protection of Personal Data (LOPDP).
The obligation covers incidents that affect or may affect the confidentiality, integrity, or availability of data. Accordingly, it includes leaks, unauthorized access, loss, alteration, or unavailability of personal information.
Main obligations for companies
- Timely escalation: the processor must inform the controller within a maximum of two days. Once the controller has received the communication, it must notify the SPDP within a term of five days.
- Reporting to the SPDP: the notification is submitted digitally through the National Personal Data Registration System (SISPDP): https://servicios.spdp.gob.ec. The system issues a receipt confirmation that must be retained.
- Communication to data subjects: when applicable, it must be clear, accessible, and timely; it must describe the breach, indicate the date of detection or the estimated period, the measures adopted, and protection recommendations.
- Contact channels: communication must be carried out through the usual channels used to relate to data subjects. Publication through mass media is only appropriate if the organization does not have a pre-established official channel.
Aspects of greatest impact
Failure to make the required notifications may constitute a serious infraction under the LOPDP. Notifications received will be evaluated by the SPDP and may be referred to the General Intendancy for Control and Sanction.
Confidentiality breaches warrant a priority response: the SPDP considers them essentially permanent, given that exposed data may subsequently be used, distributed, or published. The exposure of sensitive data or special categories increases the level of risk.
Recommended actions
- Update your incident response protocol to incorporate risk assessment for data subjects and regulatory deadlines.
- Define an internal escalation matrix among technology, information security, legal, compliance, communications, and the Data Protection Officer, when applicable.
- Adjust contracts with data processors to require notice within two days and to establish an electronic communication channel.
- Prepare notification formats and evidence records to document the incident, its containment, and the decisions adopted.
- Review access controls, backups, continuity, and recovery, prioritizing higher-risk processing activities.
Effective Date
The Resolution was signed on September 9, 2026, and enters into force upon its publication in the Official Registry. It is recommended to confirm this publication to determine the exact enforceability date.
Should you require advice regarding the notification of security breaches, please contact our Personal Data Protection team.
This document does not constitute legal opinion; it is intended for general informational purposes only.
Should you require specific advice, please contact us at the following addresses:
Share
Related News
Related Practice Areas
RELATED PROFESSIONALS


