Skip to main content
Data protection

Resolution No. SPDP-SPD-2026-0040-R

Escrito por:

Executive Summary

Overview of the technical standard

What it regulates. The technical standard governs two processes. The first is how data controllers and data processors must notify personal data security breaches; and the second is how the Superintendency of Personal Data Protection (the “SPDP”) manages the notifications it receives.

To whom it applies. Its scope is the same as that of the Organic Law on Personal Data Protection (the “LOPDP”). In practice, it covers any public or private organization that processes personal data under that law, whether as a data controller or data processor. The data controller is the party that decides on the processing. The data processor processes data on behalf of the data controller, for example, a cloud or IT services provider.

Who issues it and when it takes effect. The Resolution was issued by the SPDP and entered into force on September 24, 2026.

Key concepts:

  • Personal data protection incident: a security event that has compromised, or is likely to compromise, the confidentiality, integrity, or availability of personal data.
  • Three types of breach: confidentiality, integrity, and availability. The same incident may result in more than one type.
  • Dimensions (temporal severity). Integrity and availability breaches may be: 1) temporary if they can be restored; 2) permanent if the data cannot be recovered; or 3) irreversible if there is no technical possibility of restoring it. Confidentiality breaches are “essentially permanent” because data that has already been accessed may be used or published at any time. In addition, they are considered irreversible when the data subject cannot change the data, especially if it is sensitive data.
  • SISPDP: National Personal Data Registry System. It is the portal where notifications are received by the SPDP, at https://servicios.spdp.gob.ec.
  • AIxSPDP: expert support system based on “agentic” artificial intelligence,[1] with human intervention at every stage. The standard expressly clarifies that it is not an automated decision-making system.

Obligations by type of party

PartyRequired Actions
Data controller• Notify the SPDP of the breach through the SISPDP and by digital means, via the web portal: https://servicios.spdp.gob.ec.
 • Notify data subjects in clear and simple language. The communication must include, at a minimum: 1) the nature of the breach; 2) the date of detection or the estimated period (where possible); and 3) the measures adopted and recommendations for data subjects.
 • Use its usual communication channels with data subjects, announcements on its website, email, or other direct means.
 • Publish in a mass medium only if it does not have an official channel pre-established with data subjects, respecting the principles of minimization and relevance.
 • Adopt technological, physical, administrative, organizational, and legal measures to prevent, reduce, and mitigate risks.
Data processor• Notify the data controller of the breach within a maximum period of two days.
 • Send the information required by the General Regulations of the LOPDP (the “RGLOPDP”).
 • Communicate it by email, unless the data processing agreement designates another electronic means.
SPDP – IIT (Office of the Superintendent for Technological Innovation and Data Security)• Manage notifications confidentially and for preventive, investigative, analytical, and statistical purposes.
 • Review and oversee, with human intervention, the analysis produced by the AIxSPDP, and decide whether to refer the case to the ICS.
 • Monitor cases that are not referred, to determine whether the risk increases over time.
SPDP – ICS (Office of the Superintendent for Oversight and Sanctions)• Receive cases referred by the IIT with a reasoned and signed report recommending that an oversight proceeding be initiated.
SPDP (institutional)• Publish the AIxSPDP risk models and ontologies on its website within six months. Ontologies are the schemas used by the system to classify information.
 • Publish updates to those models.
 • Coordinate, where appropriate, with ARCOTEL, incident response teams (CSIRT/CERT), and foreign authorities.

Key deadlines

DeadlineObligationConsequence of Non-Compliance
Maximum 2 daysThe data processor notifies the data controller.The LOPDP sanctions regime and the terms agreed in the data processing agreement apply.
5 business days from when the data controller receives the communicationThe data controller notifies the SPDP.Failure to notify the SPDP is a serious infringement under the LOPDP.
3 business days from when it became aware of the risk (LOPDP)The data controller notifies the data subjects.Failure to notify the data subjects is a serious infringement under the LOPDP.
6 months from the entry into forceThe SPDP publishes its risk models and AI ontologies.–
6 months from the entry into forceThe internal process manuals prepared by the IIT are reviewed.–

Additional relevant information (practical impact)

  • Mandatory digital channel. Notification to the SPDP is made through the SISPDP. Other official channels are permitted only if the system is unavailable, and the SPDP will verify that circumstance before validating the notification. It is advisable to document any system outage with screenshots and the time.
  • Acknowledgment of receipt. Upon submitting the form, the SISPDP automatically generates an acknowledgment and sends it to the email address from which the notification was submitted. It is recommended that the notification be submitted from a controlled corporate inbox, not a personal one.
  • AI filter and human review. The AIxSPDP discards forms that are not breach notifications and validates those that meet the requirements of the RGLOPDP. It then estimates the risk level, and a human team reviews the result before deciding whether the case proceeds to oversight. An incomplete or poorly structured notification may be delayed or not processed.
  • “Monitoring status.” Cases that are not referred to the ICS remain under monitoring under the supervision of the IIT, particularly confidentiality breaches, whose impact may appear later. Therefore, the fact that an oversight proceeding is not opened immediately does not close the regulatory risk.
  • Confidentiality of notifications. Notifications are handled confidentially and subject to strict access controls.
  • Cooperation among authorities. The SPDP may coordinate with ARCOTEL, CSIRT/CERT, and, in incidents with international scope, with data protection authorities in other countries. For multinational groups, this requires coordinating notifications in the different jurisdictions.
  • Data processing agreements (DPAs). Email is the default channel between the data processor and the data controller, unless the agreement specifies another electronic means. It is advisable to review agreements with providers to define contacts, the channel, the two-day period, and the minimum content of the communication.
  • Evolving standard. The SPDP may update the standard at any time based on technological developments.

Legal Notice. This executive summary does not constitute legal advice, and each situation should be assessed case by case with a qualified professional. The points raised are general observations based on the text of the technical standard. They do not replace a full legal analysis of the LOPDP, its General Regulations, or other applicable provisions, to which the standard itself refers. In addition, the SPDP may revise and update the technical standard at any time. It is therefore advisable to confirm that the standard is in force and to check its current text before making any decisions.


[1]“Agentic AI is an artificial intelligence system that can accomplish a specific goal with limited supervision. It consists of AI agents-machine learning models that mimic human decision-making to solve problems in real time. In a multiagent system, each agent performs a specific subtask required to reach the goal and their efforts are coordinated through AI orchestration.” Striker, C. What is agentic AI? https://www.ibm.com/mx-es/think/topics/agentic-ai


© TobarZVS 

This publication contains information of general interest and does not constitute legal opinion on specific issues. Any analysis will require legal advice from the Firm.