Binding law — in force AI-adjacent law
Decisions based solely or partly on automated assessments: notice of the right at first communication, explanation and contest (Ecuador LOPDP Arts. 20-21)
Ecuador's Organic Personal Data Protection Law gives the data subject a right not to be subject to a decision based solely or partly on assessments produced by automated processes, including profiling, that produces legal effects on them or infringes their fundamental rights and freedoms; to that end they may ask the controller for a reasoned explanation of the decision, make observations, ask for the assessment criteria of the automated program, ask for the types of data used and their source, and contest the decision before the controller or processor (Art. 20). The right does not apply where the decision is necessary for a contract, is authorised by applicable rules, a court order or a reasoned order of a competent technical authority with suitable safeguards, rests on the data subject's explicit consent, or carries no serious impacts or verifiable risks for the data subject. The right cannot be waived in advance through mass adhesion contracts, and it must be reported explicitly, by any suitable means, no later than the first communication with the data subject that reports a decision based solely on automated assessments. For children and adolescents, sensitive data or children's data may not be processed in such decisions without the express authorisation of the data subject or their legal representative, or an essential public interest with specific safeguards (Art. 21). Detect a model output that becomes a decision about a person with no automated-decision notice and contest route, and no human decision.
Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 26 May 2021
- Official source
- Cover (Registro Oficial, Year II, No. 459, 70 pages; Quito, Wednesday 26 May 2021) · captured 3 Oct 2026 · anchor hash (SHA-256)
24a6b66db939…· 7 more anchors in the data release - Verification
- Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- The criteria-of-assessment and data-source requests are not detected separately
- Art. 21 (children's and sensitive data in automated decisions) is not detected
- Advance waivers in adhesion contracts are not detected
1 more known limit in the data release.
Who it applies to
- Duty falls on: controller, processor
- Systems covered: automated decision, consequential decision
- Controllers and processors processing personal data in Ecuador, domiciled in Ecuador, or outside Ecuador when the processing relates to offering goods or services to data subjects residing in Ecuador or monitoring their behaviour there, or when Ecuadorian law applies by contract or public international law (Art. 3), that take decisions based solely or partly on automated assessments, including profiling, with legal effects or effects on fundamental rights. In force since publication in the Registro Oficial on 2021-05-26. How the 'partly' automated reach, the fourth exception (no serious impacts or verifiable risks) and the two-year transitional period for processing that predated the Law apply are counsel questions.
- Not covered:
- Natural persons using the data in family or domestic activities; deceased persons (subject to Art. 28); anonymised data while the data subject cannot be identified; journalistic activities and other editorial content (Art. 2(a)-(d))
- Personal data whose processing is governed by specialised rules of equal or higher rank on natural-disaster risk management and State security and defence; data or databases for preventing, investigating, detecting or prosecuting criminal offences or executing criminal penalties by competent State bodies; data identifying legal persons (Art. 2(e)-(g))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.
Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.
What this provision adds:
- At the latest in the first communication reporting a decision based solely on automated assessments, tell the person explicitly of their Art. 20 right.
- Let the person ask for a reasoned explanation, make observations, ask for the assessment criteria and the types and source of the data used, and contest the decision before the controller or processor.
- Do not make the person waive the right in advance in a mass adhesion contract.
- For children and adolescents, use no sensitive or children's data in the decision without express authorisation of the data subject or their legal representative, unless an essential public interest with specific safeguards applies (Art. 21).
Example (Python + OpenAI SDK), before:
verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
deny(applicant)
send_decision_email(applicant, 'Your application was not approved.')After:
out = client.chat.completions.create(model=MODEL, messages=msgs,
response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
if requires_human_review('credit'): # a person decides
review_queue.enqueue(applicant.id, proposal=result)
else: # solely automated, recorded basis
deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 18 items with binding law in 18 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id ec-lopdp-art20.automated-decision-rights · review status: primary source derived