TwinEthos homeRequest access

Law

Ecuador SPDP rule on personal data in AI systems (SPDP-SPD-2026-0009-R)

Superintendencia de Protección de Datos Personales (SPDP) · EC · 2 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: spdp.gob.ec.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Tell data subjects when AI systems process their data, for what purposes, and that the processing is automated (Ecuador, SPDP Resolution 2026-0009-R Art. 5.1)

Resolution SPDP-SPD-2026-0009-R, Art. 5 opening and 5.1 (inform the data subject of processing through AI systems, its purposes and automated nature) · official text · In force: applies since 10 Mar 2026 · EC

From 2026-03-10, Ecuador's SPDP general rule on personal data in AI systems (Resolution SPDP-SPD-2026-0009-R) Art. 5.1 requires controllers and processors that process personal data in AI systems to inform the data subject clearly, specifically, determinately and transparently about the processing carried out through AI systems, including its purposes and its automated nature. It binds anyone who develops, trains, implements, deploys or provides AI systems processing Ecuadorian data subjects' data, wherever located. Detect a privacy notice that never describes the AI processing and its automated nature.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Mar 2026
Official source
Resolution SPDP-SPD-2026-0009-R, Art. 5 opening and 5.1 (inform the data subject of processing through AI systems, its purposes and automated nature) · captured 2 Oct 2026 · anchor hash (SHA-256) 4612e6655250… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Notices outside the repository
  • In-product notices at the AI feature
  • The notice may be served from a CMS outside the repository; a repository copy may lag the published notice.

Who it applies to

  • Duty falls on: controller, processor
  • Controllers and processors that develop, train, implement, deploy or provide AI systems processing personal data of data subjects in Ecuador, wherever the system or provider is located: inform data subjects of the processing through AI systems, its purposes and its automated nature. In force since publication in Registro Oficial No. 240 (2026-03-10). The reform 2026-0037-R (signed 2026-09-09; publication not confirmed) narrows processors' duties to those with access, visibility or effective control of the data; whether it is in force, and how the LOPDP's information duties combine with Art. 5.1, are questions for counsel (review flag).
  • Not covered:
    • AI systems that do not process personal data within the LOPDP's material and territorial scope (Art. 1, third paragraph)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Describe the AI processing in the notice at collection in plain language, and wire an objection route that stops it for the person.

A section of the privacy notice, and a short notice at the AI feature itself, that says an AI system processes the person's data, for which purposes, that the processing is automated, and what the main risks are, in plain language for the people who use the feature (children included where they can use it). Next to it, an objection route (a setting, form or endpoint) that records the objection and that the AI pipeline checks before processing that person's data, so objecting has an effect rather than only being stated.

Where it goes: 1 application source code, 2 data models, 14 user-facing text.

What this provision adds:

  • Inform the data subject clearly, specifically and transparently that their data is processed by AI systems, for which purposes, and that the processing is automated.

Example (Privacy notice (informativa)), before:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

After:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

### Uso dell'intelligenza artificiale
Le domande che scrivi all'assistente sono elaborate da un sistema di intelligenza artificiale per
risponderti e per classificare la richiesta. Il trattamento e' automatizzato; i rischi principali sono
risposte inesatte e l'invio del testo al nostro fornitore del modello. Puoi opporti in ogni momento da
Impostazioni > Privacy > Assistente IA: da quel momento i tuoi dati non sono piu' inviati al modello.

Control: People whose data an AI feature processes are not told about that processing in plain language, or not told how to object. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ec-spdp-ai.ai-processing-information · review status: primary source derived

Binding law — in force

Risk management and an impact assessment before developing an AI system that processes personal data (Ecuador, SPDP Resolution 2026-0009-R Arts. 5.2, 6)

Resolution SPDP-SPD-2026-0009-R, Art. 6 (risk management and impact assessment before developing the AI system) · official text · In force: applies since 10 Mar 2026 · EC

From 2026-03-10, Ecuador's SPDP rule on personal data in AI systems requires controllers and processors, before developing an AI system that processes personal data, to carry out risk management and an impact assessment under the LOPDP, its General Regulation and SPDP rules (Art. 6), and to carry out risk management and impact assessments for personal data protection when processing personal data in AI systems (Art. 5.2). An organizational duty: the assessment is a document, not code.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Mar 2026
Official source
Resolution SPDP-SPD-2026-0009-R, Art. 6 (risk management and impact assessment before developing the AI system) · captured 2 Oct 2026 · anchor hash (SHA-256) ae6b1bba1f4d… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 9 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Code cannot show this item: the evidence is a kept record or process.

Who it applies to

  • Duty falls on: controller, processor
  • Controllers and processors that develop AI systems processing personal data of data subjects in Ecuador: risk management and impact assessment before development, and risk management and impact assessments while processing. In force since 2026-03-10. When an impact assessment is mandatory under the LOPDP and its General Regulation, and whether the 0037-R reform (processors with access, visibility or control) applies, are questions for counsel (review flag).
  • Not covered:
    • AI systems that do not process personal data within the LOPDP's material and territorial scope (Art. 1, third paragraph)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.

A per-system impact assessment, distinct from the organizational risk register, that looks outward: intended use and context, who is affected (individuals, groups including vulnerable ones, society), foreseeable benefits and harms (rights, safety, fairness, access, wider societal effects), reasonably foreseeable misuse, mitigations, residual impact, and sign-off. The AI system owner maintains it within the AI management system and revisits it before release and on any material change of model, data, or use. Keep it next to the model card and have a release check confirm a current assessment exists for each deployed system.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

What this provision adds:

  • Complete the risk management and the impact assessment before development starts, following the LOPDP, its General Regulation and SPDP rules.

Example (Impact assessment record (docs/impact/)), before:

# Resume screener
Risk: low. Approved.

After:

# AI system impact assessment: resume screener (v3, 2026-09-01)
- Intended use: rank applications for recruiter review; no automatic rejection
- Affected: applicants; groups at risk: career-gap, non-native-language applicants
- Harms: unfair exclusion, opaque ranking; societal: narrowing of hiring pools
- Mitigations: subgroup ranking audit each release; recruiter sees all applicants
- Residual impact: medium, accepted by Head of Talent (signed 2026-09-03)
- Revisit: on model, feature, or use change

Control: AI system deployed without an AI system impact assessment. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id ec-spdp-ai.assessment-before-development · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.