{
 "jurisdiction_id": "EC",
 "jurisdiction": "Ecuador",
 "url": "https://dataprotection.gi/jurisdictions/ecuador/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 54,
  "sub_modules": 57,
  "source_register": 49
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, actively enforced, single-instrument regime with a fully operational independent supervisor; only source of amber risk is the pending Digital Omnibus reform tracked in enforcement_and_redress.recent_developments_180d.",
   "claims": [
    {
     "statement": "The European Data Protection Supervisor (EDPS) is the independent supervisory authority responsible for monitoring the processing of personal data by EU institutions and bodies, advising on policies/legislation affecting privacy, and cooperating with other supervisory authorities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases/2025/edps-reprimands-frontex-non-compliance-regulation-eu-20191896_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions and bodies when they process personal data and repeals Regulation (EC) 45/2001, adopting a principle-based approach in line with the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/subjects/regulation-20181725_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The processing of operational personal data by Europol and the European Public Prosecutor's Office is excluded from the scope of the EUDPR and instead governed by specific provisions in their founding legal acts, though their administrative processing of personal data (e.g. staff management) is subject to the Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/EN/legal-content/summary/protection-of-individuals-with-regard-to-the-processing-of-personal-data-by-eu-institutions-bodies-offices-and-agencies.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "After designation, the data protection officer of a Union institution or body shall be registered with the European Data Protection Supervisor by the institution or body which designated him or her.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Substantively aligned with GDPR; anonymisation/pseudonymisation boundary is an active area of guidance development, not a gap.",
   "claims": [
    {
     "statement": "Article 5 of Regulation (EU) 2018/1725 sets out the lawfulness-of-processing principle governing which legal bases a Union institution or body may rely upon, mirroring the structure of GDPR Article 6.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://edps.europa.eu/sites/edp/files/publication/19-09-27_admin_fines_sanctions_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where processing is based on consent, the controller must be able to demonstrate that the data subject consented, and withdrawal of consent must be as easy as giving it, without affecting the lawfulness of prior processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 10 of the EUDPR restricts processing of data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data on sex life/sexual orientation, subject to enumerated exceptions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/en/LSU/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 8 July 2026, the EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, bringing clarity to the notion of anonymous data, taking into account the CJEU ruling in Case C-413/23 P EDPS v SRB of 4 September 2025.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/node_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is comprehensive and actively supervised; some rights may be restricted under Art 25 internal-rules mechanism for specified public-interest grounds (investigations, security), which is a lawful derogation, not a gap.",
   "claims": [
    {
     "statement": "The right of access under EUDPR allows a data subject to obtain confirmation that data concerning him or her are processed, the purposes of processing, and the logic involved in automated decisions, exercisable without unnecessary constraints, at any time, free of charge.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/system/files/2024-02/EDPS2024-04-CEA-right-of-access_EN.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The data subject has the right to obtain from the controller rectification of inaccurate personal data without undue delay, including completion of incomplete data by supplementary statement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The right to erasure is enshrined in Article 19 of the EUDPR for EUIs, with similarities to Article 17 GDPR for EU/EEA countries; the EDPS conducted a fourth Coordinated Enforcement Action fact-finding exercise on EUI compliance with the right to erasure in 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases/2025/edps-participates-fourth-coordinated-enforcement-action-focus-right-erasure-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPS may order the rectification or erasure of personal data or restriction of processing pursuant to Articles 18, 19 and 20 of the EUDPR, and notify such actions to recipients to whom the data have been disclosed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/sites/default/files/publication/19-09-27_powers_of_edps_under_regulation_eu_2018-1725_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Article 22, the data subject has the right to receive personal data concerning him or her in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The data controller must respond to a data subject's request for access to their personal data without undue delay and in any event within one month from receipt, which may be extended by two further months where necessary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/data-protection/glossary/r_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Fully codified and actively supervised (breach-notification web-portal, DPIA lists, DPO dismissal-consent rules updated January 2026); no material gaps identified.",
   "claims": [
    {
     "statement": "Article 39(1) of Regulation (EU) 2018/1725 requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons, with Article 39(3) providing a non-exhaustive illustrative list.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_recommendation_201901_edps_39.4_dpia_list_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EU institutions, bodies, offices and agencies are required to designate a Data Protection Officer, and the Regulation establishes that a DPO may not be dismissed or penalised by the controller for performing their tasks without the EDPS's prior consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202600199",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPS Decision 01/2026 of 16 January 2026 establishes detailed procedural rules on the requirement of prior EDPS consent for the dismissal of DPOs, requiring EUIs to submit a complete dismissal request with supporting documentation before any intended dismissal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202600199",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Each controller shall maintain a record of processing activities under its responsibility in writing, including electronic form, and Union institutions and bodies shall keep their records in a central, publicly accessible register unless inappropriate given their size.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/data-protection/glossary/r_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 28 (joint controllers) of the EUDPR is among the provisions for which infringement can be sanctioned with an administrative fine under Article 66.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://edps.europa.eu/sites/edp/files/publication/19-09-27_admin_fines_sanctions_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 33 (security of processing) is expressly listed among the infringements for which fining is set out under Article 66 of the EUDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://edps.europa.eu/sites/edp/files/publication/19-09-27_admin_fines_sanctions_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EUDPR introduces a duty on all EU institutions and bodies to report certain types of personal-data breach to the EDPS within 72 hours of becoming aware of the breach, where feasible, and to inform affected individuals without undue delay if the breach is likely to result in high risk.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/subjects/data-breach_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data processed under the EUDPR must be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the data are processed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/en/LSU/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Framework is complete, but EUDPR itself does not generate adequacy decisions (it relies on GDPR Art 45(3)/LED Art 36(3) decisions) — a structural cross-reference rather than a gap, tracked here as amber for interoperability clarity.",
   "claims": [
    {
     "statement": "Any judgment of a court or tribunal, or decision of an administrative authority, of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the absence of an adequacy decision pursuant to Article 45(3) of the GDPR or Article 36(3) of the Law Enforcement Directive, or of appropriate Article 48 safeguards, an EUI transfer to a third country or international organisation may take place only under enumerated conditions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Data Protection Supervisor may adopt standard contractual clauses for EUI international-transfer purposes, and pre-existing SCCs/BCRs adopted under the old Directive 95/46 remain valid but must be adapted to Regulation (EU) 2018/1725 before continued use.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/sites/default/files/publication/flowcharts_and_checklists_on_data_protection_brochure_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 17 September 2025, the EDPS issued an Opinion on the negotiating mandate for a framework agreement between the EU and the United States on the exchange of information for security screenings and identity verifications, functioning as a de facto transfer-risk assessment for a major international data-sharing instrument.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Transmissions of personal data to recipients established in the Union other than Union institutions and bodies are subject to additional safeguard conditions under the EUDPR, distinct from the stricter third-country transfer regime of Articles 46-50.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "green",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are well-documented for financial-supervision and health agencies; credit-scoring and education have no dedicated EUI sub-regime, which is expected given the nature of Union institutions rather than a compliance gap.",
   "claims": [
    {
     "statement": "ESMA, following Article 25 of Regulation (EU) 2018/1725 and after an EDPS opinion, adopted internal rules permitting it to restrict data-subject rights of access, rectification, erasure and restriction of processing in the context of its investigations or inquiries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019Q1125(01)",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPS Decision 46/2026 authorises the use of an administrative arrangement based on the EDPS Model Administrative Arrangement for transfers of personal data from the European Medicines Agency to the Council of Europe's EDQM, pursuant to Article 48(3)(b) of the EUDPR, in the context of a medicines sampling and testing cooperation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/subjects/regulation-20181725_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services alongside the EUDPR, and is due to be repealed/amended as part of the Digital Omnibus proposal.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/data-protection/legislation_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPS's February 2025 Newsletter reports an EDPS reprimand issued to EPSO (the EU Personnel Selection Office) concerning its data-processing practices, alongside continued monitoring of AI use in EUI recruitment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/publications/newsletters/newsletter-113_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EIOPA adopted a Decision, following Article 25 of Regulation (EU) 2018/1725 and after consulting the EDPS, laying down rules restricting data-subject rights (access, rectification, erasure, restriction) in the framework of its supervisory procedures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019Q0826(01)",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core cookie/consent-signal policy is in active reform (Digital Omnibus); several sub-modules are genuinely inapplicable to the EUI-controller context rather than gaps.",
   "claims": [
    {
     "statement": "The ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services and is targeted for amendment by the Digital Omnibus proposal alongside the GDPR and EUDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/data-protection/legislation_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and the EDPS strongly support the Digital Omnibus's objective of addressing consent fatigue and cookie-banner proliferation via automated, machine-readable indications of individuals' processing choices.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPS newsletter reporting flags scrutiny of whether the European Commission organised a micro-targeting campaign on the social-media platform X, indicating active EDPS review of EUI targeted-communications practices.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/publications/newsletters/newsletter-113_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "green",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Mature, actively-resourced supervisory framework (dedicated EDPS AI Unit since Oct 2024, published AI Compass 2026-2027); amber risk only from the pending Digital Omnibus on AI timeline changes.",
   "claims": [
    {
     "statement": "Automated individual decisions under Article 24 of the EUDPR shall not be based on special categories of personal data referred to in Article 10(1), unless narrow exceptions apply with suitable safeguards for the data subject's rights, freedoms and legitimate interests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The right of access allows a data subject to obtain from the controller confirmation of processing, the purposes, and the logic involved in any automated decision process concerning him or her.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/system/files/2024-02/EDPS2024-04-CEA-right-of-access_EN.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPS's mapping exercise for its AI Act role identified more than one hundred AI systems currently deployed or under development across EUIs, with the highest concentration of high-risk use cases in the Area of Freedom, Security and Justice and in employment/recruitment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/system/files/2026-03/26-03-17_edps-compass-under-ai-act-2026-2027_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 43(1) of the AI Act designates the EDPS as a notified body in charge of conformity assessment for high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation and emotion recognition under Annex III(1) of the AI Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/system/files/2026-03/26-03-17_edps-compass-under-ai-act-2026-2027_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Genetic data is enumerated as a special category of personal data under Article 10 of the EUDPR, subject to restrictive processing conditions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_recommendation_201901_edps_39.4_dpia_list_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Legal acts adopted on the basis of the Treaties, or internal rules on the operation of Union institutions and bodies, may restrict Articles 14-22, 35-36 EUDPR where the restriction respects the essence of fundamental rights and is a necessary and proportionate measure in a democratic society, and such restrictions must be clear, precise, published in the Official Journal, and adopted at the highest management level.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core child-consent rule is codified and confirmed, but education-settings and dependent-adults sub-modules have no dedicated EUI content, and minor-specific profiling bans are inferred rather than explicit.",
   "claims": [
    {
     "statement": "Where point (d) of Article 5(1) of the EUDPR applies, in relation to the offer of information society services directly to a child, the processing of a child's personal data is lawful where the child is at least 13 years old.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a child is below the age of 13, EUDPR processing of the child's information-society-service data is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this, taking into consideration available technology.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32018R1725",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 4 July 2025, the EDPS and EDPB Trainees organised the 'From Cradle to Cloud: Surveillance and Digitalisation around Childhood' conference to foster discussion on the digital rights of children and minors, reflecting active but non-binding EDPS engagement on minors' data protection.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/subjects/charter-fundamental-rights/article-8-right-data-protection_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ecuador/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "EDPS enforcement toolkit is active and demonstrably used against major EUIs (including the European Commission itself); amber-adjacent risk stems only from pending Digital Omnibus changes to underlying substantive rules, not from an enforcement capacity gap.",
   "claims": [
    {
     "statement": "Article 58 of Regulation (EU) 2018/1725 confers the EDPS a wide range of investigative powers including risk-based compliance audits, and corrective powers including ordering rectification/erasure/restriction, imposing administrative fines under Article 66 for non-compliance with EDPS orders, and ordering suspension of data flows to a recipient in a Member State, third country, or international organisation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/sites/default/files/publication/19-09-27_powers_of_edps_under_regulation_eu_2018-1725_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Court of Justice of the European Union has unlimited jurisdiction to review administrative fines imposed by the EDPS under Article 66, and may cancel, reduce or increase those fines within the limits of that Article.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following enforcement proceedings by the EDPS, the European Commission demonstrated compliance with Regulation (EU) 2018/1725 in relation to its use of Microsoft 365, following the EDPS's Decision of 8 March 2024 which had identified infringements and imposed corrective measures, with compliance confirmed by 9 December 2024.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 8 January 2025, the EDPS issued a reprimand to Frontex for infringing Regulation (EU) 2019/1896 by systematically sharing personal data of suspects of cross-border crime with Europol without assessing whether such sharing was strictly necessary, following an EDPS audit opened in October 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases/2025/edps-reprimands-frontex-non-compliance-regulation-eu-20191896_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The budgetary authority shall ensure that the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with the EDPS budget shown in a separate budgetary heading of the Union's general budget.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on the data subject's behalf.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/EN/legal-content/summary/protection-of-individuals-with-regard-to-the-processing-of-personal-data-by-eu-institutions-bodies-offices-and-agencies.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Any person who has suffered material or non-material damage as a result of an infringement of the EUDPR has the right to receive compensation from the responsible Union institution or body, subject to the conditions provided for in the Treaties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2018/1725/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, which amends Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and several directives, following the Commission's formal consultation under Article 42(2) EUDPR on 25 November 2025.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/press-publications/press-news/press-releases/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key-concerns_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB launched its 2026 Coordinated Enforcement Framework action on 19 March 2026, shifting focus from the 2025 right-to-erasure action to compliance with transparency and information obligations under Articles 12-14 GDPR, with 25 DPAs participating during 2026.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/cef-2026-edpb-launches-coordinated-enforcement-action-on-transparency-and-information_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "At a high-level meeting in Dublin on 16-17 July 2026, the EDPB called for a clear legal basis for the sharing of information among regulators with different competences, and discussed expanding cooperation to support consistent GDPR application.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/node_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}