🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
EC · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 49 sources retrieved model claude-sonnet-5 ·

Ecuador

EC schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 54 claims · 49 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
54Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, actively enforced, single-instrument regime with a fully operational independent supervisor; only source of amber risk is the pending Digital Omnibus reform tracked in enforcement_and_redress.recent_developments_180d.

Primary frameworkRegulation (EU) 2018/1725 (EUDPR)
Traffic-light rationale — GreenComprehensive, actively enforced, single-instrument regime with a fully operational independent supervisor; only source of amber risk is the pending Digital Omnibus reform tracked in enforcement_and_redress.recent_developments_180d.

Sub-modules (5)

Regulator And AuthorityGreen

The EDPS is the independent supervisory authority responsible for monitoring and enforcing EUDPR compliance across ~80 EU institutions, bodies, offices and agencies; Wojciech Wiewiórowski holds the post.

Claims: CLM-EC-a1b2c3d4

Act And InstrumentsGreen

Core instrument is Regulation (EU) 2018/1725, supplemented by Commission Decision (EU) 2020/969 (DPO/restrictions implementing rules) and the EDPS Rules of Procedure.

Claims: CLM-EC-b2c3d4e5

Material ScopeGreen

EUDPR governs processing of personal data by Union institutions and bodies, including administrative processing by Europol/EPPO for staff matters; operational law-enforcement data of Europol/EPPO is carved out to their own founding legal acts, and a specific EUDPR chapter aligned with the Law Enforcement Directive applies to EU bodies processing operational data (e.g. Eurojust).

Claims: CLM-EC-c3d4e5f6

Territorial ScopeAmber

EUDPR has no GDPR-style extraterritorial reach over non-EU private controllers; it applies to Union institutions and bodies as controllers regardless of where their processing physically occurs. This is a structurally different scope concept than GDPR Art 3, and should not be conflated with it.

Regulator Registration And FilingGreen

Each EUI must designate a DPO who is registered with the EDPS after designation; EUIs must also maintain a Record of Processing Activities (ROPA) under Art 31, made publicly accessible via a central register where feasible.

Claims: CLM-EC-d4e5f6a7

Category narrative90 words

JID=EC covers the data-protection regime applicable to the EU institutions, bodies, offices and agencies (EUIs) themselves — i.e. the European Commission, Parliament, Council, agencies, EU IT-systems bodies, etc. — as controllers, NOT the GDPR regime applicable to private/public-sector controllers inside EU Member States (that is the domain of the 27 MS JIDs). The operative instrument is Regulation (EU) 2018/1725 (the 'EUDPR'), which replaced Regulation (EC) 45/2001 and mirrors the GDPR's principle-based architecture but is a distinct, self-contained legal instrument with its own supervisory authority, the European Data Protection Supervisor (EDPS).

Sources and claims (4)
  1. ConfirmedEDPSThe European Data Protection Supervisor (EDPS) is the independent supervisory authority responsible for monitoring the processing of personal data by EU institutions and bodies, advising on policies/legislation affecting privacy, and cooperating with other supervisory authorities.
  2. ConfirmedEDPSRegulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions and bodies when they process personal data and repeals Regulation (EC) 45/2001, adopting a principle-based approach in line with the GDPR.
  3. ConfirmedPublications Office of the EUThe processing of operational personal data by Europol and the European Public Prosecutor's Office is excluded from the scope of the EUDPR and instead governed by specific provisions in their founding legal acts, though their administrative processing of personal data (e.g. staff management) is subject to the Regulation.
  4. ConfirmedPublications Office of the EUAfter designation, the data protection officer of a Union institution or body shall be registered with the European Data Protection Supervisor by the institution or body which designated him or her.

#

Substantively aligned with GDPR; anonymisation/pseudonymisation boundary is an active area of guidance development, not a gap.

Primary frameworkRegulation (EU) 2018/1725, Chapter II
Traffic-light rationale — GreenSubstantively aligned with GDPR; anonymisation/pseudonymisation boundary is an active area of guidance development, not a gap.

Sub-modules (4)

Lawful BasesGreen

Art 5 EUDPR sets the enumerated lawful bases for EUI processing (consent, contract, legal obligation, vital interests, public-interest task/official authority) as the EUI-context analogue of GDPR Art 6.

Claims: CLM-EC-e5f6a7b8

Special CategoriesGreen

Art 10 restricts processing of special-category data (ethnic/racial origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, sex life/orientation), with Art 11 governing criminal-conviction data.

Claims: CLM-EC-a7b8c9d0

Pseudonymisation And AnonymisationGreen

The EDPB, sitting alongside the EDPS's own guidance function, adopted guidelines on anonymisation in July 2026 clarifying the notion of anonymous data in light of CJEU case-law directly involving an EUI (EDPS v SRB), of direct relevance to EUI compliance practice.

Claims: CLM-EC-b8c9d0e1

Category narrative52 words

EUDPR Chapter II mirrors GDPR Arts 5-11: lawfulness of processing (Art 5), conditions for consent (Art 7), special categories (Art 10), and criminal-conviction data (Art 11). Recent EDPB/EDPS guidance (July 2026) on anonymisation clarifies the boundary between personal and anonymous data post-CJEU C-413/23 P EDPS v SRB, directly relevant to EUI processing.

Sources and claims (4)
  1. ConfirmedEDPSArticle 5 of Regulation (EU) 2018/1725 sets out the lawfulness-of-processing principle governing which legal bases a Union institution or body may rely upon, mirroring the structure of GDPR Article 6.
  2. ConfirmedPublications Office of the EUWhere processing is based on consent, the controller must be able to demonstrate that the data subject consented, and withdrawal of consent must be as easy as giving it, without affecting the lawfulness of prior processing.
  3. ConfirmedPublications Office of the EUArticle 10 of the EUDPR restricts processing of data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data on sex life/sexual orientation, subject to enumerated exceptions.
  4. ConfirmedEDPBOn 8 July 2026, the EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, bringing clarity to the notion of anonymous data, taking into account the CJEU ruling in Case C-413/23 P EDPS v SRB of 4 September 2025.

#

Rights framework is comprehensive and actively supervised; some rights may be restricted under Art 25 internal-rules mechanism for specified public-interest grounds (investigations, security), which is a lawful derogation, not a gap.

Primary frameworkRegulation (EU) 2018/1725, Arts 14-25
Traffic-light rationale — GreenRights framework is comprehensive and actively supervised; some rights may be restricted under Art 25 internal-rules mechanism for specified public-interest grounds (investigations, security), which is a lawful derogation, not a gap.

Sub-modules (5)

Access RightGreen

Art 17 grants the right of access, exercisable without unnecessary constraints, free of charge; the EDPS ran a Coordinated Enforcement Action reviewing EUI right-of-access practice in 2024.

Claims: CLM-EC-c9d0e1f2

Rectification And ErasureGreen

Art 18 grants rectification of inaccurate data; Art 19 grants erasure ('right to be forgotten') on enumerated grounds; the EDPS ran a Coordinated Enforcement Action on the right to erasure in 2025.

Claims: CLM-EC-d0e1f2a3, CLM-EC-e1f2a3b4

Restriction And ObjectionGreen

Art 20 grants restriction of processing; Art 23 grants the right to object on grounds relating to the data subject's particular situation; both may be restricted under the Art 25 internal-rules mechanism.

Claims: CLM-EC-f2a3b4c5

Data PortabilityGreen

Art 22 grants the right to receive personal data in a structured, machine-readable format and to transmit it to another controller.

Claims: CLM-EC-a3b4c5d6

Deadlines And Response WindowsGreen

Controllers must respond to data-subject requests without undue delay and in any event within one month of receipt, extendable by two further months where necessary, with reasons communicated to the data subject.

Claims: CLM-EC-b4c5d6e7

Category narrative47 words

EUDPR Arts 14-24 grant EUI data subjects rights of information, access, rectification, erasure, restriction, portability and objection, with a general one-month response deadline (extendable by two months). The EDPS actively supervises these rights via Coordinated Enforcement Framework participation (2024 access review, 2025 erasure review, 2026 transparency review).

Sources and claims (6)
  1. ConfirmedEDPSThe right of access under EUDPR allows a data subject to obtain confirmation that data concerning him or her are processed, the purposes of processing, and the logic involved in automated decisions, exercisable without unnecessary constraints, at any time, free of charge.
  2. ConfirmedPublications Office of the EUThe data subject has the right to obtain from the controller rectification of inaccurate personal data without undue delay, including completion of incomplete data by supplementary statement.
  3. ConfirmedEDPSThe right to erasure is enshrined in Article 19 of the EUDPR for EUIs, with similarities to Article 17 GDPR for EU/EEA countries; the EDPS conducted a fourth Coordinated Enforcement Action fact-finding exercise on EUI compliance with the right to erasure in 2025.
  4. ConfirmedEDPSThe EDPS may order the rectification or erasure of personal data or restriction of processing pursuant to Articles 18, 19 and 20 of the EUDPR, and notify such actions to recipients to whom the data have been disclosed.
  5. ConfirmedPublications Office of the EUUnder Article 22, the data subject has the right to receive personal data concerning him or her in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.
  6. ConfirmedEDPSThe data controller must respond to a data subject's request for access to their personal data without undue delay and in any event within one month from receipt, which may be extended by two further months where necessary.

#

Fully codified and actively supervised (breach-notification web-portal, DPIA lists, DPO dismissal-consent rules updated January 2026); no material gaps identified.

Primary frameworkRegulation (EU) 2018/1725, Chapters III-IV
Traffic-light rationale — GreenFully codified and actively supervised (breach-notification web-portal, DPIA lists, DPO dismissal-consent rules updated January 2026); no material gaps identified.

Sub-modules (7)

Accountability And DpiaGreen

Art 39(1) requires a DPIA where processing is likely to result in a high risk to rights and freedoms; the EDPS has adopted binding, non-exhaustive DPIA-trigger lists under Art 39(4)/(5).

Claims: CLM-EC-c5d6e7f8

Dpo RequirementsGreen

DPO designation is compulsory for every EUI; the DPO may only be dismissed with the EDPS's prior consent, with detailed procedural Rules adopted by EDPS Decision 01/2026 (16 January 2026), entering into force early 2026.

Claims: CLM-EC-d6e7f8a9, CLM-EC-e7f8a9b0

Ropa RequirementsGreen

Art 31 requires each controller to maintain a record of processing activities, in writing (including electronic form), centrally registered and made publicly accessible unless disproportionate given EUI size.

Claims: CLM-EC-f8a9b0c1

Joint Controller ArrangementsGreen

Art 28 governs joint-controller arrangements between Union institutions/bodies; infringement of Art 28 is expressly fineable under Art 66.

Claims: CLM-EC-a9b0c1d2

Security MeasuresGreen

Art 33 requires appropriate technical and organisational security-of-processing measures; infringement is expressly fineable under Art 66(2)/(3).

Claims: CLM-EC-b0c1d2e3

Breach NotificationGreen

EUIs must notify the EDPS of a personal-data breach presenting a risk to rights and freedoms within 72 hours of becoming aware, where feasible, and notify affected individuals without undue delay where the breach is likely to result in high risk; a dedicated encrypted-notification web form is maintained.

Claims: CLM-EC-c1d2e3f4

Retention And DisposalGreen

EUDPR's storage-limitation principle requires that personal data be kept in identifiable form no longer than necessary for the purposes for which it is processed.

Claims: CLM-EC-d2e3f4a5

Category narrative52 words

EUDPR Chapter IV imposes accountability (Art 4(2)), DPIA obligations (Art 39), mandatory DPO designation with EDPS-consent-gated dismissal (Art 44, reinforced by EDPS Decision 01/2026), ROPA (Art 31), joint-controller (Art 28) and processor (Art 29) rules, security-of-processing duties (Art 33), 72-hour breach notification to the EDPS (Art 34-35), and storage-limitation/retention principles (Art 4(1)(e)).

Sources and claims (8)
  1. ConfirmedEDPBArticle 39(1) of Regulation (EU) 2018/1725 requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons, with Article 39(3) providing a non-exhaustive illustrative list.
  2. ConfirmedOfficial Journal of the EUEU institutions, bodies, offices and agencies are required to designate a Data Protection Officer, and the Regulation establishes that a DPO may not be dismissed or penalised by the controller for performing their tasks without the EDPS's prior consent.
  3. ConfirmedOfficial Journal of the EUEDPS Decision 01/2026 of 16 January 2026 establishes detailed procedural rules on the requirement of prior EDPS consent for the dismissal of DPOs, requiring EUIs to submit a complete dismissal request with supporting documentation before any intended dismissal.
  4. ConfirmedEDPSEach controller shall maintain a record of processing activities under its responsibility in writing, including electronic form, and Union institutions and bodies shall keep their records in a central, publicly accessible register unless inappropriate given their size.
  5. ConfirmedEDPSArticle 28 (joint controllers) of the EUDPR is among the provisions for which infringement can be sanctioned with an administrative fine under Article 66.
  6. ConfirmedEDPSArticle 33 (security of processing) is expressly listed among the infringements for which fining is set out under Article 66 of the EUDPR.
  7. ConfirmedEDPSThe EUDPR introduces a duty on all EU institutions and bodies to report certain types of personal-data breach to the EDPS within 72 hours of becoming aware of the breach, where feasible, and to inform affected individuals without undue delay if the breach is likely to result in high risk.
  8. ConfirmedPublications Office of the EUPersonal data processed under the EUDPR must be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the data are processed.

#

Framework is complete, but EUDPR itself does not generate adequacy decisions (it relies on GDPR Art 45(3)/LED Art 36(3) decisions) — a structural cross-reference rather than a gap, tracked here as amber for interoperability clarity.

Primary frameworkRegulation (EU) 2018/1725, Arts 46-50
Traffic-light rationale — AmberFramework is complete, but EUDPR itself does not generate adequacy decisions (it relies on GDPR Art 45(3)/LED Art 36(3) decisions) — a structural cross-reference rather than a gap, tracked here as amber for interoperability clarity.

Sub-modules (6)

Transfer MechanismsGreen

In the absence of a GDPR/LED adequacy decision or Art 48 safeguards, an EUI transfer to a third country/international organisation may only occur on enumerated conditions; Art 49 additionally provides that third-country judicial/administrative orders demanding disclosure are enforceable only if based on an international agreement (e.g. MLAT).

Claims: CLM-EC-e3f4a5b6

Adequacy ReceivedRed

EUDPR does not itself operate an 'adequacy received' concept analogous to a Member State's inbound recognition; EUIs instead rely on the same GDPR/LED adequacy-decision architecture as Member States.

Adequacy GrantedAmber

Adequacy decisions relevant to EUI transfers are granted under GDPR Art 45(3)/LED Art 36(3), not under EUDPR itself; EUDPR Art 47 simply cross-references those decisions for EUI use.

Claims: CLM-EC-f4a5b6c7

Sccs And BcrsGreen

Art 48 allows the Commission or the EDPS to lay down standard contractual clauses for EUI transfers, including clauses that may build on certifications granted under GDPR Art 42; pre-GDPR-era SCCs/BCRs must be adapted to EUDPR requirements before continued use.

Claims: CLM-EC-a5b6c7d8

Transfer Impact AssessmentAmber

No standalone EUDPR provision names a formal 'transfer impact assessment' step distinct from the Art 46-48 safeguards analysis; EDPS opinion practice (e.g. its September 2025 Opinion on an EU-US framework agreement for security-screening data exchange) functions as the practical equivalent for high-profile international agreements.

Claims: CLM-EC-b6c7d8e9

Data LocalisationGreen

EUDPR imposes no blanket data-localisation mandate; instead it relies on the Art 46-50 transfer-safeguard cascade and the Art 49 restriction on recognising third-country compulsion orders absent an international agreement.

Claims: CLM-EC-c7d8e9f0

Category narrative50 words

EUDPR Chapter V (Arts 46-50) governs transfers by EUIs to third countries/international organisations: a general principle (Art 46), transfers on the basis of GDPR/LED adequacy decisions (Art 47), appropriate safeguards including EDPS-adopted SCCs (Art 48), non-recognition of third-country judgments absent an international agreement (Art 49), and narrowly-construed derogations (Art 50).

Sources and claims (5)
  1. ConfirmedPublications Office of the EUAny judgment of a court or tribunal, or decision of an administrative authority, of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union.
  2. ConfirmedPublications Office of the EUIn the absence of an adequacy decision pursuant to Article 45(3) of the GDPR or Article 36(3) of the Law Enforcement Directive, or of appropriate Article 48 safeguards, an EUI transfer to a third country or international organisation may take place only under enumerated conditions.
  3. ConfirmedEDPSThe European Data Protection Supervisor may adopt standard contractual clauses for EUI international-transfer purposes, and pre-existing SCCs/BCRs adopted under the old Directive 95/46 remain valid but must be adapted to Regulation (EU) 2018/1725 before continued use.
  4. ProbableEDPSOn 17 September 2025, the EDPS issued an Opinion on the negotiating mandate for a framework agreement between the EU and the United States on the exchange of information for security screenings and identity verifications, functioning as a de facto transfer-risk assessment for a major international data-sharing instrument.
  5. ProbablePublications Office of the EUTransmissions of personal data to recipients established in the Union other than Union institutions and bodies are subject to additional safeguard conditions under the EUDPR, distinct from the stricter third-country transfer regime of Articles 46-50.

#

Sectoral overlays are well-documented for financial-supervision and health agencies; credit-scoring and education have no dedicated EUI sub-regime, which is expected given the nature of Union institutions rather than a compliance gap.

Primary frameworkRegulation (EU) 2018/1725, Art 25 (sector/agency-specific restriction decisions)
Traffic-light rationale — GreenSectoral overlays are well-documented for financial-supervision and health agencies; credit-scoring and education have no dedicated EUI sub-regime, which is expected given the nature of Union institutions rather than a compliance gap.

Sub-modules (7)

Financial Sector OverlayGreen

EU financial-supervision agencies such as ESMA and EIOPA, as EUIs, have each adopted EDPS-consulted internal-rules decisions under Art 25 restricting certain data-subject rights (e.g. right of access, rectification, erasure) in the context of supervisory investigations/inquiries.

Claims: CLM-EC-d8e9f0a1

Health Sector OverlayGreen

EDPS Decision 46/2026 authorised a Model Administrative Arrangement for transfers of personal data from the European Medicines Agency (EMA) to the Council of Europe's Directorate for the Quality of Medicines & HealthCare for a sampling/testing cooperation programme.

Claims: CLM-EC-e9f0a1b2

Telecoms And EprivacyAmber

EUDPR Art 36 (confidentiality of communications) sits alongside the ePrivacy Directive 2002/58/EC, which the EDPS notes 'is due to be repealed'; the pending Digital Omnibus proposal would further amend the ePrivacy Directive alongside the GDPR and EUDPR.

Claims: CLM-EC-f0a1b2c3

Employment DataAmber

EDPS supervisory activity covers EUI staff-management processing, including a reprimand of EPSO (EU Personnel Selection Office) over remote-testing practices, and active monitoring of AI use in recruitment/HR processes across EUIs.

Claims: CLM-EC-a1b2c3d5

Credit And ScoringRed

No distinct EUI credit-scoring sub-regime was identified; EUIs are not consumer-credit actors in the way private financial institutions are.

Absence provenance: not recorded. Searched: EDPS credit scoring EU institutions, EUDPR credit reporting sectoral rules.

EducationRed

No distinct statutory EUI education-sector sub-regime was identified beyond general EUDPR principles; EDPS public engagement on AI-in-education is awareness-raising rather than a binding sectoral overlay.

Absence provenance: not recorded. Searched: EDPS education sector data protection EUI, EUDPR school data processing.

InsuranceGreen

EIOPA, as an EUI insurance/pensions supervisory agency, operates under an EDPS-consulted Art 25 internal-rules decision restricting data-subject rights in the context of its supervisory investigations.

Claims: CLM-EC-b2c3d5e6

Category narrative91 words

Because JID=EC covers the Union institutions themselves, 'sectors' map onto specific EUIs/agencies rather than private industry: EU financial-supervision agencies (ESMA, EIOPA, EBA) apply EUDPR with Art 25 internal-rules restrictions for their supervisory investigations; health-related EUIs (EMA, ECDC) process personal data under EUDPR with EDPS-authorised inter-agency transfer arrangements; ePrivacy/telecoms confidentiality rules for EUI electronic communications sit alongside EUDPR Art 36; and EUI employment/recruitment processing (including EPSO testing and AI-in-hiring) is an active EDPS supervisory focus. Credit-scoring, education, and insurance are not distinct statutory sub-regimes for EUIs beyond EIOPA's Art 25 restriction decisions.

Sources and claims (5)
  1. ConfirmedOfficial Journal of the EUESMA, following Article 25 of Regulation (EU) 2018/1725 and after an EDPS opinion, adopted internal rules permitting it to restrict data-subject rights of access, rectification, erasure and restriction of processing in the context of its investigations or inquiries.
  2. ConfirmedEDPSEDPS Decision 46/2026 authorises the use of an administrative arrangement based on the EDPS Model Administrative Arrangement for transfers of personal data from the European Medicines Agency to the Council of Europe's EDQM, pursuant to Article 48(3)(b) of the EUDPR, in the context of a medicines sampling and testing cooperation.
  3. ConfirmedEDPSThe ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services alongside the EUDPR, and is due to be repealed/amended as part of the Digital Omnibus proposal.
  4. ProbableEDPSThe EDPS's February 2025 Newsletter reports an EDPS reprimand issued to EPSO (the EU Personnel Selection Office) concerning its data-processing practices, alongside continued monitoring of AI use in EUI recruitment.
  5. ConfirmedOfficial Journal of the EUEIOPA adopted a Decision, following Article 25 of Regulation (EU) 2018/1725 and after consulting the EDPS, laying down rules restricting data-subject rights (access, rectification, erasure, restriction) in the framework of its supervisory procedures.

#

Core cookie/consent-signal policy is in active reform (Digital Omnibus); several sub-modules are genuinely inapplicable to the EUI-controller context rather than gaps.

Primary frameworkDirective 2002/58/EC (ePrivacy) read with Regulation (EU) 2018/1725, Art 36
Traffic-light rationale — AmberCore cookie/consent-signal policy is in active reform (Digital Omnibus); several sub-modules are genuinely inapplicable to the EUI-controller context rather than gaps.

Sub-modules (6)

Cookies And TrackersAmber

EUI web services are subject to the ePrivacy Directive alongside EUDPR; the Digital Omnibus proposal targets ePrivacy amendments addressing cookie-banner consent fatigue.

Claims: CLM-EC-c3d5e6f7

Dark PatternsRed

No EUI-specific dark-pattern prohibition distinct from general GDPR/DSA-level discourse was identified for the EC/EUDPR context.

Absence provenance: not recorded. Searched: EDPS dark patterns EUI, EUDPR deceptive design prohibition.

Opt Out SignalsAmber

The Digital Omnibus proposal introduces requirements on automated, machine-readable indications of individuals' choices regarding data processing, which the EDPB/EDPS jointly support as a solution to consent fatigue.

Claims: CLM-EC-d5e6f7a8

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regime specific to EUIs was identified.

Absence provenance: not recorded. Searched: EDPS clean room data collaboration EUI.

Cross Context AdvertisingAmber

EDPS newsletter reporting references an EDPS review of whether the European Commission organised a micro-targeting campaign on a social-media platform (X), indicating active EDPS scrutiny of EUI targeted-communication practices.

Claims: CLM-EC-e6f7a8b9

Direct MarketingRed

EUIs, as public bodies, are not typically direct-marketing actors; no dedicated EUDPR direct-marketing consent/suppression regime was identified.

Absence provenance: not recorded. Searched: EUDPR direct marketing consent EUI.

Category narrative65 words

EUIs are public-sector controllers, not commercial adtech operators, so several sub-modules (dark patterns, clean rooms/DCR, direct marketing) have no dedicated EUDPR content; however, EUI websites/communications fall under Art 36 confidentiality-of-communications and the ePrivacy Directive, and the EDPS has itself investigated an EUI's own targeted-communication practices (a European Commission social-media micro-targeting campaign). The pending Digital Omnibus proposes EU-wide automated consent-signal mechanisms relevant to cookie/tracker consent generally.

Sources and claims (3)
  1. ConfirmedEDPSThe ePrivacy Directive 2002/58/EC provides additional data-protection rules for telecommunications networks and internet services and is targeted for amendment by the Digital Omnibus proposal alongside the GDPR and EUDPR.
  2. ConfirmedEDPBThe EDPB and the EDPS strongly support the Digital Omnibus's objective of addressing consent fatigue and cookie-banner proliferation via automated, machine-readable indications of individuals' processing choices.
  3. UncertainEDPSEDPS newsletter reporting flags scrutiny of whether the European Commission organised a micro-targeting campaign on the social-media platform X, indicating active EDPS review of EUI targeted-communications practices.

#

Mature, actively-resourced supervisory framework (dedicated EDPS AI Unit since Oct 2024, published AI Compass 2026-2027); amber risk only from the pending Digital Omnibus on AI timeline changes.

Primary frameworkRegulation (EU) 2018/1725, Art 24; Regulation (EU) 2024/1689 (AI Act) as applied to EUIs
Traffic-light rationale — GreenMature, actively-resourced supervisory framework (dedicated EDPS AI Unit since Oct 2024, published AI Compass 2026-2027); amber risk only from the pending Digital Omnibus on AI timeline changes.

Sub-modules (6)

Profiling RestrictionsGreen

Art 24 restricts automated individual decision-making including profiling, and decisions may not be based on special-category data save under narrow exceptions with safeguards.

Claims: CLM-EC-f7a8b9c0

Automated Decision Making TransparencyGreen

The right of access under Art 17 extends to information on the logic involved in any automated decision-making process concerning the data subject.

Claims: CLM-EC-a8b9c0d1

Ai Risk AssessmentsGreen

The EDPS published its 'Compass' for its AI Act role (17 March 2026), identifying over 100 AI systems deployed or under development across EUIs and setting four strategic supervisory pillars for 2026-2027.

Claims: CLM-EC-b9c0d1e2

Biometric RegimeGreen

Article 43(1) of the AI Act designates the EDPS as the notified body for conformity assessment of high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation, and emotion recognition.

Claims: CLM-EC-c0d1e2f3

Genetic DataGreen

Genetic data is enumerated among the EUDPR special categories under Art 10, subject to the same restrictive processing conditions as other sensitive categories.

Claims: CLM-EC-d1e2f3a4

State Surveillance CarveoutsAmber

Art 25 permits EUIs to restrict data-subject rights (Arts 14-22, 35-36) where necessary and proportionate to safeguard enumerated public-interest objectives (including security and defence), subject to publication of the restricting legal act/internal rule in the Official Journal and EDPS consultation.

Claims: CLM-EC-e2f3a4b5

Category narrative67 words

EUDPR Art 24 (automated individual decision-making including profiling) is the EUI-context analogue of GDPR Art 22. Since 2024 the EDPS additionally holds a sui generis role under the AI Act (Regulation (EU) 2024/1689) as the competent supervisory/market-surveillance authority and notified body for EUI AI systems, including biometric high-risk systems (remote biometric identification, categorisation, emotion recognition). Art 25 permits national-security/defence-adjacent restrictions on data-subject rights via published internal rules.

Sources and claims (6)
  1. ConfirmedPublications Office of the EUAutomated individual decisions under Article 24 of the EUDPR shall not be based on special categories of personal data referred to in Article 10(1), unless narrow exceptions apply with suitable safeguards for the data subject's rights, freedoms and legitimate interests.
  2. ConfirmedEDPSThe right of access allows a data subject to obtain from the controller confirmation of processing, the purposes, and the logic involved in any automated decision process concerning him or her.
  3. ConfirmedEDPSThe EDPS's mapping exercise for its AI Act role identified more than one hundred AI systems currently deployed or under development across EUIs, with the highest concentration of high-risk use cases in the Area of Freedom, Security and Justice and in employment/recruitment.
  4. ConfirmedEDPSArticle 43(1) of the AI Act designates the EDPS as a notified body in charge of conformity assessment for high-risk AI systems of EUIs in the areas of remote biometric identification, biometric categorisation and emotion recognition under Annex III(1) of the AI Act.
  5. ConfirmedEDPBGenetic data is enumerated as a special category of personal data under Article 10 of the EUDPR, subject to restrictive processing conditions.
  6. ConfirmedPublications Office of the EULegal acts adopted on the basis of the Treaties, or internal rules on the operation of Union institutions and bodies, may restrict Articles 14-22, 35-36 EUDPR where the restriction respects the essence of fundamental rights and is a necessary and proportionate measure in a democratic society, and such restrictions must be clear, precise, published in the Official Journal, and adopted at the highest management level.

#

Core child-consent rule is codified and confirmed, but education-settings and dependent-adults sub-modules have no dedicated EUI content, and minor-specific profiling bans are inferred rather than explicit.

Primary frameworkRegulation (EU) 2018/1725, Art 8
Traffic-light rationale — AmberCore child-consent rule is codified and confirmed, but education-settings and dependent-adults sub-modules have no dedicated EUI content, and minor-specific profiling bans are inferred rather than explicit.

Sub-modules (5)

Age VerificationGreen

Where consent is the legal basis, EUDPR Art 8(1) deems processing of a child's data lawful where the child is at least 13 years old in the context of an offer of information-society services directly to the child.

Claims: CLM-EC-f3a4b5c6

Minor Profiling BansAmber

No EUDPR provision creates a categorical profiling ban specific to minors beyond the general Art 24(4) restriction on special-category-based automated decisions; the EDPS has engaged in public conferences on children's digital rights (e.g. its 'From Cradle to Cloud' event) but this is soft-law engagement, not a binding minor-specific profiling prohibition.

Claims: CLM-EC-b5c6d7e8

Education SettingsRed

No dedicated EUI education-settings sub-regime under EUDPR was identified.

Absence provenance: not recorded. Searched: EDPS education settings children EUI data protection, EUDPR school-specific provisions.

Dependent AdultsRed

No dedicated EUDPR provision addressing dependent/vulnerable adults distinct from general data-subject rights was identified.

Absence provenance: not recorded. Searched: EDPS dependent adults vulnerable persons EUDPR, EUDPR incapacitated data subject provisions.

Category narrative58 words

Article 8 of the EUDPR is the EUI-context analogue of GDPR Art 8, setting the age threshold for a child's own consent to information-society services at 13 (with parental-responsibility-holder consent required below that age) — notably EUDPR sets a fixed 13-year floor rather than the GDPR's Member-State-adjustable 13-16 range. Dedicated EUI education-settings and dependent-adults sub-regimes were not identified.

Sources and claims (3)
  1. ConfirmedPublications Office of the EUWhere point (d) of Article 5(1) of the EUDPR applies, in relation to the offer of information society services directly to a child, the processing of a child's personal data is lawful where the child is at least 13 years old.
  2. ConfirmedPublications Office of the EUWhere a child is below the age of 13, EUDPR processing of the child's information-society-service data is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this, taking into consideration available technology.
  3. ProbableEDPSOn 4 July 2025, the EDPS and EDPB Trainees organised the 'From Cradle to Cloud: Surveillance and Digitalisation around Childhood' conference to foster discussion on the digital rights of children and minors, reflecting active but non-binding EDPS engagement on minors' data protection.

#

EDPS enforcement toolkit is active and demonstrably used against major EUIs (including the European Commission itself); amber-adjacent risk stems only from pending Digital Omnibus changes to underlying substantive rules, not from an enforcement capacity gap.

Primary frameworkRegulation (EU) 2018/1725, Arts 58, 65-66, 86
Traffic-light rationale — GreenEDPS enforcement toolkit is active and demonstrably used against major EUIs (including the European Commission itself); amber-adjacent risk stems only from pending Digital Omnibus changes to underlying substantive rules, not from an enforcement capacity gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Art 58 confers the EDPS a wide range of investigative, corrective (including data-flow-suspension), and authorisation/advisory powers; Art 66 allows the EDPS to impose administrative fines on a Union institution or body for non-compliance with specified EDPS orders, with the CJEU holding unlimited jurisdiction to cancel, reduce or increase such fines.

Claims: CLM-EC-c6d7e8f9, CLM-EC-d7e8f9a0

Enforcement Activity IndexGreen

Following EDPS enforcement proceedings and a March 2024 Decision identifying infringements and imposing corrective measures, the European Commission demonstrated compliance with the EUDPR regarding its use of Microsoft 365 by December 2024; the EDPS separately reprimanded Frontex in January 2025 for unlawful data-sharing with Europol, and reprimanded EPSO over remote-testing practices.

Claims: CLM-EC-e8f9a0b1, CLM-EC-f9a0b1c2

Regulator Funding And CapacityGreen

The Union budgetary authority is required to ensure the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with a separate budgetary heading; the EDPS also established a dedicated AI Unit in October 2024 to operationalise its expanded AI Act mandate.

Claims: CLM-EC-a0b1c2d3

Collective Redress And Class ActionsAmber

The EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on their behalf, functioning as a limited representative-action mechanism.

Claims: CLM-EC-b1c2d3e4

Private Right Of ActionGreen

Any person who has suffered material or non-material damage as a result of an EUDPR infringement has the right to receive compensation from the responsible Union institution or body, subject to Treaty conditions, alongside the right to a judicial remedy before the CJEU.

Claims: CLM-EC-c2d3e4f5

Recent Developments 180DAmber

Within the last 180 days: the EDPB/EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal (Feb 2026) and a Joint Opinion on the 'Digital Omnibus on AI' (Jan 2026); the EDPS published its AI Act 'Compass' for 2026-2027 (17 March 2026); the EDPB launched its 2026 Coordinated Enforcement Framework action on transparency/information obligations (19 March 2026); the EDPS/BfDI/BayLfD held a high-level Digital Omnibus debate (8 June 2026); the EDPB adopted anonymisation and generative-AI web-scraping guidelines (8 July 2026); and the EDPB, meeting in Dublin, called for a clearer legal basis for cross-regulatory information sharing among regulators (16-17 July 2026).

Claims: CLM-EC-d3e4f5a6, CLM-EC-e4f5a6b7, CLM-EC-f5a6b7c8

Category narrative116 words

The EDPS has a full investigative/corrective/authorisation power toolkit under Art 58 (audits, orders, suspension of data flows, administrative fines under Art 66 for non-compliance with EDPS orders), with Art 65 giving affected individuals a right to compensation and Art 66(3) giving the Court of Justice unlimited jurisdiction to review fines. Enforcement activity in the trailing ~24 months includes the Commission Microsoft 365 decision (March 2024, compliance confirmed December 2024), the Frontex reprimand (January 2025), an EPSO reprimand, and ongoing own-initiative investigations (EU Parliament Wi-Fi, Europol's 'big data challenge'). Article 86 preserves a representative-complaint mechanism via not-for-profit organisations. Recent 180-day developments (Feb-Aug 2026) are dominated by the Digital Omnibus reform process and the EDPS's AI Act 'Compass'.

Sources and claims (10)
  1. ConfirmedEDPSArticle 58 of Regulation (EU) 2018/1725 confers the EDPS a wide range of investigative powers including risk-based compliance audits, and corrective powers including ordering rectification/erasure/restriction, imposing administrative fines under Article 66 for non-compliance with EDPS orders, and ordering suspension of data flows to a recipient in a Member State, third country, or international organisation.
  2. ConfirmedPublications Office of the EUThe Court of Justice of the European Union has unlimited jurisdiction to review administrative fines imposed by the EDPS under Article 66, and may cancel, reduce or increase those fines within the limits of that Article.
  3. ConfirmedEDPSFollowing enforcement proceedings by the EDPS, the European Commission demonstrated compliance with Regulation (EU) 2018/1725 in relation to its use of Microsoft 365, following the EDPS's Decision of 8 March 2024 which had identified infringements and imposed corrective measures, with compliance confirmed by 9 December 2024.
  4. ConfirmedEDPSOn 8 January 2025, the EDPS issued a reprimand to Frontex for infringing Regulation (EU) 2019/1896 by systematically sharing personal data of suspects of cross-border crime with Europol without assessing whether such sharing was strictly necessary, following an EDPS audit opened in October 2022.
  5. ConfirmedPublications Office of the EUThe budgetary authority shall ensure that the EDPS is provided with the human and financial resources necessary for the performance of its tasks, with the EDPS budget shown in a separate budgetary heading of the Union's general budget.
  6. ConfirmedPublications Office of the EUThe EUDPR permits a data subject to mandate a not-for-profit organisation to lodge a complaint with the EDPS on the data subject's behalf.
  7. ConfirmedPublications Office of the EUAny person who has suffered material or non-material damage as a result of an infringement of the EUDPR has the right to receive compensation from the responsible Union institution or body, subject to the conditions provided for in the Treaties.
  8. ConfirmedEDPSThe EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, which amends Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and several directives, following the Commission's formal consultation under Article 42(2) EUDPR on 25 November 2025.
  9. ConfirmedEDPBThe EDPB launched its 2026 Coordinated Enforcement Framework action on 19 March 2026, shifting focus from the 2025 right-to-erasure action to compliance with transparency and information obligations under Articles 12-14 GDPR, with 25 DPAs participating during 2026.
  10. ConfirmedEDPBAt a high-level meeting in Dublin on 16-17 July 2026, the EDPB called for a clear legal basis for the sharing of information among regulators with different competences, and discussed expanding cooperation to support consistent GDPR application.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ecuador
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 54 claim(s), 49 source(s) in the cumulative register.