La Ley de Protección de datos protege la información personal de los ecuatorianos, pero aún falta una Superintendencia que la defienda

Ecuador’s Personal Data Protection Law aims to safeguard citizens’ privacy and information security, yet its full implementation remains stalled. Although approved in 2021, the regulatory framework was delayed until late 2023, and the crucial supervisory authority has not yet been established. This hiatus prevents the enforcement of penalties against entities that violate users’ rights, leaving a significant gap in institutional oversight despite the law’s existence. The legislation establishes clear distinctions between privacy and security violations, protecting users from unauthorized data collection by call centers and mitigating risks from cyberattacks that expose sensitive personal information. It empowers individuals to question how their data was obtained and seek compensation for its misuse. By defining severe infractions, the law intends to compel both the public and private sectors to guarantee the integrity of the information they manage, fostering a safer digital environment for all users. This situation is highly relevant to open data, as regulatory vacuums often lead to inconsistent data governance standards. Without an active authority, there is no unified mechanism to audit, sanction, or promote ethical data-handling practices. This lack of enforcement hinders the development of a trustworthy ecosystem where open data initiatives can coexist with robust privacy protections, potentially discouraging responsible data sharing and innovation until the legal framework is fully operational.

Source: eluniverso.com
Published on 2023-12-09