Registro Oficial del Ecuador · 24 Sep 2026 · 9 vistas
Ecuador demands risk analysis before using biometric systems
Por FactBox Admin

The Superintendency of Personal Data Protection (SPDP) issued the General Standard for the Processing of Biometric Data, which mandates the performance of a risk analysis and its corresponding impact assessment before using facial recognition, fingerprints, or iris scans. The measure is contained in resolution SPDP-SPD-2026-0039-R, published in Official Registry No. 376 on Thursday, September 24, 2026, and comes into effect upon its publication.
The standard develops the principles of the Organic Law on Personal Data Protection (LOPDP), which in its Article 4 defines biometric data as unique personal data relating to physical, physiological, or behavioral characteristics, and classifies them as sensitive. Paragraph a) of Article 25 of the LOPDP considers them special categories of personal data, and numeral 5 of Article 76 empowers the SPDP to issue general or technical regulations. The SPDP justified the regulation due to the increasing use of biometric technologies in public and private services and risks such as algorithmic discrimination, improper identification, and the reuse of data for incompatible purposes.
The processing of the instrument is detailed in the published text itself:
- Technical report INF-SPDP-IRD-2026-0020, dated March 19, 2026, from the General Intendancy for the Regulation of Personal Data Protection.
- Public socialization of the project between March 31 and April 28, 2026, for a term of twenty days.
- Legal report INF-SPDP-DAJ-2026-0013 from the Legal Advisory Directorate and memorandum SPDP-IRD-2026-166-M, dated September 8, 2026.
- Signed in Quito, D. M., on September 9, 2026, by the superintendent Fabrizio Peralta-Díaz.
- The need for the standard is established in the 2026 Institutional Regulatory Plan, approved by resolution SPDP-SPD-2025-0050-R.
Mandatory risk analysis and impact assessment
Article 5 provides that all processing of biometric data must be preceded by a risk analysis and an impact assessment that justifies the use of biometric systems for the intended purpose. Processing activities that result in the unique identification of individuals, those involving the systematic or exhaustive evaluation of personal aspects through automated processing, and those involving large-scale systematic monitoring of public access areas are considered high-risk.
Article 15 requires a mandatory Data Protection Impact Assessment (DPIA) before implementing any biometric system, with review and updates every twelve months and whenever the risk level changes. Article 16 mandates reinforced security measures in accordance with the SPDP Risk Management and Impact Assessment Guide, and Article 13 conditions the use of biometrics on it being strictly necessary and the absence of other less invasive means.
Specific Prohibitions and Limits
- Mass and indiscriminate identification of people in public spaces is prohibited, unless enabled by the express mandate of a regulation with the rank of law (Article 20).
- Reusing biometric data for purposes other than those that legitimized its initial collection is prohibited (Article 12).
- The processing of biometric data of children and adolescents for identification purposes is prohibited, except for justified exceptions (Article 21).
- Decisions with legal effects may not be based exclusively on automated biometric identification systems (Article 18).
- The controller must prioritize the use of biometric templates and avoid the storage of raw data unless there is a strict technical necessity (Article 4.8).
Adolescents between fifteen and seventeen years old may grant their explicit consent themselves, provided the information is in language adapted to their age (Article 22).
Deadlines and Scope for the Public and Private Sectors
The regulation is applicable to the processing of biometric data for identification purposes carried out by controllers and processors in the public and private sectors subject to the territorial scope of the LOPDP, including automated or partially automated procedures (Article 2). When processing is based on consent, the controller must offer the data subject at least one equivalent alternative mechanism that does not require biometrics (Article 7).
The transitional provision grants twelve months, counted from the publication in the Official Registry, for those already using biometric systems to adapt their processes and systems. Article 11 specifies that biometric authentication in operations subject to enhanced due diligence obligations, in accordance with regulations for the prevention of fraud, money laundering, and terrorism financing, is not considered a relationship of significant asymmetry.
The impact falls on banks, businesses, airports, and state entities that already operate facial recognition, fingerprinting, or iris scanning: they must document risks, assess impact, offer non-biometric alternatives, and adapt their systems within one year, under the supervision of the SPDP.
Source: Official Registry No. 376, Thursday, September 24, 2026, Transparency and Social Control Function, p. 34 (official reference: resolution SPDP-SPD-2026-0039-R).