Quevedo & Ponce - Noticias Legales

The Superintendence of Personal Data Protection (SPDP) Issues New Key Criteria on the Use of Biometric Data and the Appointment of DPOs

The SPDP has recently issued rulings regarding the use of biometric data for labor attendance control and the obligation to appoint a Data Protection Officer (DPO) in savings and credit cooperatives. These criteria reinforce the need to protect sensitive data, require impact assessments, and ensure free consent, while establishing that cooperatives must appoint a DPO immediately to comply with current regulations and avoid sanctions.

On the Use of Biometric Data for Labor Attendance Control In Official Letter No. SPDP-IRD-2025-0065-O, the following inquiry was raised:

Is it lawful to use biometric data (fingerprints, facial recognition, etc.) to register workers’ attendance, especially in public institutions?

SPDP’s Position:

The SPDP reaffirms its previous stance issued in Official Letter No. SPDP-IRD-2025-0031-O, establishing that:

  • Biometric data are sensitive data according to Article 26 of the LOPDP, as they involve unique and irreplaceable characteristics of the individual.
  • Their use constitutes a highly invasive measure and should only be applied exceptionally when no less intrusive alternatives achieve the same objective.

Requirements for Lawful Processing:

For the use of biometric data to be lawful, the following cumulative requirements must be met:

  1. Prior proportionality assessment:

It must be demonstrated why other less intrusive alternatives (cards, digital registers, etc.) are not suitable.

  1. Impact assessment (EIPD) and documented risk management:

Risks to data subjects’ rights, mitigation measures, and information security must be analyzed.

  1. Valid and free consent of the data subject:

Consent cannot be imposed as a condition for accessing or maintaining employment. Real alternatives must be offered to those who do not provide consent.

The SPDP discards the use of “public interest” as a legal basis for this data processing.

Other Relevant Aspects:

  • Workers (or former workers) can exercise their right of access to labor documents containing their personal data (Article 13 LOPDP).
  • The right to rectify the cause of labor termination only applies when there is a final judicial ruling declaring the termination unjustified or different from what is recorded (Article 14 LOPDP).

On the Obligation to Appoint a Data Protection Officer (DPO) in Cooperatives in Official Letter No. SPDP-IRD-2025-0036-O, the following inquiry was posed:

Are savings and credit cooperatives required to appoint a Data Protection Officer (DPO) immediately, or only if the SPDP expressly requires it?

SPDP’s Position:

The SPDP states that the obligation is immediate and general, with no need for a prior request from the authority. This requirement is based on three key aspects:

  1. Legal nature of the obligated party:

Savings and credit cooperatives are part of the popular and solidarity financial system, according to Article 311 of the Constitution.

  1. Processing of special categories of data:

These entities process credit data, which are considered special category data.

  1. Large-scale processing:

The volume, frequency, and scope of data processing by these entities constitute large-scale processing, which directly triggers the obligation to appoint a DPO. This obligation also applies to cooperatives not supervised by the Superintendence of Banks.

Failure to comply with this obligation could result in administrative sanctions, as it is an essential element of the principle of proactive responsibility.

At Quevedo & Ponce, we advise companies and employers to ensure compliance with labor and data protection regulations.

Más Artículos

New Regulation for the Calculation of Fines in the Field of Personal Data Protection

New Regulation for the Calculation of Fines in the Field of Personal Data Protection

The Superintendence for the Protection of Personal Data (SPDP) has issued the Regulation for the Application of the Methodology for the Calculation of Fines in the Administrative Sanctioning Regime, along with the Models for Calculating the Amount of Administrative Fines. This regulation complements the Organic Law on the Protection of Personal Data (LOPDP) and its General Regulation (RLOPDP), strengthening the sanctioning framework and its practical application in Ecuador.

Nuevo reglamento para el cálculo de multas en materia de protección de datos personales

Nuevo reglamento para el cálculo de multas en materia de protección de datos personales

La Superintendencia de Protección de Datos Personales (SPDP) emitió el Reglamento para la Aplicación de la Metodología para el Cálculo de las Multas en el Régimen Administrativo Sancionatorio, junto con los Modelos para Calcular el Monto de las Multas Administrativas. Esta normativa complementa la Ley Orgánica de Protección de Datos Personales (LOPDP) y su Reglamento General (RLOPDP), fortaleciendo el marco sancionador y su aplicación práctica en Ecuador.

Corporate Transformation and Sports Corporations: Comply with the National Solidarity Law

Corporate Transformation and Sports Corporations: Comply with the National Solidarity Law

The new Regulation to the National Solidarity Law mandates that Simplified Stock Corporations (S.A.S.) operating in strategic sectors—such as mining, finance, insurance, telecommunications, energy, or biodiversity—must take urgent actions: either convert into another permitted corporate form, amend their bylaws to exclude such activities or voluntarily dissolve within a six-month period. Furthermore, the Regulation introduces a clear legal framework for the figure of the Sports Corporation (Sociedad Anónima Deportiva – S.A.D.), established exclusively for conducting professional sports activities.

Transformación Societaria y Sociedades Anónimas Deportivas: Cumple con la Ley de Solidaridad Nacional

Transformación Societaria y Sociedades Anónimas Deportivas: Cumple con la Ley de Solidaridad Nacional

El nuevo Reglamento a la Ley de Solidaridad Nacional obliga a las Sociedades por Acciones Simplificadas (S.A.S.) que operan en sectores estratégicos como minería, finanzas, seguros, telecomunicaciones, energía o biodiversidad, a tomar decisiones urgentes: transformarse, reformar sus estatutos o disolverse voluntariamente en un plazo de seis meses. Además, introduce un marco normativo claro para la figura de la Sociedad Anónima Deportiva (S.A.D.), diseñada exclusivamente para actividades deportivas profesionales.

El reclamo administrativo en materia de seguros

El reclamo administrativo en materia de seguros

Compartimos el artículo de nuestro socio Dr. Luis Ponce Palacios, publicado por INSULAW International, en este análisis, se examinan las implicaciones legales del reclamo administrativo que los asegurados pueden presentar ante la Superintendencia de Compañías, Valores y Seguros en Ecuador, sus posibles afectaciones a principios constitucionales y la discusión jurídica que ha llegado incluso a la Corte Constitucional.

1 5 6 7 8 9 33

Contáctanos

Tienes alguna pregunta? Gustosos te ayudaremos