New Contractual Obligation: Inclusion of Personal Data Protection Clauses
By Pedro Córdova Balda, María Paula Arellano, Gabriela Holguín, Robalino

The Superintendence for the Protection of Personal Data has issued Regulation No. SPDP-SPD-2025-0006-R, establishing the mandatory inclusion of personal data protection clauses in contracts executed within the territory of the Republic of Ecuador. The regulation includes annexed model clauses applicable to the following scenarios:
-Controller and data subject
-Controller and processor
-Controller and recipient
-Joint controllers
Although the inclusion of personal data protection clauses in contracts is mandatory, the published model clauses are for reference purposes only and are not legally binding. However, they provide a minimum standard to ensure compliance with all principles and provisions set forth in the Personal Data Protection Act.
What key elements should a personal data protection clause generally contain?
-Lawful purposes for data processing
-Identification of controllers and/or processors
-Types of data collected
-Legal basis for processing
-Data transfers (where applicable)
-Data subject rights
-Data retention periods
-Security measures