← Back to blog
#Protección de datos#LOPDP#Biometría#Videovigilancia#Ecuador

Fingerprint Time Clock or Facial Recognition Cameras? What Ecuador's New SPDP Biometric Data Rule Requires

Finger on the green-lit fingerprint reader of an access control terminal with a keypad and screen, next to a glass door

If your employees clock in with a fingerprint or their face, if your office door opens with facial recognition, or if your cameras have a feature that identifies people, there is a new rule that applies to you. Ecuador's Personal Data Protection Superintendency (SPDP) issued the General Rule for the Processing of Biometric Data, resolution SPDP-SPD-2026-0039-R, signed in Quito on September 9, 2026. Primicias summarized it with its most striking headline: it bans mass facial recognition and restricts its use on children and adolescents. But for a small business, what matters is in other articles.

What the rule covers

It applies to the processing of biometric data for identification purposes by public and private companies and institutions subject to the Organic Law on Personal Data Protection (LOPDP) (art. 2). It defines biometric data as facial images, fingerprints, voice patterns, iris scans and any other trait that identifies a person (art. 4.2). That covers the fingerprint time clock, face-based access control, selfie validation in an app and cameras with facial recognition.

Biometric data are sensitive data when used to uniquely identify a person (art. 3), and the rule treats any processing with that result as high risk (art. 5.1).

What it requires before switching on a biometric system

  • Prove it is needed. Before deploying it, you must assess whether the goal can be achieved with something less invasive. Biometrics is only admissible when strictly necessary and no other means exist (art. 13).
  • Risk analysis and data protection impact assessment (DPIA, "EIPD" in Spanish). Both are mandatory before deploying any biometric system, and the DPIA must be reviewed every 12 months and whenever the risk level changes (arts. 5 and 15).
  • A non-biometric alternative. If the system relies on consent, you must offer at least one equivalent mechanism that does not use biometrics, unless technical impossibility is documented in the DPIA (art. 7).
  • Templates, not photos. You must favor the biometric template (the mathematical representation of the fingerprint or face) and avoid storing the raw image unless strictly technically necessary (art. 4.8).
  • Reinforced security and privacy by design: minimal data, limited access and an architecture that reduces the risk of leaks (arts. 14 and 16).
  • Inform people clearly about the processing, in plain language and in a verifiable way (art. 17).
  • No reuse. A fingerprint taken for attendance cannot be used for another purpose without new consent or a valid legal basis (art. 12).
  • A person decides. Decisions with legal effects cannot rely solely on the biometric system, nor on human review that merely confirms what the machine said. The affected person can request an explanation (arts. 4.3 and 18).

The case that hits small businesses most: the time clock

The rule says there is a significant asymmetry when there is legal subordination or direct economic dependence (art. 8.1), which is exactly the employer-employee relationship. In those cases, as a general rule, a reasonable non-biometric alternative must be offered, unless there is justified technical impossibility, a law or an order from a competent authority (art. 8). The law firm AVL Abogados puts it this way: having the legal power to monitor attendance does not automatically authorize biometrics; you must show that cards, PINs or manual records are not enough.

In practice, if your staff can currently only clock in with a fingerprint, it is worth reviewing the case with the impact assessment in hand.

Cameras and facial recognition

Using biometric systems for the mass, indiscriminate identification of people in public spaces is prohibited, unless a law expressly allows it (art. 20). Watch the definition: a public space is any place the public has general access to, whether publicly or privately owned, such as shopping malls, stations, stadiums, squares or parks (art. 4.4). Anyone using facial recognition must comply with article 26 of the LOPDP, carry out the risk analysis and DPIA, apply reinforced security and review them when the technology changes (art. 19).

For minors, biometric processing for identification is prohibited unless no less invasive means exists, with a DPIA and explicit consent from the legal representative. Adolescents aged 15 to 17 may consent themselves if they receive the information in age-appropriate language (arts. 21 and 22). This matters to schools, academies and sports centers.

Deadline to comply

The resolution takes effect upon publication in the Official Registry (Registro Oficial). Those already using biometric systems have 12 months from that publication to adapt their processes and systems (transitional provision). At the time of writing we could not locate the Official Registry publication date, so we are not giving you a deadline: confirm it on the SPDP website or with your advisor. The law firm Corral Rosales agrees on the 12-month period.

What to do this week in your business

  1. Take inventory. Time clocks, fingerprint readers on doors, cameras with facial analytics, apps with selfie validation. Write down the vendor of each one.
  2. Ask the vendor whether the device stores templates or images, where they are stored, who has access and how they are deleted.
  3. Offer an alternative (card, PIN, code) to anyone who does not want to use their fingerprint or face, or document why that is not possible.
  4. Carry out or update the DPIA and put its annual review on the calendar.
  5. Inform your staff in writing and in plain language, and make sure no pay deduction or penalty depends solely on what the system records.

As with any legal matter, confirm how it applies to your case with your advisor or data protection officer.

How We Approach It at SimCodec

At SimCodec we install video surveillance, access control and networks for businesses, and we now configure them with this rule in mind: devices that store templates instead of photos, storage with limited access, non-biometric alternatives where appropriate and facial recognition features turned off when they are not needed. If you already have biometric time clocks or cameras with analytics, we help you check what they store and where.

If you want to review your systems against this rule, write to us or call our AI assistant Cyntia at +593 99 726 6838.

← Back to blog Get a quote →