← Back to blog
#IA#Protección de datos#LOPDP#Agentes de IA#Ecuador

If Your Company Uses a Chatbot or AI Agent With Customer Data, This SPDP Rule Already Applies to You

Hands holding a phone and typing in a chat conversation

Last week's news was that AI assistants now act on their own: agents that monitor channels and complete tasks, assistants that make calls and chatbots that serve customers at any hour. What many Ecuadorian companies do not know is that, since this year, using those tools with people's data has its own rules in the country: the General Rule for Guaranteeing the Right to Personal Data Protection in the Use of Artificial Intelligence Systems, issued by the Personal Data Protection Superintendency (SPDP) through resolution SPDP-SPD-2026-0009-R, signed in Quito on February 12, 2026, according to Lexis.

Who it applies to

The rule covers those who develop, implement, deploy or distribute AI systems that process personal data of Ecuadorian data subjects, regardless of where the provider or infrastructure is located, according to NMS Abogados and Lexis. Coronel & Pérez explains it with four roles: the developer who builds the system, the implementer who integrates it into internal processes, the deployer who provides a service through AI and the distributor who sells it.

The practical consequence: if your company uses a chatbot, a WhatsApp agent or an AI tool that reads customer or employee data, the rule very likely applies to you, even if another company built the software and it runs on servers abroad.

What it requires

According to the analyses by Lexis, NMS and Coronel & Pérez, which agree on the essentials, the rule requires:

  • Informing the data subject clearly and transparently that their data is processed with AI.
  • Assessing impact and managing risks of the system before and during use.
  • Security measures — administrative, technical, physical, organizational and legal — proportionate to the data processed.
  • Recording these processing activities in the company's Record of Processing Activities (RAT).
  • Periodically auditing the system's operation according to its risk level.
  • Deleting, blocking or anonymizing data once the purpose is fulfilled, subject to legal exceptions.

It also guarantees people the right not to be subject to decisions based solely or partly on automated assessments, along with their rights to information and objection. The SPDP can audit AI systems and impose corrective or precautionary measures and penalties under the LOPDP. The sources consulted do not mention a compliance grace period: the rule applies from its publication.

What it means for your chatbot or AI agent

Take a common case: a WhatsApp agent that answers questions, books appointments and collects customer details. Under the rule, five things are worth reviewing:

  1. Say so. Customers should know they are talking to an AI and what their data is used for. A short opening message and a link to your privacy policy cover much of this.
  2. A person decides what matters. If the agent approves credit, rejects a request or sets a price for a customer, there must be human review and a way for the customer to request it.
  3. Only the data you need. If booking an appointment only requires a name and phone number, do not ask for an ID number or keep the full conversation forever.
  4. Record it in the RAT. Which data the agent processes, for what purpose, where it is stored, who the provider is and how long it is kept.
  5. Ask your provider. Where the data is hosted, whether it is used to train models, what security measures apply and how it is deleted. If they cannot answer, that is a red flag.

For a customer-service chatbot, Coronel & Pérez adds obtaining informed consent where applicable and making the right to object easy to exercise. As with any legal matter, confirm how it applies to your case with your advisor or data protection officer.

How We Approach It at SimCodec

At SimCodec we design our clients' voice, WhatsApp and Telegram AI agents with these rules from the start: a notice that the customer is talking to an AI, minimal data collection, handover to a person when a decision requires it, a log of what the agent does and data hosted with clear security measures. That way automation does not turn into a compliance problem later.

If you already use a chatbot or are about to deploy one and want to review it against this rule, write to us or call our AI assistant Cyntia at +593 99 726 6838.

← Back to blog Get a quote →