Ecuador’s Risk Management Guide for Personal Data Protection. A practical view
Ecuador’s Superintendence of Personal Data Protection has published its first risk management guide. The document is ambitious: it demands that organizations justify every assumption, calibrate expert opinion, and adopt measurable models. However, it leaves a critical question unanswered, as, what methodology should companies actually use? Unlike Spain, where proportionality and maturity guide the choice of methods, Ecuador’s guide presents multiple options without prioritization. This article argues that such neutrality, while flexible, creates practical uncertainty. It suggests that organizations should adopt a mixed model, anchored in the traditional risk matrix but enriched with qualitative rationales and, where possible, quantitative tools.
Ecuador’s guide represents a turning point. For the first time in Ecuador, organizations must manage risk not through paperwork but through evidence and calibration. Every metric—whether qualitative or quantitative—requires justification. The goal is to avoid “compliance on paper” and foster a culture of demonstrable protection.
Yet, the guide stops short of offering clarity on methodology. It lists probabilistic models, Monte Carlo simulations, Bayesian approaches, and expert calibration techniques. It also describes qualitative options like the Delphi method or risk registers. But it does not say which approach should serve as the default or minimum expectation. For many companies, especially those with limited maturity, this creates uncertainty. Is a simple risk matrix enough, or does the regulator expect advanced quantitative modeling?
1.1 Spain as a Propotionality Benchmark
Spain’s Data Protection Agency, under the GDPR, also refrains from prescribing a single methodology. But it frames the choice within the principle of proportionality. Higher the risk, the more robust the methodology must be. Risk management is within corporate governance, tied to Data Protection Impact Assessments (DPIAs), and aligned with quality and security frameworks. This proportional approach gives organizations a compass. Ecuador’s guide, by contrast, offers a toolbox but no map.
1.2 The Case for a Mixed Model
In practice, few organizations in Ecuador can afford sophisticated statistical models for data processing activity. At the same time, sticking to a simplistic approach risks falling short of the regulator’s expectations.
A pragmatic solution is to adopt a mixed methodology:
- Use the traditional probability–impact matrix as the backbone. It remains the common language of risk across information security and business continuity.
- Complement it with qualitative rationales (expert opinions, scenario analysis, calibrated judgment) to avoid empty estimates.
- Where data and resources allow, add quantitative tools (probability distributions, Monte Carlo simulations) to strengthen critical assessments such as high-risk processing or DPIAs.
This hybrid approach ensures continuity with existing frameworks while gradually introducing methodological sophistication.
1.3 The Fate of the Traditional Risk Matrix
The matrix has often been criticized as too simple, but abandoning it entirely would isolate data protection from corporate governance. Its value lies in serving as a bridge, legal, IT, and risk teams already know how to use it. The challenge is not replacing the matrix but contextualizing it. Documenting its limits, enriching it with rationales, and linking it to broader governance structures.
1.4 Questions That Remain Open
Ecuador’s guide leaves practitioners with important questions:
- Should the regulator eventually define a minimum methodological baseline?
- Can organizations rely on a hybrid model and still demonstrate compliance?
- How can proportionality, so central in Spain, be translated into Ecuador’s regulatory culture?
- Will neutrality encourage innovation, or will it lead to superficial compliance?
1.5 Final Tohughts
Ecuador has taken a firm step by placing risk at the center of data protection. But ambition without methodological clarity risks confusing rather than guiding organizations. Spain shows that proportionality and maturity can orient the choice of methods. For Ecuador, the challenge is to translate neutrality into practice by encouraging a mix of tools that is credible, transparent, and suited to each organization’s reality. The open question is not whether risk should be managed, but how much complexity makes sense, and when.
Article provided by INPLP member: Andrés Terán (HEKA LAW FIRM, Ecuador)

By Dr. Tobias Höllwarth
