Brazil
  

General aspects about the Brazilian General Data Protection Law (LGPD)

August 30, 2019

 What is the relevance of the subject?

   With the increasing number of scandals involving data being leaked and misused, the advent of a new piece of legislation on the matter is crucial to protect the subjects of the information against abuses and privacy violations.
Companies that treat personal data must adapt their business model to the legislation and to the global trend of safety and data protection.
 
LGPD: what is it about?

Law 13,709/2018 will come into force on August 2020 and it regulates how personal data of individuals may be physically or digitally treated by third parties, defining limits and procedures.
What is "personal data"?
  Information related to the identified or identifiable individual. The law brings a broad concept, since every piece of isolated data or aggregated data that may identify an individual is characterized as personal data.
Examples: name, date of birth, profession, nationality, consumer habits, etc.
If a piece of data is not in any way capable of identifying
an individual, then its treatment will not be subject to the law. It is called "anonymized data".
Data on the racial or ethnical origin, religious belief, genetic or biometric data, those pieces of data related to the health or sex life, and those related to the affiliation to unions or to religious, philosophical, or political organizations, are called "sensitive personal data" and receive special attention from the law.
   What is the "treatment of data"?
The scope of the law is quite broad and lists TWENTY ACTIONS! "Treatment of Data" is every operation carried out with personal data, such as those involving:

  1. collection, (ii) production, (iii) reception, (iv) classification, (v) utilization, (vi) access, (vii) reproduction, (viii) transmission, (ix) distribution, (x) processing, (xi) filing, (xii) storage, (xiii) elimination, (xiv) assessment, (xv) information control, (xvi) modification, (xvii) communication, (xviii) transfer, (xix) broadcasting or (xx) extraction.
How to comply with the Law?
Each business must be assessed individually, considering, among other criteria, the rules and procedures already in place in the company, the level of sensitivity of the data being treated, the estimated budget for adjustment, etc. Some of the basic actions are:
MONITORING
• Continuous reviews of privacy conformity
• Privacy audits
IMPLEMENTATION
• Privacy governance measures
• Adoption of a procedure to respond to data violations
and guarantee of subjects’ rights
• Drafting and reviewing agreements
• Privacy training
DESIGN
• Adoption of a strategy and information governance plan from the beginning of the conception of the product/service
ASSESSMENT
• Data flow analysis
• Assessment of GDPR’s impact on the business
• Assessment of maturity and privacy management
    
 Who will enforce the law?
The National Data Protection Authority (ANPD) will be responsible for enforcing the law and imposing sanctions for violations. For now, while the National Authority is not working, the Public Prosecutors’ Office is proactively in charge of enforcing, implementing and inspecting the use of data.
Who may be held liable?
The Law provides for two relevant people related to those responsible for the data treatment: the "controller" and the "operator".
  Controller
individual or legal entity governed by public or private law responsible for making the decisions regarding the treatment of personal data.
Operator
individual or legal entity governed by public or private law that carries out the treatment of personal data in the controller’s name.
The controller or the operator that, due to the exercise of personal data treatment activities, causes to third parties’ property, moral, individual or collective damage, in breach of the personal data protection legislation, has the joint and several liability to redress them.

What are the sanctions set forth in the law?
 • one-time fine, of up to two percent (2%) of the income of the legal entity of private law, group or conglomerate in Brazil, in its last fiscal year, excluding taxes, capped, in its total, at fifty million Reais (BRL 50,000,000.00) per breach;
• warning, indicating the deadline for corrective actions;
• daily fine;
• disclosure of the breach, after having been properly
investigated and its occurrence confirmed;
• blocking of personal data to which the breach refers, until it is made regular;
• elimination of the personal data to which the breach refers;

Chiarottino e Nicoletti

 

Other news

Latin Counsel

Suscribe to our newsletter;

 

Our social media presence

  

  

  
 

  2018 - All rights reserved