Secuvy

Brazil LGPD Privacy Law

In September 2020, Brazil finally implemented its General Data Protection Law or Lei Geral de Proteção de Dados (LGPD). While Brazil already has 40 sectoral privacy laws at the federal level, this is the first law to provide the legal bases that authorize the use of personal data in the country.

The Brazil LGPD comprises 65 articles which lay down the enforcements that companies incorporated or trading within the country that use information of Brazilian nationals must comply with. Organisations that fail to follow the terms laid down in the law would be liable for a fine equal to 2% of their sales revenue, or even up to $50 million Brazilian Real (about USD 12 Million).

Understanding the Scope and Jurisdiction of Brazil Data Privacy Law

LGPD is applicable to organizations of all sizes operative or incorporated in Brazil. The few exceptions listed in the law in terms of scope include cases where data is collected exclusively for journalistic, artistic and academic purposes, or public safety and national defense. As for the jurisdiction, the law provides for extraterritorial jurisdiction. According to Article 3 under Brazil LGPD, any data collected or processed within the country or for the purpose of offering goods/services in the country are subject to the law. Since the law is applicable if any one of these conditions is met, the location of the organisation becomes irrelevant when we talk about the jurisdiction of this privacy law.

Explained: The Provision of Data Processing Under Brazil LGPD

Data processing under Brazil PGPD works in a similar fashion as it does in EU GDPR. Data processing is defined as the use of data, such as the collection, classification, processing, storage, sharing, transfer, elimination of personal data. According to the law, data processing entails three major roles – the operator, the controller, and the officer. Here’s a better explanation of the roles as defined under the law –

The Controller – He/She is responsible for determining the relevant data processing policies and creating associated guidelines.

The Operator – He/she ensures that the guidelines initiated by the controller are executed.

The Officer – His/Her role is to fill the gap between the controller, the data owner or subject, and the government agency or authority.

Under Article 7, the LGPD lists 10 lawful bases for data processing. They are:

  1. To comply with a legal or regulatory obligation of the controller;
  2. With the consent of the data subject;
  3. To carry out studies by research entities that ensure, whenever possible, the anonymization of personal data;
  4. To execute public policies provided in laws or regulations, or based on contracts, agreements, or similar instruments;
  5. To execute a contract or preliminary procedures related to a contract of which the data subject is a party, at the request of the data subject;
  6. To exercise rights in judicial, administrative or arbitration procedures;
  7. To protect health, in a procedure carried out by health professionals or by health entities;
  8. To protect the life or physical safety of the data subject or a third party;
  9. To fulfill the legitimate interests of the controller or a third party, except when the data subject’s fundamental rights and liberties, which require personal data protection, prevail; or
  10. To protect credit (referring to a credit score).

Other Key Enforcements Under the Brazil LGPD – A Breakdown

Just like the processing of personal data, GDPR and Brazil LGPD agree on some other basics of data privacy. However, this doesn’t mean that the two laws have nothing apart. Let’s look at some of the key enforcements under the Brazil Privacy Law to understand it better.

Definition of Personal Data – Just like in GDPR, the definition of personal data is not singular. The Brazil data privacy law clearly states that personal data could mean any data – as an individual entity or combined with other data – that identifies a natural person or subjects them to a specific treatment.

Data Subject Rights – While GDPR has 8 fundamental rights defined for the data subjects, Brazil LGPD has 9 of them. However, almost all of these 9 rights touch upon the same principles as the subject rights defined in GDPR. Here are the subject rights of the Brazil LGPD –

  1. The right to confirmation of the existence of the processing;
  2. The right to access the data;
  3. The right to correct incomplete, inaccurate or out-of-date data;
  4. The right to anonymize, block, or delete unnecessary or excessive data or data that is not being processed in compliance with the LGPD;
  5. The right to the portability of data to another service or product provider, by means of an express request
  6. The right to delete personal data processed with the consent of the data subject;
  7. The right to information about public and private entities with which the controller has shared data;
  8. The right to information about the possibility of denying consent and the consequences of such denial; and
  9. The right to revoke consent.

Data Protection Officer

This enforcement sets the Brazil LGPD apart from all other international data privacy laws. As stated under Executive Order no. 869/18, the required DPO to be appointed by each organization need not be a natural person. It could also be a committee, company or internal group. Alternatively, an organization may even outsource the position to a third party, such as a specialized data privacy as a service company or law firm.

How Secuvy Can Help You?

Secuvy’s AI-powered Privacy Platform solutions offer easy guidance to help you comply with the LGPD. Our privacy engineering and governance solutions evaluate your privacy data posture and recommend associated risks attached to sensitive data along with notification of remediation steps.

Secuvy provides detailed classification, analysis and reporting to associated risks across the data lifecycle including any gaps found and compliance with LGPD. Fast-track and automate your LGPD program using Secuvy’s privacy solutions. Please email us at info@secuvy.ai for free evaluation.

 

Related Blogs

November 15, 2024

Using Data Classification for Effective Compliance When working toward ISO 42001 compliance, data classification is essential, particularly for organizations handling large amounts of data. Following...

November 12, 2024

Laying the Groundwork for ISO 42001 Compliance Starting the journey toward ISO 42001 compliance can seem complex, but with a strategic approach, companies can lay...

November 07, 2024

A Data Subject Access Request (DSAR) is the means by which a consumer can make a written request to enterprises to access any personal data...

November 07, 2024

VRM deals with managing and considering risks commencing from any third-party vendors and suppliers of IT services and products. Vendor risk management programs are involved...

October 30, 2024

With organizations storing years of data in multiple databases, governance of sensitive data is a major cause of concern. Data sprawls are hard to manage...

October 30, 2024

 There has been a phenomenal revolution in digital spaces in the last few years which has completely transformed the way businesses deal with advertising, marketing,...

October 30, 2024

In 2023, the California Privacy Rights Act (CPRA) will supersede the California Consumer Privacy Act (CCPA), bringing with it a number of changes that businesses...

October 09, 2024

For years, tech companies have developed AI systems with minimal oversight. While artificial intelligence itself isn’t inherently harmful, the lack of clarity around how these...

September 25, 2024

Navigating the Shift in AI Compliance Regulations The latest revisions in the Justice Department’s corporate compliance guidelines signal a significant shift for companies that rely...

September 18, 2024

Introduction The threat landscape around data security evolves each year due to factors like a lack of robust security measures, improper data handling, and increasingly...

August 09, 2024

On July 25, 2024, the European Commission released its Second Report on the Application of the General Data Protection Regulation (GDPR), offering an in-depth look...

August 06, 2024

In today’s fast-paced technological landscape, the intersection of AI, data security, and compliance has become a focal point for enterprises aiming to leverage AI’s capabilities...

July 16, 2024

Today Artificial Intelligence (AI) is a part of our day-to-day activities, and knowingly or unknowingly, it impacts our actions and decision-making. With the growing use...

July 03, 2024

Single platform, privacy-driven security is the future To our colleagues in the data privacy and security space, Over the past few months, I’ve been asked...

July 03, 2024

Growing concerns over data breaches have led to a flurry of data regulations around the world that are aimed at protecting sensitive information about individuals....

June 11, 2024

Data Subject Request. What’s the Impact of Not Fulfilling? In today’s digital age, data privacy has become a paramount concern for individuals and regulatory bodies....

May 13, 2024

It’s not often a cyberattack affects a substantial portion of Americans. In early 2024, UnitedHealth Group confirmed a ransomware attack on its subsidiary, Change Healthcare,...

May 08, 2024

Inventorize personal information with data mapping and meet compliance requirements Organizations have numerous data sources spread across their IT landscape, which they use to collect,...

May 02, 2024

The State of Washington passed the My Health My Data Act (MHMDA), which is a groundbreaking data privacy law focused on protecting personal health data....

April 15, 2024

Essential CPRA Compliance Checklist: Ensuring Business Adherence to California’s Data Privacy Regulation The residents of California have a legal right to know what personal information...

Ready to learn more?

Subscribe to our newsletters and get the latest on product updates, special events, and industry news. We will not spam you or share your information, we promise.

Career Form

By subscribing, you consent to the processing of your personal data via our Privacy Policy. You can unsubscribe or update your preferences at any time.