{"id":280,"date":"2018-08-16T14:38:12","date_gmt":"2018-08-16T17:38:12","guid":{"rendered":"http:\/\/dvwca.com.br\/?p=280"},"modified":"2026-01-30T13:56:38","modified_gmt":"2026-01-30T16:56:38","slug":"sancionada-a-lei-geral-de-protecao-de-dados-do-brasil-com-veto-a-autoridade-nacional-de-protecao-de-dados-anpd","status":"publish","type":"post","link":"https:\/\/devivo.letsite.com.br\/en\/sancionada-a-lei-geral-de-protecao-de-dados-do-brasil-com-veto-a-autoridade-nacional-de-protecao-de-dados-anpd\/","title":{"rendered":"Brazil&#8217;s General Data Protection Law is enacted, but the National Data Protection Authority (ANPD) is vetoed."},"content":{"rendered":"<p><span dir=\"auto\">After eight years since the first public consultation promoted by the Ministry of Justice, Law 13.709\/2018, known as the General Data Protection Law (LGPD), was sanctioned on Tuesday (14) by President Michel Temer. The LGPD comes from PLC 4.060\/2012, which was converted into PLC 53\/2018, from the Chamber of Deputies, which creates a regulatory framework on the protection of personal data in Brazilian territory and amends Law 12.965\/16 (Marco Civil da Internet). Considering the\u00a0 18-month\u00a0<\/span><em><span dir=\"auto\">vacatio legis<\/span><\/em><span dir=\"auto\">\u00a0period \u00a0, the law will come into force in February 2020.<\/span><\/p>\n<p><span dir=\"auto\">The timing of this law&#8217;s entry into force is not a mere coincidence. Its passage through the Senate occurred under an urgency regime, driven by the entry into force of the European data protection legislation, the\u00a0\u00a0<\/span><em><span dir=\"auto\">General Data Protection Regulation\u00a0<\/span><\/em><span dir=\"auto\">\u00a0(GDPR), in May of this year. The GDPR has required many Brazilian companies operating in the European Union or processing data of European citizens to adapt in order to avoid the hefty fines stipulated in this law and the loss of contracts with local partners. Among the new rules, the requirement for adequate levels of cybersecurity in the countries to which the data of European citizens is transferred was established.<\/span><\/p>\n<p><span dir=\"auto\">It is in this context that major world economies are also seeking to respond to recent data breach incidents, such as that of Cambridge Analytica, which improperly used data from American Facebook users for electoral purposes, and here in Brazil, where the Public Prosecutor&#8217;s Office pointed to an alleged scheme of selling personal data of Brazilians by the Federal Data Processing Service (Serpro) to other public administration bodies.<\/span><\/p>\n<p><span dir=\"auto\">The LGPD (Brazilian General Data Protection Law) aims to adapt the practices of Brazilian companies to these new standards and the current scenario, placing Brazil among the more than 120 countries that have a data protection law. The law regulates the use, protection, and transfer of personal data in Brazil, in both public and private sectors, online or offline. Let&#8217;s look at some of the main points covered:<\/span><\/p>\n<p><strong><span dir=\"auto\">Scope of application\u00a0<\/span><\/strong><strong><span dir=\"auto\">:<\/span><\/strong><span dir=\"auto\">\u00a0\u00a0applicable to any activity involving the use of personal data, both in the public and private sectors, online or offline, including consumer and employment relations.<\/span><\/p>\n<p><strong><span dir=\"auto\">Extraterritorial application<\/span><\/strong><span dir=\"auto\">\u00a0: foreign companies with branches in Brazil or offering services to the national market are also subject to the law.<\/span><\/p>\n<p><strong><span dir=\"auto\">Personal, sensitive, anonymized, and public data<\/span><\/strong><span dir=\"auto\">\u00a0: specific concepts and rules have been established for each type of data collected, stored, and shared.<\/span><\/p>\n<p><strong><span dir=\"auto\">Authorization for data processing.<\/span><\/strong><span dir=\"auto\">For the processing of personal data, which includes data collection, a legal basis will always be necessary, with consent being only one of the 10 hypotheses listed by the LGPD (Brazilian General Data Protection Law) that authorize the use of data.<\/span><\/p>\n<p><strong><span dir=\"auto\">Data protection principles<\/span><\/strong><span dir=\"auto\">\u00a0: the LGPD lists 10 basic principles of data protection, including purpose, necessity, transparency, security, non-discrimination, accountability, and reporting.<\/span><\/p>\n<p><strong><span dir=\"auto\">Rights of data subjects<\/span><\/strong><span dir=\"auto\">\u00a0: data subjects will have broad rights, including the right to information, access, rectification, cancellation or deletion, opposition, and portability.<\/span><\/p>\n<p><strong><span dir=\"auto\">Data Protection Officer (DPO)<\/span><\/strong><span dir=\"auto\">\u00a0: every company subject to the LGPD must have a data protection officer, who will be a person appointed by the controller to act as a communication channel between the controller and the data subjects and the National Authority.<\/span><\/p>\n<p><strong><span dir=\"auto\">Security<\/span><\/strong><span dir=\"auto\">\u00a0: those responsible for data processing must adopt technical and administrative security measures capable of protecting personal data.<\/span><\/p>\n<p><strong><span dir=\"auto\">Mandatory notification<\/span><\/strong><span dir=\"auto\">\u00a0: notification to the ANPD (National Data Protection Authority) regarding the occurrence of information security incidents will be mandatory within a reasonable timeframe. The ANPD may also determine the notification of the data subjects involved and the public disclosure of the incident, depending on the severity of the case.<\/span><\/p>\n<p><strong><span dir=\"auto\">Sanctions<\/span><\/strong><span dir=\"auto\">\u00a0: the ANPD may apply administrative penalties for violations of the LGPD, ranging from warnings to fines that may reach R$ 50,000,000.00 (fifty million reais) per infraction.<\/span><\/p>\n<p><strong><span dir=\"auto\">National Data Protection Authority<\/span><\/strong><span dir=\"auto\">\u00a0: the LGPD established the National Data Protection Authority \u2013 ANPD, a public authority linked to the Ministry of Justice responsible for supervising the application of the law, which may establish guidelines for the protection of personal data in Brazil and will have the responsibility of developing the &#8220;National Data Protection and Privacy Policy,&#8221; with powers to monitor and apply sanctions, among other activities. Additionally, the National Data Protection and Privacy Council was created, an advisory body that will assist the ANPD.<\/span><\/p>\n<p><span dir=\"auto\">However, President Temer&#8217;s sanction included some vetoes to certain provisions of the law, most notably the veto of the creation of the ANPD and the National Council. The justification for this exclusion is the legal prohibition against the Legislative branch creating bodies that generate expenses for the Budget, which would cause a &#8220;flaw in the initiative&#8221; since only the executive branch has this prerogative. Considering the fundamental importance of these bodies for the enforceability of the law, in the coming weeks the executive branch should create them through a provisional measure or a new bill of its own authorship.<\/span><\/p>\n<p><span dir=\"auto\">Also vetoed were provisions that would have prevented the sharing of personal data by the Public Authorities with private entities, under the argument that this prohibition could make the provision of public services unfeasible, as well as Article 28 in its entirety, which provided for the publicity of the communication or shared use of personal data between public bodies and entities, as it would make the regular exercise of some public actions, such as inspection, control and administrative policing, unfeasible.<\/span><\/p>\n<p><span dir=\"auto\">Finally, some sanctions provided for in Article 52 of the Bill were vetoed, such as the suspension or prohibition of the exercise of data processing activities and the partial or total suspension of the operation of databases. This veto was due to the risk of insecurity for those responsible for such activities, and the damages resulting from the unavailability of databases.<\/span><\/p>\n<p><span dir=\"auto\">Therefore, considering the widespread use of personal data in the daily operations of companies across various sectors in Brazil, the LGPD (Brazilian General Data Protection Law) will require a significant effort for them to adapt to this new scenario as quickly as possible, given that the adaptation period is short considering all the measures to be taken. As with the European GDPR, the delayed adoption of measures can lead to operational difficulties and even the application of heavy administrative sanctions.<\/span><\/p>\n<p><span dir=\"auto\">Attorney Luiz Guilherme Silveira Franco \u2013\u00a0\u00a0<\/span><a href=\"mailto:lfranco@dvwca.com.br\"><span dir=\"auto\">lfranco@dvwca.com.br<\/span><\/a><span dir=\"auto\">\u00a0\u00a0is available to provide any further clarifications deemed necessary on this subject.<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>After eight years since the first public consultation promoted by the Ministry of Justice, Law 13.709\/2018, known [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1624,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticia"],"acf":[],"_links":{"self":[{"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/posts\/280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/comments?post=280"}],"version-history":[{"count":2,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/posts\/280\/revisions"}],"predecessor-version":[{"id":1992,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/posts\/280\/revisions\/1992"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/media\/1624"}],"wp:attachment":[{"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/media?parent=280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/categories?post=280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devivo.letsite.com.br\/en\/wp-json\/wp\/v2\/tags?post=280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}