LGPD: Key Aspects and Compliance
Home » LGPD: Key Aspects and Compliance
Understanding Brazil’s LGPD: Key Aspects and Compliance
Brazil transformed its data protection landscape by adopting the Lei Geral de Proteção de Dados (LGPD) on September 18, 2020.
Much like the European Union’s General Data Protection Regulation, the Lei Geral de Proteção de Dados is the first broad legislation on data protection in Brazil, aiming at protecting personal data and beefing up the privacy rights of individuals in Brazil.
Timeline and Scope of Enforcement
Although the LGPD officially entered into force in September 2020, its actual date for applying penalties was August 1, 2021. That said, natural persons and public authorities could exercise their rights under the LGPD right after its effective date. Prior to the LGPD, data protection in Brazil had been regulated by numerous pieces of legislation, among them the Brazilian Internet Act (Federal Law No. 12,965/2014) and several sectorial laws. These are all brought together in the LGPD as a single framework of rules.
Key Provisions and Applicability
Processing of personal data, irrespective of the medium or locality of the data processor, is subject to the LGPD if it takes place in Brazil or involves the processing of data of individuals located in Brazil. It also covers data that was collected in Brazil. Nevertheless, some kinds of data processing are exempt, such as those carried out for personal use or journalistic purposes, and data used for public safety and criminal investigations.
Rights and Definitions Under LGPD
It grants data subjects nine specific rights: access, correction, and deletion of their data; to be informed about processing; and to share their data with other services. Moreover, these rights ensure comprehensive control over personal information.
Very many of these rights correspond to the same ones established by the GDPR. The LGPD broadly defines personal data as any information related to an identifiable individual. More sensitive data, such as health and biometric information, are subject to stricter processing rules.
Legal Bases for Processing
It provides ten legal bases for processing personal data, with consent being one principal basis. Other grounds include compliance with legal obligations, execution of contracts, protection of vital interests, and protection of legitimate business interests. Additionally, organizations must maintain a record of data processing activities. This record should specify the nature of the data collected, the purpose, the retention period, and any sharing details.
Regulatory Oversight and Penalties under the LGPD
The ANPD (National Data Protection Authority) is the supervisory authority that enforces the LGPD in Brazil. Established in August 2020, the agency sets technical standards for data protection. It oversees data processing compliance and handles data breach notifications.
Non-compliance penalties may be very high: fines up to 50 million Brazilian reals or 2% of a company’s annual turnover in Brazil.
Comparison of the LGPD and GDPR
It shares several similarities with the GDPR, including data subject rights and the requirement to appoint a DPO.
However, it also has key differences. For instance, the LGPD provides ten legal bases for data processing, while the GDPR offers only six. Additionally, the LGPD expands the definition of personal data.
Furthermore, the LGPD enforcement mechanisms are not as strict as those under the GDPR—maximum fines are lower.
Wrap Up
In a nutshell, it is a great step towards the evolution of regulation in data protection in Brazil. This will align the country to international standards and also address its needs. The reason behind compliance with LGPD for organizations operating in Brazil is just that it avoids huge penalties and enhances trust.
Check this website for detailed information.
