Data protection is an extremely important topic nowadays. The LGPD’s main objective is to protect the fundamental rights of freedom and privacy, as well as the free development of the natural person’s personality.
The LGPD defines what personal data is and explains that some of it is subject to even more specific care, such as sensitive personal data and personal data about children and adolescents. The law establishes that all processed data, both in physical and digital environments, is subject to regulation.
In addition, the LGPD establishes that it does not matter whether an organization’s headquarters or its data center is located in Brazil or abroad: if there is processing of information about people—Brazilian or not—who are in national territory, the LGPD must be complied with.

The General Data Protection Law (LGPD) came into force in Brazil in September 2020 and aims to ensure the protection of Brazilian citizens’ personal data.
The LGPD establishes clear rules on the collection, storage, processing, and sharing of personal information, as well as the rights of the data subjects.
The importance of the LGPD is related to protecting the privacy and security of each person’s personal data. With the growing amount of data collected by companies, it is essential that citizens have control over their personal data and that this data is used only for legitimate purposes.
The LGPD provides several guarantees to citizens, such as being able to request that their personal data be deleted; revoke consent; transfer data to another service provider, among other actions. The data subject’s consent is considered an essential element for processing, except in the cases provided for by law.
To oversee and apply penalties for non-compliance with the LGPD, Brazil has the National Authority for the Protection of Personal Data (ANPD). The institution will have the tasks of regulating and providing preventive guidance on how to apply the law.
However, the ANPD (Law No. 13,853/2019) is not enough, which is why the General Personal Data Protection Law also provides for the existence of data processing agents and sets out their roles within organizations, such as: the controller, who makes decisions about processing; the operator, who processes data on behalf of the controller; and the data protection officer, who interacts with personal data subjects and the national authority.
Security failures can result in fines of up to 2% of the organization’s annual revenue in Brazil—limited to R$ 50 million per violation. To avoid such fines and ensure the security of users’ personal data, companies must draft governance policies; adopt preventive security measures; replicate best practices and certifications available in the market; develop contingency plans; conduct audits; resolve incidents quickly, with immediate notification of breaches to the ANPD and affected individuals.
Does your business need data protection? We have what you need! Get in touch with us today and find out how we can help you.

Leave a Reply