Cesar Peres Dulac Müller logo

CPDMA BLOG

Category:
Date: 14 de December de 2023
Posted by: CPDMA Team

The first sanctions applied by the National Agency for the Protection of Personal Data (ANPD) were a wake-up call for companies: the LGPD is a serious law and must be complied with.

Artigo de Juliana Bloise sobre a LGPD.

The General Personal Data Protection Law - Law no. 13.709/18 (LGPD) was published in 2018 and came into force in 2020. This deadline was given to public and private legal entities (processing agents) that collect, store or process personal data of individuals, in Brazil or abroad, to comply with the new regulations.

Initially, sanctions and administrative fines were imposed by consumer protection agencies (PROCON), the Public Prosecutor's Office, as well as labor and civil lawsuits, until the National Data Protection Authority (ANPD) began its inspection activities in 2021.

At first, the ANPD worked to raise awareness and educate data processors about the importance of applying good practices in the processing of personal data, in the pursuit of the fundamental right to informational self-determination (EC No. 115/22).

The personal data protection system was put into effect when the first administrative sanctions were applied by the regulatory agency.

The first company fined is a provider of telephony services, such as telemarketing and self-service via the messaging service WhatsApp. Because it is a micro-enterprise, the amount for each infraction was limited to 2% of its gross revenue, totaling R$7,200.00 per infraction.

The company was fined for failing to appoint the person responsible for processing personal data, as required by art. 41 of the LGPD, and for processing personal data without a legal basis: the company processed voters' personal data for the purposes of an election campaign, without the express consent of the data subjects, as required by art. 7, II, of the LGPD.

The Santa Catarina State Health Department (SES-SC) was the second public company to receive sanctions from the ANPD. Four warning sanctions were imposed for leaking personal data.

SES-SC infringed art. 49 of the General Personal Data Protection Act (LGPD) by neglecting the security of systems for storing and processing personal data, and by the lack of clarity, inadequacy and timeliness of the notice to data subjects, which was considered an infringement of art. 48 of the LGPD. In addition, the agency failed to submit the Personal Data Protection Impact Report (RIPD) requested by the Authority.

It should be noted that the sanctions imposed on companies are attributed to the lack of proper documents and procedures.

Thus, contractual compliance and the creation of standardized documents, without the implementation of effective practices, are not enough to guarantee compliance with the law and avoid sanctions.

The application of sanctions by the ANPD is an important instrument for the protection of personal data in Brazil. Companies must be vigilant in complying with the legislation to avoid the risk of administrative sanctions.

By: Juliana Bloise

Civil Law | CPDMA Team

Return

Recent posts

Investing in startups in Brazil: the Convertible Loan Agreement. 

In the age of technology, the start-up ecosystem has attracted many people in recent decades. This is mainly due to the rapid rise of the digital economy, which has led to many success stories of companies that today represent giant players in the market, regardless of the sector in which they operate. In this context of scalable entrepreneurial initiatives, startups have shown themselves to be a huge attraction [...]

Read more
Learn about the asset class - COPYRIGHT

Closing our series of posts on the Classes of Intellectual Property Assets, today we're going to look at the registration of COPYRIGHT. An author is the natural person who creates a literary, artistic or scientific work. Copyright protects such works and can be patrimonial (right to commercial exploitation of the work) or moral (claim of authorship, conservation [...]

Read more
SOS-RS transaction: another possibility for regularization in the post-flood scenario

On June 26, 2024, a new type of operation was published covering companies with a tax domicile in Rio Grande do Sul. This is yet another measure taken by the Federal Government to deal with the damage caused by the floods in Rio Grande do Sul. The new operation, called "SOS-RS Operation", was instituted by PGFN/MF Ordinance No. [...].

Read more
Discover the asset class - DOMAIN REGISTRATION

In our series of posts explaining the differences between the classes of intellectual assets, today we'll look at DOMAIN REGISTRATION. The protection of a website's electronic address (domain) is carried out at Registro.BR. In this case, the domain availability search is essential for registration. If a third party tries to register a [...]

Read more
Learn about de asset class - SOFTWARE REGISTRATION

Today's topic in our series of posts explaining the differences between classes of intellectual assets will be: SOFTWARE REGISTRATION. Software registration protects the computer program itself, i.e. the source code. Registration is essential for proving authorship of the development. It is done at the INPI [...]

Read more
Discover the asset class - INDUSTRIAL DESIGN

In our series of posts explaining the differences between classes of intellectual assets, today we're going to look at INDUSTRIAL DESIGN. Industrial Design is the ornamental plastic form of an object - for example, the design of a product or the set of lines applied to a product, such as a print - that gives it [...]

Read more
crossmenuchevron-down
en_USEnglish
linkedin Facebook pinterest youtube lol twitter Instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter Instagram