• Menu
  • Solutions
  • Partners
      Partner Program
      Reseller
      MSP
      Become a Partner
      Deal Registration
  • Gatelab
  • Insights
      News
      Resources
  • Company
      About us
      Careers
  • Contact
    Demo
Solutions
Partners
Partner Program Reseller MSP Become a Partner Deal Registration
Gatelab
Insights
News Resources
Company
About us Careers
Contact
Demo
What is LGPD, the Brazilian General Data Protection Law?

Updated at: Nov 13, 2019

By Gatefy

What is LGPD, the Brazilian General Data Protection Law?

Today we're going to explain more succinctly what LGPD is, its main points and how it interferes in your routine or your business if you have any connection with Brazil. LGPD is the Brazilian General Data Protection Law, a set of rules that determine how information and personal data must be treated, shared and collected. In short, the law came to protect consumers, focusing on their privacy, demanding from companies more protection and attention when dealing with third party information.

LGPD was sanctioned in 2018 and is expected to take effect in August 2020. With the law, Brazil is now included in the list of countries that have a specific law for personal data protection and security. By the way, many people have been calling LGPD "the Brazilian GDPR". We explain why: General Data Protection Regulation (GDPR) is a similar law that was implemented in the European Union in 2018 and focuses on privacy and the conscious use of personal information by companies and other organizations.

LGPD key points

Just by this brief introduction to LGPD you can see that it's going to change the routine of those who do business in Brazil. To better understand the law, it’s important to understand the context of the country and how internet browsing works nowadays.

Today, we use our personal data in a lot of things we do on the web. For example, to sign up for a social network, you need to provide your personal details. To buy that cool t-shirt online, you also need to provide your information. That is, we provide our data daily to companies. And what's worse: much of this information has no direct connection with the business purpose.

What's the result of that? Data that should be treated confidentially and privately is sold and used commercially without your permission and knowledge. Do you know when you receive a spam email from a store trying to sell you a product and wonder: how did they get my email? Who provided it? So that's what we're talking about.

LGPD wants to shed light upon this issue. On the one hand, the law requires companies to be clearer and more honest about their customers' data use and, on the other hand, it allows consumers to have more control over how their own information is used. Therefore, we may note that LGPD and other similar laws arose from the need for transparency, privacy and security.

How LGPD works in practice

According to the LGPD law, companies need to comply with 10 principles. They are: purpose, appropriateness, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and responsibility.

To summarize, LGPD's 10 principles say that companies must take security measures to protect personal data, request only data that's relevant to the company, and, ultimately, be transparent to customers, making their intentions and objectives clear.

According to Article 9, “the data owner has the right to have easy access to the information about the processing of his data, which shall be made available clearly”. The law also states that access must be made available “at any time and upon request”. In addition, the data owner may require that his data be deleted or even changed.

The agency responsible for mediating this relationship and overseeing companies is called ANPD (National Data Protection Authority). The fines for non-compliance with LGPD can reach BRL 50 million for infringement committed.

How to comply with LGPD

The first step to meet the requirements of the LGPD law is to understand who is involved in the process. There are 4 actors. See what the law says.

1. Holder or Data Owner

Person to whom personal data are subject to processing.

2. Controller

Person or company that is responsible for maintaining and processing the data.

3. Operator

Person or company that is responsible for processing the personal data on behalf of the controller.

4. Person in charge

Person appointed by the controller and operator to act as a communication channel between the controller, the data owner and the ANPD.

Once the actors are defined, the company needs to analyze and map the flow of gathering, using, and storing personal data. It's necessary to understand the cycle that information follows within the company so that adjustments can be made and vulnerabilities corrected.

Of course, this isn't a simple task, as many areas of the business need to undergo some kind of change. This is why we advise companies that do business in Brazil to seek expert help. The change to comply with the law may even involve the adoption of new technologies.

Summing it up

Despite the changes it will bring, LGPD should be observed more in terms of social responsibility and commitment. What we mean is that serious companies that value the quality of their services and consumers won’t be harmed. They will have to adapt their operation according to a law that, at first, preaches a more transparent relationship between companies and customers. This, in fact, is a worldwide movement that is landing in Brazil.

If you have any questions or would like to talk more about it, write to us: contact@gatefy.com. We can help.

LGPD in full

If you want to check out the full LGPD, in Portuguese, click here.


Latest posts

Main points of comparison between Brazilian LGPD and European GDPR

Main points of comparison between Brazilian LGPD and European GDPR

LGPD and GDPR determine how companies must handle and process such data, what rights the information owners have and what penalties apply if the rules are breached.

Tips to spot Black Friday scams.

5 tips to spot Black Friday scams

Black Friday is coming and that means the attractive pricing season has begun. Unfortunately, however, the Black Friday arrival also raises concerns.

Tricks used in emails to deliver malware

5 tricks used in emails to deliver malware

The combination of malware and email is a dangerous one. These terms are closely related to each other since email is the main malware vector.

Related posts

Can malware hack and steal your email account? How artificial intelligence and machine learning fight phishing What is big data? Social engineering history in the age of computers and the internet What is logistic regression and how do we use it in emails
Back to News
Get the latest news and
reports about cybersecurity
Ready to get a free threat
assessment for your business?

Follow us

Follow us

Like us

Solutions Gatefy Email Protection Email Encryption Email Continuity DLP
Partners Partner Program Reseller MSP Become a Partner
Company About Us Careers Gatelab Contact
Shortcuts Support News Resources Partner Portal
Miami - USA
Tel +1 305 425 9040
Curitiba - BR
Tel +55 41 4042 8280
English ▾
Português
  |   sitemap   |   documentation   |   legal   |   © 2018 Gatefy - todos os direitos reservados