Frequently asked questions
What is the LGPD and what does it require from companies?
The Brazilian General Data Protection Law (Law No. 13.709/2018), approved in August 2018, requires both companies and governments to request authorization to store personal information and disclose what will be done with that data. One of its goals is to standardize and simplify the often-ignored terms of use. The law takes effect on August 16, 2020.
Which companies need to comply with the LGPD?
Legal entities that collect data from Brazilian citizens must adapt, as well as any company headquartered anywhere in the world that targets products and services to people in Brazil. The rules apply to the processing of data from employees, customers, suppliers, and third parties. A good compliance project takes about 9 months to complete, so the timeline is tight for companies that haven't started yet.
What is the penalty for non-compliance with the LGPD?
Supervisory bodies, such as the future National Data Authority, the Public Prosecutor's Office, and agencies like Procon, may apply fines of up to 2% of a company's revenue, not exceeding R$ 50 million. That's why the law also requires companies to have a professional responsible for this, with a role similar to a data protection officer (DPO).