Brasil’s Lei Geral de Proteção de Dados (LGPD) |
Notice at Point of Collection
|
Data subjects should be informed about the specific purpose of the processing, the type, and duration of the processing, the identification of the controller along with contact information, information regarding the shared use of data by the controller and others as well as the purpose for such sharing, the responsibilities of the agents that will carry out the stated processing and the data subject’s rights under the law, |
Consent
|
Consent is one of the legal basis for data processing under this regulation and it shall refer to specific purposes. Consent given for generic purposes is considered void and if the purpose of the processing changes, consent will have to be regained. Consent should be written and documented and should be revocable at all times. |
Data Subject Requests
|
It entitles data subjects with the right to revoke consent, confirmation, access, correction, portability, deletion, information about third parties with whom their personal data has been shared with, and information about the possibility of denying consent |
Storage
|
It requires that the data needs to be deleted upon the termination of its processing period, unless it is required to fulfill any legal obligation, or use in any research while ensuring data anonymization. |
Lawful Basis for Processing Data
|
It establishes ten legal basis for processing of data, such as consent of data subject, compliance with legal obligation, execution of public policies by public administration, carrying out research studies, execution of a contract, for exercise of rights in judicial, legal or arbitration proceedings, for protection of life or physical safety, to protect health, fulfillment of the legitimate interest of the controller, for protection of credit etc. |
Cross Border Data
|
It imposes specific conditions restrictions for cross border data transfers. Personal data can be transferred outside Brazil only when adequate protection is ensured or there are safeguards in place to ensure the level of protection is essentially equivalent to that currently guaranteed by the LGPD. |
Data Security
|
It requires both the data controller and operator to take security, technical and administrative measures to protect personal data from unauthorized accesses and accidental or unlawful situations of destruction, loss, alteration, communication or any type of improper or unlawful processing. |
Breach Response
|
It demands data controllers or operators to notify the National Authority and the affected data subject of breach and damages within a reasonable time period. |