LGPD (General Data Protection Act) has been valid since last year. A recent change at the request of Sebrae and other entities, causes small businesses to have different treatment now, being waived of some obligations and simplification of adequacy procedures. That's what I'm going to explain in this article!
Reminiscing:
What is LGPD?
A General Data Protection Act (13.709/2018) aims to protect the fundamental rights of freedom and privacy and the free development of the natural person's personality. It also focuses on creating a legal security scenario, with the standardization of regulations and practices to promote the protection of personal data of every citizen in Brazil, according to existing international parameters.
The law defines what personal data are and explains that some of them are subject to even more specific care, such as sensitive personal data and personal data about children and adolescents. It also explains that all data processed, both in the physical and digital environments, are subject to regulation.
In addition, LGPD states that it does not matter whether the headquarters of an organization or its data center are located in Brazil or abroad: if there is the processing of information about people, Brazilian or not, who are in the national territory, LGPD should be observed. The law also authorises the sharing of personal data with international bodies and other countries, provided that the requirements set out therein are met.
*Source: Federal Public Ministry
See also:
- Gastronomy and Culture: A Meeting That Transcends Tastesby Dudu Gentil
- Nationalvox is honored by ALESC for its 20 years of innovation in digital marketingby Dudu Gentil
- NVX 20 years: A history of innovation, partnership and success in digital by Dudu Gentil
- Digital Transformation in Cuiabá Companies: Benefits and Challengesby Dudu Gentil
- Social media trends for 2024: platforms that are shaping digital marketingby Gustavo Trentini
- The Power of Google Evaluations: How to Improve Your Business’s Reputationby Gustavo Trentini
- 7 content to convert to funnel fund with real estate marketingby Dudu Gentil
- Enhance your sales with the power of WhatsApp Marketingby Dudu Gentil
- The new era of email marketing: how to stand out in the inboxby Dudu Gentil
- CRM for real estate and construction companies: boosting sales and loyalty to customersby Gustavo Trentini
Contents
Toggle- The importance of consent
- How the inspection works
- Small businesses need differentiated treatment
- Small enterprises will not have the benefits of easing LGPD in 2 main scenarios:
- Send WhatsApp to unknowns hurts LGPD?
- Information security
- Conclusion
The importance of consent
In LGPD, consent of the data subject is an essential element for the processing, a rule that is excluded in the cases provided for in Article 11, II, of the Law.
And here it is important to observe: the law provides several warranties to the user, such as: to be able to request that your personal data be deleted; to revoke consent; to transfer data to another service provider, among other actions. The processing of the data should be done taking into account some requirements, such as purpose and need, to be previously agreed and informed to the holder.
How the inspection works
To monitor and apply penalties for LGPD non-compliance, Brazil has the National Personal Data Protection Authority, ANPD. The institution has the tasks of regulating and guiding, preventively, how to apply the law in general.
However, the General Law on the Protection of Personal Data also provides for the existence of data processing agents and stipulates their functions in organizations such as: the controller, who makes decisions about the processing; the operator, who performs the processing on behalf of the controller; and the controller, who interacts with the data subjects and the national authority.
With regard to risk and failure management, the person responsible for managing personal data should also draft governance standards; adopt security preventive measures; replicate good practices and certifications existing in the market; draw up contingency plans; carry out audits; resolve incidents with agility, with the immediate warning about violations of the DPRK and affected individuals.
And the next paragraph requires a lot of attention:
Security failures can generate fines of up to 2% of the annual revenue of the organization in Brazil – limited to R $ 50 million per infringement. The national authority shall set penalty levels according to the seriousness of the failure and send alerts and guidelines before imposing sanctions on organisations.
Small businesses need differentiated treatment
According to Sebrae, the intention is not to exempt small businesses from the responsibility of protecting personal data, but rather to observe their specificities (as provided for in the Brazilian Constitution). Changes are an important tool to help small businesses, which correspond to 99% of Brazilian enterprises, i.e., a universe of more than 17 million companies.
“ Individual micro-enterprises and small businesses need to have equity in treatment, precisely because they do not have the size and budget of large companies. It is a matter of balance and increasing the effectiveness of the law. ", highlights Carlos Melles, president of Sebrae.
The new rules that have come into effect since January 2022 apply to:
- micro-enterprises and small enterprises,
- start-ups;
- nonprofit organisations.
Small enterprises will not have the benefits of easing LGPD in 2 main scenarios:
1.Treatment of high risk data
The new rules shall not apply when treatment is considered to be high risk for the holders. A treatment can be considered high risk when meeting at least one general criterion and a specific criterion cumulatively:
General criteria
- where processing of personal data is carried out on a large scale;
- the processing of personal data can significantly affect the fundamental interests and rights of the holders.
Specific criteria
- use of emerging or innovative technologies;
- surveillance or control of areas accessible to the public;
- decisions taken solely on the basis of automated treatment of Personal data, including those designed to define the personal, professional, health, consumer and credit profile or the personality aspects of the holder;
- use of sensitive personal data or personal data of children, adolescents and the elderly.
There are still doubts about what may or may not be considered high-risk treatment. For this reason, it is stated in the Resolution that the DPONA may provide guidelines and guidance in order to assist small treatment agents in the evaluation of high risk treatment.
To characterize a large-scale treatment, factors such as: the number of subjects, the volume of personal data involved, duration, frequency and geographical extent of the treatment performed should be considered.
2. Gross revenue exceeding the permitted limit
Companies receiving gross revenue above the permitted limit are also not included in the new rules:
- for small companies: gross revenue over R$ 4,800,000.00 (four million eight hundred thousand reais), in each calendar year;
- for startups: gross revenue over R $ 16,000,000.00 (sixteen million reais) in the previous calendar year;
- or also in the case of the company belonging to the economic group whose overall revenue exceeds the limits mentioned above.
In practice, what changes?
- Can you send whatsapp?
- Do you need to delete old data?
Among the flexibilizations envisaged are the possibility of maintaining a more simplified record of their operations, since the law requires an inventory of all data operations and also the flexibility of the procedure for the communication of security incidents. The resolution provides that the ANPD will make available a form of its own for registration and that the incident procedure will be subject to future regulation.
Other rules also allow the adoption of a simplified information security policy and different deadlines for small entrepreneurs who will, for example, have twice the time required for large companies to answer questions posed by data subjects.
One of the most striking changes is the waiver of the appointment of the Data Protection Officer (DPO), which is the person responsible for maintaining communication between the data-processing agent, its owners and the ANPD.
The new resolution will suffice to create a communication channel with data subjects. But, because of the importance of the PDO, the regulation brings an incentive for its indication, by treating it as a policy of good practice and governance.
Send WhatsApp to unknowns hurts LGPD?
Small Business Magazine, Big Business interviewed experts to answer this question:
If it's a message between personal accounts, for private purposes, it doesn't hurt LGPD. But if it has economic purposes, such as promoting products or services, and there is no legal justification for sending, it may be sanctioned.
It is worth remembering that all personal data processing needs to have a legal basis, which will be linked to the purpose of what you will do or intend to do with the data.
LGPD provides ten legal justifications for processing personal data and one of them is consent. There is also the possibility of contact to comply with legal obligations, such as demands, or to conduct studies by research bodies, for example.
So don't go around sending WhatsApp messages to anyone who didn't consent to receive your communications. Ask, understand if you want to be on your mailing list, to avoid punishments imposed by law.
Information security
The new rules made the requirements more lenient with regard to information security:
- the establishment of a simplified Information Security Policy for small businesses;
- determines that small agents should adopt essential and necessary administrative and technical measures. Here, it is important to remember that in October 2021, ANPD published a Guide to Information Security for Small Treatment Agents, containing a set of minimum measures necessary;
- the DPRK will have on the flexibility or simplified procedure of reporting of safety incident for small treatment agents, such change, however, this point remains pending regulation.
It is important to highlight that this does not exempt small companies from compliance with the other LGPD devices, including but not limited to the legal bases, principles and rights of the owners.
Conclusion
The expectation is that these measures will contribute to establishing a safer personal data protection ecosystem and, consequently, to increasing the trust of data subjects in the personal data processing agents of small businesses.
Finally, the suggested measures should be understood as good practices and complemented with others that will be identified as necessary to promote security in the informational flow of personal data, no matter how small the business is.














