The Brazilian Data Protection Authority (ANPD) published Resolution CD/ANPD No. 19, which creates the procedures and rules for recognizing the suitability of other countries or international bodies to carry out international personal data transfer operations, as well as approving the standard contractual clauses that may be used by processing agents to legitimize the international transfer of personal data.
The Brazilian Data Protection Authority (ANPD) has published Resolution CD/ANPD No. 18, which creates additional rules for the appointment of the Person in Charge (similar, although not equivalent, to the Data Protection Officer under the GDPR).
As background, according to Law No. 13.709/18 (Brazilian Data Protection Law (LGPD)), data controllers must appoint a Person in Charge. The “Person in Charge” has the primary role of serving as a communication liaison between the data controller, data subjects and ANPD, as well as providing training and guidance to the controller’s employees, and complying with any other instructions that controller may give.
On 26 April 2024, the Brazilian Data Protection Authority (ANPD) published the Resolution CD/ANPD no. 15 which approved the Regulation on Notification of Security Incident (“Regulation”). Such Regulation sets forth the mandatory procedures that data controllers must follow when notifying security incidents to ANPD and personal data subjects.
According to Law No. 13,709/18 (Brazilian General Data Protection Law, or LGPD), the controller must notify the occurrence of a security incident that may give rise to relevant risk or damage to data subjects not only to ANPD, but also to the data subjects.
The Brazilian Data Protection Authority opened on 16 August 2023, a public consultation regarding the Preliminary Study on the personal data processing legal basis of legitimate interest. The consultation will be open for 30 days (until 15 September) on the Participa Mais Brasil platform.
On 15 August 2023, the Brazilian Data Protection Authority launched a public consultation on the regulation of international transfer of personal data, which will be available for 30 days (until 14 September 2023) on the Participa Mais Brasil platfom. The draft under public consultation sets forth the Resolution of the Regulation of International Transfers of Personal Data and the Standard Contractual Clauses template, establishing provisions for the international transfer of personal data according to the Brazilian General Data Protection Law.
On 6 July 2023, the Brazilian National Data Protection Authority (ANPD) issued its first sanction for non-compliance with the Brazilian General Data Protection Law (LGPD). The ANPD’s General Supervision Coordination determined the penalties in conclusion to the administrative sanctioning process against a small business entity, due to violation of articles 7 and 41 of the LGPD, and article 5 of Resolution CD/ANPD No. 1/2021.
On 12 April, Justice Secretary Flavio Dino issued an ordinance that makes it possible to hold digital platforms accountable for the dissemination of content that promotes violence in schools. The document sets forth specific obligations for platforms, such as the immediate removal of certain content after a request from the competent authorities, systemic risk assessment, adoption of measures to prevent the spread of new threats to schools and a policy of active content moderation by application providers. In addition, platforms must prepare reports for the justice secretariat analyzing the risk factors of spreading certain illegal content, and whether recommendation algorithms or other algorithms used by platforms, as well as the content moderation practices adopted, contribute to such risk factors.
Explore Data PULSE, a platform which helps you to navigate the complex landscape of data, regulatory and IP protection concerns at each stage of the medical product life cycle. As you navigate through each key issue, Data PULSE will help you to identify and mitigate risks across multiple jurisdictions and optimize your strategy through research, market authorization and post-market study phases.