DataSunrise Achieves AWS DevOps Competency Status in AWS DevSecOps and Monitoring, Logging, Performance

LGPD Data Protection Compliance

LGPD Data Protection Compliance

The Brazilian General Data Protection Law or the LGPD (Lei Geral de Proteção de Dados Pessoais) is a law that was passed by in 2018 and came into force in 2020.

This law serves a legal basis for data usage of individuals in Brazil no matter where the data processor is located. Much like the GDPR, businesses are required to protect the data of individuals irrespective of their location.

The LGPD provides 9 rights for the data subject, provides the definition of sensitive data, and establishes a new data protection authority.

In this article, we will discuss what is the LGPD, what rights data subjects have, and how DataSunrise can help your business to stay in compliance.

The Definition of Sensitive Data

The LGPD defines sensitive data as a special category of personal data that deserve additional protection due to its sensitive nature. Sensitive data is any data connected with:

  1. Racial or ethnic origin
  2. Religious beliefs
  3. Political opinions
  4. Health or biometric data
  5. Sexual orientation
  6. Genetic data
  7. Criminal record

The processing of sensitive data is generally prohibited under the LGPD. There are exceptions such as data subject’ explicit consent, or when processing is necessary for a specific purpose, such as public health or law enforcement.

The LGPD imposes additional requirements on the processing of sensitive data, such as the requirement to obtain explicit consent from the data subject, to inform the data subject of the specific purpose of the processing, and to use higher standards of data security to ensure the protection of sensitive data.

Data Subject Rights by the LGPD

The LGPD provides the following rights for data subjects:

  1. The right to access data.
  2. The right to confirm the existing processing.
  3. The right to request the correction of inaccurate, incomplete, or out-of-date data.
  4. The right to block or delete unnecessary or excessive information if data is not processed in compliance with the LGPD.
  5. The right to transfer data to another data processor or service in a structured, commonly used, and machine-readable format.
  6. The right to request deletion of personal data.
  7. The right to know about public and private entities with which data is shared.
  8. The right to information about the possibility of denying consent and its consequences.
  9. The right to revoke consent.

However, these rights may have limitations and exceptions, such as when processing is necessary for compliance with legal obligations or the performance of a contract.

Comparison of the LGPD and the GDPR

The LGPD is similar to the GDPR in that both laws apply to businesses and organizations that process personal data regardless of their location, and both provide data subjects with similar rights. However, there are some differences between the two laws, such as the description of sensitive data, data breach notification requirements, and maximum fines.

For example, under the GDPR the maximum fine is 4% of annual global revenue or up to €20 million, whichever is higher. Under the LGPD the fines are 2% of a revenue in Brazil for the prior fiscal year or 50 million reals.

How Can Businesses Be Compliant with the LGPD?

First of all, you need to know who must comply with the LGPD. So, the LGPD applies to any natural person or legal entity that processes personal data in Brazil, regardless of their location. According to that, not only Brazilian companies but also foreign companies that process the personal data of Brazilian individuals must comply with the LGPD.

The LGPD applies to both public and private entities, and both online and offline data processing. Businesses must comply with the LGPD’s requirements, including obtaining consent, implementing technical and organizational measures for personal data protection, and providing customers with their data subject rights.

The LGPD does not apply to:

  1. If data is processed by a person strictly for individual purposes.
  2. If data is used only for journalistic, artistic, literary, or academic purposes.
  3. If data is used for national security, public safety, criminal investigations, or punishment activities.

The Autoridade Nacional de Proteção de Dados (ANPD) is the authority responsible for overseeing compliance with the LGPD, issuing rules and regulations about data protection and privacy, imposing administrative sanctions for LGPD violations, and requesting information about the processing of personal data from data controllers and processors.

To stay in compliance with the LGPD, you need the following:

  1. Appoint a DPO (Data Protection Officer). This person will be responsible for ensuring compliance with the LGPD and will serve as the intermediary between the business, individuals, and the ANPD.
  2. Identify the personal data you are working with, how it is processed, and the risks associated with that processing.
  3. Obtain individuals’ consent before collecting, using, or sharing personal data.
  4. Implement appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.
  5. Train employees on how they must comply with the LGPD and what they should do to protect personal data.
  6. Maintain documentation of compliance with the LGPD.

How DataSunrise Can Help?

DataSunrise is a data protection software that helps you to stay in compliance with various data protection acts and laws such as CCPA, HIPAA, and others.

To be compliant with the LGPD together with DataSunrise you can use Database Activity Monitoring. You will always know who has access to data, what this user has done with this data, and when. Monitoring user activity enables you to increase the visibility of user actions. If there will be any alert, DataSunrise can send notifications via email, SNMP, and various instant messengers.

DataSunrise provides Static and Dynamic Data Masking for sensitive data protection. With Dynamic Masking, you can obfuscate sensitive data at the moment of a query and do not consume any additional space for a database copy. With Static Masking, you can send sensitive information in an obfuscated format as a copy of a real database.

Format-Preserving Encryption enables you to save the original format of sensitive data.With Sensitive Data Discovery you always know where sensitive data resides. Our OCR Data Discovery enables you to search sensitive data in images without problems. Fast and accurate search enables you to apply masking, audit, and security rules to data after discovering it.

DataSunrise makes sure that your data is under control and secures it while you comply with different regulations and laws such as the LGPD.

Next

Australia Privacy Principles (APPs) Compliance

Australia Privacy Principles (APPs) Compliance

Learn More

Need Our Support Team Help?

Our experts will be glad to answer your questions.

Countryx
United States
United Kingdom
France
Germany
Australia
Afghanistan
Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bermuda
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Bouvet
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Canada
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Congo, Republic of the
Congo, The Democratic Republic of the
Cook Islands
Costa Rica
Cote D'Ivoire
Croatia
Cuba
Cyprus
Czech Republic
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard Island and Mcdonald Islands
Holy See (Vatican City State)
Honduras
Hong Kong
Hungary
Iceland
India
Indonesia
Iran, Islamic Republic Of
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Japan
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Democratic People's Republic of
Korea, Republic of
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Libyan Arab Jamahiriya
Liechtenstein
Lithuania
Luxembourg
Macao
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States of
Moldova, Republic of
Monaco
Mongolia
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia, Republic of
Northern Mariana Islands
Norway
Oman
Pakistan
Palau
Palestinian Territory, Occupied
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Helena
Saint Kitts and Nevis
Saint Lucia
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia and Montenegro
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
South Georgia and the South Sandwich Islands
Spain
Sri Lanka
Sudan
Suriname
Svalbard and Jan Mayen
Swaziland
Sweden
Switzerland
Syrian Arab Republic
Taiwan, Province of China
Tajikistan
Tanzania, United Republic of
Thailand
Timor-Leste
Togo
Tokelau
Tonga
Trinidad and Tobago
Tunisia
Turkey
Turkmenistan
Turks and Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Venezuela
Viet Nam
Virgin Islands, British
Virgin Islands, U.S.
Wallis and Futuna
Western Sahara
Yemen
Zambia
Zimbabwe
Choose a topicx
General Information
Sales
Customer Service and Technical Support
Partnership and Alliance Inquiries
General information:
info@datasunrise.com
Customer Service and Technical Support:
support.datasunrise.com
Partnership and Alliance Inquiries:
partner@datasunrise.com