{"id":5027,"date":"2018-07-12T00:00:00","date_gmt":"2018-07-12T00:00:00","guid":{"rendered":"https:\/\/dev.abes.com.br\/?p=5027"},"modified":"2023-03-28T22:07:57","modified_gmt":"2023-03-29T01:07:57","slug":"os-avancos-proporcionados-pela-lei-brasileira-de-protecao-de-dados-pessoais","status":"publish","type":"post","link":"https:\/\/dev.abes.com.br\/en\/os-avancos-proporcionados-pela-lei-brasileira-de-protecao-de-dados-pessoais\/","title":{"rendered":"The advances provided by the Brazilian Personal Data Protection Act"},"content":{"rendered":"<p><\/p>\n<div style=\"text-align: center\">\n\t<img decoding=\"async\" alt=\"\" src=\"\/wp-content\/uploads\/anterior\/Imagens\/Andriei(1).JPG\" style=\"width: 300px;height: 239px\" \/><\/div>\n<p><\/p>\n<div style=\"text-align: center\">\n\t<em>By Andriei Gutierrez, coordinator of the ABES Regulatory Committee and co-founder and coordinator of the Movimento Brasil, Pa\u00eds Digital <\/em><\/div>\n<p>&nbsp;<\/p>\n<div style=\"text-align: justify\">\n\tAfter eight years of debate, on July 10, the Personal Data Protection Bill was approved in the Federal Senate. As a next step, the text still needs to receive presidential sanction, but, without a doubt, Brazilian society can already celebrate a great victory, which makes it possible to design a digital nation project.<br \/>\n\t&nbsp;<br \/>\n\tIn the lines below, I point out the main topics of the project, as well as their similarities and differences in relation to the Data Protection models applied in other countries.&nbsp;<br \/>\n\t&nbsp;<br \/>\n\t<strong>Protection of fundamental rights and legal certainty <\/strong><br \/>\n\tIt was time to join the club of more than 130 countries that have legal frameworks for the protection of personal data. Our framework is important for the protection of fundamental rights, such as privacy, freedom of expression and the dignity of the human person against any form of discrimination. In addition, it is a relevant instrument for the private and public sectors to have legal certainty to legitimize innovations and services based on personal data.<br \/>\n\t&nbsp;<br \/>\n\t<strong>Democratic process <\/strong><br \/>\n\tWe have to be very proud, both of the final text approved by Congress, and for the democratic debate that culminated in its last version. There were two public consultations carried out by the Ministry of Justice (in 2010 and 2015), which resulted in a bill of initiative of the executive branch in 2016. Another five projects were also on the subject in the National Congress since 2012. In the last two years the The debate was heated amid 13 public hearings in the Chamber of Deputies, two in the Federal Senate and numerous meetings with parliamentarians, in addition to segments of the private sector, civil society and government engaged in the topic.<br \/>\n\t&nbsp;<br \/>\n\t<strong>GDPR inspiration with significant developments<\/strong><br \/>\n\tToday, we have mature and balanced legislation. The basic text and the entire debate were inspired by the European Union&#039;s General Personal Data Protection Act, the GDPR. However, we understand that our text goes further, as it introduces significant developments that provide greater legal support both for data-based innovations and for the international flow of that data, an indispensable condition for innovation.<br \/>\n\t&nbsp;<br \/>\n\t<strong>Comprehensiveness and territoriality <\/strong><br \/>\n\tThe bill covers any personal data, such as name, address, e-mail, age, marital status and wealth status, obtained in any type of support (paper, electronic, computer, sound and image, etc.). It applies to any treatment operation carried out by a natural person or by a legal person under public or private law, regardless of the medium, the country of its headquarters or the country where the data is located, provided that 1) the treatment operation is carried out in national territory; 2) the processing activity is aimed at offering or providing goods or services; or 3) the processing of data from individuals located in the national territory; or 4) the personal data subject to the treatment has been collected in the national territory.<br \/>\n\t&nbsp;<br \/>\n\t<strong>Legal bases for processing personal data<\/strong><br \/>\n\tThe project approved by Congress allows 10 legal possibilities for data processing, while the GDPR allows only six legal bases. This is very relevant, as it protects fundamental rights in order to allow data-driven innovations to flourish legitimately.<br \/>\n\t&nbsp;<br \/>\n\tThe legal bases mentioned in the text are:<br \/>\n\t&nbsp;<br \/>\n\t(1) informed consent (expressed for sensitive personal data),<br \/>\n\t(2) for the implementation of public policies,<br \/>\n\t(3) for the fulfillment of a legal or regulatory obligation by the controller,<br \/>\n\t(4) to carry out studies by a research body, guaranteeing, whenever possible, the anonymization of personal data;<br \/>\n\t(5) when necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party, at the request of the data subject;<br \/>\n\t(6) for the regular exercise of rights in judicial, administrative or arbitration proceedings;<br \/>\n\t(7) for the protection of the life or physical safety of the holder or third party;<br \/>\n\t(8) for the protection of health, with a procedure carried out by health professionals or by health entities;<br \/>\n\t(9) when necessary to serve the legitimate interests of the controller or of a third party, except in the event that the fundamental rights and freedoms of the holder prevail that require the protection of personal data;<br \/>\n\t(10) for credit protection.<br \/>\n\t&nbsp;<br \/>\n\t<strong>Anonymous Data<\/strong><br \/>\n\tAnonymous data is one of the fundamental pillars of data-driven innovation, for example, for carrying out research to improve a product, service or even a recommendation or treatment in the health field. Throughout the discussion process, those involved sought to ensure with the entities that the Bill did not create legal impediments that would render the treatment of anonymous data unfeasible.<br \/>\n\t&nbsp;<br \/>\n\tArticle 12 establishes that \u201canonymized data will not be considered personal data, for the purposes of this Law, except when the anonymization process to which they were submitted is reversed, using only their own means, or when, with reasonable efforts, it can be reversed\u201d .<br \/>\n\t&nbsp;<br \/>\n\t<strong><em>Vacatio Legis<\/em><\/strong><br \/>\n\tThe new rules will only come into force after a year and a half of the publication of the law, so that bodies, companies and entities can adapt to the new rules.<br \/>\n\t&nbsp;<br \/>\n\t<strong>National Personal Data Protection Authority <\/strong><br \/>\n\tThe project foresees the creation of a special autarchy linked to the Ministry of Justice with the mission of ensuring data protection, inspecting and applying sanctions, among other duties. This is still a sensitive point that needs to be sanctioned and delimited by the Executive Branch. This entity will have a fundamental role during the 18 months of adaptation until the law comes into force, either in the regulation or in the promotion of educational campaigns for organizations and society.<br \/>\n\t&nbsp;<br \/>\n\t<strong>International Data Transfer<\/strong><br \/>\n\tDespite the inspiration in European legislation, the project brings important advances with regard to the legal bases for the international transfer of data, such as, for example, the acceptance of stamps, certificates and codes of conduct that prove compliance with the law. Thus, the text includes the following legal possibilities:<br \/>\n\t&nbsp;<\/div>\n<ol>\n<li style=\"text-align: justify\">\n\t\tfor countries or international organizations that provide an adequate degree of protection of personal data as provided for in Brazilian law;<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the controller offers and proves guarantees of compliance with the principles, the rights of the holder and the data protection regime provided for in this law, in the form of:<\/p>\n<ol style=\"list-style-type:lower-alpha\">\n<li>\n\t\t\t\tspecific contractual clauses for a given transfer;<\/li>\n<li>\n\t\t\t\tstandard contractual clauses;<\/li>\n<li>\n\t\t\t\tglobal corporate standards;<\/li>\n<li>\n\t\t\t\tstamps, certificates and codes of conduct regularly issued.<\/li>\n<\/ol>\n<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the transfer is necessary to protect the life or physical safety of the holder or third party;<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the national authority authorizes the transfer;<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the transfer results in a commitment made in an international cooperation agreement;<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the transfer is necessary for the execution of public policy or legal attribution of the public service;<\/li>\n<li style=\"text-align: justify\">\n\t\twhen the holder has provided his specific and highlighted consent for the transfer, with prior information on the international character of the transaction, clearly distinguishing it from other purposes;<\/li>\n<li style=\"text-align: justify\">\n\t\tamong others.<\/li>\n<\/ol>\n<div style=\"text-align: justify\">\n\tThese are just some of the advances made by this bill and, of course, the reader can highlight other aspects of this legislation. <a href=\"\/wp-content\/uploads\/anterior\/Arquivos\/PLC 53-18 (versa~o aprovada no Senado).pdf\">Check the full text here<\/a>.<br \/>\n\t&nbsp;<\/div>\n<p>&nbsp;<br \/>\n&nbsp;<br \/>\n&nbsp;<br \/>\n&nbsp;<br \/>\n&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>By Andriei Gutierrez, coordinator of the ABES Regulatory Committee and co-founder and coordinator of Movimento Brasil, Pa\u00eds Digital After eight years of debate, on July 10, the Personal Data Protection Bill was approved in the Federal Senate. As a next step, the text still needs to receive presidential sanction, but, [\u2026]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[8,3768,19],"tags":[],"class_list":["post-5027","post","type-post","status-publish","format-standard","hentry","category-artigos","category-artigos-abes","category-ultimas-noticias"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-13 05:31:39","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category"},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/5027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/comments?post=5027"}],"version-history":[{"count":1,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/5027\/revisions"}],"predecessor-version":[{"id":59987,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/5027\/revisions\/59987"}],"wp:attachment":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media?parent=5027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/categories?post=5027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/tags?post=5027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}