{"id":66026,"date":"2023-09-04T07:19:54","date_gmt":"2023-09-04T10:19:54","guid":{"rendered":"https:\/\/dev.abes.com.br\/?p=66026"},"modified":"2024-01-23T08:54:19","modified_gmt":"2024-01-23T11:54:19","slug":"a-primeira-multa-da-lgpd-hora-de-falar-sobre-adequacao","status":"publish","type":"post","link":"https:\/\/dev.abes.com.br\/en\/a-primeira-multa-da-lgpd-hora-de-falar-sobre-adequacao\/","title":{"rendered":"The first LGPD fine: time to talk about adequacy"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-64134 alignleft\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/06\/Leonardo-Melo-Lins.jpeg\" alt=\"\" width=\"200\" height=\"200\" srcset=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/06\/Leonardo-Melo-Lins.jpeg 400w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/06\/Leonardo-Melo-Lins-300x300.jpeg 300w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/06\/Leonardo-Melo-Lins-150x150.jpeg 150w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/06\/Leonardo-Melo-Lins-12x12.jpeg 12w\" sizes=\"(max-width: 200px) 100vw, 200px\" \/>*Per <i>Leonardo Melo Lins<\/i><\/p>\n<p>The reasons that led to the application of the first fine by the National Data Protection Authority (ANPD) to a micro telemarketing company in Esp\u00edrito Santo have already been well debated. Basically, the ANPD imposed a warning and two fines: the first, \u201cdue to the failure to indicate a person in charge of processing personal data\u201d (DPO); a \u201csimple fine in the amount of R\uff04 7,200 for lack of legal hypothesis for the processing of personal data\u201d; and, finally, \u201ca simple fine in the amount of R\uff047,2000 for not complying with ANPD requests during the investigation process\u201d<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn1\">[1]<\/a>.<u><\/u><u><\/u><\/p>\n<p>In this article, I will discuss aspects of the warning given to the company and the second fine applied, taking as a reference the data on the compliance of companies with the General Data Protection Law (LGPD) released last year by Cetic.br<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn2\">[2]<\/a>. With indicators developed together with experts from academia and the public sector, the survey provided a broad overview of the current stage of personal data protection practices in Brazilian companies. \u00a0<u><\/u><u><\/u><\/p>\n<p>The first point is about the DPO<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn3\">[3]<\/a>. Although the ANPD has recently waived the presence of the person in charge in small organizations, there is a need if the company processes high-risk personal data<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn4\">[4]<\/a>. The warning given by the ANPD links the alert to other companies, and the available data show that there is still a way to consolidate the role of the DPO among Brazilian companies.<\/p>\n<p><u><\/u><u><\/u>According to the survey, 17% of Brazilian companies appointed a data officer, which is a more recurrent practice among large companies (41%)<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn5\">[5]<\/a>. With regard to the market in which they operate, the sectors of information and communication and professional activities are the ones that most presented companies that appointed a data controller, closely followed by the transport sector, but in all cases reaching a very small proportion companies.<u><\/u><u><\/u><\/p>\n<p><strong>Graph 1 \u2013 Companies, by appointment of a data officer<\/strong><u><\/u><u><\/u><\/p>\n<p><strong>Total companies (%)<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-66027 aligncenter\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/08\/unnamed.png\" alt=\"\" width=\"725\" height=\"386\" srcset=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/08\/unnamed.png 725w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/08\/unnamed-480x255.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 725px, 100vw\" \/><\/p>\n<p>It is important to mention that the data above does not imply that all companies need to appoint a data officer, or that the low proportion of DPOs will lead to widespread warnings, regardless of company size and industry. However, the data above shows that in most companies there is no professional responsible for ensuring and promoting a culture of data protection, which can avoid future warnings and fines. \u00a0<u><\/u><u><\/u><\/p>\n<p>A practical effect of this is precisely the reason for the second fine imposed: the lack of an impact report on the protection of personal data and treatment procedures, implying the absence of a flow on the entry and disposal of this data<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn6\">[6]<\/a>.\u00a0<u><\/u><u><\/u><\/p>\n<p>According to research by Cetic.br, the presence of procedures for the correct treatment of personal data is still incipient, especially in small and medium-sized companies. Only 13% of the companies made a personal data protection impact report, while 24% prepared an LGPD compliance plan. From the point of view of transparency, the scenario is also incipient, as 32% companies have developed a privacy policy that informs how personal data is treated. As you can see in the chart below, only large companies have more consolidated practices for compliance with the LGPD.<br \/>\n<u><\/u><u><\/u><\/p>\n<p><strong>Graph 2 - Companies by type of LGPD compliance action<\/strong><u><\/u><u><\/u><\/p>\n<p><strong>Total companies (%)<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-66028 aligncenter\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/08\/unnamed-1-2.png\" alt=\"\" width=\"762\" height=\"299\" \/><\/p>\n<p>In short, basic aspects of the processing of personal data need to be disseminated, especially in small and medium-sized companies. There are several practices that can lead to incorrect use of the personal data of customers and employees and that can generate other fines and warnings. \u00a0<u><\/u><u><\/u><\/p>\n<p>Even though the law is recent and there are uncertainties as to its correct adequacy, it is necessary to make the best personal data protection practices a constant at, as ensuring the proper use of data is increasingly central to the organization&#039;s reputation, as well as to avoid punishments that could bring irreversible reputational and financial damage<a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftn7\">[7]<\/a>.<u><\/u><u><\/u><\/p>\n<p>*Leonardo Melo Lins<i>\u00a0is Researcher at the ABES Think Tank, member of the Postdoctoral Program at IEA\/USP and Analyst at Cetic.br | NIC.br<\/i><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref1\">[1]<\/a>\u00a0The details of the decision can be consulted\u00a0<a href=\"https:\/\/www.gov.br\/anpd\/pt-br\/assuntos\/noticias\/anpd-aplica-a-primeira-multa-por-descumprimento-a-lgpd#:~:text=O%20descumprimento%20ao%20art.%2041,multa%20de%20R%2414.400%2C00\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.gov.br\/anpd\/pt-br\/assuntos\/noticias\/anpd-aplica-a-primeira-multa-por-descumprimento-a-lgpd%23:~:text%3DO%2520descumprimento%2520ao%2520art.%252041,multa%2520de%2520R%252414.400%252C00&amp;source=gmail&amp;ust=1692349715993000&amp;usg=AOvVaw1vJBNpXCIQi7QREqYbHaAs\">on here<\/a>.<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref2\">[2]<\/a>\u00a0More information about the search\u00a0<a href=\"https:\/\/cetic.br\/pt\/publicacao\/privacidade-e-protecao-de-dados-2021\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/cetic.br\/pt\/publicacao\/privacidade-e-protecao-de-dados-2021\/&amp;source=gmail&amp;ust=1692349715993000&amp;usg=AOvVaw3Le0z3ZMW-SK6C4Kq_ggpj\">on this link<\/a>.<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref3\">[3]<\/a>\u00a0According to the LGPD, the attributions of the person in charge of personal data are: \u201cI \u2013 accept complaints and communications from data subjects, provide clarifications and adopt measures; II \u2013 receive communications from the national authority and adopt measures; III \u2013 guide the entity&#039;s employees and contractors regarding the practices to be adopted in relation to the protection of personal data; and IV \u2013 carry out other attributions determined by the controller or established in complementary norms\u201d<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref4\">[4]<\/a>\u00a0Resolution CD\/ANPD n. 2, of January 27, 2022, in its Article 11, exempts small organizations from appointing a personal data protection officer. However, it is important to point out that the ANPD takes the organization&#039;s revenue as a size concept. More details\u00a0<a href=\"https:\/\/www.in.gov.br\/en\/%20web\/dou\/-\/resolucao-cd\/anpd-n-2-de-27-%20de-janeiro-de-2022-376562019\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.in.gov.br\/en\/%2520web\/dou\/-\/resolucao-cd\/anpd-n-2-de-27-%2520de-janeiro-de-2022-376562019&amp;source=gmail&amp;ust=1692349715993000&amp;usg=AOvVaw0aUiXgOxgcsCWMrhDMqVoB\">on here<\/a>.<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref5\">[5]<\/a>\u00a0The survey classifies the size of companies in terms of the number of people employed: up to 49, small; between 50 and 249, average; over 250, big.\u00a0<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref6\">[6]<\/a>\u00a0The impact report on the protection of personal data is defined in Article 5 of the LGPD as: \u201cdocumentation from the controller that contains the description of the processes for processing personal data that may generate risks to civil liberties and fundamental rights, as well as measures, safeguards and risk mitigation mechanisms<u><\/u><u><\/u><\/p>\n<p><a href=\"https:\/\/mail.google.com\/mail\/u\/0\/#m_-7854602286607827245_m_-1723969992454046286__ftnref7\">[7]<\/a>\u00a0It is worth remembering that several orientation guides are available in the\u00a0<a href=\"https:\/\/www.gov.br\/anpd\/pt-br\/documentose-publicacoes\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.gov.br\/anpd\/pt-br\/documentose-publicacoes&amp;source=gmail&amp;ust=1692349715993000&amp;usg=AOvVaw18sScLyzsFp-EtaitCiA_L\">ANPD website<\/a>.<\/p>\n<p><strong><em>Notice:<\/em><\/strong><em>\u00a0The opinion presented in this article is the responsibility of its author and not of ABES - Brazilian Association of Software Companies<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Leonardo Melo Lins<br \/>\nABES Think Tank researcher, member of the IEA\/USP Postdoctoral Program<\/p>","protected":false},"author":10,"featured_media":64135,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[3768],"tags":[535,4096,83,91,2676],"class_list":["post-66026","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artigos-abes","tag-autoridade-nacional-de-protecao-de-dados","tag-leonardo-melo-lins","tag-lgpd","tag-protecao-de-dados","tag-protecao-e-tratamento-de-dados-pessoais"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-13 00:33:51","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category"},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/66026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/comments?post=66026"}],"version-history":[{"count":2,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/66026\/revisions"}],"predecessor-version":[{"id":71795,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/66026\/revisions\/71795"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media\/64135"}],"wp:attachment":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media?parent=66026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/categories?post=66026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/tags?post=66026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}