Deletion of data LGPD is a right guaranteed to all users of web services located in Brazil.
Through this service, consumers can request that their personal data be removed from a website or web application once processing is complete.
To put this into perspective, Data Protection is now part of Article 5 of the Constitution, which addresses the fundamental rights of Brazilian citizens.
In other words, Data Protection is part of the legislation that protects Brazilians’ lives, education, and freedom.
That is why information security must be taken seriously, and consequently, deletion of data LGPD follows the same principle.
After all, a company that violates the LGPD may be fined up to 2% of its revenue.
In short, if a customer requests that their information be removed from your company’s database, it is better not to risk incurring this fine, right?
Table of contents
User consent
Data collection must be requested from the data subject, who must be aware of how their data will be processed when they consent to the use of their information.
In other words, this means knowing how and why the company will use your data.
These requirements are mandatory under the LGPD, which was created to safeguard consumers’ personal information both online and offline.
Yes, the LGPD protects offline data. If a company collects information from thousands of people and handles it for commercial or other purposes, this process takes place outside the virtual environment—in other words, offline.
In short, all of this is part of information security, whose core commitment to users is confidentiality.
Data portability
Although it is not common practice, users may also request that their data be transferred from one company to another. When this happens, the company that held the information may no longer access it, and its use and handling are prohibited.
deletion of data LGPD: examples
Imagine that you downloaded an app. To give you access to it, the software asked you to enter your name, email address, and phone number.
After using the app a few times, you start receiving frequent emails containing notifications and other information you do not want to receive.
The LGPD guarantees your right to request that your email address be removed from the app’s database. The web service that receives the request must provide this service free of charge.
In other words, users can request that all their data be removed or only part of it (in the previous example, just the email address).
Data processing and lifecycle
According to the LGPD, all data have a lifecycle that companies must respect.
It is important to note that the LGPD calls for the collection of data strictly necessary for the activities defined by companies. In other words, collecting additional information is not recommended.
Here is how the lifecycle of data collected by organizations works:
Step 1: data collection
This is the lead-generation stage, when information is collected through registration forms. Personal data (name, phone number, and email address) do not require authorization to be collected.
However, sensitive data (sexual and political preferences, as well as other more intimate information) require the user’s authorization. The web service must also clearly explain to users how this information will be used. Companies generally describe this in detail in their Privacy Policy.
It is worth noting that registration forms without email verification do not achieve the goal of generating leads.
That is because typing errors are common and occur frequently, such as entering Gmail instead of Gmail. As a result, emails containing errors invalidate the lists.
The email verification API SafetyMails prevents invalid emails from entering websites, apps, landing pages, and any service that uses registration forms.
This way, incorrect email addresses are automatically corrected, ensuring that the list contains only real, valid email addresses.
Step 2: data storage by the LGPD operator and controller
Data storage through a marketing automation platform must comply with the information security framework adopted by the company that collected the data.
The Data Protection Officer — Data Protection Officer in Portuguese—is the LGPD operator and controller, that is, the professional responsible for keeping customer, supplier, and company data secure, as well as ensuring the company’s compliance with the LGPD.
Step 3: data use and sharing
Information about how data is used must be accessible to users and is described in the company’s Terms of Use and Privacy Policy. These documents must also clarify how data is shared with third parties (who they are, how long the sharing will last, and so on).
Step 4: deletion of data LGPD and disposal
The deletion of data LGPD occurs at the user’s request, but the National Data Protection Authority (ANPD) may also legally request that the information be removed.
There is also the option of deletion of data LGPD (which is less commonly used) when information is no longer relevant to the company. However, most companies prefer to retain former users’ information in their databases in case they resume contact and carry out specific re-engagement campaigns.
FAQ
How does the LGPD protect users’ data when they want to remove their information from web services?
Data deletion is one of the user’s rights and is described in Article 18 of the LGPD, which states that data subjects may request the removal of their data from web services to which they have given authorization at any time.
What is data portability, and how is it carried out?
Data portability means that users can transfer their personal and/or sensitive information from one company to another. Consumers can request portability at any time, just as they can request data deletion.
How do companies process their customers’, suppliers’, and third parties’ data?
Ideally, a dedicated professional should handle information security. The Data Protection Officer is responsible for data processing and answers to authorities for the handling of information.
Can partial data removal be requested from a database?
Yes, it can. Users who are dissatisfied with the use of one piece of their data can request its removal without stopping using the web service, which contains other personal data belonging to them.
