GDPR and LGPD These are data protection regulations that need to be understood, so that Brazilian companies can act without problems in different business circumstances.

The GDPR — General Data Protection Regulation — is the set of information security standards approved in 2018 by the countries of the European Union, and has served as a model for the creation of the LGPD — General Data Protection Law — which are the Brazilian data protection laws, in force in the country since 2020.

But why should Brazilian companies comply with GDPR standards if we are not in any EU country?

Keep following to find out!

Why should Brazilian companies comply with GDPR standards?

GDPR and LGPD have the same degree of importance for Brazilian companies, because of two reasons:

  • export of products and services.
  • data management of companies belonging to the EU.

Let’s see in detail what each of these items means:

As a rule, companies from anywhere in the world (in this case, we are talking about Brazilian companies) must respect the rules of the GDPR when they interact with citizens of the European Union.

This includes various types of business, such as exporting products and services, e-commerces that sell to the European public, access by citizens of the European Union to products that are in Brazil (a course, for example), among an infinity of other commercial relations.

The other reason why Brazilian companies must comply with the rules of the GDPR is the collection and management of the personal data of European citizens.

That is, a company that works in the digital is responsible for the data itself, including the information of its customers and suppliers.

This means that, if there is the theft or leakage of personal data, the Company is responsible for the failure in the information security, bearing the relevant penalties and fines. Therefore, it is so important that Brazilian companies understand the GDPR parameters.

It is important to highlight that the same goes for foreign companies operating in Brazil. In other words, companies that relate to Brazilian citizens are susceptible to the LGPD rules and, in case of non-compliance, receive the appropriate penalties.

Does your agency comply with the LGPD? Watch the webinar we created and find all the information you need to know about this subject!

GDPR and LGPD Similarities and differences

fines and penalties

In cases of non-compliance with the rules of the lgpd, companies receive sanctions and fines of up to 2% of revenue revenue, with a limit of R$ 50 million per process. The full description is found in Article 52 of the LGPD.

In the case of GDPR, companies that do not comply with the laws receive a fine of up to 4% of the billing, or €20 million per process. The full description is in Article 83 of the GDPR.

supervisory bodies of GDPR and LGPD

In Brazil, the National Data Protection Agency — ANPD — is the body responsible for inspecting the LGPD’s good practices.

In the EU, the European Data Protection Board — EDPB — (European Data Protection Committee in Portuguese), is the supervisory body of GDPR.

Personal data and sensitive data

According to the LGPD, personal data are those that identify the individual: first, last name, RG and CPF, and can also be extended to the email address and telephone.

Sensitive data are those that exploit the intimacy of the citizen, such as political, sexual, sexual preferences, religious convictions, etc.

The two laws differ in some points related to personal data, however, they are identical in the treatment of sensitive data, which must have the user’s consent, when they are collected in the registration forms.

In this way, both the user and the registration form are protected. However, the protection of registration forms goes beyond the user’s consent.

It is also necessary to prevent typing errors that happen very often, invalidating the emails that enter the lists. Who has never typed Gamil instead of Gmail, for example?

Protect your email lists with Real-time verification API SafetyMails.

GDPR and LGPD: Data deletion

Both laws guarantee users the right to fully or partially delete their data from the Web Services. This also includes the correction of data, if it is the will of the holder.

In the GDPR, the description of these rights is in Articles 12 to 23 and in the LGPD, in article 18.

data from children and adolescents

Both GDPR and LGPD require permission from the person in charge or legal representative to collect personal data from minors.

In Brazil, those under age are under 18. The description of the standard is in Article 14 of the LGPD.

In the EU, it is a minor who is under 16 years old. The description of the standard can be found in article 8 of the GDPR.

specialized professional

the presence of a then — Data Protection Officer — is required for all companies that use data collection and handling in large quantities.

In summary, this professional is responsible for inspecting the security of the company’s information, both in the legal part and in the technological part (cybersecurity).

Both GDPR and LGPD require a DPO, with the exception that in Brazil, the presence of this professional in small companies and startups is waived.

Conclusion

Data protection is essential for companies to be aware of how poor management can harm an individual.

On the other hand, it is of equal relevance for the citizen to count on the protection of the law so that its privacy is not invaded and/or marketed.

And speaking of protection, it is essential that digital marketers work with email validation.

This is the best way to protect your email lists from spamtraps, bounces and other risky emails that take great damage to email marketing campaigns.

Open your account for free and watch your email marketing results take off!

FAQ

Why is it important for Brazilian companies to know the GDPR?

Every company that relates to European citizens must know the GDPR, as the e-commerce negotiations, export of products and services, among others, involve the population of European countries. In addition, the Brazilian companies that collect and handle the data of European citizens also need to respect the European Union’s data protection regulation.

What are the main fines of GDPR and LGPD?

In the case of the LGPD, the company that infringes the laws receives a fine of up to 2% of the billing amount, or R$ 50 million per process. In the case of GDPR, companies that fail to comply with the laws take up to 4% fine on billing or €20 million per process.

What are personal data and sensitive data?

Personal data are those that can identify the individual, such as name, surname, RG and CPF. Sensitive data are those that involve people’s intimacy, such as religious convictions, sexual preferences, etc.

What is DPO?

The Data Protection Officer is the professional in charge of inspecting whether the Company is respecting the GDPR (in the case of the EU) or the LGPD (in the case of Brazil). The professional is requested by the two legislations, with waiver for small companies and startups in Brazil.



Categorized in:

Data Protection,