What is GDPR and what does it mean for Brazil’s Data Protection Law?

The General Data Protection Regulation, or the European Union’s Data Protection Law, was created in the wake of a historic data breach.

Who remembers the Facebook and Cambridge Analytica scandal?

In 2014, Facebook launched a personality quiz app that went viral. Its purpose was to collect users’ data to benefit American politicians such as former President Donald Trump, Senator Ted Cruz, and others.

To access the “innocent” little game, people had to click through the Terms of Use, consenting to hand over their data. So far, nothing unusual—the user had agreed.

The problem was that data from users’ friends on social networks was collected without their consent. As a result, information was gathered from thousands of people around the world, totaling 50 million accounts. In Brazil alone, there were about 440,000 accounts!

The data, sold by Facebook to Cambridge Analytica, a British political consulting firm, sparked the scandal involving the politicians who benefited.

With the data in hand, the politicians’ teams could learn about the public’s preferences and use them to shape campaign strategies.

The exposé of the data breach and sale, published by The New York Times and The Guardian, set in motion the first steps toward drafting what is GDPR and its role in Data Protection today, since until then no country had enacted laws to protect users’ privacy.

How EU Data Protection Works

Every European citizen is protected by the GDPR when it comes to their data. This means that any country outside the EU must comply with its rules to safeguard the personal information of people born and living in European countries.

For example, companies outside the EU that sell products or services to a European citizen must comply with the GDPR’s rules.

In this way, businesses commit to meeting the legal requirements that prevent users’ data from being leaked—and subsequently sold.

In other words, what is GDPR, the most important part of Information Security, is being upheld.

The reverse is also true: foreign companies that sell products and services to Brazilian citizens must also comply with the LGPD.

It is essential for a company selling products or services to foreign citizens to communicate, through a formal email, or through notices posted on its website, that it complies with the country’s data protection laws. Such steps help build credibility with leads.

And credibility is the foundation of good Data Protection Management. Do you know whether your agency complies with the LGPD?

Watch the webinar presented by the COO of SafetyMails and subject-matter expert Rodrigo Gonçalves, and get answers to all your questions!

Is your agency compliant with the LGPD?

GDPR’s Influence on the LGPD

The GDPR was created in 2016, and the LGPD in 2018. The former served as a model for Brazil’s Data Protection Law.

Many of its principles are suited to conducting business online without violating users’ privacy.

For example, both Brazil and the EU have regulatory authorities responsible for implementing and enforcing the laws, as well as imposing sanctions and fines.

In Brazil, the ANPD — National Data Protection Authority — is responsible for overseeing compliance with the LGPD.

In the EU, the EDPB — European Data Protection Board — is responsible for overseeing the implementation of the GDPR.

Fines and Penalties

Penalties for violating the laws are also similar. Companies that fail to comply with the LGPD may face sanctions and fines of up to 2% of total gross revenue per violation.

Companies that violate the GDPR may be fined up to 4% of total revenue or €20 million per case.

It’s important to remember that Brazilian companies doing business with European citizens are subject to EU fines and penalties, and vice versa.

In other words, complying only with your own country’s data protection laws is not enough. Anyone working with foreign leads needs to understand the laws of their clients’ countries of origin.

GDPR and the LGPD: Differences

There is a slight difference between the two frameworks in how they define Personal Data and Sensitive Personal Data. In Brazil, the former includes users’ names, phone numbers, CPF numbers, and email addresses.

In the EU, the definition of personal data covers more information: any data that can identify a person—including pseudonyms and even data that has been de-identified but can be used to re-identify someone—is considered personal data.

Sensitive data—information relating to a user’s private life, such as political or religious preferences, gender identity, and so on—is treated the same way under both Data Protection frameworks.

Information about children and adolescents is treated slightly differently because the age of majority is 18 in Brazil and 16 in the EU. However, the approach to handling this information is the same.

In short, both frameworks require a guardian’s permission to collect personal data from minors.

FAQ

What is the GDPR, and how was it created?

The GDPR, or the General Data Protection Regulation, is the body of data protection laws in the European Union. It was created in response to the need for laws and regulations to safeguard internet users’ privacy, following a historic data breach involving Facebook and Cambridge Analytica, a British political consulting firm.

How does the GDPR influence Brazil’s data protection laws?

As the GDPR was the first data protection framework of its kind, it served as a model for drafting the LGPD. The two have similarities in how fines and other penalties may be applied to Brazilian companies that violate the law.



Categorized in:

Data Protection,