Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

Lopes Pinto, Nagasse Advogados Rua Helena, 235, 4th floor Vila Olímpia São Paulo – SP 04552-050 Brazil

Tel: +55 11 2665 9200 Fax: +55 11 98311 0108 Email: contato@lopespinto.com.br Web: www.lopespinto.com.br

1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws In Brazil, the protection of privacy is fundamen - tally established in the Federal Constitution of 1988 (Article 5, X), which considers it inviolable, and therefore protected against any act of inva - sion or misuse. Next, the Civil Code (Article 21) also considers that the private life of individuals is inviolable. Both rules seem to be in tune with the basic principle of the inviolability of privacy, and both extend their effects to the three known dimensions of privacy: the private dimension, the intimate and the secret. In addition, directly or indirectly, other rules also have a strongly col - laborative role in the protection of privacy, such as the Statute of the Child and Adolescent (Law 8.069/90), the Consumer Protection Code (Law 8.078/90) and the Civil Rights Framework for the Internet (Law 12.965/14). Resulting from the protection of privacy is the protection of personal data, thus considered those references or attributes that identify or can identify a living natural individual. In this con -

text, the General Data Protection Law, known as LGPD (Law 13,709/18), was born, the main purpose of which is to give effectiveness to the protection of personal data, a component of individual assets, included in the Constitution as a fundamental right of each citizen. From a legislative point of view, the Brazilian LGPD is mirrored in the General Data Protection Regulation, or GDPR, approved in the Europe - an Union in 2016. The concepts, premises and principles of the GDPR, in general, have been incorporated into the LGPD, except for some terminology. This is the case, for example, with the expression “personal data”, which the GDPR preferred to call “personal information”, even though “information” is more of an organised composition of “data”, and “data” refers better to a minimum referential unit. Brazilian legislation differs from US legislation. While the Brazilian legislation applies to the entire national territory and to all activities, in the US certain activities have their own regula - tion (HIIPA, for the health sector), and the same is also true for each state, as in California with the CCPA.

40

CHAMBERS.COM

Powered by