BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados
1.4 Data Protection Fines in Practice In the last two years, the Brazilian regulator has acted more intensively, and many administra - tive proceedings have been concluded, most of them with stricter recommendations and even penalties (the so-called sanctioning processes). Some of these cases draw more attention: • the Ministry of Health, opened in 2022 to investigate non-compliance with the ANPD’s request, absence of a personal data officer (DPO) and failure to report a security incident; and • Santa Catarina State Department of Health, opened in 2022 for lack of communication to holders of security incidents, absence of security measures and non-compliance with ANPD determinations. But the regulator has also turned its efforts to the private sector, and more than twenty inspection proceedings have been opened against aviation companies, telecom giants, gas distributors and even managers of ride-hailing apps. 1.5 AI Regulation The Brazilian regulator has faced challenges regarding the regulation of AI, especially due to the exponential visibility and relevance of the topic, its technological tools, and its implications for people’s privacy and data protection. Brazil does not yet have a specific normative and regulatory system for AI. It was only in December 2024 that the Senate approved a Bill that regu - lates AI, and now this Bill is being examined in the Chamber of Deputies. In a way, the Project brings important concepts, especially by placing the human being as the principal “of all things”, at the centre of decisions.
Among other rules, the text of the Bill consid - ers as high risk any AI system that can cause significant harm to individuals or groups, which includes: • selection of students, recruitment of workers, and concessions of public services; • management of migratory processes; • evaluation of calls for essential services, and operation of autonomous vehicles; and • biometric identification systems. For the Project, high-risk systems will be sub - ject to strict governance, permanent monitoring and the requirement of bias mitigation meas - ures. Organisations that use these technologies will need to conduct security testing and adopt practices that ensure transparency and fairness. In the field of Copyright, companies that use protected content to train AI tools will have to remunerate the owners of the works, consider - ing principles of proportionality and reasonable - ness. The Bill also takes care of the use of data, with rules on moderation of use, centralised reg - istration and benefits (direct and indirect) to the holders, as the case may be. Some topics, such as social media algorithms and online content moderation, were not includ - ed in the current Bill and will be dealt with sepa - rately. But some systems were banned, includ - ing autonomous weapons, citizen ranking tools for access to public goods and services, and risk assessments for criminal behaviour. 1.6 Interplay Between AI and Data Protection Regulations One of the main concerns about AI regulation – including by the Brazilian personal data regu - lator – is to ensure that the use of AI considers and respects the privacy of individuals and their
42
CHAMBERS.COM
Powered by FlippingBook