Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation In Brazil, although not at the pace of other coun - tries, especially those in the EU, there are certain initiatives aimed at regulating IoT. Some Bills are in progress, such as the following. • 3,949/20 – national Internet of Things policy, addressing aspects such as security, privacy, and protection of personal data. Objective: create a regulatory environment that stimu - lates innovation and the development of IoT solutions. • 1,126/21 – regulation of connected devices, defining responsibilities for manufacturers and service providers. Objective: increase the security and protection of personal data col - lected through IoT devices. • 2,494/21 – creation of guidelines for the implementation of IoT solutions in areas such as health, public safety, and agriculture. Objective: to promote the responsible and safe use of technology to improve efficiency in strategic sectors. • 2,885/21 – security of personal data in IoT devices, with rules for the protection and management of private information. Objec - tive: to combat the misuse of data and ensure the privacy of data subjects and users. • 3,183/21 – interoperability of IoT devices, aiming to ensure that different systems can communicate effectively. Objective: to facilitate the integration of technologies and promote a more symmetrical IoT ecosystem. Unfortunately, there is still no legal framework for IoT in Brazil. Even with Decree 9,854/19, the issue was not resolved. This is because this

number of individuals, faster and more economi - cally than the filing of thousands of separate law - suits based on the same security incident. Article 22 of the General Data Protection Law provides that: “The defense of the interests and rights of data subjects may be exercised in court, individually or collectively, in accord - ance with the provisions of the relevant legis - lation, regarding the instruments of individual and collective protection.” This basically means that the LGPD has well absorbed the concept of “class protection”, a type of protection that goes beyond merely individual interests, since it covers needs based on a “general and abstract interest”. On the other hand, other modalities of privacy protection and responsible and consequent use of personal data have already been admitted in Brazil. One of these modalities is the Conduct Adjustment Agreement, or TAC, in which the government, taking upon itself the defence of meta-individual rights and prerogatives, signs, with the organisation accused of violating pri - vacy, a kind of formal commitment, with specific clauses and conditions, which can, if not fulfilled, be taken to the Judiciary as an enforceable title. An example of this was the TAC that the Pub - lic Prosecutor’s Office of the Federal District and Territories formalised with a digital finan - cial institution responsible for the data leak of almost 20,000 account holders. In this case, the banking institution paid BRL1.5 million in moral damages, intended for public agencies that fight cybercrimes.

45

CHAMBERS.COM

Powered by