Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

Decree is not exactly a technical regulation of IoT, but only a set of premises aimed at imple - menting and developing IoT in the national ter - ritory. In the current context, and while IoT regulation is not approved, the General Data Protection Law has been used to safeguard personal data circulating in IoT environments and systems, so that the privacy of data subjects is minimally protected. Subjects such as collection, sharing, use, and processing of data in IoT systems are considered according to the rules of the LGPD. But even so, with the new IoT trends, specific regulation is highly necessary to deal with top - ics such as: • AI, which will make IoT-connected devices more efficient and user-friendly; • “edge computing”, which can bring more speed in the exchange of information within the network and autonomy to devices that should relieve the work of servers; • LEO-based satellite connectivity, which can expand the possibilities of IoT, especially in agriculture and logistics, thanks in part to the wide coverage and low latency provided by near-Earth satellites; and • convergence of LPWAN technology, which promises to bring more multi-connectivity, providing end-to-end (E2E) connections, which are very important for sectors such as mobility. 3.2 Interaction of Data Regulation and Data Protection Personal data is part of the assets of individu - als, and the Brazilian Federal Constitution estab - lished that the protection of this data is a fun - damental right, which means a right placed in a category above other rights. As a result, there is

no longer a “free zone” for the processing and use of personal data, especially with the emer - gence of the General Data Protection Law. From this regulation, processing personal data becomes an expressly disciplined activity, and this includes not only the processing itself, but also the need for a purpose, the obligation to use a “legal basis” for each processing, respect for privacy as a premise and limitation regarding the processing of special category data, which includes sensitive data (LGPD, Article 11). Basically, the regulation on personal data, provided for in the LGPD, is based on protec - tive principles, among which are adequacy, necessity, quality, transparency, security, and non-discrimination (LGPD, Article 6). But that is not all. The legislation requires that all data processing respects the rights of the data sub - ject (Articles 17 and 18, LGPD), which includes access to data, correction, updating, deletion and anonymisation. In addition, outstanding actions, such as the need for a centralised record of the processing of personal data, maintained by the controller (Article 37, LGPD), the minimisation (essential - ity and necessity) of data to be processed, and the controller’s liability for damages resulting from the misapplication of the LGPD or its non- compliance, complement the data protection framework in Brazil. 3.3 Rights and Obligations Under Applicable Data Regulation Even with the National Internet of Things Plan, instituted by Decree 9,854/19, and Law 14,108/20, which creates incentives for IoT systems and reduces to zero the rate of certain taxes and contributions for machine-to-machine

46

CHAMBERS.COM

Powered by