BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados
3.4 Regulators and Enforcement In general, Brazil has a regulator for issues involv - ing personal data, the National Data Protection Authority, or ANPD, established by the LGPD (Article 55-A), created by Decree 13,853/19 and whose structure was established by Decree 10,474/20. For the legislation, the ANPD “aims to guarantee the fundamental right to the protec - tion of personal data, the fundamental rights of freedom and privacy, and the free development of the personality of the natural person” (Decree 10,474, Article 1). Unlike other nations, the regulatory regime for the protection of personal data in Brazilian lands follows the “one theme, one regulator” model, which means that, in this matter, the ANPD has a “superposition” role, acting on any other public agents if the topic refers to personal data. In short, what are called “cookies” are small text files that store what the user is doing for a period of time. Cookies store browsing history, logins and passwords, and perform a service in systems known as search engines. Because of the ability of cookies to store information, it is possible for them to work in texts, spreadsheets, presentations and even offline. There are First and Third-Person cookies. The First-Person Traces are generated by the domain itself, and this means that, from the point of view of the page visited, they are the “digital traces”, or “footprints”, that the user leaves when look - ing for a product, looking for information or even making a compliment or complaint. When the system generates a “cookie”, it has an identifier that records the information in the company’s 4. Sectoral Issues 4.1 Use of Cookies
communications, there are Bills under discus - sion on the subject. Some concerns surround the topic of IoT. Pro - tecting users’ privacy is one of them. In IoT, devices are always collecting and sharing per - sonal data, in some way and to some extent, which raises questions about their misuse. Another is the security of connected devices. With the interconnection of things, different risks arise, such as unauthorised access to systems and the possibility of cybercrimes. Civil liability is also a concern. With IoT, it is pos - sible for a connected device to cause harm to other people, due to security failures, malfunc - tions, or decisions made autonomously. After all, this is a dilemma that is difficult to solve. Devic - es connected via IoT can, at some point in the chain, interact inappropriately, and this cannot always be attributed to a construction or design flaw. This is because there will always be room for a certain “autonomy of the non-conscious will”, which makes the responsibility for events enter a grey area. That is also why, for IoT companies, the integ - rity of user data should be the highest priority, supported by a data protection strategy that is fully compliant with legislation, whatever it may be. As devices continuously record and process personal data, it is necessary to meticulously address the data protection obligations of each business, including how user data is stored, pro - cessed, and handled. As such, when produc - ing IoT devices, privacy by design is essential, which can include purpose limitation, data mini - misation, accuracy, storage limitation, integrity, and confidentiality.
47
CHAMBERS.COM
Powered by FlippingBook