Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

database, as well as in the user’s browser. Third- party cookies are from a source external to the domain – that is, companies that are third parties to the visited page that also trigger their cookies to record their visitors’ information. In general, cookies capture user information, and can even capture some personal data, hence the controversy around the subject. In view of this, the captured personal data may not only have a destination with which the holder does not agree, but can also be stored indefinitely, creat - ing a “non-expirable bank”. In the context of the EU’s GDPR, there is a 12-month limit for the use of a cookie, and con - sequently the personal references it captures or uses, but in the LGPD there is no similar rule. What can be done is to apply the principle of necessity (LGPD, Article 6, III), according to which data can only be stored for the period necessary to fulfil the purpose expected of it. Thus, if a cookie loads personal data that no longer needs (or cannot) be used, it becomes legally invalid. To regulate cookie issues, it is essential to have a policy, and it is important to include some condi - tions, such as the types of cookies that the con - troller can use, what their functionalities are, how long they are stored or kept, how they are used, how they can be avoided and what the conse - quences are of a “personal block” of cookies. In addition, it is necessary to consider making it clear to the user that some cookies (session cookies, for example) do not collect personal data directly, but only store information in the form of an identification. But there are cook - ies that, even unintentionally, record all the text fields filled in during browsing, and this makes the data collection very varied, or even mali -

cious, depending on the intention of the person who produced the cookie. 4.2 Personalised Advertising and Other Online Marketing Practices Personalised advertising is not exactly a new concept. Since the 1970s, it has been known to be a marketing strategy that makes use of data about consumer behaviours and preferences to produce targeted and relevant ads or even to speculate on potential user preferences about one or another product or service. Legally, personalised advertising is delimited by some rules, especially the Consumer Protection Code (CDC), the General Data Protection Law (LGPD) and, less directly, by Law 12,232/10. The main legal element that guides personal - ised advertising is legal responsibility, which involves not only respecting people’s rights and prerogatives, including their privacy, but also considering the protection of personal data and the principles of transparency and adequate information. The legal context of personalised advertising generally considers the following aspects. • Data collection. • Audience segmentation. • Algorithms and Machine Learning. • User Experience. • Privacy challenges. • Transparency and consent (if applicable). • Results and metrics. • Transparency. • Essentiality and necessity. 4.3 Employment Privacy Law Labour relations in Brazil have long been part of concerns about the protection of privacy and security of personal data, not least because

48

CHAMBERS.COM

Powered by