Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

without processing personal data, employer– employee interaction would be impossible. This processing is present during all phases of the employment relationship: • in the pre-contractual phase, with the obtain - ing of identification data, curriculum vitae and references of the candidate for the job vacancy; • in the execution phase, via data collection for registration, payment of salaries, union mem - bership and health; and • in the post-employment relationship phase, with the storage of data of former employees for labour and social security purposes and making them available to inspection agen - cies. In this sense, the regulation of the processing of personal data in the employment relationship faces some (major) challenges. • Processing of sensitive personal data, such as those related to biometrics, sexual orien - tation, pathologies and union membership – how to do this to give this data additional protection coverage, in order to store it in a watertight manner and with strictly limited access. • Image processing, so that an essential need (such as giving access to the company’s premises) does not transform ordinary data into sensitive data, based on the inadequate or pernicious handling of these images. • Sharing personal data with public bodies in a way that only occurs under essential circum - stances and, even then, using secure and approved platforms. • Facial and body recognition. • Inclusion of data on race and ethnicity in employee records (Law 14,553/23).

• Processing of data of children and adoles - cents. 4.4 Transfer of Personal Data in Asset Deals When it comes to transactions with assets, whatever they may be, this raises very serious questions in terms of privacy protection and the processing of personal data. In general, transac - tions like this require handling of personal data, without which the operations cannot take place. But this handling leads to some aspects. • Digital assets (cryptocurrencies, tokens, etc) often operate on decentralised networks, and their transactions are recorded on block - chains, offering some transparency and strong privacy implications. • Much of the blockchains are public, which means that transactions can be traced. Even if the accesses occur via pseudonyms, data analysis can reveal the identity of users, com - promising their privacy. • Certain cryptocurrencies have been specifi - cally designed to offer greater privacy, using techniques such as obfuscation of addresses and transactions, but this does not mean an absolute guarantee that the personal data involved will not be discovered and used irregularly. • Regulators are concerned about privacy in asset transactions, precisely because of the difficulty in balancing transparency to combat money laundering, cybercrime, and tax eva - sion with the protection of users’ privacy and their personal data. • Privacy in asset transactions involves the topic of consent, but, from the perspective of Brazil’s General Data Protection Law, consent is a very fluid legal basis that allows its with - drawal at any time by the user, which would

49

CHAMBERS.COM

Powered by