Data Protection and Privacy 2025

BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados

leave the transaction without specific legal support. • Smart contracts, which automate blockchain transactions, can be programmed to include privacy and data protection clauses, but effective implementation is highly complex. • Technologies such as zk-SNARKs (which change the way data is shared) have been exploited to enable verifiable transactions without revealing personal data and sensitive information. • Privacy concerns can impact the adoption of digital assets, as environmental users are hesitant to engage in systems that do not ensure adequate protection for their personal data. Basically, processing personal data in the asset trading environment considers the same princi - ples and requirements applicable in any other data processing, which must include at least: • an explicit purpose and at least one legal basis authorised by law; • minimisation of personal data (less is more); • transparency; • personal data protection rules by design; • Prior Privacy Impact Assessment; • legal compliance; • Security Incident Management; • establishing controller–operator rules; • sharing agreements with third parties; and • adoption of centralised registry protocols. 5. International Considerations 5.1 Restrictions on International Data Transfers Recently, the National Data Protection Authority, the Brazilian regulator, approved and published a specific rule on the international transfer of

personal data, especially from Brazil to other countries. This rule (Resolution CD/ANPD 19/2, or International Data Transfer Regulation) estab - lishes conditions under which the international transfer of personal data is possible and consid - ered legitimate. The transfer, according to the ANPD rule, must, obviously, characterise the international sending or receiving of data (involving, therefore, different countries) (Article 5, ANPD), refer to processing subject to national legislation on the protection of personal data, and be supported by a legal hypothesis and a valid international transfer mechanism (Article 4, ANPD). In addition, as established in the rule (Article 9, ANPD), “The international transfer of data may only be carried out to meet legitimate, specific, explicit and informed purposes to the holder, without the possibility of further processing in a manner incompatible with these purposes...”, and even so, “it shall be limited to the minimum necessary to achieve its purposes, covering the pertinent data, proportionate and not excessive in relation to the purposes of the data process - ing.” On the other hand, every international transfer of data will always depend on a transfer mecha - nism considered valid (Article 9, II, ANPD): • an adequacy decision, issued by the ANPD, or via standard clauses; • standard contractual clauses, global corpo - rate standards (BCRs), or specific contractual clauses; or • in the cases of LGPD, Article 33, II, “d”, and III to IX.

50

CHAMBERS.COM

Powered by