BRAZIL Law and Practice Contributed by: Japyassú Resende Lima and Fabiana Lopes Pinto Santello, Lopes Pinto, Nagasse Advogados
5.2 Government Notifications and Approvals In Brazil, international transfers of personal data are not necessarily subject to government notifi - cation or approval. However, there are regulatory conditions, provided for both in the General Data Protection Law and in Resolution CD/ANPD 19/2, or International Data Transfer Regulation. These conditions, in practice, subject the exporter of data abroad to a series of proce - dural requirements, such as the choice of a valid method of transfer, among those referred to in Resolution CD/ANPD 19/2 (Article 9, II). But, in addition, it is up to the controller – who is the one who, ultimately, makes decisions related to the processing of personal data – to take some pre - cautions, such as limiting the data to be trans - ferred, obtaining authorisation (and, in certain cases, consent) from the data subject, and con - trolling the data transferred and the international recipient of such data. 5.3 Data Localisation Requirements For practical purposes, localisation of personal data means both keeping personal data within the borders within which it was collected and complying with the security and privacy require - ments of the place where it is or where it is to be processed. There is a distinction to consid - er between data location and data residency, although sometimes the two expressions are used interchangeably. Data residency applies most to where data is or is stored; data localisa - tion, on the other hand, is the action of meeting the requirements of the data residency point. Data localisation can be of three types: • the first, called “constriction”, is the one in which data cannot be transferred across bor -
ders, unless a copy is stored in the locality of the original jurisdiction; • the second, known as “mitigated”, is the one that, in addition to the need to copy the data, requires that the data processing must also be done locally; and • the third, “restrictive”, prohibits the sending of data abroad. Many jurisdictions do not require strict com - pliance with the localisation of personal data, while others have requirements that oblige organisations to localise their data as accu - rately and reasonably as possible. But even if some jurisdictions do not require localisation, heavily regulated sectors, such as finance and healthcare, can adopt good practices, such as recommending that controllers establish a “safe circle” where data can be processed, including localisation, to additionally avoid regulatory and civil questions and litigation. Locating personal data when the case involves a single controller based in a single country is clearly easier to fulfil, and even more so when the infrastructure used is local, such as on per - fectly identified and established servers. It is more complicated to locate data in the case of cloud or overcloud computing, since the serv - ers are accessed via the internet, which allows them to be located anywhere on the globe. In this case, it seems clear that organisations that rely on cloud computing have less visibility into where their data is handled and stored, as it is up to the cloud vendor to deal with such issues. But it is good to remember that it is the con - troller – not the cloud provider – who must pre - sent information requested by the data subject, which includes knowing where their data is being processed or maintained. Therefore, it is always good and recommended that the control -
51
CHAMBERS.COM
Powered by FlippingBook