<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Arquivos Data Protection - Souto Correa Advogados</title>
	<atom:link href="https://www.soutocorrea.com.br/en/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.soutocorrea.com.br/en/tag/data-protection/</link>
	<description>Escritório de advocacia especializado nas áreas de direito administrativo e regulatório, direito ambiental, direito contencioso, contratos, direito imobiliário, direito societário, direito trabalhista e direito tributário</description>
	<lastBuildDate>Wed, 27 Aug 2025 20:57:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.0.11</generator>
	<item>
		<title>ANPD Approves the Regulation on Dosimetry and Application of Administrative Penalties of LGPD</title>
		<link>https://www.soutocorrea.com.br/en/client-alerts/anpd-aprova-o-regulamento-de-dosimetria-e-aplicacao-de-sancoes-administrativas-da-lgpd/</link>
		
		<dc:creator><![CDATA[marketing]]></dc:creator>
		<pubDate>Wed, 01 Mar 2023 13:27:42 +0000</pubDate>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Proteção de Dados]]></category>
		<guid isPermaLink="false">https://www.soutocorrea.com.br/client-alerts/anpd-aprova-o-regulamento-de-dosimetria-e-aplicacao-de-sancoes-administrativas-da-lgpd/</guid>

					<description><![CDATA[<p>The Brazilian National Data Protection Authority (“ANPD”) published yesterday the Resolution CD/ANPD Nr. 4, of February 24, 2023, which approves the long-awaited Regulation on Dosimetry and Application of Administrative Penalties (“Regulation”).</p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/client-alerts/anpd-aprova-o-regulamento-de-dosimetria-e-aplicacao-de-sancoes-administrativas-da-lgpd/">ANPD Approves the Regulation on Dosimetry and Application of Administrative Penalties of LGPD</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The Brazilian National Data Protection Authority (“ANPD”) published yesterday the Resolution CD/ANPD Nr. 4, of February 24, 2023, which approves the long-awaited Regulation on Dosimetry and Application of Administrative Penalties (“Regulation”).<br><br>The <strong>Regulation’s aim</strong> is to establish parameters and criteria for the application of administrative penalties by ANPD, as well as the methods and dosimetry for calculation of fine’s base value.<br><br>In addition to the inclusion of certain definitions, the Regulation defined and established criteria for the administrative penalties provided for in article 52 of the LGPD, as summarized below:</p>



<ul><li><span style="text-decoration: underline;"><strong>Warning:</strong></span> it may be applied for low and moderate level violations and does not characterize specific recurrence or whenever correctional measures are needed;</li><li><span style="text-decoration: underline;"><strong>Simple fine:</strong></span> it may be applied when the offender has not complied with preventive or correctional measures applied within ANPD´s deadlines; the violation is classified as high level; or whenever a different sanction is not suitable;</li><li><span style="text-decoration: underline;"><strong>Daily fine:</strong></span> it may be applied to ensure compliance within a specified period, with a non-pecuniary penalty or with a determination established by ANPD, or when the offender, after notification of the irregularities, fails to correct them within due time; obstructs the inspection activity ; or practices a permanent violation that has not ceased until the decision.</li><li><span style="text-decoration: underline;"><strong>Publication of the violation after its occurrence has been duly investigated and confirmed:</strong></span> it may be applied considering the relevance and public interest of the matter and consists of the disclosure of the violation by the offender.</li><li><span style="text-decoration: underline;"><strong>Blocking of personal data to which the violation refers to up to duly regularization:</strong></span> temporary suspension of any processing operation of the personal data to which the violation refers, up to the regularization of the conduct.</li><li><span style="text-decoration: underline;"><strong>Exclusion of personal data to which the violation refers:</strong></span> it consists of the exclusion of data stored in a database. The offender must immediately communicate the data exclusion to the treatment agents with whom he/she has shared the data, except in cases specified in the regulation.</li><li><span style="text-decoration: underline;"><strong>The partial suspension of the database operation to which the violation refers:</strong></span> it will be applied for a maximum period of six months, extended for an equal period until the processing activity is regularized by the controller. This penalty can only be applied if one of the other penalties, except for warning, has already been applied for the very same case.</li><li><span style="text-decoration: underline;"><strong>Suspension of the personal data processing activity to which the violation refers:</strong></span> it will be applied for a maximum period of six months, extended for an equal period. This penalty can only be applied if one of the other penalties, except for warning, has already been applied for the very same case.</li><li><span style="text-decoration: underline;"><strong>The exercise of activities related to partial or total ban of data processing:</strong></span> it consists of the partial or total ban of operations involving the personal data processing, and may be applied in cases where there is a recurrence of a violation punished with partial suspension of the database operation or suspension of the processing personal data activity; personal data processing occurs for illegal purposes or without legal support; or the offender loses or does not meet the technical and operational conditions to maintain the adequate personal data processing. This penalty can only be applied if the other sanctions, except for warning, has already been applied for the very same case.</li></ul>



<p>The Regulation has also established (i.) a series of criteria to be observed in the administrative procedure; (ii.) the classification of violations; (iii.) method for calculating fines, including the incidence of aggravating and mitigating factors; (iv.) deadline for payment of fines among other factors relevant for the penalties under the LGPD application.<br><br>Regarding the calculation of&nbsp;<strong>fines’ amounts</strong>, the Regulation has established a specific methodology that can be accessed&nbsp;<a href="https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-4-%20de-24-de-February-de-2023-466146077" target="_blank" rel="noreferrer noopener">here</a>, which takes into account the classification of the violation, the offender&#8217;s revenue at the last available fiscal year prior to the application of the penalty and the degree of the damage.<br><br>The&nbsp;<strong>maximum fines’&nbsp;amounts</strong>&nbsp;remain limited to 2% of the revenue of the private legal entity, group or conglomerate of companies in Brazil in their last fiscal year, excluding taxes, or R$ 50,000,000.00.&nbsp;<strong>Minimum fines’ amounts</strong>&nbsp;​​were also defined.<br><br>Considering that the Regulation is already in force and that ANPD has already all the necessary parameters to start the application of penalties, it is relevant that companies comply with the LGPD to avoid the application of the penalties and future impacts, not only under a financial point of view, but also under a reputational one.<br><br>Contact our data protection experts for further information.</p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/client-alerts/anpd-aprova-o-regulamento-de-dosimetria-e-aplicacao-de-sancoes-administrativas-da-lgpd/">ANPD Approves the Regulation on Dosimetry and Application of Administrative Penalties of LGPD</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Global Data Review 2023</title>
		<link>https://www.soutocorrea.com.br/en/noticias/global-data-review-2023/</link>
		
		<dc:creator><![CDATA[marketing]]></dc:creator>
		<pubDate>Wed, 04 Jan 2023 12:41:17 +0000</pubDate>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Proteção de Dados]]></category>
		<guid isPermaLink="false">https://www.soutocorrea.com.br/noticias/global-data-review-2023/</guid>

					<description><![CDATA[<p>Souto Correa was listed among the global top law firms in data protection by the Global Data Review (GDR) 100 – 2023, a ranking organized by Global Data Review. </p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/noticias/global-data-review-2023/">Global Data Review 2023</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Souto Correa Advogados foi listado entre os melhores escritórios de advocacia do mundo em proteção de dados pelo Global Data Review (GDR) 100 &#8211; 2023, ranking do Global Data Review. A publicação é a única que analisa as capacidades, o histórico e a reputação de mercado das empresas líderes no setor, examinando não apenas as competências em privacidade e proteção de dados dos escritórios de advocacia, mas também seus trabalhos em outras legislações que envolvem a temática de dados &#8211; incluindo disputas B2B sobre aquisição de bases de dados, responsabilidade por incidentes de segurança, antitruste, o uso de leis de PI e de confidencialidade para proteção da propriedade de dados. <br/><br/>Para mais informações, clique <strong><a href="https://lnkd.in/gjdh2bYw" target="_blank" rel="noreferrer noopener">aqui</a></strong>.</p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/noticias/global-data-review-2023/">Global Data Review 2023</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>ANPD publishes a guide on cookies and personal data protection</title>
		<link>https://www.soutocorrea.com.br/en/client-alerts/anpd-lanca-guia-orientativo-sobre-cookies-e-protecao-de-dados-pessoais/</link>
		
		<dc:creator><![CDATA[marketing]]></dc:creator>
		<pubDate>Thu, 20 Oct 2022 21:11:39 +0000</pubDate>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Proteção de Dados]]></category>
		<guid isPermaLink="false">https://www.soutocorrea.com.br/client-alerts/anpd-lanca-guia-orientativo-sobre-cookies-e-protecao-de-dados-pessoais/</guid>

					<description><![CDATA[<p>On October 18, 2022, the National Data Protection Authority ("ANPD") launched the guidelines "Cookies and Personal Data Protection". The guide aims to provide a general overview of the use of Cookies in online environments, taking into consideration the precautions that data processing agents must take regarding protecting personal data. Also, the guide intends to elucidate positive and negative practices in elaborating Cookie Banners in the electronic environment through illustrative cases. </p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/client-alerts/anpd-lanca-guia-orientativo-sobre-cookies-e-protecao-de-dados-pessoais/">ANPD publishes a guide on cookies and personal data protection</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>On October 18, 2022, the National Data Protection Authority (&#8220;ANPD&#8221;) launched the guidelines &#8220;Cookies and Personal Data Protection&#8221;. The guide aims to provide a general overview of the use of Cookies in online environments, taking into consideration the precautions that data processing agents must take regarding protecting personal data. Also, the guide intends to elucidate positive and negative practices in elaborating Cookie Banners in the electronic environment through illustrative cases.&nbsp;</p>



<p><strong>Definition of Cookies</strong></p>



<p>The guide defines Cookies as &#8220;files installed in a user&#8217;s device that allow the gathering of certain information, that may include personal data, to meet several purposes&#8221; and clarifies that, through the use of Cookies, it is possible, for example, to register information of a user in a certain website, such as his credit card number, his login, or a product previously added to his shopping cart.</p>



<p><strong>Attribution of a Lawful Basis</strong></p>



<p>According to the guide, the attribution of a lawful basis provided in the Brazilian General Data Protection Law (&#8220;LGPD&#8221;) is necessary to enable the use of Cookies. In this sense, consent and legitimate interest are the most relevant ones.</p>



<p><strong>Consent </strong></p>



<p>The guide exemplifies cases in which the use of consent is not appropriate. These include:</p>



<p>• Strictly Necessary Cookies &#8211; since in these cases, the processing of the information is essential for the functioning of the website or service, and therefore there is no effective condition for the free manifestation of the data subject; and </p>



<p>• Cookies that are strictly necessary to comply with legal obligations and duties, especially in cases with a clear and direct link between data processing through Cookies and the exercise of typical state prerogatives by public entities and bodies.</p>



<p><strong>Legitimate Interest</strong></p>



<p>As for legitimate interest, the guide informs that it may be employed when the use of Cookies is strictly necessary and in the case of analytical Cookies, which are responsible for measuring audience. However, in cases of Cookies used for advertising purposes, the ANPD reinforces that this lawful basis may not always be used and recommends applying the balancing test to determine the prevalence of the fundamental rights and freedoms of the data subjects concerning the legitimate interests of the controller or third parties.</p>



<p><strong>Good Practices</strong></p>



<p>Not exhaustively, the guide exposes good practices to be considered when setting up Cookie Banners, such as</p>



<p>• The provision of a button that allows rejecting all cookies that are not necessary;</p>



<p>• The provision of an access link for the data subjects to exercise their rights, such as obtaining details about the use of their data, the retention period, requesting the disposal of data, and revoking consent;</p>



<p>• The classification of Cookies into categories;</p>



<p>• The description of the categories of Cookies according to their uses and purposes, with a simple explanation of these purposes;</p>



<p>• Obtaining consent for each specific purpose;</p>



<p>• Disabling Cookies based on consent by default; and</p>



<p>• The provision of information on whether browser settings can block cookies.</p>



<p>Unadvised Practices&nbsp;</p>



<p>Also, the guide lists some inadvisable practices in the elaboration of Cookies banners, for example:</p>



<p>• The use of a single button, with no management option, in the case of using the legal basis of consent;</p>



<p>• The impossibility or impediment in the visualization of the buttons to reject or configure Cookies, emphasizing the acceptance button;</p>



<p>• The impossibility or impediment of rejecting all Cookies that are not necessary;</p>



<p>• The activation of Cookies that are not necessary by default so that the user must manually deactivate them;</p>



<p>• The non-availability of second-level Cookie Banners;</p>



<p>• The failure to provide information and direct, simplified, and proper mechanisms for the exercise of the data subject&#8217;s rights to revoke consent and object to the processing of their data;</p>



<p>• The difficulty in managing Cookies;</p>



<p>• The display of information on the Cookie policy in a foreign language only;</p>



<p>• The display of the Cookie list in an exaggeratedly granular manner;</p>



<p>• Linking the obtaining of consent to the full acceptance of the conditions of use of Cookies without providing effective options to the data subject.</p>



<p>Although the guide deals primarily with processing personal data by Cookies in the electronic environment, its guidelines apply to processing personal data through similar tracking technologies, observing the particularity of the case in question.</p>



<p>Furthermore, even though the guide exposes good practices to be followed by processing agents, it is emphasized that compliance with the guidelines contained therein does not exempt agents from observing the LGPD instructions.&nbsp;</p>



<p>Access the full guide by clicking <a href="https://www.gov.br/anpd/pt-br/documentos-e-publicacoes/guia-orientativo-cookies-e-protecao-de-dados-pessoais.pdf" target="_blank" rel="noreferrer noopener">here</a>.</p>



<p>For more information, please contact our Data Protection team.</p>
<p>O post <a rel="nofollow" href="https://www.soutocorrea.com.br/en/client-alerts/anpd-lanca-guia-orientativo-sobre-cookies-e-protecao-de-dados-pessoais/">ANPD publishes a guide on cookies and personal data protection</a> apareceu primeiro em <a rel="nofollow" href="https://www.soutocorrea.com.br/en/">Souto Correa Advogados</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
