SlideShare uma empresa Scribd logo
1 de 16
Draft Bill of Law on the Protection of Personal Data
RENATO L. MONTEIRO
2
Brazil – Sectorial legislation
 PROVISIONAL MEASURE 2.200/2001: digital certification;
 FEDERAL LAW 8.078/1990: Consumer Code, which regulates consumer databases;
 FEDERAL LAW 9.983/2000: crime of inserting false data in public administration information
systems;
 COMPLEMENTARY LAW 105/2001: regulates confidentiality with the financial system;
 FEDERAL LAW 10.406/2002: civil code, which regulates personalities rights
 FEDERAL LAW 12.414/2011: addresses the issue of protection of personal data within credit
protection database;
 FEDERAL LAW 12.527/2011: right to access to information stored in public databases;
 FEDERAL LAW 12.551/2011: addressees the issue of teleworking within Labor Legislation;
 FEDERAL LAW 12.737/2012: crime of invading computer devices (C. Dieckmann);
 DECREE 7.962/2013: e-commerce changes to the Consumer Code;
 FEDERAL LAW 12.846/2013: anticorruption act (Clean Company Act)
 FEDERAL LAW 12.965/2014: Brazilian Civil Rights Framework for the Internet
3
The Civil Rights Framework for the Internet
and the digital compliance
Almost every company that has a
website or collects personal data
electronically is obligated to comply
with Brazilian rules.
• “The Civil Rights Framework
for the Internet necessarily
reinforces the need of
compliance with information
security principles and unveil
the need of establishing a
privacy compliance structure”
It’s good to know that the need of creating a privacy compliance structure is going to
be reinforced by specific federal legislation about the protection of personal data,
which the draft’s main points we will exposed herein.
4
Protection of Personal Data (Draft Bill of Law)
The public debate for the drafting
of the data protection bill is
opened until July 5th. Everyone is
welcome to participate and
collaborate on the elaboration of
an innovative and protective new
text.
The proposed discussion aims on
the strengthening of fundamental
rights while encouraging
innovation and tackling
challenging global issues.
5
Protection of Personal Data (Draft Bill of Law)
• Jurisdiction;
• Scope of application;
• Personal data;
• Sensitive data;
• Consent (exemptions);
• Data subject´s rights;
• Data Protection Authority;
• Privacy Officer;
• International data transfers;
• Binding Corporate Rules – BCRs;
• Global corporate rules;
• Data breaches and notification
requirements
• Liability;
• Penalties;
• Vacatio Legis.
"Consent is the key-point of the law"
6
Jurisdiction and scope
• Jurisdiction: the law shall be applied to any processing operations performed through
totally or partially automated means, by a natural person or by a legal person under
public or private law, regardless of:
• the country where the natural or legal person are located; and
• the country where the database is located, provided that:
I - The processing operation is performed within the national territory; or
II - The personal data subject to processing have been collected within the
national territory (data subject must be in Brazil at the time of collection,
regardless of his/her nationality).
• Scope: the law shall not be applied to:
• any data processing that is:
I - Performed by a natural person for exclusively personal purposes; or
II - Performed for exclusively journalistic purposes.
III- Public safety, defense, State security, public investigation activities an
the repression of criminal offences (general principles).
7
Personal data
• Personal data: the concept of personal data was widened when compared to the
previous version of the text. It has been influenced by current discussions in Europe
towards updating the data protection legal framework;. The current definition of the
Brazilian law is based on the EU Regulation:
any data related to an identified or identifiable natural person, including
identification numbers, location data, or electronic identifiers
• Sensitive data: sensitive data can now be collected, treated and processed in more
cases, as long as there is proper consent, which has received some guidelines on the
text and must be different and separate from the regular consent; The forthcoming
DPA will have the authority to issue some additional requirements. But at
the moment, when law goes into effect, there might not be some
issued additional requirements. Nonetheless, the consent must be different from the
method used for regular personal data.
• Anonymous data: there is an ongoing trend to consider anonymous data as personal
data regarding the protections listed on the draft bill.
8
Consent
Consent: the requirements to obtain consent and which information must be given to
the subject have been broadened. The specific purpose to collect and process the
data must be informed to the subject prior to obtaining his consent. When consent
is given, the data subject shall be clearly, adequately, and ostensibly informed about the
following points:
I - Specific purpose of the processing;
II - Form and duration of the processing;
III - Identification of the controller;
IV - Controller's contact data;
V - subjects or categories of subjects to whom the data can be communicated, as
well as the scope
of disclosure;
VI - Responsibilities of the agents that will perform the processing; and
VII - data subject's rights
Right to denial: subjects have the right to deny the collection of their personal data
without limiting their access to the services, with some exceptions;
9
Consent exemptions
Consent is exempt in the case of:
• unrestricted public access data
• legal obligation by the controller;
• Data shared by public authorities;
• Contractual obligations;
• historical, scientific, or statistical research, ensuring,
whenever possible, the dissociation of the personal data;
• The regular exercise of rights in legal or administrative
proceedings;
• life or physical safety;
• Healthcare;
• Legitimate interests?
10
Data subject´s rights
The personal data subject is entitled to obtaining:
• Confirmation of the existence of data processing;
• Access to the data (interoperable and open format);
• Correction of incomplete, inaccurate, or outdated data;
• (anonymization) dissociation, blocking, or cancellation of
unnecessary or excessive data;
• Data portability???
• Right to opposition;
• Right to review: the data subject is entitled to request a review of
decisions based solely on automated processing of personal data and
that affect their interests, including decisions aimed at defining their
profile or evaluate aspects of their personality.
• The controller shall provide, whenever requested, adequate
information about the criteria and procedures used for the
automated decision.
11
Data Protection Authority
• Data Protection Authority: the previous version of the text
clearly created a separate and independent data protection
authority. The new version excluded this chapter of the text,
referring to a “competent authority”, without defining what
will constitute it.
• Privacy Officer: companies will have to employ Privacy
Officers who will be responsible to overview the compliance
with the law and also serve as a bridge between the company
and the “competent authority”; The previous version of the bill
had set a minimum size of 200 employees. The current version
does not set this bottom line, but it might be further regulation
by the DPA.
12
Data Protection Authority
http://www.technologylawdispatch.com/2014/08/privacy-data-protection/brazilian-data-protection-authority-fines-internet-provider-159m/
http://www.reuters.com/article/2012/03/08/us-google-brazil-idUSBRE82718F20120308
13
International Data Transfers
• Adequate level of protection: international transfer of personal data is only
allowed for countries that provide a level of protection for personal data that is
equivalent to the level established in this Law, with some exceptions:;
• Binding Corporate Rules – BCRs: a long standing tool in the EU data
protection system, Binding Corporate Rules are now included on the new
version of the text, what can broadly enhance the flow of data until the
Brazilian legal system adapts itself to the new data protection environment;
• Global corporate rules: the possibility of data flow within the same corporate
structure was also tackled on the new version of the project;
• Special and specific consent: in the case of countries that do not provide a
level of protection, transfer is possible through a specific statement, different
from the consent pertaining to other processing operations; and with prior
and specific information about the international nature of the operation,
including a warning about the risks involved
14
Liability
• Data breaches and notification
requirements: The controller shall
immediately report any security incident
which might damage the data subjects to the
competent body. Prompt notification to the
data subjects affected by the security
incident shall be mandatory, regardless of
the competent body's decision, in cases in
which the incident endangers the data
subjects' personal safety or can damage
them.
• Liability: The current version sets that both
the data processor and the data controller
can be held liable for mishandling personal
data. Subsidiary liability refers to the need to
prove that the company was at fault when
mishandling the data.
• Penalties: may be cumulatively applied. Non
compliance with the law may lead to:
• A simple or daily fine;
• The disclosure of the breach;
• Dissociation of the personal data;
• Blocking of the personal data;
• Suspension of the processing of
personal data for a period no longer
than two years;
• Cancellation of the personal data;
• Prohibition of the processing of
sensitive personal data for a period no
longer than ten years; and
• Prohibition of database operation for a
period no longer than ten years.
• Vacatio Legis: companies will now have
120 days from the implementation of the law
to adapt to the new data protection
rules. But there is no estimation of time. It
might take some years.
RENATO L. MONTEIRO
@renatolmonteiro
Renato Leite Monteiro
rmonteiro@opiceblum.com.br
www.opiceblum.com.br

Mais conteúdo relacionado

Mais procurados

Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill Mathew Chacko
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_indiaAltacit Global
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for OpsKamil Rextin
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislationUlf Mattsson
 
Revision Data Protection Act (Eduardo And Salvador)
Revision   Data Protection Act (Eduardo And Salvador)Revision   Data Protection Act (Eduardo And Salvador)
Revision Data Protection Act (Eduardo And Salvador)itgsabc
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
 
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonPatton Boggs LLP
 
Personal Data Privacy and Information Security
Personal Data Privacy and Information SecurityPersonal Data Privacy and Information Security
Personal Data Privacy and Information SecurityCharles Mok
 
State Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork QuiltState Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork QuiltRochester Security Summit
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Werksmans Attorneys
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminarBrowne Jacobson LLP
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Werksmans Attorneys
 

Mais procurados (19)

Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Privacy Access Letter I Feb 5 07
Privacy Access Letter I   Feb 5 07Privacy Access Letter I   Feb 5 07
Privacy Access Letter I Feb 5 07
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislation
 
Revision Data Protection Act (Eduardo And Salvador)
Revision   Data Protection Act (Eduardo And Salvador)Revision   Data Protection Act (Eduardo And Salvador)
Revision Data Protection Act (Eduardo And Salvador)
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Cloud primer
Cloud primerCloud primer
Cloud primer
 
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
 
Personal Data Privacy and Information Security
Personal Data Privacy and Information SecurityPersonal Data Privacy and Information Security
Personal Data Privacy and Information Security
 
State Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork QuiltState Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork Quilt
 
Evertio Schrems II
Evertio Schrems IIEvertio Schrems II
Evertio Schrems II
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...
 

Destaque

Te hapori akotahi
Te hapori akotahiTe hapori akotahi
Te hapori akotahidiggsuzi
 
Типовые сценарии атак на современные клиент-серверные приложения
Типовые сценарии атак на современные клиент-серверные приложенияТиповые сценарии атак на современные клиент-серверные приложения
Типовые сценарии атак на современные клиент-серверные приложенияAdvanced monitoring
 
The role of the internet
The role of the internetThe role of the internet
The role of the internetgovement
 

Destaque (8)

Question 6
Question 6Question 6
Question 6
 
Te hapori akotahi
Te hapori akotahiTe hapori akotahi
Te hapori akotahi
 
Πάσχα στην Κύπρο
Πάσχα στην ΚύπροΠάσχα στην Κύπρο
Πάσχα στην Κύπρο
 
Trabajo avión
Trabajo aviónTrabajo avión
Trabajo avión
 
Diretiva Comunitária Proteção de Dados Pessoais
Diretiva Comunitária Proteção de Dados PessoaisDiretiva Comunitária Proteção de Dados Pessoais
Diretiva Comunitária Proteção de Dados Pessoais
 
Типовые сценарии атак на современные клиент-серверные приложения
Типовые сценарии атак на современные клиент-серверные приложенияТиповые сценарии атак на современные клиент-серверные приложения
Типовые сценарии атак на современные клиент-серверные приложения
 
The role of the internet
The role of the internetThe role of the internet
The role of the internet
 
Area of a triangle
Area of a triangleArea of a triangle
Area of a triangle
 

Semelhante a Draft Bill on the Protection of Personal Data

DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADr. Oliver Massmann
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityEmerson Bryan
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxssuser36d167
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...Dr. Oliver Massmann
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Dr. Oliver Massmann
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analyticsshekharkanodia
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hrTushar Rajput
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Edouard Nguyen
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 

Semelhante a Draft Bill on the Protection of Personal Data (20)

DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 
GDPR Summary
GDPR SummaryGDPR Summary
GDPR Summary
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 

Mais de Renato Monteiro

FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...
FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...
FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...Renato Monteiro
 
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - Final
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - FinalCIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - Final
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - FinalRenato Monteiro
 
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...Renato Monteiro
 
Proteção de dados pessoais e o Marco Civil da Internet
Proteção de dados pessoais e o Marco Civil da InternetProteção de dados pessoais e o Marco Civil da Internet
Proteção de dados pessoais e o Marco Civil da InternetRenato Monteiro
 
Medical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtMedical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtRenato Monteiro
 
Medical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtMedical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtRenato Monteiro
 

Mais de Renato Monteiro (6)

FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...
FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...
FIESP - Iniciativa privada - regular o uso de dados pessoais é bom para voce...
 
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - Final
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - FinalCIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - Final
CIAB - Impato da Lei de Proteção de Dados Pessoais - 22.06.16 RLM - Final
 
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...
Reflexão geral sobre a responsabilidade dos agentes no tratamento aos dados p...
 
Proteção de dados pessoais e o Marco Civil da Internet
Proteção de dados pessoais e o Marco Civil da InternetProteção de dados pessoais e o Marco Civil da Internet
Proteção de dados pessoais e o Marco Civil da Internet
 
Medical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtMedical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thought
 
Medical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thoughtMedical technologies and data protection issues - food for thought
Medical technologies and data protection issues - food for thought
 

Último

8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptxPamelaAbegailMonsant2
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理ss
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理Airst S
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubham Wadhonkar
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargainingbartzlawgroup1
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理bd2c5966a56d
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理Airst S
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.tanughoshal0
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYJulian Scutts
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理Airst S
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersJillianAsdala
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理Airst S
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理e9733fc35af6
 
一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理Airst S
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteDeepikaK245113
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理F La
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdfBritto Valan
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理e9733fc35af6
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书irst
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringSteering Law
 

Último (20)

8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptx
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
一比一原版(UC毕业证书)堪培拉大学毕业证如何办理
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
 
一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 

Draft Bill on the Protection of Personal Data

  • 1. Draft Bill of Law on the Protection of Personal Data RENATO L. MONTEIRO
  • 2. 2 Brazil – Sectorial legislation  PROVISIONAL MEASURE 2.200/2001: digital certification;  FEDERAL LAW 8.078/1990: Consumer Code, which regulates consumer databases;  FEDERAL LAW 9.983/2000: crime of inserting false data in public administration information systems;  COMPLEMENTARY LAW 105/2001: regulates confidentiality with the financial system;  FEDERAL LAW 10.406/2002: civil code, which regulates personalities rights  FEDERAL LAW 12.414/2011: addresses the issue of protection of personal data within credit protection database;  FEDERAL LAW 12.527/2011: right to access to information stored in public databases;  FEDERAL LAW 12.551/2011: addressees the issue of teleworking within Labor Legislation;  FEDERAL LAW 12.737/2012: crime of invading computer devices (C. Dieckmann);  DECREE 7.962/2013: e-commerce changes to the Consumer Code;  FEDERAL LAW 12.846/2013: anticorruption act (Clean Company Act)  FEDERAL LAW 12.965/2014: Brazilian Civil Rights Framework for the Internet
  • 3. 3 The Civil Rights Framework for the Internet and the digital compliance Almost every company that has a website or collects personal data electronically is obligated to comply with Brazilian rules. • “The Civil Rights Framework for the Internet necessarily reinforces the need of compliance with information security principles and unveil the need of establishing a privacy compliance structure” It’s good to know that the need of creating a privacy compliance structure is going to be reinforced by specific federal legislation about the protection of personal data, which the draft’s main points we will exposed herein.
  • 4. 4 Protection of Personal Data (Draft Bill of Law) The public debate for the drafting of the data protection bill is opened until July 5th. Everyone is welcome to participate and collaborate on the elaboration of an innovative and protective new text. The proposed discussion aims on the strengthening of fundamental rights while encouraging innovation and tackling challenging global issues.
  • 5. 5 Protection of Personal Data (Draft Bill of Law) • Jurisdiction; • Scope of application; • Personal data; • Sensitive data; • Consent (exemptions); • Data subject´s rights; • Data Protection Authority; • Privacy Officer; • International data transfers; • Binding Corporate Rules – BCRs; • Global corporate rules; • Data breaches and notification requirements • Liability; • Penalties; • Vacatio Legis. "Consent is the key-point of the law"
  • 6. 6 Jurisdiction and scope • Jurisdiction: the law shall be applied to any processing operations performed through totally or partially automated means, by a natural person or by a legal person under public or private law, regardless of: • the country where the natural or legal person are located; and • the country where the database is located, provided that: I - The processing operation is performed within the national territory; or II - The personal data subject to processing have been collected within the national territory (data subject must be in Brazil at the time of collection, regardless of his/her nationality). • Scope: the law shall not be applied to: • any data processing that is: I - Performed by a natural person for exclusively personal purposes; or II - Performed for exclusively journalistic purposes. III- Public safety, defense, State security, public investigation activities an the repression of criminal offences (general principles).
  • 7. 7 Personal data • Personal data: the concept of personal data was widened when compared to the previous version of the text. It has been influenced by current discussions in Europe towards updating the data protection legal framework;. The current definition of the Brazilian law is based on the EU Regulation: any data related to an identified or identifiable natural person, including identification numbers, location data, or electronic identifiers • Sensitive data: sensitive data can now be collected, treated and processed in more cases, as long as there is proper consent, which has received some guidelines on the text and must be different and separate from the regular consent; The forthcoming DPA will have the authority to issue some additional requirements. But at the moment, when law goes into effect, there might not be some issued additional requirements. Nonetheless, the consent must be different from the method used for regular personal data. • Anonymous data: there is an ongoing trend to consider anonymous data as personal data regarding the protections listed on the draft bill.
  • 8. 8 Consent Consent: the requirements to obtain consent and which information must be given to the subject have been broadened. The specific purpose to collect and process the data must be informed to the subject prior to obtaining his consent. When consent is given, the data subject shall be clearly, adequately, and ostensibly informed about the following points: I - Specific purpose of the processing; II - Form and duration of the processing; III - Identification of the controller; IV - Controller's contact data; V - subjects or categories of subjects to whom the data can be communicated, as well as the scope of disclosure; VI - Responsibilities of the agents that will perform the processing; and VII - data subject's rights Right to denial: subjects have the right to deny the collection of their personal data without limiting their access to the services, with some exceptions;
  • 9. 9 Consent exemptions Consent is exempt in the case of: • unrestricted public access data • legal obligation by the controller; • Data shared by public authorities; • Contractual obligations; • historical, scientific, or statistical research, ensuring, whenever possible, the dissociation of the personal data; • The regular exercise of rights in legal or administrative proceedings; • life or physical safety; • Healthcare; • Legitimate interests?
  • 10. 10 Data subject´s rights The personal data subject is entitled to obtaining: • Confirmation of the existence of data processing; • Access to the data (interoperable and open format); • Correction of incomplete, inaccurate, or outdated data; • (anonymization) dissociation, blocking, or cancellation of unnecessary or excessive data; • Data portability??? • Right to opposition; • Right to review: the data subject is entitled to request a review of decisions based solely on automated processing of personal data and that affect their interests, including decisions aimed at defining their profile or evaluate aspects of their personality. • The controller shall provide, whenever requested, adequate information about the criteria and procedures used for the automated decision.
  • 11. 11 Data Protection Authority • Data Protection Authority: the previous version of the text clearly created a separate and independent data protection authority. The new version excluded this chapter of the text, referring to a “competent authority”, without defining what will constitute it. • Privacy Officer: companies will have to employ Privacy Officers who will be responsible to overview the compliance with the law and also serve as a bridge between the company and the “competent authority”; The previous version of the bill had set a minimum size of 200 employees. The current version does not set this bottom line, but it might be further regulation by the DPA.
  • 13. 13 International Data Transfers • Adequate level of protection: international transfer of personal data is only allowed for countries that provide a level of protection for personal data that is equivalent to the level established in this Law, with some exceptions:; • Binding Corporate Rules – BCRs: a long standing tool in the EU data protection system, Binding Corporate Rules are now included on the new version of the text, what can broadly enhance the flow of data until the Brazilian legal system adapts itself to the new data protection environment; • Global corporate rules: the possibility of data flow within the same corporate structure was also tackled on the new version of the project; • Special and specific consent: in the case of countries that do not provide a level of protection, transfer is possible through a specific statement, different from the consent pertaining to other processing operations; and with prior and specific information about the international nature of the operation, including a warning about the risks involved
  • 14. 14 Liability • Data breaches and notification requirements: The controller shall immediately report any security incident which might damage the data subjects to the competent body. Prompt notification to the data subjects affected by the security incident shall be mandatory, regardless of the competent body's decision, in cases in which the incident endangers the data subjects' personal safety or can damage them. • Liability: The current version sets that both the data processor and the data controller can be held liable for mishandling personal data. Subsidiary liability refers to the need to prove that the company was at fault when mishandling the data. • Penalties: may be cumulatively applied. Non compliance with the law may lead to: • A simple or daily fine; • The disclosure of the breach; • Dissociation of the personal data; • Blocking of the personal data; • Suspension of the processing of personal data for a period no longer than two years; • Cancellation of the personal data; • Prohibition of the processing of sensitive personal data for a period no longer than ten years; and • Prohibition of database operation for a period no longer than ten years. • Vacatio Legis: companies will now have 120 days from the implementation of the law to adapt to the new data protection rules. But there is no estimation of time. It might take some years.
  • 15. RENATO L. MONTEIRO @renatolmonteiro Renato Leite Monteiro rmonteiro@opiceblum.com.br