BMA Advogados
Publications

Four years into Brazil's General Data Protection Law: The new challenges in Compliance

18.09.2024 2 min read

Brazil’s General Data Protection Law (“LGPD” – Lei Geral de Proteção de Dados Pessoais) came into force on September 18, 2020, although the legislation itself makes no reference to that date. Instead, September 18, 2020 is the day on which Law 14.058/2020 was published in Brazil’s official gazette, the Diário Official da União. 

The National Data Protection Authority (“ANPD” – Autoridade Nacional de Proteção de Dados) is now up and running, and so far it has published seven guides, decided eight regulatory enforcement proceedings at first instance (two have also been decided at second instance), and has contributed to various other documents and public events. 

The ANPD’s work in building a solid regulatory structure is essential, not least because there are a number of gaps in the LGPD that must be filled by regulations issued by the Authority. On the other hand, ensuring compliance with the LGPD in a regulatory landscape that is still under construction is a complex task.

In preparing this e-book, we have been guided by BMA’s DNA: practical, direct, and detailed, sharing our experience in data protection matters through useful information that can be immediately applied to solve problems our clients face. 

In the following pages, we address what has changed over the last four years: the record-keeping obligations created by the ANPD, interpretations by the Authority that can provide guidance to organizations subject to the LGPD, and other public statements by the ANPD that merit attention. We have also prepared a compliance checklist to help you assess your organization’s current state and identify points that may need attention to ensure alignment with the legislation and best market practices.


>>> CLICK HERETO DOWNLOAD AND COMPLETE THE CHECKLIST