top of page

LGPD Penalties Finally Come into Effect

  • Mirna Conceição
  • Aug 2, 2021
  • 3 min read

Despite efforts by various sectors to postpone the entry into force of the LGPD in 2020, the law effectively came into force in September of that year. However, the application of the penalties established under the law was postponed until August 1, 2021. At the time, many considered this a major victory, as companies would “gain” another year to begin their compliance projects.


Moreover, among the more pessimistic observers, there was an expectation that the LGPD would simply “not take hold” and, consequently, would be destined to fail once its penalties finally came into force.


However, the once-distant date of August 1, 2021 eventually arrived and, even after so many cyberattacks occurred in Brazil over the previous year across a wide range of public and private sectors, there were still those who doubted the potential impact of the LGPD. In Brazil alone, data breaches increased by 493%, according to a scientific study published in January 2021 in the Journal of Data and Information Quality


Even before the LGPD came into force, cases involving violations of personal data were already addressed by the Brazilian Consumer Protection Code and the Brazilian Civil Rights Framework for the Internet, not to mention the constitutional protection of privacy and intimacy, which are recognized as fundamental rights under the Brazilian Federal Constitution. This demonstrates that such rights had already been protected by the Judiciary for many years.


Therefore, what is genuinely new is the need to raise general awareness regarding personal data protection rights, since those rights were already present in Brazilian legislation even before the LGPD came into force.



Although the much-feared penalties under the LGPD are now in effect, proper care regarding the collection, storage, use, and sharing of individuals’ personal data—aimed at ensuring privacy, security, and transparency in data processing—is still far from becoming a reality in Brazil.


According to a survey conducted by ICTS Protiviti, fewer than 30% of organizations had begun mapping their data in order to manage related risks, while approximately 84% of Brazilian companies still lacked clear guidelines regarding compliance.²


Some still promote the idea that simply updating a privacy policy, implementing opt-in mechanisms, and displaying cookie notices on websites is sufficient to demonstrate compliance. However, this approach is entirely mistaken, since compliance with the legislation must involve numerous additional measures, such as internal data protection policies, risk-mitigation actions, and the adaptation of documents and instruments containing personal data. As a result, several departments within a company or public authority may need to be involved.


With an active Brazilian National Data Protection Authority (ANPD) genuinely committed to regulating and enforcing the LGPD—even if, at this initial stage, its approach is primarily educational and preventive while a culture of data protection is gradually being disseminated throughout Brazil—it is clear that penalties will soon begin to be imposed on organizations that leave the personal data of customers, partners, and employees vulnerable.


Administrative penalties include simple warnings; one-time or daily fines of up to 2% of a legal entity’s revenues, limited to a total of BRL 50,000,000.00 per violation; the blocking or deletion of personal databases; and, perhaps most serious of all, the obligation to publicize the violation through electronic media and widely circulated newspapers. This may cause immeasurable damage to an organization’s image and create the risk of loss of reputation for an established brand.


In determining the applicable penalties, the following criteria will be taken into account: (i) the severity and nature of the violations and the rights involved; (ii) the good faith and cooperation of the infringing party; (iii) recurrence of the conduct; (iv) the infringer’s economic condition and the extent of the damage caused; and (v) the adoption of good-practice policies and internal measures aimed at minimizing the damage.


Another important point is that solid contracts between business partners may be jeopardized if one company is committed to complying with the LGPD while the other shows no concern in this regard. In other words, a company that takes personal data protection seriously may have a clear reason to discontinue a partnership where the other party does not demonstrate the same level of care, particularly in light of potential joint liability for data breaches involving information shared between partner companies.


Against this background, even though consumers and organizations are still becoming familiar with the LGPD’s rules, rights, and obligations, and although it remains uncertain exactly how its enforcement will ultimately develop as further regulations are issued, one thing is certain: the law is here to stay. Regardless of the penalties provided for under the law, the positive value generated by responsible privacy and data protection practices is far greater, as it can distinguish companies from their competitors and encourage stronger engagement among their own employees.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page