This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| General Personal Data Protection Law (Brazil) | |
|---|---|
| Name | General Personal Data Protection Law |
| Long name | Lei Geral de Proteção de Dados Pessoais |
| Enacted by | National Congress of Brazil |
| Citation | Law No. 13.709/2018 |
| Territorial extent | Brazil |
| Date enacted | 14 August 2018 |
| Status | in force |
General Personal Data Protection Law (Brazil) The General Personal Data Protection Law establishes a legal framework for processing personal data in Brazil governing rights, obligations, and enforcement mechanisms. It was enacted by the National Congress of Brazil and implemented alongside institutions such as the National Data Protection Authority (ANPD), shaping compliance across sectors including finance, telecommunications, health care in Brazil, and e‑commerce. The law interacts with international instruments and foreign regulatory regimes to influence cross‑border data flows and corporate governance.
The law, promulgated as Law No. 13.709/2018, was debated in the Federal Senate (Brazil) and the Chamber of Deputies (Brazil), with input from stakeholders including Confederação Nacional da Indústria, Associação Brasileira de Empresas de Tecnologia, and civil society groups such as Sociedade Brasileira de Direito Digital. It aligns domestic rules with principles found in the European Union's General Data Protection Regulation and dialogues with multilateral instruments like the Organisation for Economic Co-operation and Development guidelines and the Council of Europe's instruments. The law’s implementation was overseen by the Presidency of Brazil and regulatory design by the Ministry of Justice and Public Security prior to the operationalization of the ANPD.
Scope provisions distinguish processing in public sector bodies such as the Presidency of the Federative Republic of Brazil agencies from private sector actors including Banco do Brasil, Itaú Unibanco, and multinational firms like Google and Facebook. Definitions cover terms drawn from comparative law including "personal data", "sensitive personal data", "processing", "controller", and "processor", paralleling language used by the European Commission and national data laws in countries such as Argentina and Mexico. Specific categories—biometric, health, racial, and religious data—mirror protections found in the Universal Declaration of Human Rights and regional jurisprudence from the Supreme Federal Court of Brazil.
The statute codifies principles like purpose limitation, data minimization, transparency, and accountability referenced in reports by the Inter-American Commission on Human Rights and the United Nations. Data subject rights include access, correction, deletion, portability, and objection, comparable to remedies in decisions of the European Court of Justice and regulatory guidance from the Information Commissioner's Office in the United Kingdom. Collective rights and consumer protection interfaces engage institutions such as the National Consumer Secretariat (SENACON) and labor oversight by the Ministry of Labor and Employment (Brazil).
Controllers and processors — entities like Vale S.A., Petrobras, Telefonica Brasil, and cloud providers such as Amazon Web Services — must implement technical and organizational measures, conduct impact assessments, and appoint data protection officers where applicable, drawing on standards from International Organization for Standardization and recommendations by the Brazilian Internet Steering Committee (CGI.br)]. Contracts, audit trails, and incident response align with practices used by multinational auditors like Deloitte, PwC, and KPMG in their compliance engagements. Public bodies including the Ministry of Health (Brazil) and private hospitals coordinate on health data processing under sectoral rules.
Enforcement powers are vested in the National Data Protection Authority (ANPD), which may issue fines, corrective measures, and administrative warnings, following rulemaking procedures similar to agencies such as the Information Commissioner's Office and the Federal Trade Commission in the United States. Sanctions range from reprimands to substantial fines that affect corporations like Nubank and logistics firms operating with cross‑border data, and may trigger litigation before the Supreme Federal Court of Brazil or administrative appeals to the Federal Court of Accounts (TCU).
Sectors including banking in Brazil, retail chains such as Magazine Luiza, digital platforms like Mercado Libre, and advertising networks have adapted privacy governance, contracting practices, and cybersecurity investments. Compliance strategies include appointing privacy counsel from firms like Mattos Filho and conducting vendor due diligence informed by guidance from Confederação Nacional do Comércio and international frameworks from ISO/IEC JTC 1. Startups in hubs like São Paulo and Belo Horizonte incorporate privacy by design to access markets and venture capital from investors including SoftBank.
Cross‑border transfer mechanisms reference adequacy determinations comparable to the European Commission adequacy decisions and rely on instruments such as contractual clauses, binding corporate rules used by Microsoft and Apple, and safeguards endorsed by the World Trade Organization and Organisation for Economic Co-operation and Development. Brazil’s law has prompted negotiations with trading partners including the European Union, United States, and regional blocs like MERCOSUR to facilitate lawful transfers and mutual assistance between regulators in investigations and enforcement.
Category:Brazilian legislation