What is the LGPD?

The General Personal Data Protection Law (Law No. 13,709/2018), known as the LGPD, establishes rules for the collection, use, storage, sharing, and deletion of personal data by public and private organizations.

Its purpose is to ensure greater transparency and control for data subjects regarding the processing of their personal information.

 

Who oversees compliance with the LGPD?

Oversight is carried out by the Brazilian National Data Protection Authority (ANPD), the body responsible for guiding, regulating, and supervising compliance with data protection legislation in Brazil.

Other bodies and entities may also act in specific situations, according to their legal responsibilities.

 

Who is the data subject?

A data subject is any natural person to whom personal data relates.

For example, a customer, employee, supplier, job applicant, visitor, or any individual whose personal information is processed by the organization.

 

What are personal data?

They are information related to an identified or identifiable natural person.

Examples:

  • Name;
  • CPF or ID card number;
  • Address;
  • E-mail;
  • Telephone;
  • Date of birth;
  • IP address;
  • Location data;
  • Financial information;
  • Photographs linked to a person.

 

What are sensitive personal data?

They are data that require additional protection due to their potential to cause discrimination or significant impacts on privacy.

They include information about:

  • Racial or ethnic origin;
  • Religious belief;
  • Political opinion;
  • Trade union membership;
  • Health information;
  • Sex life;
  • Genetic data;
  • Biometric data.

 

What is personal data processing?

Processing is any operation performed on personal data.

Examples include:

  • Collection;
  • Recebimento;
  • Classification;
  • Use;
  • Sharing;
  • Storage;
  • Access;
  • Modification;
  • Deletion;
  • Disposal.

 

In which situations does the LGPD apply?

The LGPD applies to the processing of personal data carried out in Brazil or intended for individuals located within Brazilian territory, regardless of whether the processing occurs in physical or digital form.

 

In which situations does the law allow the processing of personal data?

The LGPD allows the processing of personal data when there is an appropriate legal basis, including:

  • Data subject's consent;
  • Compliance with a legal or regulatory obligation;
  • Performance of a contract;
  • Regular exercise of rights;
  • Protection of life or physical integrity;
  • Credit protection;
  • Legitimate interest, when permitted by law;
  • Other situations provided for under the LGPD.

 

What is consent?

Consent is the free, informed, and unambiguous expression by which the data subject agrees to the processing of their data for a specific purpose.

It is important to note that not all data processing depends on consent, as the LGPD provides other legal bases for its execution.

 

Can I withdraw previously granted consent?

Yes.

The data subject may request the withdrawal of consent at any time, subject to the applicable legal provisions.

The withdrawal does not invalidate processing activities lawfully carried out before the request.

 

What are the rights of data subjects?

Among the main rights provided under the LGPD are:

  • Confirmation of the existence of processing;
  • Access to personal data;
  • Correction of incomplete or outdated information;
  • Anonymization, blocking, or deletion when applicable;
  • Data portability;
  • Information about data sharing;
  • Withdrawal of consent;
  • Request for clarifications regarding the processing carried out.

 

How can I request information or exercise my rights?

Requests may be submitted through the LGPD Contact Channel provided by PCA.

To ensure the security of information, it may be necessary to verify the identity of the requester before processing the request.

 

What is a controller?

A controller is the natural person or legal entity responsible for making decisions regarding the processing of personal data.

In its business activities, PCA may act as the controller of personal data processed within its own internal processes.

 

What is an operator?

An operator is the natural person or legal entity that processes personal data on behalf of the controller, following its instructions.

Service providers contracted to process data on behalf of the organization may act in this capacity.

 

What is a DPO or Data Protection Officer?

The Data Protection Officer (DPO) is the professional responsible for acting as a communication channel between:

  • The organization;
  • Data subjects;
  • The Brazilian National Data Protection Authority (ANPD).

It also assists the organization in promoting good privacy and data protection practices.

 

Who is PCA's DPO?

PCA designates the following person as its Data Protection Officer (DPO):

Data Protection Officer (DPO)
Nityananda Portellada
DPO Consultant at Next4Sec Security Intelligence
E-mail: lgpd-dpo@pca.com.br

 

What is the ANPD?

The Brazilian National Data Protection Authority (ANPD) is the body responsible for regulating, guiding, and overseeing the enforcement of the LGPD throughout the national territory.

 

In the event of a security incident involving personal data, will data subjects be informed?

When a security incident may result in risk or significant harm to data subjects, PCA will adopt the appropriate measures required by law, including the communications mandated by the LGPD and the guidelines issued by the ANPD.

 

How does PCA protect personal data?

PCA adopts technical and organizational measures to protect the information under its responsibility, including:

  • Access control;
  • System monitoring;
  • Use of encryption when applicable;
  • Security updates;
  • Risk assessments;
  • Internal information security policies;
  • Employee training and awareness programs.