Geographical scope
),
},
{
text: ‘Applies to the data processing of Brazilian residents, no matter where the data processor is based.’,
},
{
text: ‘Applies to data processing of EU residents, regardless of where the data processor is located.’,
},
],
},
{
items: [
{
text: (
Legal basis for processing
),
},
{
text: ‘Requires a legal basis to process data. LGPD provides 10 legal bases, such as consent, compliance with regulatory obligations, and protection of data subject’s physical safety.’,
},
{
text: ‘Requires a legal basis to process data, such as consent, contract, compliance with legal obligations, and protection of vital and public interests.’,
},
],
},
{
items: [
{
text: (
Data subjects’ rights
),
},
{
text: ‘Access, correction, and deletion of data, data portability, and the right to be informed about data processing.’,
},
{
text: ‘Access, rectification, erasure (“right to be forgotten”) of data, data portability, and the right to be informed.’,
},
],
},
{
items: [
{
text: (
Data protection officer (DPO)
),
},
{
text: ‘Requires data controllers to appoint a DPO.’,
},
{
text: ‘Requires both data controllers and processors to appoint DPOs.’,
},
],
},
{
items: [
{
text: (
Data breach notification
),
},
{
text: ‘Data processors must notify the National Data Protection Authority (ANPD) and the data subject about data breaches immediately.’,
},
{
text: ‘Data processors must notify supervisory authorities and data subjects about a data breach within 72 hours if the breach poses a threat to individual rights and freedoms.’,
},
],
},
{
items: [
{
text: (
Fines and penalties
),
},
{
text: ‘Fines up to 2% of the organization’s revenue, a maximum of 50 million reais per violation.’,
},
{
text: ‘Fines up to €20 million or 4% of an organization’s global annual revenue, whichever is higher.’,
},
],
},
{
items: [
{
text: (
International data transfers
),
},
{
text: ‘Allows international data transfers to countries or international organizations that meet specific requirements of LGPD.’,
},
{
text: ‘Allows data transfers to countries that comply with certain GDPR requirements.’,
},
],
},
{
items: [
{
text: (
Authority
),
},
{
text: ‘Controlled by the National Data Protection Authority (ANPD).’,
},
{
text: ‘Each EU member state has its own supervisory authority coordinated by the European Data Protection Board (EDPB).’,
},
],
},
]}
/>
The post The importance of Brazil’s General Data Protection Law (LGPD) first appeared on NordVPN.