Data443 Blog

Who must comply with Brazil's LGPD?

Written by Jason Remillard | Jan 15, 2019 7:00:00 PM

 Who must comply with LGPD?

Any individual or legal entity with data processing activities that:

  • Are carried out in Brazil
  • Are for the purpose of offering or supplying goods or services in Brazil or relate to individuals located in Brazil
  • Involve personal data collected in Brazil

Who doesn’t have to comply?

LGPD does not apply to data processing carried out:

  • By a person for a strictly personal purpose
  • Exclusively for journalistic, artistic, literary or academic purposes
  • Exclusively for national security, national defense, public safety or criminal investigation/punishment activities

What happens when businesses breach LGPD law?

They can face a fine of up to R$50 million (approximately 12 million USD) or 2 percent of total revenue in Brazil, whichever is higher.

LGPD is just the next step in global privacy laws, as Gartner states that by 2022, half of our planet’s population will have their personal information protected under local privacy regulations in line with the GDPR, up from a tenth today. Also, by 2025, at least 25% of the world’s nations will be in “reciprocal adequacy agreement” with the EU or China, up from a few countries today.

 

Ask us how Data443’s latest Privacy Manager™, ClassiDocs™, and ARALOC™ can support you!

 

#LGPDNoFear