Brazil Amps Up Enforcement of Data Protection Law
Actions in the last six months of the Brazilian National Data Protection Authority ("ANPD") suggest that it intends to aggressively enforce the Brazilian Data Protection Law ("LGPD"). The LGPD applies to any entity that processes personal data of individuals in Brazil regardless of whether the entity has operations in the country. Such entities must, therefore, actively implement data privacy compliance policies.
Notable recent actions taken by the ANPD include: (i) promulgation of a regulation on the appointment of a data protection officer ("DPO") by data controllers, detailing a DPO's roles and responsibilities under the LGPD; (ii) enjoining the use by Meta Platforms Inc. of personal data from social media platforms for training artificial intelligence systems; (iii) promulgation of a regulation requiring disclosure of security incidents to affected individuals and the ANPD and a related order requiring public disclosure of data breaches by the National Social Security Institute; and (iv) promulgation of a regulation on international transfer of personal data, under the LGPD, and standard contractual clauses that can be implemented in connection with such transfers.