Even with it being in effect, the LGPD (General Data Protection Law) is still the source of many doubts and confusion, both on the part of individuals (who are the data subjects) and on the part of companies (which are the processing agents).
Doubts and questions are natural, especially when dealing with new legislation, which promotes countless changes in the corporate routine.
To help you better understand what changes with the Law, created to guarantee privacy and the conscious use of personal data by the public and private sectors, we have prepared a guide with the main questions and answers on the topic. Continue reading and check it out:
LGPD: 20 answers to the main questions
1. What is the LGPD?
In summary, the Data Protection Law determines certain rules, principles, and responsibilities related to the processing of personal data. Generally speaking, we can say that the LGPD has arrived to dictate the rules of the game for everything that is allowed or prohibited to do with the data of individuals.
2. Since when has the LGPD been in effect?
Since September 18, 2020.
3. What data is protected by the LGPD?
All personal data related to individuals is protected by the Law.
On the other hand, information about legal entities or confidential information is not protected by the LGPD, as there are other specific legislations for this type of information.
4. What is personal data?
By personal data, we mean information such as: full name, residential address, CPF, RG, CNH, passport, voter registration card, email address, and other personal identification documents which, when combined, can promote the recognition of a person, directly or indirectly.
5. What is sensitive personal data?
According to the LGPD, sensitive personal data refers to "racial or ethnic origin, religious conviction, political opinion, affiliation with a union or religious, philosophical or political organization, data referring to health or sexual life, genetic or biometric data, when linked to a natural person."
6. Which organizations need to align?
Practically all of them. This is because the General Data Protection Law is applied in any processing operation carried out by a natural person or legal entity governed by public or private law, regardless of the medium, the country of headquarters, or the country of the data location, provided that:
it carries out personal data processing operations in Brazilian territory;
it collects data in Brazil;
it aims to offer or supply goods or services, or process the data of individuals located in the national territory.
7. What does data processing encompass?
Extremely broad, the concept of data processing involves all the processes that can be carried out with personal information, such as: collection, production, receipt, classification, utilization, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, diffusion, or extraction.
8. Does the size of the company impact compliance with the LGPD?
No. Regardless of the size of a company, if it carries out the processing of personal data, even if it is only of its team of employees, it must comply with the law.
9. Under what conditions is the LGPD not applied?
In general, the LGPD is not applied to the processing of personal data for private and non-economic purposes, in addition to other specific purposes such as journalistic, artistic, academic, and those aimed at public and national security.
10. Is the LGPD valid only for information collected on the internet?
Not only. The Law is valid for data collected on any type of channel, such as, for example, a form filled out by a client or a recording of a phone call.
11. In case of non-compliance with the Law, what are the penalties imposed?
Organizations that violate the rules of the LGPD can be fined up to 2% of their gross revenue or receive penalties of up to R$ 50 million per infraction.
In addition, the General Data Protection Law also provides for other possible sanctions, such as making the infraction public and banning the continuation of data processing.
12. Who are the actors of the LGPD?
The General Data Protection Law involves four actors. They are: data subject, controller, operator, and officer.
13. Who is the data subject?
According to the Law, the data subject is the “natural person to whom the personal data that are the object of processing refer”. Or, in other words, the users who make their information available for collection and storage.
14. Who is the data controller?
According to the Law, the controller is the “natural or legal person, governed by public or private law, who is responsible for decisions regarding the processing of personal data”. In practice, this actor refers to the company or person who coordinates and defines how the collected personal data will be processed.
15. Who is the data operator?
According to the Law, the operator is the “natural or legal person, governed by public or private law, who carries out the processing of personal data on behalf of the controller”. That is, under no circumstances may the operator process the data without the controller's permission.
16. What is the officer or DPO?
According to the Law, the officer, or DPO (Data Protection Officer), is the “person appointed by the controller and operator to act as a communication channel between the controller, the data subjects, and the National Data Protection Authority (ANPD)”. In practical terms, they are the Law Inspector within an organization.
17. What is the ANPD?
The ANPD is the National Data Protection Authority, responsible for the application, inspection, compliance, and drafting of standards and procedures regarding the law.
18. What are the principles for the processing of personal data?
The General Data Protection Law determines 10 principles that guide the processing of personal data, such as: purpose, adequacy, necessity, free access, quality of data, transparency, security, prevention, non-discrimination, responsibility, and accountability.
19. How does the General Data Protection Law impact companies?
The Law directly impacts how organizations operating in Brazilian territory handle personal data. According to the rules, it is up to companies to:
be more transparent and conscious in relation to the use of personal data of their clients, partners, and users;
adopt protection mechanisms and security, preventing data leaks and violations;
adopt measures that allow data subjects to have control and access to their own information.
20. What rights does the Law guarantee to data subjects?
The Law guarantees data subjects the rights of confirmation of the existence of processing, access to information, correction of data, anonymization, blocking or deletion of data, and the possibility of filing a complaint against the controller before the ANPD and consumer defense bodies.
Did you enjoy discovering the 20 answers to the main questions surrounding the LGPD? If this article was useful to you, share it on your social media and bring this information to more people who might be interested.
Otherwise, keep an eye on the Blog of CodeBit. We will have news here soon.
A big hug, and see you in the next post!




