{"id":2760,"date":"2021-02-25T11:55:08","date_gmt":"2021-02-25T14:55:08","guid":{"rendered":"https:\/\/www.lhlaw.com.br\/?post_type=publicacoes&#038;p=2760"},"modified":"2021-03-23T14:45:07","modified_gmt":"2021-03-23T17:45:07","slug":"brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication","status":"publish","type":"publicacoes","link":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/","title":{"rendered":"Brazilian Data Protection Authority releases first orientations on Data Breach Communication"},"content":{"rendered":"<p>The Brazilian Data Protection Authority (ANPD) has recently released in its website the\u00a0<a href=\"https:\/\/www.gov.br\/anpd\/pt-br\/documentos-e-imagens\/modelo_envio_de_contribuicoes_incidente_de_seguranca__final.docx\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.gov.br\/anpd\/pt-br\/documentos-e-imagens\/modelo_envio_de_contribuicoes_incidente_de_seguranca__final.docx&amp;source=gmail&amp;ust=1616604658903000&amp;usg=AFQjCNFD1Y7ZXoetBUmNPkTHwzOnNVymOA\">form for communicating data breaches<\/a>, as well as orientations on what to do when a personal data breach happens.<\/p>\n<p>The document is meant to be a guide for both controllers and processors, while the matter is discussed through a public consultation process, as foreseen in ANPD\u2019s Regulatory Agenda.<\/p>\n<p>Such an agenda is a planning document that summarizes the regulatory actions that are considered a priority and will be subject to studies or resolutions, in the years 2021 and 2022.<\/p>\n<p>Previously, the Authority adopted the same method to gather information and work on a differentiated regulatory environment for small businesses.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>What should companies do in case of a data breach?<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>Accordingly to the ANPD, a data breach is \u201cany adverse event, confirmed or under suspicion, related to a personal data security breach, such as unauthorized, accidental or unlawful access that results in destruction, loss, alteration, leakage or any form of improper or unlawful data processing, that may pose a risk to the rights and freedoms of the personal data subject\u201d.<\/p>\n<p>When facing a data breach, the ANPD recommends the following actions to be taken:<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Evaluate internally the nature, category and amount of data subjects affected by the data breach, as well as the type of personal data affected and probable and concrete consequences;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Communicate the entity\u2019s DPO;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Communicate the Data Controller, in case the breach happened on the Processor\u2019s end;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Communicate the ANPD and data subjects, in case a relevant risk to the latter is considered possible to happen;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Document the incident and the measures taken to analyze it.<\/p>\n<p>In this guidance, the ANPD indicates that the communication should be made within 2 (two) days from the date the incident was acknowledged.<\/p>\n<p>If it is not possible to provide complete information on the incident at the moment of communication, it is possible to submit supplementary communications, with new information obtained, or clarifications for any questions ANPD would arise.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Information on the public consultation process<\/strong><\/p>\n<p>Accordingly to the technical note published on February 22<sup>nd<\/sup>, the ANPD intends to build \u201cclear boundaries that make it possible to distinguish security incidents that may bring relevant risks or damages and that may require additional measures from those whose threat, if any, can be disregarded.\u201d<\/p>\n<p>After collecting the public contributions, the ANPD will present the first draft of the regulation on the reporting of incidents, which will be submitted to a new round of public consultation and hearings.<\/p>\n","protected":false},"featured_media":2667,"template":"","categories":[82,69],"class_list":["post-2760","publicacoes","type-publicacoes","status-publish","has-post-thumbnail","hentry","category-notes","category-reports"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados\" \/>\n<meta property=\"og:description\" content=\"The Brazilian Data Protection Authority (ANPD) has recently released in its website the\u00a0form for communicating data breaches, as well as orientations on what to do [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/\" \/>\n<meta property=\"og:site_name\" content=\"Loeser e Hadad Advogados\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/LoeserBlanchetHadad\/?ref=bookmarks\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-23T17:45:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2021\/02\/resized_17690-1-1024x463.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"463\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@LbhLaw\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/\",\"url\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/\",\"name\":\"Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lhlaw.com.br\\\/site\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/resized_17690-1.png\",\"datePublished\":\"2021-02-25T14:55:08+00:00\",\"dateModified\":\"2021-03-23T17:45:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lhlaw.com.br\\\/site\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/resized_17690-1.png\",\"contentUrl\":\"https:\\\/\\\/www.lhlaw.com.br\\\/site\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/resized_17690-1.png\",\"width\":3264,\"height\":1476,\"caption\":\"Foi apresentado na \u00faltima sexta-feira (19\\\/02), pelo deputado Eduardo Bismarck (PDT-CE), o Projeto de Lei n\u00ba 500 de 2021, que prop\u00f5e um novo adiamento das [\u2026] #lgpd #timeloeserehaddad\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Publica\u00e7\u00f5es\",\"item\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/publicacoes\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Brazilian Data Protection Authority releases first orientations on Data Breach Communication\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/\",\"name\":\"Loeser e Hadad Advogados\",\"description\":\"Direito empresarial | S\u00e3o Paulo, Rio, Bras\u00edlia e Campinas\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#organization\",\"name\":\"Loeser e Hadad Advogados\",\"url\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.lhlaw.com.br\\\/site\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/logo_loeser_e_hadad_advogados.png\",\"contentUrl\":\"https:\\\/\\\/www.lhlaw.com.br\\\/site\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/logo_loeser_e_hadad_advogados.png\",\"width\":200,\"height\":95,\"caption\":\"Loeser e Hadad Advogados\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lhlaw.com.br\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/LoeserBlanchetHadad\\\/?ref=bookmarks\",\"https:\\\/\\\/x.com\\\/LbhLaw\",\"https:\\\/\\\/www.instagram.com\\\/loeser_blanchet_hadad\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/loeser-blanchet-hadad-advogados\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCRh4AJ_fY9fTunW76tgPAUA?view_as=subscriber\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/","og_locale":"en_US","og_type":"article","og_title":"Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados","og_description":"The Brazilian Data Protection Authority (ANPD) has recently released in its website the\u00a0form for communicating data breaches, as well as orientations on what to do [&hellip;]","og_url":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/","og_site_name":"Loeser e Hadad Advogados","article_publisher":"https:\/\/www.facebook.com\/LoeserBlanchetHadad\/?ref=bookmarks","article_modified_time":"2021-03-23T17:45:07+00:00","og_image":[{"width":1024,"height":463,"url":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2021\/02\/resized_17690-1-1024x463.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_site":"@LbhLaw","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/","url":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/","name":"Brazilian Data Protection Authority releases first orientations on Data Breach Communication - Loeser e Hadad Advogados","isPartOf":{"@id":"https:\/\/www.lhlaw.com.br\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/#primaryimage"},"image":{"@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2021\/02\/resized_17690-1.png","datePublished":"2021-02-25T14:55:08+00:00","dateModified":"2021-03-23T17:45:07+00:00","breadcrumb":{"@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/#primaryimage","url":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2021\/02\/resized_17690-1.png","contentUrl":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2021\/02\/resized_17690-1.png","width":3264,"height":1476,"caption":"Foi apresentado na \u00faltima sexta-feira (19\/02), pelo deputado Eduardo Bismarck (PDT-CE), o Projeto de Lei n\u00ba 500 de 2021, que prop\u00f5e um novo adiamento das [\u2026] #lgpd #timeloeserehaddad"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/brazilian-data-protection-authority-releases-first-orientations-on-data-breach-communication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/www.lhlaw.com.br\/en\/"},{"@type":"ListItem","position":2,"name":"Publica\u00e7\u00f5es","item":"https:\/\/www.lhlaw.com.br\/en\/publicacoes\/"},{"@type":"ListItem","position":3,"name":"Brazilian Data Protection Authority releases first orientations on Data Breach Communication"}]},{"@type":"WebSite","@id":"https:\/\/www.lhlaw.com.br\/en\/#website","url":"https:\/\/www.lhlaw.com.br\/en\/","name":"Loeser e Hadad Advogados","description":"Direito empresarial | S\u00e3o Paulo, Rio, Bras\u00edlia e Campinas","publisher":{"@id":"https:\/\/www.lhlaw.com.br\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lhlaw.com.br\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.lhlaw.com.br\/en\/#organization","name":"Loeser e Hadad Advogados","url":"https:\/\/www.lhlaw.com.br\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lhlaw.com.br\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2023\/03\/logo_loeser_e_hadad_advogados.png","contentUrl":"https:\/\/www.lhlaw.com.br\/site\/wp-content\/uploads\/2023\/03\/logo_loeser_e_hadad_advogados.png","width":200,"height":95,"caption":"Loeser e Hadad Advogados"},"image":{"@id":"https:\/\/www.lhlaw.com.br\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/LoeserBlanchetHadad\/?ref=bookmarks","https:\/\/x.com\/LbhLaw","https:\/\/www.instagram.com\/loeser_blanchet_hadad\/","https:\/\/www.linkedin.com\/company\/loeser-blanchet-hadad-advogados\/","https:\/\/www.youtube.com\/channel\/UCRh4AJ_fY9fTunW76tgPAUA?view_as=subscriber"]}]}},"_links":{"self":[{"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/publicacoes\/2760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/publicacoes"}],"about":[{"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/types\/publicacoes"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/media\/2667"}],"wp:attachment":[{"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/media?parent=2760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lhlaw.com.br\/en\/wp-json\/wp\/v2\/categories?post=2760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}