Pular para conteúdo

Brazil LGPD (Lei 13.709/2018) Compliance — EPPA

EPPA processes Art. 11 sensitive data of Brazilian patients only after ANPD-aligned safeguards are in place

The LGPD treats health data with stricter conditions than ordinary personal data (Art. 11). Several mechanisms that work for non-sensitive data — including the broad legitimate-interest basis — are not available for sensitive data. Until the safeguards in §4 to §6 below are in place, EPPA must not be deployed in Brazil outside an explicit-consent research protocol.

1. Document identity

Field Value
Document title Brazil LGPD Compliance — EPPA
Document ID EPPA-BR-LGPD-001
Version 0.1 (draft)
Status Draft — not approved
Effective date n/a
Owner LABIS UCA — Brazil Privacy lead (to be appointed)
Linked documents 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md

2. Regulatory anchors

  • Lei 13.709/2018 — Lei Geral de Proteção de Dados Pessoais (LGPD), amended by Lei 13.853/2019 and Lei 14.010/2020.
  • Resolução CD/ANPD 1/2021 — Regulamento do processo de fiscalização e do processo administrativo sancionador.
  • Resolução CD/ANPD 2/2022 — Regulamento de aplicação da LGPD para agentes de tratamento de pequeno porte.
  • Resolução CD/ANPD 4/2023 — Regulamento de dosimetria e aplicação de sanções administrativas.
  • Resolução CD/ANPD 15/2024Verify current number/title — guidance on data subject rights handling [TBD verify].
  • Constituição Federal Art. 5 inc. LXXIX (added by EC 115/2022) — fundamental right to personal data protection.
  • ANVISA RDC 751/2022 — software como dispositivo médico (parallel device-regulation track for EPPA).

3. Scope of LGPD applicability

Per Art. 3, LGPD applies when:

  • The processing operation is carried out in Brazilian territory;
  • The processing aims to offer or supply goods or services to, or process data of, individuals located in Brazilian territory; or
  • The data being processed was collected in Brazilian territory.

EPPA deployed in a Brazilian clinic satisfies the first two prongs. Even an extraterritorial cloud deployment processing data of Brazilian patients falls within LGPD scope.

4. Sensitive personal data (Art. 5 inc. II + Art. 11)

4.1 Definition

Art. 5 inc. II defines "dado pessoal sensível" as data relating to racial or ethnic origin, religious conviction, political opinion, trade-union or religious-organisation membership, dado referente à saúde, sex life, genetic data and biometric data — when linked to a natural person.

EPPA processes:

  • Dado referente à saúde — postural-assessment outputs, markers, clinical interpretation.
  • Dado biométrico — facial features visible in the photographs.

Both are sensitive personal data under Art. 5 inc. II.

4.2 Lawful basis for sensitive data (Art. 11)

Unlike Art. 7 (which lists ten bases for ordinary personal data, including the broad "legitimate interest" of Art. 7 inc. IX), Art. 11 lists a narrower set for sensitive data:

Art. 11 Basis EPPA applicability
inc. I Specific, prominent and informed consent of the data subject or legal representative Default for clinical research deployments.
inc. II(a) Statutory or regulatory compliance by the controller Not applicable.
inc. II(b) Shared processing necessary to execute public policies provided for in laws or regulations Not applicable (LABIS is a private university).
inc. II(c) Studies by research entities, ensuring whenever possible the anonymisation of sensitive data Available for academic research with face-blur / pseudonymisation.
inc. II(d) Regular exercise of rights, including in contract and judicial procedures Not applicable.
inc. II(e) Protection of life or physical integrity Not applicable.
inc. II(f) Health protection, in procedures performed by health professionals, health services or health authorities Available in a treating-clinician deployment.
inc. II(g) Guarantee of fraud prevention and security of the holder, in identification and authentication processes in electronic systems Not applicable.

Legitimate interest does not apply to sensitive data

The Art. 7 inc. IX legitimate-interest basis is not available for sensitive data under Art. 11. This is a load-bearing difference from GDPR Art. 9 — in GDPR, Art. 9(2)(j) "scientific research with appropriate safeguards" mirrors LGPD Art. 11 inc. II(c) closely, but LGPD has no legitimate-interest fallback for sensitive data at all.

For EPPA, the default is Art. 11 inc. I (explicit consent), with Art. 11 inc. II(c) (research) as alternative when explicit consent is infeasible and anonymisation is practical.

5. Roles, controller and operator (Art. 5 incs. VI–VIII)

LGPD term Definition (Art. 5) EPPA role
Controlador Natural or legal person that takes decisions regarding processing LABIS UCA in the research-use phase; the deploying clinic in a clinical deployment
Operador Natural or legal person that processes personal data on behalf of the controller Hosting provider, SMTP relay, backup processor
Encarregado (DPO) Person appointed by the controller and operator LABIS UCA must appoint one before Brazilian deployment

5.1 DPO (Encarregado) requirement — Art. 41

Art. 41 requires the controller to appoint a DPO. The DPO's identity and contact information must be publicly disclosed, clearly and objectively, preferably on the controller's website.

Resolução CD/ANPD 2/2022 grants reduced obligations for "small-size processing agents", which may not be obliged to appoint a DPO under §5 of that resolution; however, processing sensitive health data on a non-trivial scale generally precludes the small-size exemption.

For EPPA, the conservative position is to appoint a DPO.

6. International transfers (Art. 33 to Art. 36)

6.1 General regime

Art. 33 enumerates the conditions under which international transfer of personal data is permitted. The conditions parallel GDPR Chapter V but diverge in detail.

Art. 33 Mechanism EPPA applicability
inc. I To countries or international organisations recognised by ANPD as providing an adequate level of protection Argentina-EU-Brazil adequacy chain TBD; ANPD has not published an adequacy decision list as of date of this document
inc. II Where the controller offers and proves guarantees of compliance with LGPD, including specific contractual clauses, standard contractual clauses, global corporate norms or seals/certifications regularly issued Default for EPPA — ANPD-approved standard clauses (Resolução CD/ANPD 19/2024 [TBD verify number])
inc. III When the transfer is necessary for international legal cooperation Not applicable
inc. IV When the transfer is necessary for the protection of the life or physical integrity of the data subject or third party Not applicable
inc. V When the ANPD authorises the transfer Per-case
inc. VI When the transfer results from a commitment assumed in an international cooperation agreement Not applicable
inc. VII When the transfer is necessary for the execution of a public policy or attribution of public service Not applicable
inc. VIII When the data subject has provided specific and highlighted consent for the transfer, with prior information about the international nature of the operation, clearly distinguishing it from other purposes Available as a backup
inc. IX When necessary for the execution of a contract or preliminary procedures related to a contract of which the data subject is a party, at his/her request Not applicable
inc. X When necessary for the regular exercise of rights in judicial, administrative or arbitration procedures Not applicable

6.2 EPPA transfer matrix (Brazil-deployment scenario)

Flow Origin Destination Mechanism
App hosting (planned EU region) BR clinic EU Art. 33 inc. II — ANPD standard contractual clauses with the hosting provider
App hosting (planned US region) BR clinic US Art. 33 inc. II — ANPD standard clauses + DPIA (RIPD) per Art. 38
Research-data sharing with Argentina co-investigator BR AR Art. 33 inc. II — clauses; AR is not yet ANPD-adequate even though it is GDPR-adequate
Research-data sharing with EU co-investigator BR EU Art. 33 inc. II — clauses + research-protocol consent

ANPD adequacy list pending

As of the date of this document, ANPD has not published an adequacy decision recognising specific countries. Until that list exists, Art. 33 inc. I is unavailable in practice and every international transfer must rely on Art. 33 inc. II or inc. VIII. Monitor ANPD publications.

7. Data subject rights (Art. 18)

Right Article EPPA SLA
Confirmação da existência de tratamento Art. 18 inc. I Within 15 days from request (Art. 19 §3)
Acesso aos dados Art. 18 inc. II Within 15 days
Correção Art. 18 inc. III Reasonable time
Anonimização, bloqueio ou eliminação de dados desnecessários, excessivos ou tratados em desconformidade Art. 18 inc. IV Reasonable time
Portabilidade Art. 18 inc. V Subject to ANPD regulation
Eliminação dos dados pessoais tratados com base no consentimento (com exceções) Art. 18 inc. VI After consent withdrawal
Informação sobre entidades públicas e privadas com as quais o controlador realizou uso compartilhado Art. 18 inc. VII On request
Informação sobre a possibilidade de não fornecer consentimento e sobre as consequências da negativa Art. 18 inc. VIII At collection
Revogação do consentimento Art. 18 inc. IX, Art. 8 §5 Immediate

8. Incident notification (Art. 48)

Art. 48 requires the controller to notify the ANPD and the affected data subjects of any security incident that may create relevant risk or damage to data subjects. The wording:

O controlador deverá comunicar à autoridade nacional e ao titular a ocorrência de incidente de segurança que possa acarretar risco ou dano relevante aos titulares.

Unlike GDPR Art. 33 (72-hour fixed window), LGPD Art. 48 §1 specifies "em prazo razoável" — a reasonable time — and references the ANPD to specify this. In practice, ANPD guidance and Resolução CD/ANPD 15/2024 [TBD verify number/date] indicate a target of within two business days from knowledge for notifications to ANPD, with the data-subject notification on a slightly extended timeline.

8.1 Required content of incident notification (Art. 48 §1)

  • Description of the nature of the affected personal data.
  • Information about the data subjects involved.
  • Indication of the technical and security measures used.
  • Risks related to the incident.
  • Reasons for delay, if applicable.
  • Measures taken or to be taken to mitigate the effects of the loss.

EPPA's incident-response runbook (planned in 50-secdev-checklist.md) must produce this content on a 24-hour SLA from confirmed incident.

9. DPIA (Relatório de Impacto à Proteção de Dados Pessoais — RIPD), Art. 38

Art. 38 empowers ANPD to require an RIPD ("Relatório de Impacto à Proteção de Dados Pessoais") from the controller, particularly for high-risk processing such as sensitive data. The GDPR DPIA in 30-gdpr-dpia.md is closely analogous and can be adapted to LGPD requirements with the following deltas:

GDPR Art. 35 element LGPD Art. 38 / 50 equivalent Notes
Description of processing and purpose Same Use GDPR DPIA §2 verbatim with LGPD reference.
Necessity and proportionality Same Re-reference Art. 11 inc. I or inc. II(c) instead of Art. 9(2)(j).
Risk assessment Same Reuse §4 of the GDPR DPIA.
Measures envisaged Same Reuse §5 of the GDPR DPIA.
Consultation with the DPO Same The DPO must be consulted.
ANPD consultation in high residual risk Same in spirit Art. 38 confers ANPD discretion.

The RIPD must be available to ANPD on demand.

10. LGPD vs GDPR — load-bearing differences

Topic GDPR LGPD Implication for EPPA
Legitimate interest for sensitive data Available under Art. 9(2)(g)–(j) with specific conditions Not available — Art. 11 list is exhaustive Always use consent or research-anonymisation basis
Incident notification 72 hours from knowledge (Art. 33) "Reasonable time" — ANPD guidance ≈ 2 business days [TBD] Faster SLA in practice; align with the tighter of the two
Data subject right of access 1 month (Art. 12(3)) 15 days (Art. 19 §3) EPPA SLA must be 15 days
Adequacy decisions EU Commission publishes list ANPD has not published a list yet All international transfers via clauses (Art. 33 inc. II)
Sanctions cap €20 M or 4 % global turnover 2 % of revenue in Brazil, capped at BRL 50 M per infraction (Art. 52) Different cap but still material
DPO disclosure Generally required for sensitive data Required + must be publicly disclosed (Art. 41 §1) EPPA must publish DPO contact on the website
Privacy by design Recital 78 Art. 46 §2 Same substantive standard
Anonymisation Recital 26 Art. 5 inc. III, Art. 12 LGPD defines anonymisation; anonymised data is out of LGPD scope (Art. 12)

11. ANPD oversight

The Autoridade Nacional de Proteção de Dados is the enforcement authority. It can:

  • Issue warnings (Art. 52 inc. I).
  • Impose simple fines (Art. 52 inc. II) up to 2 % of revenue in Brazil, capped at BRL 50 M.
  • Impose daily fines (Art. 52 inc. III).
  • Order the publication of the violation (Art. 52 inc. IV).
  • Order blocking or elimination of the data (Art. 52 inc. V to VII).
  • Suspend or prohibit processing (Art. 52 inc. X to XII).

Resolução CD/ANPD 4/2023 (dosimetry) lays out the methodology for calibrating sanctions.

12. Records of processing (Art. 37)

The controller must keep a record of processing operations. Required content overlaps the GDPR Art. 30 ROPA. EPPA's ROPA skeleton in 30-gdpr-dpia.md §8 must be extended with LGPD-specific columns:

  • Hipótese legal aplicável (Art. 11 inc. I, II(c), II(f)).
  • Encarregado (DPO) identified.
  • Transferências internacionais com base no Art. 33.

13. Open questions

  1. Confirm ANPD adequacy list. Monitor ANPD publications for the first adequacy decisions.
  2. Confirm ANPD international transfer clauses. Verify the current Resolução number publishing the model contractual clauses (Resolução CD/ANPD 19/2024 is the working reference; verify).
  3. Confirm incident notification SLA. Resolução CD/ANPD 15/2024 (or equivalent) is the operative guidance; verify and lock the EPPA SLA.
  4. Confirm small-size exemption applicability. Likely not applicable given sensitive-data processing scale, but document the determination.

References