Brazil's Supreme Court (STF) states that public servants who violate the General Data Protection Law (LGPD) will be held accountable for misconduct.

Estimated reading time: 2 minutes

Summary

In times when the LGPD (Brazilian General Data Protection Law) is so much in the spotlight and companies across the country have been working and adapting their systems and cultures to comply with the law, the burning question arises: how does the issue of data processing stand when it comes to the public sector?

On the last day, September 15th, Supreme Court It was unanimous in stating that the sharing of personal data across public agencies It must comply with all the requirements of the General Data Protection Law, and if non-compliance with the regulations is found, the State will be held objectively liable for the damages caused to individuals.

Furthermore, the employee who violates the duty to disclose as established in article 23, I, of the LGPD, intentionally, will be held liable for the act of administrative impropriety from article 11, IV, of Law 8.429/1992:  "Denying publicity to official acts, except when they are essential for the security of society and the State or in other cases established by law."

Gilmar Mendes says the council should include civil society participation.

The minister Gilmar Mendes voted to proceed in accordance with the Constitution regarding the decree, that is, the sharing of personal data between public bodies presupposes that it is carried out for legitimate and specific purposes and must comply with the requirements of GDPR

Furthermore, the data sharing between state institutions It is mandatory to respect the principle of publicity contained in the LGPD (Brazilian General Data Protection Law), which states that the processing of personal data by public bodies must be promoted. "for the fulfillment of its public purpose, in the pursuit of the public interest, with the objective of executing legal competencies or fulfilling the legal attributions of the public service"Since "The circumstances under which personal data is processed in the exercise of their powers should be disclosed, providing clear and up-to-date information on the legal basis, purpose, procedures and practices used to carry out these activities, in easily accessible media, preferably on their websites."

If this sharing violates regulations, the State will be liable for the damages caused, and if there is intent or negligence, the responsible employee may be held liable for the data breach through a legal action brought by the public administration.

According to the magistrate's understanding, the State must be held objectively liable in cases of administrative misconduct, provided that the objective requirements are met, that is, that intent is confirmed within the parameters established by the Supreme Court.

Finally, Cármen Lúcia's recommendation was unanimously approved in the session: the public administration will have to justify, in advance and in detail, the use and sharing of personal data, respecting the guidelines stipulated by the LGPD (Brazilian General Data Protection Law).

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also