The General Data Protection Law (LGPDLaw No. 13.709, approved in 2018 but only came into effect in September 2020, establishes rules aimed at defining the conditions for the collection, storage, and processing of personal information.
Although it doesn't have a direct relationship with labor relations, it also becomes important in this scenario, since the relationship between the company and the employee generates a series of confidential and personal information.
European law (GDPR) specifically addressed this relationship between regulation and labor relations, establishing certain special considerations based on company size, for example.
In Brazil, although the LGPD (Brazilian General Data Protection Law) does not have specific provisions regarding labor relations, it can also be applied to the data generated in this interaction, precisely to guarantee the protection of both parties.
To better understand this entire scenario and the new developments it has brought, many business owners turn to the services of labor law consulting, thus having the means to adapt in order to comply with the requirements of the law.
In fact, even though it is recent and still raises a number of questions, understanding it better is essential to meet the requirements and to be sure that you are acting correctly with regard to the data generated by your company.
If you want to better understand the subject, in order to correctly coordinate all the information generated in your company's professional relationships, this content is for you.
Therefore, continue reading this article and understand the effects of the General Data Protection Law, the phases in which it should be applied, and the penalties for establishments that do not comply with it as stipulated.
What is the LGPD and what are its effects on companies?
Anyone who starts a business knows that there are various requirements for the company to operate legally. Therefore, knowledge of the laws, about occupational medicine And information about taxes owed is essential.
More recently, a new regulation has emerged on the scene, the so-called General Data Protection Law, which aims to protect and regulate the sharing of data obtained through different means.
Technology has been a significant contributing factor to this, as the use of the internet and various digital platforms offering diverse services to professionals collect different data from their users.
The data provided during the use of a given system must be protected, preventing the loss of information without user authorization. After all, access to personal information exposes people to fraud and can compromise their security.
In recent times, companies that have adopted the format home-office Much of their content became exposed, since different types of activities depended on access to the business's private data.
In this way, just like the property security While it has become indispensable in physical establishments to ensure the protection of people, the protection of different types of corporate information has become even more important.
Thus, when establishing a relationship with its employees, the company obtains a range of personal information that needs to be properly stored and protected.
It is in this sense that the LGPD (Brazilian General Data Protection Law) becomes important in the employment relationship, guaranteeing the security of what are considered sensitive data, some examples of which are:
- Racial or ethnic origin;
- Political opinions;
- Philosophical or religious beliefs;
- Union membership;
- Questions about health, genetics, or biometrics.
Since access to this information can lead to discrimination against employees, it is essential that the establishment that obtained such data stores it correctly.
Not surprisingly, the LGPD (Brazilian General Data Protection Law) must be strictly followed in the pre-hiring, hiring, and post-hiring phases, whether in direct employment contracts or in... outsourcing of concierge services, for example.
1. The LGPD in the pre-contractual phase
This stage marks the first contact between the company and the prospective employee, and it generally occurs within a recruitment process, which can be carried out by the human resources department or by companies specializing in this service.
It is at this point that the company announces the job opening on the market, then begins receiving resumes and conducting interviews, getting to know the candidates better and thus being able to select the one with whom they feel most suited to the position.
If the company chooses to apply the process to IT outsourcingShe should be aware that some information that could lead to discrimination in the selection of candidates is prohibited, such as requesting credit checks or blood tests from participants.
In the pre-hiring phase, it is the company's obligation to clarify to unsuccessful candidates what will be done with the data and documents they provided, making the following clear. your policy the use of this information.
2. The LGPD in the contractual phase
A company specializing in independent auditThe manager, who has selected one of the candidates in the recently applied selection process, should then communicate in a practical and objective manner with the new employee.
Therefore, it needs to communicate its data processing policy, so that the employee must (or must not) give consent regarding what is stipulated therein.
During the professional's employment period, the contracting company has access to various personal information about its employees, thus obligating it to... applying the LGPD as a way to protect them.
In the standard registration form, it is possible that the professional's political affiliation may be questioned. By obtaining this information, the company becomes responsible for restricting third-party access to each employee's file.
Furthermore, it is common for employees to periodically perform health checkups, which assess the worker's physical condition and check for potential occupational problems arising from the workday.
It is important to emphasize that in these cases, tests such as pregnancy tests, cancer screenings, or HIV tests should not be performed, as they may result in discrimination against the professional in the workplace.
Another important point is that, when presenting a medical certificate to justify absence from work, the document does not need to include the ICD (International Classification of Diseases and Related Health Problems) code, respecting the employee's privacy.
However, in cases where the professional's condition during that period is recorded, the information must be kept confidential so as not to impact the workplace's routine.
Finally, it's worth mentioning that the sharing of data with health insurance providers, when medical coverage is offered by the company, must be expressly authorized by the employee.
All these precautions are essential to ensure that all personal information of each of the company's employees is secure and properly stored by the establishment.
3. The LGPD in the post-contractual phase
Every employment relationship has a beginning and an end, and the LGPD (Brazilian General Data Protection Law) also has effects in the post-contractual phase. When an employee leaves the company, it is important to also take precautions with their personal information.
Thus, regardless of whether the contract was signed directly with the establishment or through the hiring of outsourced laborThe company must inform the professional about the termination of the use of their data, either at their request or due to legal requirements.
This is especially important because all information obtained during the employment relationship must be stored at the establishment for two years after the termination date.
Ultimately, this is the maximum period within which an employee can file a labor lawsuit, so the company can keep all documentation related to the employment contract until the end of this period.
These are the main effects that the General Data Protection Law brings to labor relations, so complying with it correctly ensures that the company fulfills its role towards its employees.
What are the penalties for those who do not comply with the LGPD (Brazilian General Data Protection Law)?
Regardless of the segment in which the company operates, whether it's with document scanning or accountingTherefore, obligations regarding employee data must be met.
However, when these regulations are ignored by establishments, the LGPD provides for penalties for this.
Among the main measures, it is possible to mention the application of warnings, so that the company can adapt and comply with what is stipulated in the Law.
There are also fines, both small and large, which can reach up to 50 million reais. Other measures include the blocking and deletion of personal data.
All of this aims to ensure that companies comply with legislation, making the employment relationship safer and free from problems.
Therefore, be sure to ensure that the LGPD (Brazilian General Data Protection Law) is present in your establishment, in order to guarantee the protection of your employees' information and to be certain that you are correctly following current laws.
This text was originally developed by the blog team Investment Guide, where you can find hundreds of informative content about various segments.



















