The decision was upheld by the Twelfth Appellate Panel of the Judicial Section of São Paulo/SP, as the evidence attached to the case file proved the leak by the agency, violating the guidelines stipulated by the General Data Protection Law (LGPD).
The case came to light after a beneficiary, a resident of Marília, SP, reported that immediately after the approval of her death pension benefit – due to the death of her husband – in June 2021, she began receiving numerous telemarketing calls, SMS messages, and WhatsApp messages offering personal loans.
She then filed a lawsuit seeking compensation for moral damages due to the leak of her data by the INSS (Brazilian National Institute of Social Security). The 1st Chamber of the Federal Special Court of Marília/SP ruled in her favor.
INSS claimed that no data breach had occurred.
The INSS (Brazilian National Social Security Institute) then filed an appeal, claiming that there had been no security breach in its systems, and that it was not possible to prove that the calls were related to any kind of data leak from the agency.
The court analyzed the case and concluded that, given the speed with which these telemarketing companies gained access to the plaintiff's personal data and beneficiary status, it could only have been the result of a data breach at the INSS (Brazilian National Social Security Institute).
"The legislation establishes that personal data of natural persons contained in databases must be protected, being used only for legitimate, specific purposes and informed to the data subject, and it is the responsibility of the data controllers to use effective security measures capable of preventing unauthorized access by third parties." "If the leak had been carried out by another operator (for example, the bank through which the plaintiff receives their social security benefits), there would not have been genuine harassment of the plaintiff by various credit companies, but only by that interested third party.""This is what Janaína Gomes, the judge presiding over the case, stated."
The decision, which was based on article 42 of the LGPD (Brazilian General Data Protection Law), obliges the data controller, in this case the regulatory body, to compensate the affected data subject.
The judge confirmed the moral damages, as the harassment suffered by the beneficiary exceeded any limit considered normal. "This incessant distress lasted for at least 15 days, and during a difficult time in her life, given the recent loss of her husband and the medical treatment she was undergoing."
"It would be up to the INSS (Brazilian National Social Security Institute) to implement administrative measures aimed at preventing the violation of personal data under its protection, which, as is known, has not been happening, given the easy access to the confidential information of beneficiaries by financial institutions.""That's all," concluded the rapporteur.
The decision was unanimously upheld by the Twelfth Appeals Panel, which ruled in favor of the plaintiff, obligating the INSS (Brazilian National Institute of Social Security) to pay R$ 2,5.



















