The General Data Protection Law is increasingly gaining importance in the country as the population's level of awareness grows.
Once data subjects become aware of the need to protect their information, companies will, in turn, need to invest in having a robust structure that offers this protection. But what do legal bases have to do with the matter?
Being the LGPD a regulation created to provide guarantees of protection and privacy For users to have control over the use, sharing, and processing of their data, it is expected that a structure will exist to effectively enforce this law.
The legal basis of General Law of Data Protection These are the conditions that make this processing possible; in other words, they are conditions stipulated by law to ensure that the collection and processing of data are done correctly.
We can therefore say that a company that collects and processes personal data... without a properly adequate legal basis, is acting irregularly.
With the accelerated development of technology and the digital world, several loopholes have been created, allowing access to information that until then only authorized individuals possessed.
In this way, a lawless land culture was created where companies gained access to data irregularly and used it for their own profit, without any legal basis. consent of the holders of this data.
Understanding the legal basis of the General Data Protection Law (LGPD)
From this, the legal bases of the LGPD They were created as a way to provide greater protection to data subjects.
In total, there are 10 legal bases, which are prerequisites for the processing of personal data and are not dependent on each other, allowing companies to choose those that best suit their way of working:
- Consent of the data subject;
- Legitimate interest;
- Compliance with legal or regulatory obligations;
- Treatment by the public administration;
- Conducting studies and research;
- Contract execution or preparation;
- Regular exercise of rights;
- Protection of life and physical safety;
- Health protection for the policyholder;
- Credit protection.
According to article 5, item X of the LGPD (Brazilian General Data Protection Law), data processing is defined as... “any operation performed with personal data […]”.
And this processing must be carried out by a data protection professional, better known as a data controller. DPOIt is up to him to choose which data will be used. From there, he must choose which legal bases will be used.
Based on the legal principle of consent, data processing can only be carried out with the authorization of the data subject, prohibiting the use of data collected without their knowledge.
The text by Felipe Palhares, Luís Prado, and Paulo Vidigal lists some points to help in choosing the best legal basis for a company to adopt:
“(i) it is ideal to choose a single legal basis for each treatment (although, in the specific case, there may be some overlap and/or coexistence of bases);
(ii) no legal basis is more important or better than another. This is a menu of alternative hypotheses, the application of which will depend on the purpose pursued by the processing activity, as well as the circumstances highlighted above;
(iii) Strictly speaking, the legal bases require that the processing be necessary to achieve a specific purpose (for example, compliance with a rule or the performance of a contract). Thus, if it is possible to achieve the purpose without carrying out the processing, it is likely that there is no legal basis for it;
(iv) it is recommended that the legal bases be determined, in a documented manner, prior to processing, given that each of them produces a range of its own effects, which may require adjustments to the activities and measures to be addressed in advance by the processing agents;
(v) there is no express legal obligation to inform the data subject of the legal basis, since the legal basis is not one of the criteria enshrined in art. 9 of the LGPD;
(vi) after the definition, strictly speaking, the legal basis should not be changed, otherwise it may be found that the initial classification was made incorrectly, triggering irregularities in the operation up to that point; and
(vii) in case of modification of the purpose for processing personal data, it will be necessary to assess whether it is possible to sustain the processing on the originally defined basis, which involves analyzing the compatibility of the new purpose with the previous one. (PALHARES, PRADO and VIDIGAL, 2021, p. 149)”.
Finally, it is important to highlight that, according to the LGPD (Brazilian General Data Protection Law), the data controller may only use personal data that is based on at least one of the 10 legal bases mentioned here. In other words, the controller is obliged to inform which legal basis it uses in each processing of personal data.



















