ANPD publishes Regulation on the requirements for appointment of the Person in Charge (“Encarregado”)
The Brazilian Data Protection Authority (“ANPD“) published the Resolution CD/ANPD No. 18, which creates additional rules for the appointment of the Person in Charge (similar, although not equivalent to the Data Protection Officer under GDPR) – the “Regulation“.
As a background, according to Law No. 13.709/18 (Brazilian Data Protection Law or “LGPD“), data controllers must appoint a Person in Charge. The “Person in Charge” has the primary role of serving as a communication liaison between the data controller, data subjects and ANPD, and also to provide training and guidance to the controller’s employees, and to comply with any other instructions that controller may give.
Accordingly, the Regulation sets forth the procedures that must be followed for the appointment of the Person in Charge, including personal qualifications that the Person in Charge must meet.
Some of the Regulation’s key aspects are:
- The Person in Charge can be either an individual or legal entity;
- The appointment of the Person in Charge must be made by means of a formal act (written, dated and signed document). This document must be provided to the ANPD upon request;
- The processing agent must formally appoint a substitute to act in the place of the Person in Charge during any period of vacancy in the position;
- The appointment of a Person in Charge by data processors is optional, but will be deemed as a good practice/ mitigation measure for the applicability of potential fines;
- It is necessary to disclose, in a prominent and easily accessible place (e.g. the website or other communication channels often used to contact data subjects), the name of the individual or legal person appointed as the Person in Charge, as well as their contact information;
- The Person in Charge must be able to communicate clearly and precisely with data subjects and the ANPD, in Portuguese;
- The Person in Charge’s professional qualifications should be determined by the processing agent, in light of the context, volume, and risk of the processing activities performed by the processing agent;
- The Person in Charge can have an additional role within the company or organization, as long as such additional role does not create a conflict of interest in the performance of their duties as the Person in Charge.
The Regulation is binding and effective since yesterday, July 18,2024.