LGPD for small handling agents

In a recent publication in the DOU, the ANPD submits to public consultation the draft of the Resolution that will regulate the application of LGPD for small handling agents, as well as opening registrations for a public hearing on the topic.

  • Who are considered small treatment agents?

- Micro-enterprises, small businesses, startups, non-profit legal entities, natural persons and unincorporated entities that assume controller or operator obligations.

  • What is addressed in the draft?

- It exempts small processing agents from the obligation to keep records of personal data processing operations; to confer portability of the data subject's data to another service or product provider; and to appoint a Personal Data Controller (also known as DPO), subject, however, to the provision of a channel of communication with data subjects.

- It relaxes the obligations to comply with requests from personal data subjects; to submit an impact report (which can be done in simplified form when required); and to adopt security incident reporting, which can be simplified.

- It provides that they must adopt essential and necessary administrative and technical measures, based on minimum information security requirements for the protection of personal data.

- The prediction that the ANPD will release guidance guides on the application of LGPD for small handling agents.

We reinforce that the Regulation is not yet applicable, being subject to public consultation and public hearing. Its draft is available here. Suggestions may be sent until 29 September, through the platform "Participa + Brasil", available here.