Home
Understand the legal bases of the LGPD

Understand the legal bases of the LGPD

4 years ago
João Bruno Soares
6 minutes

At the beginning of everything are the legal bases of the LGPD, that is, the legal grounds (legitimate reasons) why companies not only can, but must access customer data in order to do their jobs well.
You might wonder, isn’t selling a product or providing a service a legitimate reason to use customer data? What if I need this information in order to meet the terms of a contract? And in fact, both of these are examples of situations addressed by the legal bases of the LGPD.

These ten legal bases describe the conditions that justify the use of personal data, and they were designed to encompass all of the various hypothetical reasons data usage may be necessary. They are the structural basis that supports the ethical use of data, in order to prevent this same legislation from becoming a subterfuge used to circumvent other equally essential regulations.

Your task as manager or the person in charge of your company's data is to find among these ten the basis that best suits your business model and other governing legislation to which your company is subject. This applies to all possible steps included in data processes within your company, such as:

  • Collection,
  • Storage,
  • Treatment,
  • Transference,
  • Sharing of personal data.

Remember, we are talking about the right to privacy in the context of data that not only identifies the citizen, but also assigns them to behavioral and demographic matrices.

According to the LGPD, sensitive personal data include:

Racial or ethnic origin, religious or philosophical beliefs, political opinions, union membership, genetics, biometrics, and issues about a person's health or sex life.

With that in mind, let's look at the 10 legal bases of the LGPD.

They are:

  1. Consent of the data holder.
  2. Legitimate interest.
  3. Legal obligation.
  4. Compliance with public policies.
  5. Research bodies.
  6. Execution of contracts.
  7. Exercise of rights.
  8. Protection of life.
  9. Guardianship of health.
  10. Credit protection.

Before we delve into each of the legal bases, let’s separate “consent” and “legitimate interest” into a category of their own, because despite being the most popular, they are less straightforward than the others and require additional care in their use. The eight bases that follow are clearer and more secure from a legal perspective.

Now, let’s take a closer look at each one:

1 – Data Holder's Consent

This is perhaps the most widely known legal basis in the entire market. There are already many sites that have used it to adapt to the LGPD by displaying the well-known warning, “This site uses cookies…” Well, whether in the virtual or offline environment, consent is a very quick way to obtain authorization from customers so that businesses can legally access their data and provide their services.

However, it is worth noting that the law specifies that this consent must be in writing, or by means that demonstrate the unequivocal expression of the holder's will. Therefore, when citizens are asked to give their consent, they must have clarity, ease, and the freedom to do so autonomously.

Precisely here is a feature that differentiates this legal basis from the others: it must be as easy for customers to revoke their consent as it is for them to provide it in the first place.

Thus, it is important that the collection of consent, or opt-in (in the language of the market) is as agile and easy as revocation, or opt-out. This means that consent should not generate friction in the commercial relationship. Legal experts emphasize that, as a business owner, you should not rely solely on this modality to legitimize your use of data because this form of authorization tends to be fragile.

This is exactly why AdOpt so greatly values the agility, speed, and appearance of its communication, which corresponds with the visual identity of the company in question.

When we studied the GDPR and its impact on large publishers (news and content portals) we saw that one of the biggest effects of those huge and unattractive notices (which look like the legal department designed them in Word) was the increase in bounce rate, a digital marketing and UX metric that shows the percentage of visitors that leave your website as soon as they access it.

Imagine yourself in your store watching customers come and go in a matter of seconds, without introducing themselves, asking for a product, or interacting with a salesperson.

This is the in-person analogy for the bounce rate metric. So, think carefully about the cookie notice you place on your site. It can act as a giant barrier for your customers.

Finally, understand that the use of consent in online and offline environments must be integrated with the other steps of data use and processing within your company. Therefore, it’s important to map the flow of data within your company so that you do not miss any blindspots.

2 – Legitimate Interest.

This is the second most popular legal basis and perhaps the most widespread because, for many, legitimate interests serve as a lifeline or card up the sleeve if they cannot fit in with the others.

This doesn't make it any less important, but it is necessary to emphasize that “legitimate interest” is somewhat subjective when we consider the parties: data owner versus data operator or controller. After all, money talks and commercial interests can speak louder. But not all commercial interests will necessarily constitute a legitimate interest for the use of such data.

Why not? Because this could damage the individual rights of the owner or even another express provision of the LGPD. Article 10 of the LGPD establishes that the legitimate interest of the controller can only serve as a basis for the processing of personal data for legitimate purposes, considered from concrete situations, which include but are not limited to:

1) support and promotion of the controller's activities and;

2) protection, in relation to the holder, of the regular exercise of their rights or provision of services that benefit them, respecting their legitimate expectations and fundamental rights and freedoms.

Therefore, it’s important to ensure that the use of data is legitimately justified by the provision of the service or sale of the product, without any deviance that could weaken this legal basis under other current legislation.

3 – Legal Obligation.

As the LGPD is a fairly recent law, there are many other laws that oblige companies to, for example, collect, process, and share citizens’ personal data for other prior purposes. As such, if your business model, activity, or process is already subject to legislation in force that requires you to collect data, this legislation would be the best justification for its usage.

An example of this would be the personal data that companies must collect from their employees to report to the Ministry of Labour, Social Security, etc. Here, the holders - and in this case also employees, could not oppose their data being shared due to the legal obligation that the company is fulfilling by doing so.

4 – Compliance with Public Policies.

This is perhaps one of the biggest benefits that the LGPD has given to data subjects, all of us citizens, and every taxpayer in this country. Governments must also comply with the LGPD, making this one of the biggest - if not the biggest - legal bases of the LGPD.

Today, the government, one of the institutions that benefits most from its citizens' data, including commercially, must also conform with this regulation.

According to article 7, paragraph III of the LGPD, public administration bodies need to comply with the law when processing or sharing personal data for the execution of public policies, contracts, agreements, or similar instruments, without the need for the consent of the holders.

Although there is no need for consent, data owners still have the right to a clear and unambiguous explanation of the purposes for which their data has been collected and the processes to which it is subject. A final note, however, is that public administration is not subject to fines. However, it is still subject to warnings, publication of infractions, and restriction or even deletion of data.

5 – Research Bodies.

The LGPD also authorizes scientific researchers and developers to access personal data for the purpose of their studies. It is recommended, however, that this information is always anonymized in order to guarantee the privacy of the holders and to avoid possible leaks. This way the identities of the research subjects are protected, and the researchers themselves can rest assured of the safety of their scientific methods.

6 – Execution of Contracts.

Once a contract is signed, the parties have their obligations and rights established therein. Thus, once a data holder has signed such a contract, the legal basis for the proper use of their data has been established. In this case, the owner himself gives his data and legitimizes the legal basis for its use as part of the document.

In this sense, the situation is quite similar to that of consent. However, unlike with consent, if the data owner changes their mind, revocation of their permission is not as simple, since the contract has its own force of validity and may include additional legal bindings.

7 – Exercise of Rights.

Another legal purpose for using personal data, by choice of the data controller, is the regular exercise of rights in judicial, administrative, or arbitration proceedings.

This legal basis aims to guarantee the right of one party to produce evidence against another in legal proceedings. This is intended to prevent one party from being able to defensively obstruct the other from accessing and processing data as part of the legal process.

8 – Life Protection.

The use of data is also granted by law in cases that relate to the protection of the life or physical integrity of the data owners, or third parties.

Based on article 11, section II of the LGPD, sensitive data may be processed without providing the consent of the owner if it is essential for the protection of life or the physical safety of these or third parties.
As an example, imagine the work of first responders who bring in unconscious people in emergencies. Once the citizen and their medical records have been identified within a medical or hospital network, their information may be shared among physicians for the sake of the person, without their consent.

9 – Guardianship of Health.

As in the previous item, the LGPD also provides a legal basis that authorizes the access and processing of data for the protection of health, as long as it is carried out by a health professional, health services, or a health authority.

This legal basis tends to be widely discussed and put to the test, mainly because of the interest in information that can be used on a public and commercial basis. However, the legislation emphasizes that data sharing cannot be performed in order to harm the owner or gain economic advantage over them.
For example, imagine a scenario where access to some of the owner's health information automatically readjusted their health plan. This would be categorically vetoed by the LGPD. In other words, health plan operators are prohibited from using this data to assess risk or decide whether or not to accept clients.

10 – Credit Protection.

The 10th and final legal basis is intended to ensure that in situations of collection or debt incurred, data owners do not use the mechanisms of the LGPD as a loophole to escape their financial obligations.
An example would be if the owner requested that the creditor financial institution delete their data from its database, or even from agencies such as Boa Vista and Serasa, thus circumventing the charge.
This also tends to be a much discussed legal basis given the controversial implications that the context involves.

Legal bases are just the foundation!

Finally, we hope we’ve made these ten legal bases clear enough that you’ll be able to process data within the guidelines of the law.

With this in hand, you’re ready to take the next steps on the path to compliance.

To deepen your understanding, our next chapter is: What is the ideal privacy policy for your company?

Tags

Legal basis
LGPD

Related posts

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

Understand the meaning of the LGPD for your company

Surely you've already seen the predictions of fines and sanctions, processes. But, what does it mean to your company?

AdOpt post

Fines in LGPD - What are they, amounts, and compliance deadlines

In this article, we will answer all your questions regarding fines under the LGPD (Brazil's General Data Protection Law).

AdOpt post

How to delete cookies and cache in Chrome and other browsers?

Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?

AdOpt post

Why are cookie banners everywhere?

Want to understand why there are cookie banners on every website you visit today? This article is for you!

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

Key Differences between LGPD and GDPR and the Impact on Internet Cookies

While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.

AdOpt post

10 Marketing Processes You Should Rethink under the LGPD!

In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

LGPD for marketing | A practical guideline.

Every day, millions of users generate data on the web, which is used by companies around the globe to improve their offerings. Therefore, in 2018, a law was created to regulate the use of personal data by companies, and this directly impacts digital marketing. We're talking about LGPD.

AdOpt post

What is the ideal privacy policy for your company?

Is there an ideal and _foolproof_ Privacy Policy? This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.

AdOpt post

Tips on how to notify users after a change on the Terms of Use.

Terms of Use are quite literally the contract established between you and the company offering that product or service in a digital manner. Therefore, not only their development but also any eventual changes require careful consideration.

AdOpt post

ROPA in LGPD? Get to Know the Records of Processing Activities.

Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.

AdOpt post

Everything about the Brazilian LGPD - General Data Protection Law.

All the important information about the General Data Protection Law - LGPD: what it is, why it exists, how it works, when it came into force, who it applies to, potential fines, steps for compliance, and its legal principles.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

LGPD & COOKIES - ANPD Releases "Guidance on Cookies and Personal Data Protection"

On October 18, 2022, the National Data Protection Authority (ANPD) released the "Guidance on Cookies and Personal Data Protection." Highly anticipated by professionals in the field, this document is of utmost importance as it examines various applicable legal scenarios and establishes the requirements to be observed in the case of cookie usage.

AdOpt post

GDPR and Cookies all you need to know

Understanding the General Data Protection Regulation (GDPR) and its impact on cookies is essential. So, let's break it down, step by step.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

AdOpt CMP

AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪