Glossary
For a better understanding of the new terms related to data processing and to avoid confusion in their use, the General Data Protection Law (LGPD) prescribes standardized concepts (Art. 5, LGPD). One of the concepts that deserves attention is that of personal data itself. By considering an identifiable piece of information as personal data, the law expanded the range of possibilities subject to its protection. This is because, depending on the concrete circumstance, any information capable of identifying a person or, when combined with others, allows identification, even indirectly, will be considered personal data. This includes information such as profession, age, specialty, academic background, IP address, user geolocation, among others.
Below is a list of the terms defined in the Law:
- Personal Data: information related to an identified or identifiable natural person;
- Sensitive Personal Data: personal data about racial or ethnic origin, religious belief, political opinion, membership in a union or organization of a religious, philosophical, or political nature, data related to health or sexual life, genetic or biometric data, when linked to a natural person;
- Anonymized Data: data related to a data subject that cannot be identified, considering the use of reasonable and available technical means at the time of its processing;
- Database: a structured set of personal data, established in one or more locations, in electronic or physical form;
- Data Subject: a natural person to whom the personal data being processed refers;
- Controller: a natural or legal person, public or private, responsible for decisions regarding the processing of personal data;
- Processor: a natural or legal person, public or private, who processes personal data on behalf of the controller;
- Data Protection Officer: a person appointed by the controller and processor to act as a channel of communication between the controller, data subjects, and the National Data Protection Authority (ANPD);
- Processing Agents: the controller and the processor;
- Processing: any operation performed with personal data, including collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction;
- Anonymization: the use of reasonable and available technical means at the time of processing, through which data loses the possibility of direct or indirect association with an individual;
- Consent: a free, informed, and unequivocal expression by which the data subject agrees to the processing of their personal data for a specific purpose;
- Blocking: temporary suspension of any processing operation, by keeping personal data or the database;
- Elimination: deletion of data or a set of data stored in a database, regardless of the procedure employed;
- International Data Transfer: the transfer of personal data to a foreign country or international organization of which the country is a member
- Shared Use of Data: communication, dissemination, international transfer, interconnection of personal data, or shared processing of personal databases by public entities in the performance of their legal competencies, or between these and private entities, reciprocally, with specific authorization, for one or more types of processing allowed by these public entities, or among private entities;
- Data Protection Impact Report (DPIA): documentation by the controller that contains the description of personal data processing processes that may pose risks to civil liberties and fundamental rights, as well as measures, safeguards, and risk mitigation mechanisms;
- Research Entity: a body or entity of the direct or indirect public administration or a nonprofit legal entity legally established under Brazilian laws, with headquarters and jurisdiction in the country, that includes in its institutional mission or in its social or statutory purpose basic or applied research of a historical, scientific, technological, or statistical nature; and
- National Authority: a body of public administration responsible for safeguarding, implementing, and overseeing compliance with this Law throughout the national territory.