A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so. Local data protection regulations have required data controllers to report such breaches in certain circumstances.
Under Brazil’s General Data Privacy Law, employers (and other data controllers and processors) are required to inform the national authority and the data subject if a security incident which may create risk or damages to the data subjects occurs.
The communication must be completed in a reasonable timeframe (to be determined by the data protection authority) and include:
Individual unauthorized information disclosures or access may be resolved directly between the employer (as the data controller) and the employee (as the impacted data subject). In the event that there is no agreement, the employer would be subject to the penalties. More detailed instructions relating to responding to a data breach may be announced by the national data protection authority in the future.