{"id":11708,"date":"2021-10-08T11:56:14","date_gmt":"2021-10-08T08:56:14","guid":{"rendered":"https:\/\/snov.io\/knowledgebase\/?p=11708"},"modified":"2024-07-05T16:28:53","modified_gmt":"2024-07-05T13:28:53","slug":"lgpd-faq-for-snov-io-users-and-clients","status":"publish","type":"post","link":"https:\/\/snov.io\/knowledgebase\/lgpd-faq-for-snov-io-users-and-clients\/","title":{"rendered":"LGPD FAQ (for Snov.io users and clients)"},"content":{"rendered":"<h2><b>What is the LGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Brazil's General Data Protection Act (Lei Geral de Prote\u00e7\u00e3o de Dados) (LGPD) is the comprehensive privacy and security law governing the protection of personal data in Brazil. LGPD was enacted on August 14, 2018.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Under the LGPD, any information that makes it possible to identify an individual can be considered <\/span><b>personal data<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The key definitions of the LGPD are similar to GDPR. For example, there are two main roles that a company can take on in personal data processing activities. These are the <\/span><b>data controller<\/b><span style=\"font-weight: 400;\"> and <\/span><b>data processor<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><b>data controller<\/b><span style=\"font-weight: 400;\"> is an entity in charge of making the decisions regarding the processing of personal data, while a <\/span><b>data processor<\/b><span style=\"font-weight: 400;\"> is an entity that processes personal data on behalf of a data controller. However, in comparison with the GDPR, the LGPD does not explain the concept of joint controllership.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, the concept of <\/span><b>joint controllership <\/b><span style=\"font-weight: 400;\">was introduced by ANPD (Brazil\u2019s data protection authority) in its guidelines and can be understood as \"the joint, common or convergent determination, by two or more controllers, of the purposes and essential elements for the realization of the treatment of personal data, through an agreement that establishes the respective responsibilities regarding compliance with the LGPD\".<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a company fails to comply with LGPD requirements, a national authority, i.e. ANPD may apply administrative sanctions against such a company, including fines of up to 2% of the company\u2019s revenue in its last fiscal year, excluding taxes, capped at R$ 50,000,000 (approximately USD 10,000,000) per infraction.<\/span><\/p>\n<h2><b>Is it necessary to receive consent to process emails?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No, it is not strictly necessary. The LGPD provides ten legal bases for the processing of personal data. We mostly rely on four of them, e.g. during the processing of the prospects\u2019 email addresses as a controller we rely on legitimate interest. When we act as a processor, we believe that clients have the appropriate legal basis to transmit your personal data to us, including by obtaining valid consent from data subjects to do so.<\/span><\/p>\n<h3><b>What is legitimate interest?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The legitimate interest basis is one of the ten legal bases for personal data processing under the LGPD.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We have defined that the processing of emails relies on our, yours, and the prospects\u2019 legitimate interests which are the following:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">contribution to business cooperation between you and your potential prospects;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">creation and assistance in discovering the new business-targeted marketing and sales opportunities for you and your potential prospects;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">your interest in the expansion of the database of the potential prospects;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">development of the new unique platform that simplifies and facilitates professional interaction between businesses;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">your interest in the use of an online platform for businesses that combines sales, CRM, analytics, marketing, and email service functionality;<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">prospects\u2019 interest in the approach of new potential and verified clients or suppliers;<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">prospects\u2019 interest in commercializing the use of their publicly posted information related to their professional or business interests\/occupation.<\/span><\/li>\n<\/ul>\n<h2><b>How does Snov.io ensure it has the right to process email contacts?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We do our best to ensure that our activities comply with the requirements of the LGPD.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Under <\/span><span style=\"font-weight: 400;\">Article 10 of the LGPD<\/span><span style=\"font-weight: 400;\">, the controller shall adopt measures to ensure transparency of data processing based on their legitimate interests.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Snov.io has completed a legitimate interest assessment regarding all personal data whose processing is based on legitimate interest, including emails. We concluded that the data subject\u2019s fundamental rights and freedoms, which require personal data protection under applicable laws, do not prevail in this case and therefore do not contradict with requirements of Article 10 of the LGPD.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can read more about the processing roles of Snov.io here. For more information, please check our <\/span><a href=\"https:\/\/snov.io\/privacy-policy\"><span style=\"font-weight: 400;\">Privacy Policy<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/snov.io\/joint-controllership-agreement\"><span style=\"font-weight: 400;\">Joint Controllership Agreement<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><b>How does Snov.io fulfil the rights of prospects under the LGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We do our best to comply with the requirements of the LGPD, guidelines issued by ANPD, and applicable laws.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Snov.io fulfils the prospects\u2019 rights as follows:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">undertakes appropriate technical and organizational measures to ensure secure processing and transfer of prospects\u2019 personal data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">fulfils the prospects\u2019 requests regarding the processing of their personal data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">answers the prospects\u2019 questions regarding the processing of their personal data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">processes prospects\u2019 personal data on a lawful basis under the LGPD;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">transfers prospects\u2019 personal data only to the trusted service providers.<\/span><\/li>\n<\/ul>\n<h2><b>Do you need to comply with the LGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We would strongly recommend that you comply with the requirements of the LGPD when this act applies to your data processing activities. Please note that you act as a joint data controller together with us regarding the prospects\u2019 personal data you provide us with.\u00a0<\/span><\/p>\n<p><b>Important<\/b><span style=\"font-weight: 400;\">: as joint data controllers, we should cooperate and provide reasonable assistance to each other in order to ensure fulfilment of the prospects\u2019 rights, so in case you receive requests from the prospect, you may contact us. For more information, please check our <\/span><a href=\"https:\/\/snov.io\/joint-controllership-agreement\"><span style=\"font-weight: 400;\">Joint Controllership Agreement<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you have any other questions about Snov.io data processing activities, in particular regarding Snov.io commitments under the LGPD, do not hesitate to contact us at <\/span><a href=\"mailto:help@snov.io\"><span style=\"font-weight: 400;\">help@snov.io<\/span><\/a><span style=\"font-weight: 400;\"> or via live chat in the lower right corner.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is the LGPD? Brazil&#8217;s General Data Protection Act (Lei Geral de Prote\u00e7\u00e3o de Dados) (LGPD) is the comprehensive privacy and security law governing the protection of personal data in Brazil. LGPD was enacted on August 14, 2018.\u00a0 Under the LGPD, any information that makes it possible to identify an individual can be considered personal [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[620],"tags":[],"_links":{"self":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts\/11708"}],"collection":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/comments?post=11708"}],"version-history":[{"count":0,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts\/11708\/revisions"}],"wp:attachment":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/media?parent=11708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/categories?post=11708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/tags?post=11708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}