BlackTree Security · Infrastructure · Automation · AI

Brazil Defined the DPO Role. Independence Now Has to Be Operational.

Brazil’s data protection authority published Resolution CD/ANPD No. 18 on 17 July 2024. It turns the LGPD’s data protection officer into a more defined governance function, with rules for appointment, contact, resources, activities and conflicts of interest.

The LGPD already required controllers to appoint an encarregado, commonly described as a data protection officer or DPO. What remained less clear was how that role should operate in practice. Resolution 18 fills much of that gap.

The regulation does not transform the DPO into the person solely responsible for compliance. The processing agent remains responsible. Instead, the DPO becomes a formal communication and advisory function connecting individuals, the ANPD and the organisation.

Appointment must be formal and visible

The DPO may be a natural person or a legal entity and may be internal or external. The appointment must be made through a formal act that identifies the role and its activities. Organisations also need a substitute to cover absences, vacancies or impediments.

Contact information must be publicly available in a clear and objective way, generally on the controller’s electronic channels. The point is accessibility. A privacy inbox that is not monitored, or a named officer without a working escalation route, does not create an effective channel.

Resources and access determine whether the role works

Processing agents must provide the human, technical and administrative resources necessary for the DPO’s activities. They must also give the DPO appropriate access to strategic decision-makers and to information needed for the function.

This is where a nominal appointment can fail. A DPO cannot advise on a new analytics platform, investigate a complaint or coordinate an ANPD request if the role learns about processing only after deployment. Privacy review must be connected to product, procurement, security, human resources and legal workflows.

The DPO advises, receives and guides

The regulation describes activities such as receiving communications from data subjects and the ANPD, taking appropriate measures, guiding employees and contractors on data protection practices and performing other functions assigned by the processing agent or complementary rules.

That makes the role broad, but not unlimited. Business owners still need to own the risks created by their processing. Security teams still need to operate controls. Leadership still needs to approve resources and risk decisions. The DPO should make those decisions better informed and more accountable.

Conflicts of interest need active management

The processing agent must ensure that the DPO can act with ethical, technical and operational independence and must watch for conflicts of interest. The DPO must also declare situations that could compromise the role.

A conflict can arise when the same person advises on compliance while also deciding why and how personal data will be processed. Job titles alone do not resolve the issue. Organisations should examine actual decision rights, incentives and reporting lines.

What organisations should do

  1. Document the DPO appointment and substitute in a formal internal act.
  2. Publish reliable contact details and test the intake and escalation process.
  3. Define access to leadership, processing records, projects, incidents and complaints.
  4. Separate the DPO’s advisory work from business decisions that could create conflicts.
  5. Record how recommendations are handled and who accepts any residual risk.

Independence is a workflow, not a title

Resolution 18 gives Brazilian organisations a clearer model for the DPO. The more difficult task is operational: ensuring the role receives information early, can reach decision-makers and can challenge processing without becoming the owner of every privacy obligation.

Official sources

This article provides general information and is not legal advice.

Continue the series: LATAM Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *