Personal Data Protection – LGPD
The Brazilian General Data Protection Law (Law No. 13709/2018), also known as LGPD, was enacted to safeguard fundamental rights, including freedom, privacy, and the free development of individual personality. The law governs the processing of personal data—whether in physical or digital form—by individuals or legal entities in both the public and private sectors. It covers a broad range of operations carried out through manual or digital means.
Under the LGPD, data processing encompasses any activity involving personal data, including its collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.
In the public sector, data processing primarily serves the implementation of public policies, as established by law, regulations, contracts, agreements, or similar legal instruments. Additionally, when the processing of personal data is necessary to fulfill a legal or regulatory obligation, the institution does not require the data subject’s consent.
The LGPD aims to ensure the protection of personal and sensitive data collected during the activities of both public and private institutions. Compliance with the law involves implementing security measures and responsible data-handling practices.
The objective is not to stop collecting personal and sensitive data, but to do so responsibly by limiting data collection to what is necessary, processing data appropriately, and assisting data subjects with any requests concerning their personal information.
The role of the Data Protection Officer
The Data Protection Officer (DPO) plays a crucial role in ensuring compliance with the LGPD. They serve as the primary point of contact between the institution, data subjects, and the National Data Protection Authority (ANPD).
According to Article 41, §2 of the LGPD, the DPO is responsible for:
- receiving and addressing complaints or inquiries from data subjects;
- handling communications from the ANPD and taking appropriate action;
- providing guidance to employees, collaborators, and contractors on best practices for data protection; and
- performing additional duties as determined by the data controller or applicable regulations.
Data Protection Officer at UFSC: Rodrigo Fernandes de Rezende
Deputy Data Protection Officer:
E-mail: gt.lgpd@contato.ufsc.br
For more information about Data Protection at UFSC, visit lgpd.ufsc.br/.



