This content is restricted.
Brief
Summary:
The Autoridade Nacional de Proteu00e7u00e3o de Dados (ANPD) has issued decisions in two sanctioning processes against the Instituto Nacional de Seguro Social (INSS) and the Secretaria de Estado de Educau00e7u00e3o do Distrito Federal (SEEDF). Both public entities were found to have violated legal provisions on personal data treatment and were sanctioned accordingly.
The INSS was condemned for not reporting a security incident that occurred in 2022, which exposed personal data such as CPF, bank data, and birth dates. The ANPD deemed that the incident could have caused significant harm to the rights of the data owners and ordered the INSS to publish the infraction on its website and mobile app for 60 days.
The SEEDF was sanctioned for violating various provisions of the Lei Geral de Proteu00e7u00e3o de Dados (LGPD) and the ANPD's Regulation on Inspection. The ANPD found that the SEEDF failed to maintain a register of personal data processing activities, submit a Data Protection Impact Report, notify data owners of a security incident, and use systems that meet security requirements and good practices.
These sanctions aim to ensure the protection of personal data and the rights of data owners.
Highlights content goes here...
This content is restricted.
