top of page

HR and GDPR: How to Protect Sensitive Data and Avoid Fines Up to 2% of Revenue

Foto do escritor: DBS Partner
DBS Partner
há 6 horas
2 min de leitura

Medical certificates, occupational health exams, and biometric data require differentiated handling under Brazil's GDPR-equivalent law (LGPD) — and one common mistake can be costly: keeping this data longer than the law allows


HR and GDPR: How to Protect Sensitive Data

HR departments handle more sensitive personal data than any other area of a company — medical certificates, pre-employment health exams, biometric time-clock data, union membership, and disability status for quota compliance. Under GDPR, sensitive data is defined as information that could expose someone to discrimination, and it therefore requires differentiated handling, a specific legal basis, and stronger security measures. Non-compliance can result in fines of up to 2% of the company's annual revenue.


Not all health data requires a formal diagnosis


A common mistake is assuming that only a formal medical diagnosis counts as sensitive data. In practice, any information that directly or indirectly reveals someone's health condition falls into this category — including medical certificates, occupational exam results, and leave-of-absence records kept in HR systems.


Retention periods: not everything is kept indefinitely


Each type of sensitive data has its own retention period. Occupational health records must be kept for up to 20 years, per Brazilian occupational health and safety regulations. Résumés and exam results for candidates who were not hired, on the other hand, should be retained for a limited period — typically 6 to 12 months. Once the purpose for collecting the data has been fulfilled and there is no legal requirement to retain it, sensitive data must be deleted or anonymized.


Essential best practices


  • Apply the "need to know" principle: only those who genuinely need access to a piece of data should have it

  • Store sensitive data with encryption — never in open spreadsheets or on personal devices

  • Classify information by sensitivity level and purpose of use

  • Prepare a data protection impact assessment (DPIA) when required

  • Set clear retention and deletion timelines for each type of data


Conclusion


Handling sensitive data responsibly isn't just a legal requirement — it's what protects a company from penalties and builds trust with employees. As Brazil's data protection authority (ANPD) steps up enforcement, having documented processes has shifted from a competitive advantage to a baseline necessity, particularly for foreign companies managing a Brazilian subsidiary's HR operations from abroad.



Source: Contábeis, Abimapi, and Barbieri Advogados | Adaptation and review: DBS Partner Team



DBS Partner helps companies structure HR and payroll processes in compliance with GDPR, safeguarding employee data throughout the entire employment lifecycle. Get in touch with our team and protect your business from unnecessary risk. Prefer to reach us directly? Email us at dbs@dbspartner.com.br.

Comentários


bottom of page