In a 2016 book titled L’Homme Nu (literally “The Naked Man”), French authors Marc Dugain and Christophe Labbé discuss how tech giants own our data – and essentially our lives. Being able to sell our private data to the highest bidder is, in the authors’ opinion, the real danger of the century. Not terrorism, not by a long shot.

Recent scandals have shed light on this danger and exposed parts of a very secretive industry: how companies profit from our information. Remember the Cambridge Analytica scandal? The controversial British company used the data of 87 million people (Brazilians included) with electoral intentions – pushing campaigns such as Brexit and Donald Trump’s U.S. presidential bid. Since the scandal broke, the firm folded, but its directors have another company waiting to take its business.

Countries have tried to tame this use of personal data. On May 25, the European Union enacted the General Data Protection Regulation (GDPR), a privacy legal framework designed to make sure users know and understand how and for what purpose companies collect their data. The GDPR doesn’t allow companies to use personal data without explicit consent from users. Remember receiving a boatload of notifications about privacy policy updates? Well, you can thank GDPR for that.

The need for consent

The law will come into effect in 2020, giving companies 18 months to adapt to the new rules. After that point, personal data can only be collected with explicit consent – otherwise, the company will be infringing on the law. Companies will also have to inform if the information will be shared with other entities. If that's the case, they will need another consent form.

This goes for public and private entities, based in Brazil or abroad. It means that both Google and Facebook, for example, will have to comply with Brazil's General Personal Data Protection Act if they want to maintain their Brazilian operations.

Users can revoke consent at any given moment, after which data can no longer be collected. Exceptions to the law are cases of public security, national defense, or journalistic investigations.

No generic terms of consent

Companies cannot use deceiving small-print forms or generic terms anymore. Terms of consent must be highlighted from the rest – and the text has to be clear and specific. Consent based on broad terms will be automatically voided.

Data collected must be coherent with apps

Remember those personality quizzes on Facebook that ended up collecting your political preferences, socioeconomic data, and consumer behavior? Those will no longer be legal. Companies can only collect information that is relevant to the service they provide. For instance, a car-sharing app can access your location, or a video-call app can access your camera and microphone. But the rule will be to collect as little information as possible.

Medical information cannot be sold to third parties

Information collected by healthcare services are now considered to be "sensitive personal data." According to the law approved by Congress, medical information cannot be used for "economic gain." Entities conducting studies on public healthcare issues can still access databases as long as their use is strictly for research purposes.

Ethnicity, religion, sexual preferences

The bill also deems as sensitive personal data "any data relative to someone's religious, political or sexual preferences, philosophical convictions, nationality, ethnicity, participation in social or political movements, health, genetic or biometric information."

Data of minors

Starting in 2020, any data from minors can only be collected with the explicit consent of their parents or legal guardian. No company can condition the participation of minors in games or apps to the supply of their personal data.

Compliance officer

Companies – and state institutions – must publicly inform who is the person responsible for the treatment of users' personal data. The Data Protection Officer – who will act as a form of "compliance officer" – must oversee all data treatment policies within an organization and make sure they are in line with legislation.

The European Union also created this position – which will create over 28,000 jobs across the bloc. In Brazil, estimates suggest the market for such professionals will also be in the tens of thousands, due to the market's size. Brazil accounts for almost 100 million Facebook users alone, for instance.

Checks and balances

If there's a security breach, authorities must be immediately informed. Companies cannot mimic Uber, which disclosed a hacker attack that leaked personal data from millions of users one year after it happened. Companies which suffer leaks can face fines of up to BRL 50 million per infraction and could be barred from continuing to collect users' data.

According to Brazil's General Personal Data Protection Act, data cannot be used to the detriment of users. So, if a bank rejects someone's credit based on data it has collected, it is possible to appeal and even command an audit to verify if the decision was based on discriminatory information, such as gender, ethnicity, religion, or sexual orientation.

