Privacy Policy
1. Introduction and institutional commitment
Charneski Advogados (“Charneski”, “Firm” or “we/us”), a law firm registered with the CNPJ under No. 10.720.318/0001-09, headquartered at Rua Antônio Carlos Berta, 475, suites 1807 and 1808, Jardim Europa, CEP 91340-020, Porto Alegre/RS, holds the protection of personal data and the duty of professional secrecy as essential values of its practice.
This Personal Data Protection and Privacy Policy (“Policy”) is a formal document, approved by the Firm's management and made publicly available, describing in a clear, transparent, and accessible manner how we collect, use, store, share, protect, and delete personal data, in compliance with Law No. 13,709/2018 (General Personal Data Protection Law – “LGPD”), with the resolutions and guidelines of the National Data Protection Authority (“ANPD”), and with the duty of professional secrecy imposed by the Statute of Advocacy (Law No. 8,906/1994) and the OAB Code of Ethics and Discipline.
This Policy observes, in particular, the information requirements set forth in Art. 9 of the LGPD and integrates the Firm's Privacy Governance Program (Art. 50 of the LGPD).
It applies to all processing of personal data carried out by the Firm, covering clients and potential clients, parties and third parties involved in lawsuits/demands, employees and candidates, suppliers and partners, visitors of our digital channels, and any data subjects whose data is processed within the scope of legal services provision.
2. Definitions
For the purposes of this Policy, the following definitions apply, in line with Art. 5 of the LGPD:
- Personal data — information related to an identified or identifiable natural person.
- Sensitive personal data — data concerning racial or ethnic origin, religious belief, political opinion, trade union membership or membership in a religious, philosophical or political organization, data concerning health or sex life, genetic or biometric data, when linked to a natural person.
- Data subject — natural person to whom the personal data being processed refers.
- Processing — any operation carried out with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction.
- Controller — person who is responsible for decisions regarding the processing of personal data.
- Operator — person who conducts the processing of personal data on behalf of the controller.
- Subprocessor — third party subcontracted by the operator to assist in the processing, on behalf and under the instructions of the controller.
- Data Protection Officer (DPO/Encarregado) — person appointed to act as a communication channel between the controller, the data subjects, and the ANPD.
- ANPD — National Data Protection Authority (Autoridade Nacional de Proteção de Dados).
- International transfer — transfer of personal data to a foreign country or international organization.
- Security incident — adverse event, confirmed or under suspicion, related to a security breach that may result in relevant risk or damage to personal data or their subjects.
3. Processing Roles: Controller and Operator
The Firm acts as a controller regarding the personal data it processes for its own purposes – for example, data of employees, candidates, suppliers, potential clients, and visitors of its channels.
In the performance of advocacy, the Firm frequently acts as an operator, processing personal data on behalf of and under the instructions of its clients (controllers), strictly to enable the provision of the contracted legal services and always under the duty of professional secrecy. In these cases, the Firm's specific obligations observe, in addition to this Policy, the provisions of the respective service agreements and data protection instruments signed with the client.
4. Processed Data, Purposes, and Legal Bases
In compliance with Art. 9 of the LGPD, the Firm informs, in a summarized manner, the main categories of data it processes, the purposes, and the respective legal bases (Arts. 7 and 11 of the LGPD):
| Category of data subjects / data | Main purposes | Legal basis (LGPD) |
|---|---|---|
| Clients and potential clients (identification, contact, professional and financial data) | Provision of legal services and consulting; contract management; communication; billing and collection | Art. 7, V and IX; Art. 7, II (legal/regulatory obligation) |
| Opposing parties, witnesses, and third parties related to cases/demands | Establishment, exercise, or defense of rights in judicial, administrative, and arbitration proceedings | Art. 7, VI; Art. 11, II, “a” (sensitive data) |
| Employees, interns, and candidates | Personnel and payroll management; recruitment and selection; compliance with labor and social security obligations | Art. 7, II and V; Art. 11, II, “a” and “b” |
| Suppliers and partners | Management of contracts and relationship with third parties | Art. 7, V |
| Website visitors and contact channel users | Answering requests; information security; channel improvement | Art. 7, IX (legitimate interest); Art. 7, I (consent), when applicable |
The processing observes the principles of Art. 6 of the LGPD, notably purpose, adequacy, necessity, transparency, security, prevention, non-discrimination, and accountability.
5. Processing of Sensitive Personal Data
Due to the nature of advocacy, the provision of services by the Firm may involve the processing of sensitive personal data – for example, health data, biometric data, union membership, religious belief, political opinion, or racial or ethnic origin – when such data is necessary for the establishment, exercise, or defense of clients' rights.
In these hypotheses, the processing is based on the legal grounds of Art. 11 of the LGPD, in particular the regular exercise of rights in judicial, administrative, or arbitration proceedings (Art. 11, II, “a”), or the specific and highlighted consent of the data subject, when applicable.
The processing of sensitive data observes the principle of necessity (minimization) and is subject to reinforced safeguards: restricted access to professionals strictly involved in the demand (need-to-know), encryption, access controls, and the professional secrecy duty of advocacy.
6. Data Inventory and Record of Processing Activities (ROPA)
The Firm maintains a personal data inventory/mapping and a Record of Processing Activities (ROPA), pursuant to Art. 37 of the LGPD, with the objective of documenting the processing operations it performs, as controller and operator.
The inventory and ROPA record, among other elements: the categories of data and data subjects; the purposes and legal bases; the flows and sharing with operators, subprocessors, and third parties; any international transfers; retention periods; and applicable security measures.
The ROPA is kept updated under the coordination of the DPO, being reviewed periodically and whenever there is a new processing operation or relevant change in existing operations.
7. Sharing of Data with Third Parties, Operators, and Subprocessors
7.1. Whom we share with
For the adequate provision of its services, the Firm may share personal data, to the extent strictly necessary and in accordance with the applicable legal bases, with: corresponding attorneys and partner law firms; experts and technical assistants; bodies of the Judiciary Branch and administrative and arbitration courts; public bodies and entities, when required by law or by order of an authority; technology providers (cloud storage, email, and process and document management systems); and accountants, auditors, and consultants.
7.2. Measures for secure and compliant sharing
Sharing observes measures designed to ensure data protection and compliance with the LGPD, including:
- entering into contracts with specific data protection clauses (Data Processing Agreement - DPA), imposing confidentiality and secrecy obligations;
- limiting the sharing to the purpose and volume of data necessary, with documented instructions and prohibition of use for the third party's own purposes;
- requiring the third party to adopt compatible technical and administrative security measures; and
- obligation to return or securely delete data upon termination of the relationship.
7.3. Evaluation and selection of operators and subprocessors
When subcontracting other companies to assist in the processing of personal data (subprocessors), the Firm adopts a third-party evaluation and governance process, which comprises:
- Prior due diligence: application of an information security and LGPD compliance assessment questionnaire, verifying the supplier's policies, certifications, and history;
- Contractual clauses: formalization of a Data Processing Agreement (DPA) and confidentiality, security, audit, and liability clauses, binding the subprocessor to the same obligations imposed on the operator;
- Authorization and transparency: when the Firm acts as an operator, subcontracting occurs only upon authorization of the client (controller) and under the terms defined by them;
- Awareness and monitoring: guidance and, when applicable, training on data protection obligations, in addition to periodic reassessment of the subprocessor and compliance with contracted obligations.
8. International Transfer of Data
For the performance of its activities, the Firm uses cloud technology services – notably the Microsoft environment (SharePoint and Microsoft 365) – for storage, collaboration, and communication. The use of these services may imply the storage or processing of personal data on servers located outside Brazil, configuring international data transfer.
Such transfers observe Art. 33 of the LGPD and the International Data Transfer Regulation (Resolution CD/ANPD No. 19/2024), relying on appropriate mechanisms and safeguards, in particular:
- standard contractual clauses approved by the ANPD (or equivalent contractual clauses) incorporated into contracts with technology providers;
- adequacy decisions and other guarantees provided for in Art. 33, when applicable; and
- preference for providers that offer recognized security controls and, when feasible, options for data residency in Brazil.
The Firm maintains a record of international transfers in its inventory/ROPA and adopts, with providers, the contractual data protection instruments that incorporate the aforementioned standard clauses.
9. Retention and Deletion of Data
Personal data is maintained only for the time necessary to fulfill the purposes for which they were collected, respecting the applicable legal, regulatory, contractual, and professional periods – for example, statute of limitations, obligations to store procedural, accounting, and tax documents, and OAB rules.
Retention management is performed based on timeframes defined in the inventory/ROPA, reviewed periodically. Once the retention period ends, or when data is no longer necessary, it is securely deleted or anonymized, except for the conservation hypotheses authorized by Art. 16 of the LGPD (such as compliance with legal or regulatory obligations and regular exercise of rights).
Deletion is done by methods that prevent information recovery, covering the secure disposal of digital files (logical and physical deletion) and the destruction of physical documents and media, maintaining an adequate record of deletions, under the DPO's coordination.
10. Rights of Data Subjects and Service Channel
Pursuant to Art. 18 of the LGPD, data subjects may, at any time, request from the Firm:
- confirmation of the existence of processing;
- access to data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
- portability of data to another service provider, observing commercial and professional secrets;
- deletion of personal data processed based on consent, except for legally permitted conservation cases;
- information about entities with which data is shared;
- information about the possibility of not providing consent and the consequences of refusal; and
- revocation of consent.
The Firm provides a free and facilitated channel for the exercise of these rights by contacting the DPO at the email address privacidade@charneski.com.br. Requests are answered within the timeframes and conditions provided for in the LGPD, and the Firm may adopt reasonable measures to verify the applicant's identity for the data subject's own safety. The Firm does not make solely automated decisions that produce legal effects or significantly impact data subjects.
11. Data Protection Officer (DPO)
The Firm maintains a formally appointed Data Protection Officer, pursuant to Art. 41 of the LGPD:
- Data Protection Officer (DPO): Heron Charneski
- Contact Channel: privacidade@charneski.com.br
The DPO acts as a communication channel between the Firm, the data subjects, and the ANPD, being responsible for, among other duties: receiving complaints and communications from data subjects, providing explanations, and taking actions; receiving communications from the ANPD; guiding employees on data protection practices; and coordinating the Privacy Governance Program. This same channel also serves for receiving complaints/reports related to personal data protection.
The formal appointment act of the DPO is set forth in Annex II of this Policy.
12. Security, Technical, and Administrative Measures
In compliance with Art. 46 of the LGPD, the Firm adopts security, technical, and administrative measures to protect personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination, including:
12.1. Technical measures
- profile-based access control and the principle of least privilege (need-to-know);
- multi-factor authentication (MFA) and robust password policy;
- encryption of data in transit and at rest;
- regular backups and recovery mechanisms;
- use of recognized technology providers (Microsoft 365/SharePoint environment), with log records, system updates/patches, and protection against malicious code.
12.2. Administrative measures
- internal information security and data protection policies;
- confidentiality and secrecy agreements signed by employees and third parties, reinforced by the professional secrecy duty of advocacy;
- periodic training, sending of guides and communications, and privacy and security awareness programs;
- access management in the admission and termination processes and device control; and
- control of physical access to installations and adequate storage of documents.
13. Security Incident Management and Response
The Firm maintains a Security Incident Response Plan, which establishes the procedures to be adopted in the face of an incident involving personal data, encompassing stages of detection, containment, eradication, recovery, root cause investigation, risk assessment, recording, and continuous improvement.
The Plan also provides for the following notification obligations:
- Clients and contracting controllers: when the Firm acts as an operator, it communicates the occurrence of an incident to the affected client (controller) in the manner and within the timeframes provided for in the respective services agreement, to enable the actions and communications under the controller's responsibility;
- ANPD and data subjects: when applicable, it communicates the ANPD and the affected data subjects, observing the Security Incident Communication Regulation (Resolution CD/ANPD No. 15/2024), within 3 (three) business days counted from the knowledge of the incident that may result in relevant risk or damage, with the minimum content required by the rule;
- Record: maintains a record of incidents, including those not communicated, for a minimum period of 5 (five) years.
The detailed operational procedures for incident response are set forth in Annex I – Security Incident Response Plan, an integral part of this Policy.
14. Audits and Periodic Review
The Firm conducts periodic audits and evaluations to verify compliance with the obligations provided for in the data protection legislation and to review prevention and personal data protection measures and controls.
These verifications combine: (i) internal audits and assessments, conducted by the Firm's team under the DPO's coordination; and (ii) independent evaluations by specialized third parties, when applicable. The review covers policies, the inventory/ROPA, contracts with operators and subprocessors, and technical and administrative security measures, with the definition of corrective action plans. Audits are performed, at minimum, annually and whenever there is a significant change in processing operations or a relevant incident.
15. Privacy Governance Program
The practices described in this Policy integrate the Firm's Privacy Governance Program (Art. 50 of the LGPD), which brings together policies and procedures, the DPO's actions, the maintenance of the inventory/ROPA, third-party management, incident handling, training and awareness actions, and continuous improvement, demonstrating the Firm's commitment to personal data protection and accountability.
16. Updates to this Policy
This Policy may be updated at any time to reflect improvements in our practices or legal and regulatory changes. The current version will always be available on our official channels, with an indication of the update date. Relevant changes may be communicated through appropriate channels.
17. Legislation applicable and Contact
This Policy is governed by Brazilian legislation, in particular by the LGPD and ANPD rules. Questions, requests, and complaints related to personal data protection may be sent to the DPO at the email address privacidade@charneski.com.br.
Charneski Advogados
Approved by the Firm's management.
Porto Alegre/RS, July 2, 2026.
Annex I – Security Incident Response Plan
This Plan integrates the Personal Data Protection and Privacy Policy of Charneski Advogados and details the procedures to be adopted in the face of security incidents involving personal data, in compliance with Arts. 46 and 48 of the LGPD and Resolution CD/ANPD No. 15/2024.
I.1. Purpose and scope
Establish a clear and timely flow to identify, contain, treat, communicate, and record security incidents involving personal data, reducing risks and damages to data subjects. It applies to all partners, employees, interns, and third parties who process personal data on behalf of the Firm.
I.2. Definition of security incident
A security incident is considered to be any adverse event, confirmed or under suspicion, related to a security breach that may result in unauthorized access, destruction, loss, alteration, leakage, improper communication, or any form of inappropriate or unlawful processing of personal data.
I.3. Response team and responsibilities
Incident response is coordinated by the DPO, with the support of the managing partners and the person responsible for or supplier of information technology, and may involve legal and communication advice when necessary. It is the DPO's responsibility to centralize information, guide measures, deliberate on communications, and maintain records.
I.4. Phases of incident handling
- Detection and internal communication: any person who identifies or suspects an incident must communicate it immediately to the DPO through the channel privacidade@charneski.com.br;
- Evaluation and classification: assessment of the nature and categories of affected data, the number of data subjects, the causes, and the potential risk or damage (item I.5);
- Containment: immediate measures to stop the incident, such as systems isolation, revocation of access, and blocking of compromised accounts;
- Eradication and recovery: elimination of the cause and secure restoration of services, including from backup copies;
- Root cause investigation: verification of the incident's origins and the exploited vulnerabilities;
- Communication: appropriate internal and external notifications, in the form of item I.6;
- Closure and lessons learned: recording of the incident, review of controls, and adoption of improvements.
I.5. Severity classification
| Level | Criterion | Action |
|---|---|---|
| Low | No personal data affected or irrelevant risk to data subjects. | Contain, correct, and record internally. |
| Medium | Personal data affected, with no evident relevant risk or damage. | Contain and evaluate; communicate contracting clients according to the contract; monitor the need for communication to the ANPD. |
| High | Personal data affected with potential relevant risk or damage (includes sensitive data). | Trigger communications to clients, the ANPD, and data subjects within the period of item I.6. |
I.6. Communications and timeframes
- Internal: immediate to the DPO and managing partners;
- Clients and contracting controllers: when the Firm acts as an operator, communication in the manner and within the timeframes provided for in the services agreement, to enable the actions under the controller's responsibility;
- ANPD and data subjects: when the incident may result in relevant risk or damage, within 3 (three) business days counted from the knowledge (6 business days for small-sized agents), observing the minimum content of Resolution CD/ANPD No. 15/2024.
The communication to the ANPD and data subjects must contain, at a minimum: the description of the nature and categories of affected data; the number of data subjects involved; the technical and security measures adopted; the risks related to the incident; the measures adopted to reverse or mitigate the effects; the date of occurrence and knowledge; and the DPO's contact information.
I.7. Recording, storage, and continuous improvement
All incidents, including those not communicated to the ANPD and data subjects, are recorded and maintained for a minimum period of 5 (five) years. After each relevant incident, the Firm conducts a post-incident review, updates controls, and promotes training, testing this Plan periodically.
I.8. Contact
Data Protection Officer (DPO): Heron Charneski — privacidade@charneski.com.br. Channel for internal communication of incidents and for contact by data subjects and the ANPD.
Annex II – Act of Appointment of the Data Protection Officer
Charneski Advogados, a law firm registered with the CNPJ under No. 10.720.318/0001-09, headquartered at Rua Antônio Carlos Berta, 475, suites 1807 and 1808, Jardim Europa, CEP 91340-020, Porto Alegre/RS, by its managing partners, in the use of their attributions and in compliance with Art. 41 of Law No. 13,709/2018 (LGPD) and Resolution CD/ANPD No. 18/2024, resolves:
Art. 1 To appoint Mr. Heron Charneski as the Data Protection Officer (DPO) of the Firm, responsible for acting as a communication channel between the Firm, the data subjects, and the National Data Protection Authority (ANPD).
Art. 2 The DPO is responsible for: (i) receiving complaints and communications from data subjects, providing clarifications, and adopting measures; (ii) receiving communications from the ANPD and adopting measures; (iii) guiding employees and third parties on data protection practices; (iv) coordinating the Privacy Governance Program and the Incident Response Plan; and (v) executing other duties determined by the Firm or provided for in complementary regulations.
Art. 3 The identity and contact information of the DPO (privacidade@charneski.com.br) will be publicly disclosed, in a clear and objective manner, in a prominent and easily accessible location on the Firm's website, pursuant to Resolution CD/ANPD No. 18/2024.
Art. 4 The Firm will ensure the DPO autonomy, absence of conflict of interest, and the resources and accesses necessary for the proper performance of their functions.
Art. 5 This act comes into force on the date of its signing, for an indefinite term, producing effects until eventual revocation or formal replacement.
Porto Alegre/RS, July 2, 2026.
Heron Charneski
Managing Partner — Charneski Advogados
OAB/RS 63,441
Tiago Rios Coster
Managing Partner — Charneski Advogados
OAB/RS 88,953
Aware and in agreement, as Data Protection Officer (DPO): Heron Charneski.
