Personal Data Processing Agreement — SUIDChain DPA

 

This Personal Data Processing Agreement, referred to as the “DPA, forms part of the Terms of Use, the commercial proposal, the service order, the contract form, and any other documents entered into for the use of the SUIDChain platform.

This DPA is entered into between:

Client: a legal entity, organization, institution, project, or professional identified in the Main Agreement, hereinafter referred to as “Client” or “Data Controller”;

and

Sautlink Tecnologia da Informação e Comércio Eletrônico Imp. e Exp. Ltda., registered with the CNPJ under No. 12.031.849/0001-01, responsible for operating SUIDChain, hereinafter referred to as “SUIDChain” or “Operator.”

The Client and SUIDChain shall be referred to individually as a “Party” and collectively as the “Parties.”

This DPA governs the processing of personal data by SUIDChain on behalf of the Client and must be interpreted in conjunction with the Privacy Policy, the Terms of Use, and the Master Agreement.

1. Legal Basis and Applicable Regulations

This DPA shall be interpreted in accordance with Brazilian law, specifically:

  • Law No. 13,709/2018 — General Personal Data Protection Law — LGPD;
  • Law No. 12,965/2014 — Brazilian Civil Rights Framework for the Internet;
  • Decree No. 8,771/2016;
  • Law No. 8,078/1990 — Consumer Protection Code, where applicable;
  • Law No. 10,406/2002 — Civil Code;
  • CD/ANPD Resolution No. 15/2024 — Regulation on the Reporting of Security Incidents;
  • CD/ANPD Resolution No. 19/2024 — Regulations on International Data Transfers;
  • other rules, regulations, and guidelines issued by the National Data Protection Agency (ANPD).

When a transaction is subject to foreign law, the Parties may enter into a specific amendment, without precluding the application of Brazilian law when it is mandatory.

2. Definitions

For the purposes of this DPA:

2.1 Personal Data

Information relating to an identified or identifiable natural person.

2.2 Sensitive Personal Data

Personal data regarding racial or ethnic origin, religious beliefs, political opinions, union membership, or membership in religious, philosophical, or political organizations; data concerning health or sex life; and genetic or biometric data linked to a natural person.

2.3 Account Holder

A natural person to whom the processed personal data relates.

2.4 Controller

A natural or legal person responsible for decisions regarding the processing of personal data.

2.5 Operator

A natural or legal person who processes personal data on behalf of the Controller and in accordance with the Controller’s lawful and documented instructions.

2.6 Suboperator

A third party contracted by SUIDChain to perform, on its behalf, the processing operations necessary for the provision of services.

2.7 Treatment

Any operation performed on personal data, including collection, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, evaluation, modification, disclosure, transfer, extraction, authorized publication, anonymization, blocking, or deletion.

2.8 Customer Data

Data, files, documents, records, and information entered, submitted, integrated, imported, generated, or stored by the Customer through the services.

2.9 Security Incident

A confirmed incident that compromises the confidentiality, integrity, availability, or authenticity of personal data.

2.10 Main Contract

Proposal, request, contract form, work order, signed contract, license, or any other instrument establishing the business relationship between the Parties.

2.11 Services

Features provided by SUIDChain, including:

  • issuance and management of SUIDs;
  • creation of SUID Passes;
  • generating and scanning QR codes;
  • digital identification of products, lots, and collections;
  • traceability of raw materials, processes, and supply chains;
  • organization of information regarding origin, authorship, production, and territory;
  • management of documents, records, and compliance information;
  • dashboards, reports, and metrics;
  • data intelligence resources;
  • APIs and integrations;
  • logistics resources, freight quotes, and label printing;
  • support, implementation, training, and consulting related to the platform.

3. Purpose

This DPA sets forth the terms and conditions for the processing of personal data by SUIDChain on behalf of the Client during the provision of services.

The treatment will be limited to:

  • the features included in the subscription;
  • in accordance with the Client's lawful and documented instructions;
  • for the purposes described in the Main Agreement and in this DPA;
  • for the period necessary to provide the services;
  • in accordance with applicable legal and regulatory requirements.

SUIDChain will not use the personal data processed on behalf of the Client for its own purposes that are inconsistent with the instructions received.

4. Roles of the Parties

4.1 The Client as the Data Controller

As a general rule, the Customer will be the Data Controller for the personal data that it enters, imports, integrates, or directs to be processed through the platform.

The Customer shall be responsible for:

  • determine the purposes of the processing;
  • determine what data will be collected or entered;
  • establish the applicable legal framework;
  • provide data subjects with the information required by the LGPD;
  • obtain consent when that is the legal basis used;
  • ensure the quality, accuracy, and timeliness of the data;
  • define authorized users;
  • establish retention periods;
  • determine what information may be published on SUID Passes;
  • respond to requests from data subjects;
  • assess the need to report incidents to the ANPD and to data subjects;
  • Do not enter data obtained illegally, through abuse, or by deception;
  • not to perform treatments that are incompatible with the contracted services.

4.2 SUIDChain as an Operator

SUIDChain will act as a Data Processor when processing personal data on behalf of the Client and in accordance with the Client’s instructions.

In these situations, SUIDChain should:

  • comply with the Client's lawful and documented instructions;
  • limit the processing to the purposes specified in the contract;
  • take appropriate safety measures;
  • maintain confidentiality;
  • assist the Client in fulfilling its obligations;
  • notify the Client whenever it believes that an instruction may violate the law;
  • maintain the information necessary to demonstrate compliance with this DPA.

4.3 SUIDChain as an Independent Controller

SUIDChain may act as an independent Data Controller with respect to the data required for:

  • account creation and management;
  • identification of the Client's representatives;
  • billing and collections;
  • contract management;
  • fraud prevention;
  • platform security;
  • customer service and support;
  • compliance with legal obligations;
  • advocacy for rights;
  • sending operational communications;
  • generation of anonymized statistics.

These operations will be governed by the SUIDChain Privacy Policy.

5. Documented instructions

The following will be considered documented instructions:

  • the Master Agreement;
  • this DPA;
  • the settings configured on the platform;
  • the information provided by the Customer;
  • requests submitted through official channels;
  • integration authorizations;
  • the work orders accepted by the Parties.

SUIDChain may suspend or reject instructions that:

  • are manifestly unlawful;
  • violate the rights of third parties;
  • compromise the platform's security;
  • involve excessive or incompatible data;
  • require functionality not included in the contract;
  • result in the improper publication of data;
  • involve high-risk treatment that has not been previously evaluated.

Significant changes in the nature, purpose, scope, or risk of the processing may require a technical assessment and additional contracting.

6. Customer Obligations

The Customer represents and warrants that:

  • has a legal basis for processing the data;
  • the data was collected lawfully;
  • The account holders were duly notified;
  • the information provided to SUIDChain is appropriate and necessary;
  • has authorization to use images, testimonials, stories, and professional information;
  • shall respect the rights of artisans, producers, employees, suppliers, and other rights holders;
  • will not use the platform for discrimination, abusive surveillance, or unlawful treatment;
  • will protect your credentials;
  • will periodically review its users' access;
  • will immediately report any suspected compromise of the account.

The Customer must not register:

  • third-party passwords;
  • full credit card numbers;
  • unnecessary bank information;
  • unnecessary personal documents;
  • complete home addresses on public websites;
  • medical records;
  • biometric data;
  • health information;
  • data on children or adolescents without a legal basis and a specific assessment;
  • sensitive data that is incompatible with the services.

7. SUIDChain's Obligations

SUIDChain is expected to:

  • process data solely for the purpose of providing the services;
  • ensure that authorized individuals are bound by confidentiality;
  • limit access based on professional needs;
  • maintain authentication and authorization controls;
  • protect data from unauthorized access;
  • maintain incident response procedures;
  • assist the Client in serving account holders;
  • contribute to risk assessments and impact reports;
  • report incidents to the Customer;
  • maintain a record of the relevant sub-operators;
  • delete, return, or anonymize the data upon completion of the services, subject to the legal grounds for retention;
  • not to sell personal data processed on behalf of the Client;
  • not to share data for purposes inconsistent with the Master Agreement.

8. Confidentiality

SUIDChain will allow access to personal data only to employees, service providers, and subcontractors who need this information to perform their services.

These individuals must:

  • be subject to confidentiality obligations;
  • use the data only for authorized activities;
  • comply with access controls;
  • preserve credentials;
  • report suspected incidents;
  • comply with internal security policies.

Confidentiality obligations will remain in effect after the termination of the professional or contractual relationship.

9. Information Security

SUIDChain will implement appropriate technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, disclosure, or improper processing.

The measures may include:

  • role-based access control;
  • individual user identification;
  • authentication and credential management;
  • additional authentication for administrative environments;
  • protection of data in transit;
  • logical segregation between accounts;
  • activity logs;
  • backups;
  • availability monitoring;
  • system updates;
  • vulnerability fixes;
  • infrastructure protection;
  • supplier management;
  • business continuity;
  • disaster recovery;
  • incident response procedures;
  • secure development processes.

SUIDChain does not claim to hold any certifications, seals, or audit reports that have not been formally obtained and documented.

The Customer acknowledges that no technological environment is completely immune to risks and must take appropriate measures with respect to its own devices, networks, users, and credentials.

10. Security Incidents

SUIDChain must notify the Client, without undue delay, of any confirmed security incident involving personal data processed on its behalf.

Whenever reasonably possible, the initial notification will be provided within 24 hours of the incident being confirmed.

If not all the information is available, SUIDChain may issue a preliminary report and provide additional details as the investigation progresses.

The report should include, when available:

  • description of the nature of the incident;
  • estimated date or time period of the occurrence;
  • the date on which SUIDChain became aware of the issue;
  • categories of affected data;
  • categories and estimated number of holders;
  • systems or services involved;
  • possible consequences;
  • containment measures;
  • corrective measures;
  • recommendations to the Client;
  • contact channel for follow-up.

The Client, in its capacity as the Data Controller, will be responsible for assessing whether the incident could pose a significant risk or cause significant harm, and for notifying the ANPD and data subjects within the statutory time limits.

SUIDChain will provide the Customer with the information reasonably necessary for these communications.

The Parties shall preserve documents, records, and evidence related to the incident.

This communication shall not constitute an automatic admission of guilt or liability.

11. Data Subjects' Rights

The Client will be primarily responsible for receiving and responding to requests from data subjects regarding the processing carried out under its authority.

Given the nature of the services, SUIDChain will assist the Client in responding to requests for:

  • confirmation that processing is taking place;
  • access;
  • correction;
  • update;
  • anonymization;
  • block;
  • elimination;
  • portability, where applicable;
  • information about shares;
  • opposition;
  • withdrawal of consent;
  • review of automated decisions;
  • information about the criteria used in automated decisions.

If SUIDChain receives a request directly regarding data processed on behalf of the Client, it may forward the request to the Controller, unless there is a legal obligation to act directly.

SUIDChain shall not be responsible on behalf of the Client for decisions that fall exclusively within the Controller’s purview.

12. Impact Report and Regulatory Cooperation

Upon reasonable request, SUIDChain will provide available information to assist the Customer:

  • in the preparation of a Personal Data Protection Impact Assessment;
  • in risk assessment;
  • in compliance with the ANPD;
  • in the description of the safety measures;
  • in identifying sub-operators;
  • in the analysis of international transfers;
  • in responses to headlines;
  • in incident investigation.

The decision regarding the need for the report and responsibility for its final content will rest with the Client as the Data Controller.

Extraordinary activities, extensive audits, or specific development projects may be subject to additional contracts.

13. Sub-operators

The Customer grants SUIDChain general authorization to use subcontractors necessary for the provision of the services.

SUIDChain is expected to:

  • evaluate suppliers based on the risks involved;
  • limit access to the necessary data;
  • enter into contractual agreements that include data protection obligations;
  • require confidentiality and security measures;
  • maintain an up-to-date list of relevant sub-operators.

The list will be available at:

[INSERT THE URL FOR THE SUB-OPERATORS PAGE]

If a sub-operator is added or replaced in a way that could materially affect the processing, SUIDChain will endeavor to notify the Client with reasonable advance notice.

The Customer may raise an objection based on specific risks to data protection.

The Parties will seek a solution that may include:

  • additional clarification;
  • additional security measures;
  • alternative configuration;
  • disabling the affected feature;
  • suspension of the part of the service directly affected.

In the event of a security emergency, unavailability, or legal requirement, a supplier may be replaced without prior notice, with notification provided as soon as possible thereafter.

14. International Data Transfer

The Customer acknowledges that certain providers of infrastructure, storage, communications, support, or integration services may process data outside of Brazil.

SUIDChain will only carry out international transfers based on a mechanism authorized by the LGPD and ANPD regulations.

Transfers may use, as applicable:

  • adequacy decision issued by the ANPD;
  • ANPD's standard contractual clauses;
  • standard clauses recognized as equivalent;
  • specific contractual provisions that have been previously approved;
  • approved global corporate standards;
  • international legal cooperation;
  • protection of life or physical integrity;
  • performance of a contract or related procedures;
  • specific and explicit consent, when legally valid;
  • another option permitted by law.

When Brazilian standard contract clauses are used, their official text shall be incorporated into the applicable instrument without any incompatible modifications.

SUIDChain should provide clear information on:

  • purpose of the transfer;
  • country or region of destination;
  • data categories;
  • duration;
  • agents' responsibilities;
  • rights of data subjects;
  • security measures;
  • customer service channel.

15. SUID Passes and Public Information

The Customer may use the platform to create public pages associated with products, lots, collections, organizations, artisans, or producers.

The Customer shall be responsible for:

  • select the public fields;
  • verify the information;
  • have a legal basis for publication;
  • obtain permissions for images and testimonials;
  • determine what professional information may be disclosed;
  • keep the content accurate and up-to-date;
  • respond to requests for corrections or retractions.

The following should not be published in SUID Passes:

  • CPF;
  • ID card or passport;
  • full home address;
  • banking information;
  • home phone;
  • personal email address;
  • passwords;
  • health data;
  • sensitive data without a legal basis;
  • information about children or adolescents;
  • confidential documents;
  • trade secrets;
  • information that could put the data subject at risk.

SUIDChain may suspend or remove content that:

  • violate the law;
  • improperly expose a person;
  • infringes on the rights of third parties;
  • was published without authorization;
  • compromises safety;
  • violates the Terms of Use.

16. Blockchain and Integrity Records

When using blockchain or distributed ledger technologies, the following should be prioritized:

  • hashes;
  • technical identifiers;
  • transaction references;
  • timestamps;
  • evidence of existence;
  • integrity tests;
  • pseudonymized records.

Personal data should not be entered directly, in plain text, onto a public or immutable blockchain without a specific technical and legal assessment.

When a technical test is recorded in an immutable environment:

  • The original data should, whenever possible, be stored in a separate database;
  • The content displayed may be corrected or removed;
  • A technical transaction that has already been recorded may not be deleted;
  • The evidence should not, on its own, reveal the original content;
  • Measures such as de-identification, anonymization, or restriction may be adopted.

The Customer should avoid entering personal information in fields intended for permanent records.

17. Sensitive personal data

As a general rule, the processing of sensitive data is not included in the standard scope of services.

The Customer must not enter sensitive data without:

  • demonstrated need;
  • specific legal basis;
  • risk assessment;
  • contractual authorization;
  • definition of access controls;
  • additional security measures;
  • specified retention period.

SUIDChain may require a technical evaluation or refuse to process the request if the risk is incompatible with the platform.

18. Children and Adolescents

The Customer must not enter data regarding children or adolescents without:

  • legitimate purpose;
  • appropriate legal basis;
  • best interests assessment;
  • appropriate information for those in charge;
  • enhanced security measures;
  • compliance with the LGPD, the Statute of Children and Adolescents, and Brazilian laws applicable to the digital environment.

Data on children or adolescents should not be published in SUID Passes without a specific review and appropriate authorization.

SUIDChain may block or remove information posted in violation of this clause.

19. Retention, Return, and Disposal

During the term of the contract, the data will be retained for as long as necessary to provide the services.

After the termination, the Customer may request, within the time limit set forth in the Main Contract:

  • data export;
  • file return;
  • elimination;
  • anonymization;
  • Temporary maintenance for migration.

Once the transition period has ended, SUIDChain may delete or anonymize the data, except when retention is necessary to:

  • compliance with a legal obligation;
  • regular exercise of rights;
  • fraud prevention;
  • incident investigation;
  • maintenance of financial records;
  • representation in administrative, judicial, or arbitration proceedings.

Residual copies may remain temporarily in protected backups until they are replaced through normal retention cycles.

During this period, they should not be used for any other purposes.

Anonymized data and aggregated statistics may be retained when they do not allow for the identification of data subjects by reasonable means.

20. Access logs

When applicable to SUIDChain as a provider of Internet applications, access logs must be kept confidential in a controlled and secure environment for the period required by the Brazilian Civil Rights Framework for the Internet.

Such records will be provided only in cases authorized by law or pursuant to a valid court order.

21. Audit

Upon reasonable request, SUIDChain will provide the information necessary to demonstrate compliance with this DPA.

The demonstration may take place through:

  • internal policies;
  • questionnaires;
  • description of controls;
  • supplier documents;
  • available reports;
  • technical meetings;
  • certificates actually obtained;
  • evidence related to the contracted service.

Audits must:

  • must be requested at least 30 days in advance;
  • take place during business hours;
  • have a proportionate scope;
  • protect trade secrets;
  • not to compromise safety;
  • not allow access to other customers' data;
  • be conducted by an independent professional who is bound by confidentiality.

Unless there is a relevant incident, a determination by the ANPD, or concrete evidence of noncompliance, the Client may request an audit covering a 12-month period.

The costs will be borne by the Client, except when the audit identifies a material nonconformity directly attributable to SUIDChain.

22. Requests from Authorities

If SUIDChain receives a request from a public authority regarding Customer data, it shall, where legally permitted:

  • verify the validity of the request;
  • notify the Client;
  • limit the supply to what is strictly necessary;
  • record the request;
  • protect information covered by trade secrets;
  • to contest manifestly excessive claims, where legally appropriate.

If disclosure to the Customer is prohibited, SUIDChain must comply with the legal obligation and record the restriction.

23. Liability

Each Party shall be responsible for complying with the obligations imposed on it by law, this DPA, and the Master Agreement.

The Customer shall be liable for damages resulting from:

  • lack of a legal basis;
  • irregular collection;
  • illegally registered data;
  • unlawful instructions;
  • improper publication;
  • lack of image authorization;
  • compromised credentials under your responsibility;
  • misuse by its users;
  • failure to comply with the recommended safety measures.

SUIDChain will respond within the limits set forth by the LGPD when:

  • failure to comply with one's own legal obligation;
  • to perform treatment in violation of lawful instructions;
  • acting outside the scope of the contract;
  • fail to implement the security measures set forth in this DPA;
  • cause damage directly related to conduct attributable to it.

The Operator’s joint and several liability shall apply in the circumstances provided for by the LGPD, particularly when the Operator fails to comply with the law or fails to follow the Controller’s lawful instructions.

The limitations set forth in the Main Contract shall apply only to the extent they are not prohibited by law.

24. Term

This DPA takes effect upon acceptance or signature of the Master Agreement and will remain in effect as long as SUIDChain processes personal data on behalf of the Client.

The obligations regarding confidentiality, security, cooperation, disposal, and liability will remain in effect for as long as necessary following the termination.

25. Prevalence of documents

In the event of a conflict:

  1. Mandatory provisions of the law or the ANPD shall prevail;
  2. Standard international data transfer clauses shall apply to the transaction in question;
  3. This DPA shall take precedence over the Main Agreement with respect to the processing of personal data;
  4. The Master Agreement shall govern commercial matters not related to data protection.

26. Changes

SUIDChain may update this DPA to reflect:

  • legal changes;
  • new ANPD regulations;
  • changes to services;
  • new sub-operators;
  • safety improvements;
  • infrastructure changes.

Significant changes will be communicated to the Customer via email, a notice on the platform, or another contractual channel.

Changes that materially reduce data protection will not be applied retroactively without an appropriate legal basis.

27. Governing Law and Jurisdiction

This DPA will be governed by Brazilian law.

The jurisdiction specified in the Main Contract shall apply.

In the absence of a contractual provision to the contrary, the courts of the District of São Paulo, State of São Paulo, shall have jurisdiction, subject to mandatory rules of jurisdiction and consumer rights, where applicable.

28. Communications

Communications related to this DPA should be made through the following channels:

SUIDChain — Privacy and Data Protection

Operator: Sautlink Tecnologia da Informação e Comércio Eletrônico Imp. e Exp. Ltda.
CNPJ: 12.031.849/0001-01
Email: [CONFIRM: privacidade@suidchain.com]
Contact Person: [INSERT NAME OR COMPANY NAME]
Address: [INSERT FULL BUSINESS ADDRESS]

Notices to the Customer will be sent to the email address provided in the registration or in the Master Agreement.


APPENDIX I — Treatment Details

1. Purpose

Provision of services related to digital identification, traceability, generation of SUIDs, SUID Passes, QR codes, storage, integrations, reporting, and data analytics.

2. Duration

During the term of the Main Contract and for the additional period necessary to:

  • migration;
  • export;
  • compliance with legal obligations;
  • execution of backup cycles;
  • the regular exercise of rights.

3. Nature of the transactions

Operations may include:

  • collection;
  • reception;
  • record;
  • organization;
  • storage;
  • appointment;
  • use;
  • update;
  • integration;
  • transmission;
  • analysis;
  • authorized publication;
  • export;
  • anonymization;
  • block;
  • elimination.

4. Purposes

  • provide the contracted services;
  • manage users;
  • record traceability information;
  • identify products, lots, and collections;
  • generate SUIDs and QR codes;
  • make SUID Passes available;
  • organize evidence;
  • generate reports and metrics;
  • perform authorized integrations;
  • provide support;
  • ensure safety;
  • follow documented instructions.

5. Categories of account holders

Depending on the Customer's use:

  • platform users;
  • representatives of the Client;
  • employees;
  • artisans;
  • producers;
  • suppliers;
  • cooperative members;
  • members of associations;
  • project participants;
  • employees of organizations;
  • brand or product managers;
  • logistics operators;
  • consumers, when their data is entered into the system;
  • people mentioned in documents or evidence.

6. Data Categories

  • name;
  • email;
  • work phone;
  • position;
  • function;
  • organization;
  • user ID;
  • authorized image;
  • professional profile;
  • area of operation;
  • city, state, or country;
  • participation in products, batches, or projects;
  • production techniques;
  • professional information;
  • IP address;
  • browser;
  • device;
  • usage events;
  • support messages;
  • files sent;
  • data related to authorized integrations.

7. Sensitive Data

They are not included in the standard scope.

Your treatment will depend on an evaluation and specific authorization.

8. Frequency

The processing may continue throughout the use of the services.


ANNEX II — Technical and Administrative Measures

SUIDChain will adopt the following measures, depending on the nature and risk of the operation:

Governance

  • security and privacy policies;
  • definition of responsibilities;
  • training and awareness;
  • access management;
  • risk assessment;
  • supplier management;
  • incident response.

Access Control

  • individual identification;
  • needs-based access;
  • permission review;
  • privileges restriction;
  • removal of unnecessary access points;
  • credential protection.

Data Protection

  • protection during transmission;
  • logical segregation;
  • minimization;
  • pseudonymization, where applicable;
  • backups;
  • restoration mechanisms;
  • safe disposal.

Infrastructure

  • monitoring;
  • event logs;
  • system updates;
  • vulnerability management;
  • network security;
  • service continuity;
  • disaster recovery.

Development

  • change control;
  • room dividers;
  • pre-publication testing;
  • protection of technical credentials;
  • vulnerability remediation.

Incidents

  • internal communication channel;
  • screening;
  • containment;
  • research;
  • record;
  • impact assessment;
  • notification to the Customer;
  • corrective measures;
  • documentation of the actions taken.

ANNEX III — List of Sub-Operators

This list should be completed based on the suppliers actually used.

Suboperator Service Data involved Location
[WEB HOSTING PROVIDER] Hosting and Infrastructure Account data, traceability, and technical records [COUNTRY/REGION]
[DATABASE PROVIDER] Storage Data Processed on the Platform [COUNTRY/REGION]
[EMAIL PROVIDER] Operational Communications Name, email, and messages [COUNTRY/REGION]
[PAYMENT PROVIDER] Payments and Subscriptions Registration and Billing Information [COUNTRY/REGION]
[ANALYTICS SERVICE] Usage Analysis IP, device, and events [COUNTRY/REGION]
[SUPPORT SERVICE] Customer Service Registration and Requests [COUNTRY/REGION]
[BLOCKCHAIN PROVIDER] Integrity Tests Hashes and Technical Identifiers [COUNTRY/NETWORK]
[LOGISTICS INTEGRATION] Shipping and labels Information Required for Shipping [COUNTRY/REGION]

ANNEX IV — International Transfers

In the case of an international transfer:

  • the exporter must be identified;
  • the importer must be identified;
  • the categories of data must be described;
  • The affected account holders must be notified;
  • the countries of destination must be indicated;
  • the legal mechanism to be used must be defined;
  • the safety measures must be described;
  • The rights of data subjects must be guaranteed.

When the ANPD’s standard contract clauses are used, the current official text must be incorporated into the contract in its entirety and without any incompatible modifications.


SUIDChain — Sustainable Unique Identifier

Digital identity, traceability, and intelligence to transform origin, production, and impact into verifiable evidence.