To demonstrate Machado Meyer's commitment to the security and privacy of data/information collected from its Staff Members and Dependents, Candidates, and Partners.
2. DATE OF EFFECTIVENESS
The Policy is effective as of February 9, 2021, for an indefinite period of time, and may be revised and updated whenever necessary, according to the responsibility matrix provided in item 8 of this document.
3. TO WHOM IT APPLIES
The Policy applies to all persons who were or are Staff Members and their Dependents, Candidates, and Partners of Machado Meyer.
4. GENERAL GUIDELINES
4.1 The Policy will be published and disclosed by Machado Meyer internally on its intranet and externally on its website www.machadomeyer and will be available for reading, according to the following wording, directed to the specific public - "STAFF MEMBERS, CANDIDATES, AND THIRD PARTIES".
4.2 We explain in the Policy, clearly and transparently, for people who were or are Staff Members and their Dependants, Candidates, and Partners, what is done with the personal Data we process.
4.3 The topics below clarify for what purposes your personal data is used, for how long, how you can access it, update it, and obtain additional information.
5. SPECIFIC GUIDELINES
5.1 We process Data of persons who were or are Staff Members and their Dependents, Candidates, and Partners in the following categories:
- Registration data (name, initials, corporate e-mail, RG, CPF, marital status, date of birth, telephone, address, profession, education, professional registration, signature, contact person, identification of the Staff Member and relative, position held, agency where he/she works, and period of employment, degree of kinship between PEP and Staff Member, employment record booklet, PIS, voter ID, reserve member certificate, education, gender, registration, description of activities performed at the client (timesheet), termination date, hiring date, and changes in position, OAB, cost center, academic certificates, Dependents (name, date of birth, birth certificates, marriage, or stable union), overtime, age of spouse and children, passport, projects carried out, name of manager, CNH, publications (books, articles, newspapers, magazines), photo, CCTV image, videos;
- Financial data (salary, consigned loan, FGTS statement, Partners' credit card);
- Sensitive data (biometrics only in units of São Paulo and the Federal District, blood type, occupational health certificates (ASO's upon hiring, periodic, return to work, and upon dismissal), disability certificate, medical certificate, physical disability, racial origin, labor union membership); and
- Behavioral data (work experience, competency assessment).
5.2 Machado Meyer, as the controlling agent, will make decisions regarding the personal data processed within the scope of the relationship established with you.
5.3 We process personal Data for the following purposes:
- Hiring people: recruitment, selection, hiring, dismissal, granting of benefits for employees and their dependants, people management, professional development, corporate education, internal communications, and contractual obligations;
- Identification of PEP - Politically Exposed Persons, including spouses/partners, stepchildren, relatives in a direct line up to second degree, for accreditation of the firm to provide services to clients, and compliance with specific legislation;
- Publication of relevant cases in legal directories that offer legal research and analysis and highlight the best law firms and professionals;
- Management of costs and expenses;
- Coordination of projects and work demands;
- Security and physical access control for Staff Members and third parties to the firm’s premises;
- Registration of Partners for the use of banking services;
- Maintaining custody of documents to support legal, tax, and business requirements;
- Records of the activities performed for the calculation of fees;
- Strengthening of brand value through external communication and sponsored events;
- Compliance with a legal or regulatory requirement (e-Social, DIRF, and D-SUP - Municipalities); and
- Information security and business continuity plan.
5.4 Machado Meyer may share your personal Data with:
- Companies that provide benefits to partners, employees, and their dependents, such as health insurance, life insurance, private pension plan, transportation vouchers, meal vouchers, and fitness centers;
- Clients for the accreditation process carried out when hiring services;
- Independent research and legal analysis companies for publication of relevant Machado Meyer cases in legal directories;
- Financial institutions for the use of banking services;
- Educational institutions and suppliers for professional development and corporate education;
- Partner firms abroad for the selection process;
- Competent public authorities (judicial and extrajudicial), government entities, regulatory or tax agencies for which Machado Meyer is subject to comply with a legal or regulatory obligation or under applicable local law.
- Operating Agents who handle your personal Data in accordance with Machado Meyer's instructions:
- Technology service providers
- Brand promotion companies, agencies organizing events promoted by Machado Meyer
- Providers of specialized services for internal and external communications, such as translation of Curriculum Vitae, photography, and filming;
- Document safekeeping services companies; and
- Providers related to physical security whenever you access our office premises.
5.5 Machado Meyer uses cloud systems, for this reason it is possible that Personal Data may be transferred outside Brazil (currently, to Chile and the USA), since they are the backup countries for the data storage of our service provider. To ensure that your Personal Data is processed solely for the stated purposes, we will adopt safeguards and guarantees such as specific clauses, standard clauses, and global corporate standards.
5.6 The Personal Data collected and processed by Machado Meyer shall be stored until the purpose of the Processing is exhausted or when there is no longer a legitimate purpose or a legal and regulatory reason that allows Machado Meyer to retain it.
5.7 We adopt safety standards set forth in applicable laws and regulations, such as:
- Training, governance, internal security policies;
- Control of storage on internal or outside servers
- Software to encrypt data collected;
- Protection against unauthorized access;
- Authorized access only to specific persons to the place where your personal information is stored, provided that such access is essential for the performance of the intended activity;
- Confidentiality of the professionals who access the information/data;
- Application of administrative, disciplinary, and legal sanctions against Staff Members and persons who unduly use your information, in violation of this Privacy and Information Security Policy;
- Absolute commitment to the principles laid down by the applicable laws and regulations, as well as the storage and deletion of data, the latter when requested;
- Access by Data Subjects to all of their information stored.
5.8 While our best efforts are put into preserving your privacy and protecting your personal Data, it is important for you to know that no transmission of information is ever completely secure. For this reason, Machado Meyer cannot fully guarantee that all the information it receives and/or sends will not be subject to unauthorized access and performed through methods designed to obtain information improperly, such as viruses or database intrusions.
5.9 In the event of a breach of Personal Data in our custody, we guarantee we will make every effort to remedy the consequences of the event.
5.10 In order to ensure your privacy and the protection of your data, Machado Meyer will facilitate the exercise of the rights described in article 18 of Law 13,709/2018, General Personal Data Protection Law, as applicable, which are:
- confirm the existence of Processing;
- access the data;
- correct incomplete, inaccurate, or outdated data;
- request anonymization, blocking, or elimination of unnecessary or excessive data or data processed in violation of the provisions of the General Personal Data Protection Law;
- request portability of data to another provider of a service or product, upon express request, in accordance with the regulations of the national authority, subject to commercial and industrial secrets;
- request erasure of personal data processed with the consent of the Data Subject, except in the cases provided for in article 16 of the General Personal Data Protection Law;
- obtain information on public and private entities with which the Controller has shared the use of data;
- obtain information about the possibility of not providing consent and the consequences of refusal; and
- request revocation of consent, pursuant to paragraph 5 of article 8 of the General Data Protection Law.
5.11 To meet the above requests, we will undertake all reasonable efforts within the shortest time possible, but you should be aware that the following may occur:
- Possible delay in service due to justifiable factors, such as the complexity of the request.
- Rejection of your request for formal (e.g., if you are unable to prove your identity) or legal reasons (e.g., request for deletion of data that may be kept by force of law or regulation; request for copy of a document that will only be provided if there is explicit consent; request for portability due to lack of specific regulation for the activity performed by Machado Meyer).
5.12 For any case of impossibility of meeting your request, Machado Meyer will provide due reasons.
5.15 In the Policy, all the relevant and necessary information regarding the Processing of your Personal Data may be found and, therefore, we strongly recommend reading this entire document.
6. TERMS AND DEFINITIONS
|Staff Member||A staff member is an individual who is hired as an employee/worker at Machado Meyer.|
|Candidate||An individual who participates in the selection process for a specific vacancy/position, who, if approved, becomes a Staff Member.|
|Partner||Individual who holds a stake in the Machado Meyer partnership.|
|Dependent||One who is subject to something or someone.|
|Personal data||Any information relating to a directly or indirectly identified or identifiable individual.|
|Sensitive personal data||Special category of personal data concerning racial or ethnic origin, religious belief, political opinion, membership in a trade union or a religious, philosophical, or political organization, concerning health or sex life, genetic or biometric data concerning individuals.|
|Individual to whom the personal Data refers, such as, for example, the persons to whom this Policy applies: persons who were or are Staff Members and their dependents, Candidates, and Partners of Machado Meyer.|
|Data Protection Officer||Person appointed by the Controller and Operator to act as a communication channel between the Controller, the data Holders, and the National Data Protection Authority (ANPD).|
|Website||Designates the electronic address www.machadomeyer.com.br and its subdomains.|
|Processing||Any operation performed with personal Data, such as those relating to the: collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, discarding, assessment, or control of the information, modification, dissemination, transfer, diffusion, or extraction.|
|Controller||An individual or legal entity, governed by public or private law, who is responsible for decisions concerning the processing of personal data.|
|Operator||Individual or legal entity, whether governed by public or private law, who carries out the Processing of personal Data on behalf of the Controller.|
- Machado Meyer Code of Conduct
- Information Security Policy
- Physical Security Policy
- Document Management Policy
- Data Protection Standard
- Legal Procedure of Data Holders
- ISO 27701
- Federal Law No. 13,709/2018 (General Personal Data Protection Law)
- Federal Law No. 12,965/2014 (Brazilian Civil Rights Framework for the Internet)
- Federal Law No. 8,078/1990 (Consumer Protection Code) and other applicable laws for the activity provided by Machado Meyer
8. RESPONSIBILITY MATRIX
|Executive Board|| |
|Information Security and Privacy Committee|| |
|Information Security|| |
|Responsible Person for personal data Processing (Data Protection Officer - DPO)|| |