1. OBJECTIVE
This Policy aims to establish Machado Meyer's guidelines for the processing of personal data within the scope of its activities, thus reiterating its commitment to respecting privacy and protecting personal data in office custody.
2. DATE OF EFFECTIVENESS
This Policy becomes effective as of its disclosure, being updated annually, in accordance with the responsibility matrix provided in the item 17 of this document.
3. TO WHOM IT APPLIES
This Policy applies to the data subjects of personal data processed by Machado Meyer:
- People who were or are Staff Members and their Dependents, Candidates, and Partners of Machado Meyer;
- All individuals linked to clients who have maintained or maintain a legal relationship with Machado Meyer;
- All individuals linked to suppliers who have maintained or maintain a commercial relationship with Machado Meyer;
- Visitors and registrants on our website, registered for Machado Meyer events, and to Third Parties visiting our Offices.
4. GENERAL GUIDELINES
4.1. The Policy is published and disclosed internally on our intranet and externally on the website www.machadomeyer.com.br and available for reading, according to the following wording.
4.2. We explain in the Policy, clearly and transparently, for the data subjects, what is done with the personal data processed by Machado Meyer.
4.3. The following topics clarify for what purposes the data subject's personal data are used, for how long, how you can access it, update it and obtain additional information.
5. WHAT PERSONAL DATA DO WE COLLECT / STORE / PROCESS?
The details of the personal data that can be collected, stored and processed by Machado Meyer are as follows:
5.1. People who were or are Staff Members and their Dependents, Candidates, and Partners of Machado Meyer
- Registration data: name, initials, corporate e-mail, RG, CPF, marital status, date of birth, personal and/or professional telephone, personal and/or professional address, profession, education, professional registration, signature, contact person, identification of the Staff Member and relative, position held, agency where he/she works, and period of employment, degree of kinship between PEP and Staff Member, employment record booklet, PIS, voter ID, reserve member certificate, education, gender, registration, description of activities performed at the client (timesheet), termination date, hiring date, and changes in position, OAB, cost center, academic certificates, class dates (corporate education), Dependents (name, date of birth, birth certificates, marriage, or stable union), overtime, age of spouse and children, passport, projects carried out, name of manager, performance evaluation (Initials, percentage of use, percentage of achievement, percentage of funding and remuneration history), CNH, publications (books, articles, newspapers, magazines), photo, CCTV image, videos;
- Financial data: salary, consigned loan, FGTS statement, Partners' credit card;
- Sensitive data: digital biometrics, blood type, occupational health certificates (ASO's upon hiring, periodic, return to work, and upon dismissal), disability certificate, medical certificate, physical disability, racial origin, labor union membership; and
- Behavioral data: work experience, competency assessment, accesses and actions performed in digital systems and environments.
5.2. All individuals linked to clients who have maintained or maintain a legal relationship with Machado Meyer
- Registration data: name, RG, CPF, CNH, PIS, CTPS, passport, voter ID, education, personal and/or professional e-mail, personal and/or professional address, home address, landline, mobile phone, language, position, company, profession, gender, date of birth, nationality, marital status, signature, photos, videos;
- Financial data: salary, as applicable in the context of the services provided to you; and
- Sensitive data: union membership, physical disability, medical certificates, medical reports, occupational health certificates - ASO, occupational accident reports - CAT, and other data that may be provided under the contractual relationship established between the Client and Machado Meyer, in the context of the provision of legal services.
5.3. All individuals linked to suppliers who have maintained or maintain a commercial relationship with Machado Meyer
- Registration data: Name, RG, CPF, CNH, PIS, INSS registration number, e-mail, business address, home address, landline, mobile phone, department, position, company, profession, date of birth, nationality, marital status, professional registration (e.g. OAB, CRC), signature, photos, videos, CCTV image;
- Financial data: bank details, salary; and
- Sensitive data: racial origin, biometrics.
5.4. Visitors and registrants on our website, registered for Machado Meyer events, and to Third Parties visiting our Offices
- Registration data: name, RG, CPF, nationality, position, e-mail, phone, mobile number, company, area of interest, date of birth, gender, contact person, CCTV image; and
- Behavioral data: pages from the Website accessed, origin of access - e.g. google search, according to Annex 1 - Cookies.
5.5. Machado Meyer requires specific consent from a parent or legal guardian to perform treatments involving personal data of children or adolescents.
5.6. Machado Meyer only processes sensitive personal data supported by legal basis, such as the explicit consent of the data subject or to comply with a legal obligation.
5.7. Machado Meyer processes common personal data based on legal grounds, such as the execution of a contract in which the data subject is involved; compliance with a legal or regulatory obligation; the legitimate interest of the controller or third parties, within the development of contracted activities; consent of the data subject.
6. WHO IS RESPONSIBLE FOR THE DATA COLLECTED?
6.1. Machado Meyer, when in the condition of controlling agent, will make decisions regarding the personal data processed within the scope of the relationship established with you.
6.2. Machado Meyer, when in the condition of operating agent, will process the personal data received from the contracting party to fulfill the obligations established by it in the contract and use personal data strictly necessary and adequate to achieve the proposed purpose.
7. FOR WHAT PURPOSES IS PERSONAL DATA PROCESSED?
There are several purposes for which personal data are processed by Machado Meyer, detailed below:
7.1. People who were or are Staff Members and their Dependents, Candidates, and Partners of Machado Meyer
- Hiring people: recruitment, selection, hiring, dismissal, granting of benefits for employees and their dependants, people management, professional development, corporate education, internal communications, and contractual obligations;
- Identification of PEP - Politically Exposed Persons, including spouses/partners, stepchildren, relatives in a direct line up to second degree, for accreditation of the firm to provide services to clients, and compliance with specific legislation;
- Publication of relevant cases in legal directories that offer legal research and analysis and highlight the best law firms and professionals;
- Management of costs and expenses;
- Coordination of projects and work demands;
- Security and physical access control for Staff Members and third parties to the firm's premises;
- Registration of Partners for the use of banking services;
- Maintaining custody of documents to support legal, tax, and business requirements;
- Records of the activities performed for the calculation of fees;
- Strengthening of brand value through external communication and sponsored events;
- Compliance with a legal or regulatory requirement (e-Social, DIRF, and D-SUP - Municipalities); and
- Information security and business continuity plan;
- Sending communication to former employees (Alumni);
- Preparation of proposals, powers of attorney, contracts, sub-establishments.
7.2. All individuals linked to clients who have maintained or maintain a legal relationship with Machado Meyer
- Rendering of the services hired by the Client to defend its interests in judicial and extrajudicial proceedings;
- Use of specialized services to manage the proceedings;
- Maintaining custody of documents to support legal, tax, and business requirements;
- Records of the activities performed for the collection of fees;
- Registration of Clients and their respective contacts for use in the correct and timely issuance of invoices;
- Client Prospecting through research of contacts via internet and social networks;
- Security and physical access control to the office premises;
- Promote brand value and engage with new contacts and potential clients through sponsored events;
- Publication of relevant cases in legal directories that offer legal research and analysis, preserving Client confidentiality as appropriate; and
- Comply with a legal or regulatory requirement.
7.3. All individuals linked to suppliers who have maintained or maintain a commercial relationship with Machado Meyer
- Hiring professionals for specialized services in judicial and extrajudicial proceedings and outsourced services (reception, cleaning, maintenance);
- Supplier management: assessment, homologation, registration, contract drafting and payments;
- Maintaining custody of documents to support legal, tax, and business requirements;
- Security and physical access control to the office premises;
- Information security and business continuity plan;
- Control of internal and external mail (Dispatch);
- Internal and external publicization (social networks) of training/events sponsored internally by Machado Meyer; and
- Compliance with a legal or regulatory requirement.
7.4. Visitors and registrants on our website, registered for Machado Meyer events, and to Third Parties visiting our Offices
- Prospect clients through research of contacts via internet and social networks;
- Maintain the Security and physical access control to the office premises;
- Promote brand value and engage with new contacts and potential clients through sponsored events;
- Establish a contact channel with the client through the Institutional Website;
- Enable online registration for events promoted by Machado Meyer;
- Offer legal services of interest to Users; and
- Carry out relationship campaigns with potential clients.
9. IS PERSONAL DATA TRANSFERRED?
Machado Meyer may carry out the international transfer of personal data, pursuant to Articles 33 through 36 of Law No. 13.709/2018 (General Personal Data Protection Law – LGPD), to firm offices, clients, and suppliers located abroad—including in the context of contracting cloud computing services where servers are situated outside the national territory (currently in the United States of America).
Such transfers take place exclusively to countries or international bodies that provide a level of personal data protection adequate to that set forth in the LGPD, or through the adoption of appropriate safeguards—such as specific contractual clauses, standard contractual clauses, global corporate rules, or other legally permitted mechanisms—ensuring compliance with the principles, data subject rights, and personal data protection regime established by applicable legislation.
Suppliers involved in international personal data transfer operations are assessed in advance regarding their compliance with technical and organizational requirements for Information Security and Privacy, with the aim of ensuring the confidentiality, integrity, and availability of the personal data processed, as well as preventing unauthorized access, security incidents, and uses incompatible with the stated purposes.
Additional information regarding personal data retention periods, adopted security measures, and data subject rights is detailed in the subsequent sections of this document, in accordance with Articles 18 and 33 of the LGPD, without prejudice to further clarifications available via request channel, as per item 14 of this document.
10. FOR HOW LONG IS PERSONAL DATA KEPT?
The Personal Data collected and processed by Machado Meyer shall be stored until the purpose of the Processing is exhausted or when there is no longer a legitimate purpose or a legal and regulatory reason that allows Machado Meyer to retain it.
11. HOW WILL WE KEEP THE DATA WE PROCESS IN OUR CUSTODY SECURE?
11.1. We adopt safety standards set forth in applicable laws and regulations, such as:
- Training, governance, internal security policies;
- Control of storage on internal or outside servers;
- Software to encrypt data collected;
- Protection against unauthorized access;
- Authorized access only to specific persons to the place where your personal information is stored, provided that such access is essential for the performance of the intended activity;
- Confidentiality of the professionals who access the information/data;
- Application of administrative, disciplinary, and legal sanctions Against Staff Members and persons who unduly use your information, in violation of this Privacy and Information Security Policy;
- Absolute commitment to the principles laid down by the applicable laws and regulations, as well as the storage and deletion of data, the latter when requested;
- Access by Data Subjects to all of their information stored.
11.2. While our best efforts are put into preserving your privacy and protecting your personal Data, it is important for you to know that no transmission of information is ever completely secure. For this reason, Machado Meyer cannot fully guarantee that all the information it receives and/or sends will not be subject to unauthorized access and performed through methods designed to obtain information improperly, such as viruses or database intrusions.
11.3. In the event of a breach of Personal Data in our custody, we guarantee we will make every effort to remedy the consequences of the event.
12. WHAT ARE MY RIGHTS AND HOW CAN I EXERCISE THEM?
12.1. In order to ensure your privacy and the protection of your data, Machado Meyer will facilitate the exercise of the rights described in article 18 of Law 13,709/2018, General Personal Data Protection Law, as applicable, which are:
- Confirm the existence of Processing;
- Access the data;
- Correct incomplete, inaccurate, or outdated data;
- Request anonymization, blocking, or elimination of unnecessary or excessive data or data processed in violation of the provisions of the General Personal Data Protection Law;
- Request portability of data to another provider of a service or product, upon express request, in accordance with the regulations of the national authority, subject to commercial and industrial secrets;
- Request erasure of personal data processed with the consent of the Data Subject, except in the cases provided for in article 16 of the General Personal Data Protection Law;
- Obtain information on public and private entities with which the Controller has shared the use of data;
- Information about the possibility of not providing consent and about the consequences of refusal; and
- Revocation of consent, pursuant to Article 8, Paragraph 5, of the General Personal Data Protection Law.
12.2. To meet the above requests, we will undertake all reasonable efforts within the shortest time possible, but you should be aware that the following may occur:
Possible delay in service due to justifiable factors, such as the complexity of the request.
Rejection of your request for formal (e.g., if you are unable to prove your identity) or legal reasons (e.g., request for deletion of data that may be kept by force of law or regulation; request for copy of a document that will only be provided if there is explicit consent; request for portability due to lack of specific regulation for the activity performed by Machado Meyer).
According to the LGPD, the deadline for responding to requests is up to 15 days, with this deadline starting from the date Machado Meyer receives the request.
12.3. For any case of impossibility of meeting your request, Machado Meyer will provide due reasons.
13. HOW CAN I ACCESS MY PERSONAL DATA?
You may contact Machado Meyer's Data Protection Officer (DPO) Daniel Guariento by e-mail
14. HOW CAN I GET MORE INFORMATION?
In the policy, all the relevant and necessary information regarding the Processing of your personal Data may be found and, therefore, we strongly recommend reading it in full. Should any questions remain after reading this policy in its entirety, you may contact our Data Protection Officer (DPO) Daniel Guariento at the following e-mail address
15. VIOLATION
Failure to comply with any of the Policy guidelines subjects the violator to investigation and, where appropriate, the imposition of disciplinary and legal sanctions by the Ethics Committee. Use of the "TEMM Voz" channel is encouraged for reporting and investigating deviations from Policy compliance, as a means of helping to maintain compliance.
16. DEFINITIONS
| Term | Definition |
|---|---|
| Contributors | All partners, lawyers, interns, assistants, and administrative staff at Machado Meyer. |
| Website user | Individual who accesses and registers on Machado Meyer's website. |
| Third Party | Individual who visits the Website and the premises of Machado Meyer, or a person who signs up for events available on the Website. |
| Personal data | Any information related to a directly or indirectly identified or identifiable individual. |
| Sensitive personal data | Special category of personal data concerning racial or ethnic origin, religious belief, political opinion, membership in a trade union or a religious, philosophical, or political organization, concerning health or sex life, genetic or biometric data concerning individuals. |
| Data subject | Individual to whom the personal Data refers, such as, for example, the persons to whom this policy applies: people who were or are Staff Members and their Dependents, Candidates, and Partners of Machado Meyer; all individuals linked to clients who have maintained or maintain a legal relationship with Machado Meyer; all individuals linked to suppliers who have maintained or maintain a commercial relationship with Machado Meyer and visitors and registrants on our website, registered for Machado Meyer events, and to Third Parties visiting our Offices. |
| Data Protection Officer (DPO) | Person appointed by the Controller and Operator to act as a communication channel between the Controller, the data Holders, and the National Data Protection Agency (ANPD). |
| Website | Designates the electronic address www.machadomeyer.com.br and its subdomains. |
| Processing | Any operation performed with personal Data, such as those relating to the: collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, discarding, assessment, or control of the information, modification, dissemination, transfer, diffusion, or extraction. |
| Controller | An individual or legal entity, governed by public or private law, who is responsible for decisions concerning the processing of personal data. |
| Operator | Individual or legal entity, whether governed by public or private law, who carries out the Processing of personal Data on behalf of the Controller. |
17. REFERENCES
- Code of Conduct
- Information Security Policy
- Physical Security Policy
- Document Management Policy
- Data Protection Standard
- ISO 27.001
- Procedure for the enforcement of Data Holders' Rights
- Federal Law No. 13,709/2018 (General Personal Data Protection Law)
- Federal Law No. 12,965/2014 (Brazilian Civil Rights Framework for the Internet)
- Federal Law No. 8,078/1990 (Consumer Protection Code) and other applicable laws for the activity provided by Machado Meyer.
18. RESPONSIBILITY MATRIX
| Responsible | Responsibilities |
|---|---|
| Executive Board | Approve the policy by a simple majority. |
| Information Security and Privacy Committee (CSI&P) | Approve the policy and its revisions by a simple majority. |
| Ethics Committee | Investigate reports of policy-related misconduct and apply appropriate sanctions. |
| Information Security | Adopt and ensure the security standards required by applicable laws and regulations throughout the processing of personal Data. |
| Responsible Person for personal data processing (Data Protection Officer - DPO) | Ensure Data subject's rights; Ensure the Processing of data in accordance with the principles and legal bases set out in applicable laws and regulations and in accordance with this Policy; Update the Policy; Monitor compliance. |
| Contributors | Understand and comply with the Policy guidelines. |
19. VERSION CONTROL
First Version:
| Created by | Position/Department | Date |
|---|---|---|
| Working Group - LGPD Project | General Officer / DPO as a service / Information Technology / Legal Administrative / Partner responsible for the Technology area | December 21, 2020 |
Second Version:
| Updated by | Position/Department | Date |
|---|---|---|
| Privacy | Privacy Specialist / DPO | August 29, 2022 |
Third Version:
| Updated by | Position/Department | Date |
|---|---|---|
| Privacy | Privacy Specialist / DPO | July 12, 2023 |
Fourth Version:
| Updated by | Position/Department | Date |
|---|---|---|
| Privacy | Privacy Specialist / DPO | August 15, 2024 |
Fifth Version:
| Updated by | Position/Department | Date |
|---|---|---|
| Privacy | Privacy Specialist | August 07, 2025 |
Sixth Version:
| Updated by | Position/Department | Date |
|---|---|---|
| Privacy | Privacy Specialist | April 24, 2026 |
| Internal Compliance | Internal Compliance | April 29, 2026 |
| Privacy | Privacy Specialist | July 01, 2026 |
Revision History:
| Version | Date | Revised by | History |
|---|---|---|---|
| V1 | December 21, 2020 | Legal Administrative | Text and layout adjustments. |
| V2 | August 29, 2022 | Privacy | Grouping of privacy policies, adjustments to the structure and wording of the document and addition of an attachment on Cookies. |
| V3 | July 12, 2023 | Privacy | Adjustments to the document's wording and inclusion in the structure. |
| V4 | July 24, 2024 | Privacy / Internal Compliance | Adjustments to the document's wording and inclusion in the structure. Standardization. |
| V5 | August 07, 2025 | Privacy / Internal Compliance | Inclusion of items reviewed by SEK. |
| V6 | April 24, 2026 | Privacy | Update to the content of item 9. |
| V6 | April 29, 2026 | Internal Compliance | Standardization. |
| V6 | July 01, 2026 | Privacy | General review of the document – no changes. |
Approval History:
| Approved by | Effective date | Date of next revision |
|---|---|---|
| Executive Board | February 9, 2021 | February 9, 2022 |
| SI&P Committee | August 31, 2022 | August 31, 2023 |
| SI&P Committee | August 28, 2023 | August 28, 2024 |
| SI&P Committee | September 09, 2025 | September 02, 2026 |
| SI&P Committee | July 01, 2026 | July 01, 2027 |
