the Federal Trade Commission (FTC)—which was created in 1914 and is entrusted
inter alia with the protection of consumers—that has become the primary privacy
enforcement agency in that country.
40 Although it is an independent law enforcement agency, the FCT’s jurisdiction is limited to challenging privacy violations
through information practices that are deemed to be deceptive or unfair.
In Brazil, a specific data protection agency is also hitherto non-existent. Some of
the tasks typically entrusted to such agencies in other countries are incumbent upon
the so-called “Internet Steering Committee” (Comité Gestor da Internet), which was
created in 1995 with the purpose of coordinating and integrating all Internet service
initiatives in Brazil. Law no. 13.709, of 13 August 2018, on the protection of
personal data, provided for the setting up of a National Personal Data Protection
Authority (Autoridade Nacional de Proteção de Dados) and a National Council for
Personal Data and Privacy Protection (Conselho Nacional de Proteção de Dados
Pessoais e da Privacidade). However, the President of the Republic vetoed that
Law’s provisions on these institutions. Subsequently, Provisional Measure
no. 869/2018 created these entities, but their setting up is still impending.
41
2.4 The Self-Regulation Instruments
Similar conclusions may be reached in respect of the relevance of self-regulation
instruments on data protection in the different jurisdictions covered by this report,
which has been encouraged inter alia by the OECD Guidelines governing the
protection of privacy and transborder flows of personal data, “whether in the
form of codes of conduct or otherwise”.
42
Such instruments are particularly relevant, given the lack of public regulation of
the sector, in the United States of America, where the Network Advertising Initiative
(NAI), comprised exclusively of digital advertising companies, has adopted a Code
of Conduct, last updated in 2017,
43 requiring transparency, an opt-in choice before
sensitive information may be used for behavioral advertising and reasonable security
provisions. The breach of the Code’s provisions may be publicized by the NAI and
reported to the FCT. Another organization, the Digital Advertising Alliance (DAA),
also seeks to establish and enforce privacy practices for digital advertising through a
set of Principles of Transparency and Control to Data Used Across Devices that
apply to Multi-Site Data and Cross-App Data gathered in either desktop or mobile
environments.
44 These instruments have, however, so far only obtained limited
results in preserving consumer privacy.
45
40 See the United States of America’s National Report, Sect. 1.4.
41 See the Brazilian National Report, Sect. 2.5.
42 See section 19d), of the Guidelines as amended in 2013.
43 Available at https://www.networkadvertising.org/sites/default/files/NAI_Code15encr.pdf.
44 Available at http://digitaladvertisingalliance.org/principles.
45 See the United States of America’s National Report, Sect. 1.5.
10
D. Moura Vicente and S. de Vasconcelos Casimiro
Précédent

- 19/540

Suivant