DATA GOVERNANCE POLICY


The Technology Area is responsible for any and all changes, updates, and dissemination of this plan/policy. 

 

Version 

Author 

Date 

Reviewed by 

Approval Date 

Changes 

01 

Marcelo Silva 

9/01/2025 

 

 

Initial Version 

02 

Marcelo Silva 

9/06/2022 

Tiago C.Sajben 

9/06/2022 

Revised Version 

03 

Filipe Oliveira 

5/09/2025 

Igo Fonseca 

12/01/2025 

Revised Version 


Introduction 

The Data Governance Policy aims to describe the rules for controlling the integrity, security, quality, and use of data throughout its lifecycle. It also defines the roles and responsibilities of all those involved in relation to data access, reading, storage, deletion, and backup of data under Braza's responsibility: 

The purpose of the Data Governance Policy is to: 

  • Define roles and responsibilities in the execution of data governance. 

  • Define best practices for data management and protection. 

  • Protect Braza's data from internal and external threats. 

  • Ensure Braza's compliance with applicable regulations (such as LGPD and GDPR). 

  • Support compliance with our Data Privacy Policy. 

 

 

1. Scope 

This policy applies to all data used by or under the responsibility of Braza. 

This policy applies to all employees and contractors (referred to herein, individually or collectively, as "You," "your," or "employees") of Braza, its owned businesses or subsidiaries (referred to herein, individually or collectively, as "we," "our," or "Braza"). 

 

 

2. Roles and Responsibilities 

 

Chief Data Officer 

The CDO has operational responsibilities for creating, processing, and integrating corporate information and managing all data management and governance functions within the companies. 

This role includes: defining strategic priorities for the company in the area of data, identifying new business opportunities related to data, and optimizing revenue generation through data. Besides, the CDO is primarily responsible for representing and promoting data as a strategic business asset within the company's executive spheres. 

Data Owner 

Responsible for who has access to information assets within their functional areas. Is responsible for the data and its assets, and must ensure that criteria such as compliance, control, access, administration, security, and business value are met. Provides operational support to the Data Steward in the day-to-day management of data. 

Data Steward 

Responsible for the quality and integrity of the data under their management. They will classify and approve access to data under their management, under the delegation of a "Data Owner," considering the role of the requesting user and the intended use. 

Data Custodian 

Responsible for the technical control of data, including security, scalability, configuration management, availability, accuracy, consistency, audit trail, backup and restore, technical standards, policies, and implementation of business rules. 

Data Governance Committee 

Responsible for managing and reviewing the Data Governance Policy. 

 

 

3. Data Classification 

Data classification is a critical component for information security and also for compliance with data protection regulations (such as LGPD and GDPR). All data in Braza must be properly classified so that we can apply the appropriate level of security and confidentiality according to its classification. 

The following are the 4 classifications to be used in Braza: 

 

Public 

Information that can be made available and accessible to any individual without impacting the company in case of leaks or information security problems. Some examples of data that can be considered public: marketing material, publicly available market data (e.g., Central Bank of Brazil). 

Internal 

Information that can only be accessed by company employees, with the possibility of impacting the company in case of leaks or information security problems. Some examples of data that should be classified as internal: communications sent by HR, OKR performance, corporate initiatives. 

Restricted 

Information accessible only to pre-defined individuals based on their need for the information to perform their duties. 

They have an impact in case of leakage, as this data can give competitors an advantage. Some examples of data that should be classified as Restricted: Revenues, Operating Volumes, Profit Margins. 

Confidential 

Personal or sensitive information with a high impact on the company in case of leaks or information security problems. The leakage of confidential data will usually imply a violation of data protection regulations with fines and damage to the Braza brand. 

 

Some examples of data that should be classified as Confidential: personal data of clients, personal data of employees, medical data of employees. 

 


 4. Security 

  • Access to data must be carried out in accordance with our User Cybersecurity Policy. 

  • Appropriate security methodologies must be applied according to the data classifications in order to safeguard the security, reliability, quality and integrity of the data. 

  • Stored data must be protected with appropriate tools, and physical access must be restricted to authorized personnel only. Access to data in Braza's repositories (Databases, Data Lake, etc.) must be stored in a way that allows access control only to authorized individuals. 

  • This policy applies to data in any format (paper, digital, or audiovisual), whether stored in files, physical documents, electronic documents, emails, electronic transactions, data stored in databases, maps, plans, photographs, or sound and video recordings. 

  • Data-related incidents should be handled in accordance with our Cybersecurity Incident Response Plan. 

 

 

 5. Access Control 

  • The "Need to Know" principle should always be applied, meaning that access to data or information should be restricted to those who legitimately need this data or information to perform their function or work. 

  • System Access Control – fundamental to ensuring the security and integrity of systems and must be aligned with our Identity and Access Management Procedure. 

 

 6. Quality and Integrity 

  • Data users must ensure that appropriate procedures have been followed to guarantee the quality and integrity of the data they access. 

  • Data changes must have a log trail, and all accesses must be auditable. 

  • Data should only be collected for legitimate uses and to add value to Braza's business. Extraction, manipulation, and reporting must be done in alignment with and with the intention of providing support to the business. 

  • Where appropriate, any data shared externally to Braza should be verified by the “Data Steward” to ensure that quality, integrity, and security will not be impacted. 

 

7. Life Cycle 


1- Retention 

  • Data will be maintained and deleted as documented in our Data Processing Policy. 


  • 2- Copies 

    • Refrain from creating unnecessary copies/duplicates of information. To ensure compliance with data protection regulations and maintain an adequate level of security, we need to control our "Data Sources". Data duplication hinders this process and increases our risk and exposure. 


    3- Data Privacy Requests 

    • Questions/Clarifications/Guidance 

    • Reporting a Risk or Incident 

    • Data Deletion Requests


    4- Data Deletion 

    • It will be documented and carried out in accordance with our Privacy Policy, Data Processing Policy, and in accordance with current data protection regulations (LGPD, GDPR, etc.) and financial regulations (BACEN, FCA, etc.) 

     

    • The deadlines defined by the regulations (LGPD, GDPR, etc.) for the response will be observed. 

     

    8. Data Sharing 

    • Information sharing must be carried out using the methods authorized by the company for Internal, Restricted or Confidential data: 

    • SharePoint/OneDrive – the preferred method to consider as it allows controlling access to the file only for authorized users. 

    • Teams – used for sharing files with corporate users. 

    • Email – can be used as a last resort, where the other two channels are not possible, with the following recommendation: for external sharing, the file must be shared with a password, and the password must be sent to the recipient via a different channel. 

    • Avoid sending Restricted/Confidential data in the body of emails for internal communications. 

    • Refrain from sending Restricted/Confidential data in the body of emails for communication with external recipients. 

    • Information sharing should be done following the same "Need to know" principle described in item 6 of this policy, restricting sharing only to necessary data. 

    • If you have any questions or need clarification, please contact us dataprivacy@braza.com.br.
      Distribution of Braza's internal, restricted, or confidential data through personal channels is not authorized (WhatsApp, personal email, Instagram, Facebook, LinkedIn are some examples of personal channels that should not be used for corporate data traffic). 

     

     9. Exceptions 

    • Any exception to the policy must be approved by the IT/Corporate Data area in advance. 

     

     10.Non-compliance 

    • An employee who has violated this policy may be subject to disciplinary action, up to and including termination of employment. 

     

    11. Reviews 

    • Reviews of this policy will take place at least annually to ensure that it meets the security requirements of Braza and the market. 

     

    12. Acronyms and Abbreviations 

    • LGPD – General Data Protection Law 

    • GDPR - General Data Protection Regulation – Regulation equivalent to LGPD for European countries 

    • FCA – Financial Conduct Authority – Regulatory institution of the financial market in the United Kingdom 

    • BACEN – Central Bank of Brazil 

     

     

     

     

     

    Author: 

     

    Reviewer: 

    [Digital Signature] 

     

    [Digital Signature] 

    Filipe Ricetti Barbosa de Oliveira  

    CORPORATE DATA 

     

    Igo Miranda da Fonseca  

    IT GOVERNANCE 

     

     

     

    Approver: 

     

    Approver: 

    [Digital Signature] 

     

    [Digital Signature] 

    Eder Nicolau Cardoso 

    HEAD OF IT INFRASTRUCTURE 

     

    Thiago César de Oliveira Rodrigues 

    HEAD OF IT 

     


    BRAZA UK LTD

    Braza UK Ltd is authorised and regulated by the Financial Conduct Authority as an Electronic Money Institution under the Electronic Money Regulations 2011 (FRN 900901). Registered in England and Wales under company number 06397296.



    © 2023

    All rights reserved.


    Contact

    +44 (0) 203 206 1551


    Registered office: Longcroft House, 2-4 Victoria Avenue London, EC2M 4NS United Kingdom. 

    Customer funds are safeguarded in segregated accounts in accordance with the Electronic Money Regulations 2011. Electronic money accounts are not covered by the Financial Services Compensation Scheme (FSCS).