
DATA GOVERNANCE POLICY
Version | Author | Date | Reviewed by | Approval Date | Changes |
01 | Marcelo Silva | 9/01/2025 |
|
| Initial Version |
02 | Marcelo Silva | 9/06/2022 | Tiago C.Sajben | 9/06/2022 | Revised Version |
03 | Filipe Oliveira | 5/09/2025 | Igo Fonseca | 12/01/2025 | Revised Version |
Introduction
The Data Governance Policy aims to describe the rules for controlling the integrity, security, quality, and use of data throughout its lifecycle. It also defines the roles and responsibilities of all those involved in relation to data access, reading, storage, deletion, and backup of data under Braza's responsibility:
The purpose of the Data Governance Policy is to:
Define roles and responsibilities in the execution of data governance.
Define best practices for data management and protection.
Protect Braza's data from internal and external threats.
Ensure Braza's compliance with applicable regulations (such as LGPD and GDPR).
Support compliance with our Data Privacy Policy.
1. Scope
This policy applies to all data used by or under the responsibility of Braza.
This policy applies to all employees and contractors (referred to herein, individually or collectively, as "You," "your," or "employees") of Braza, its owned businesses or subsidiaries (referred to herein, individually or collectively, as "we," "our," or "Braza").
2. Roles and Responsibilities
Chief Data Officer | The CDO has operational responsibilities for creating, processing, and integrating corporate information and managing all data management and governance functions within the companies. This role includes: defining strategic priorities for the company in the area of data, identifying new business opportunities related to data, and optimizing revenue generation through data. Besides, the CDO is primarily responsible for representing and promoting data as a strategic business asset within the company's executive spheres. |
Data Owner | Responsible for who has access to information assets within their functional areas. Is responsible for the data and its assets, and must ensure that criteria such as compliance, control, access, administration, security, and business value are met. Provides operational support to the Data Steward in the day-to-day management of data. |
Data Steward | Responsible for the quality and integrity of the data under their management. They will classify and approve access to data under their management, under the delegation of a "Data Owner," considering the role of the requesting user and the intended use. |
Data Custodian | Responsible for the technical control of data, including security, scalability, configuration management, availability, accuracy, consistency, audit trail, backup and restore, technical standards, policies, and implementation of business rules. |
Data Governance Committee | Responsible for managing and reviewing the Data Governance Policy. |
3. Data Classification
Data classification is a critical component for information security and also for compliance with data protection regulations (such as LGPD and GDPR). All data in Braza must be properly classified so that we can apply the appropriate level of security and confidentiality according to its classification.
The following are the 4 classifications to be used in Braza:
Public | Information that can be made available and accessible to any individual without impacting the company in case of leaks or information security problems. Some examples of data that can be considered public: marketing material, publicly available market data (e.g., Central Bank of Brazil). |
Internal | Information that can only be accessed by company employees, with the possibility of impacting the company in case of leaks or information security problems. Some examples of data that should be classified as internal: communications sent by HR, OKR performance, corporate initiatives. |
Restricted | Information accessible only to pre-defined individuals based on their need for the information to perform their duties. They have an impact in case of leakage, as this data can give competitors an advantage. Some examples of data that should be classified as Restricted: Revenues, Operating Volumes, Profit Margins. |
Confidential | Personal or sensitive information with a high impact on the company in case of leaks or information security problems. The leakage of confidential data will usually imply a violation of data protection regulations with fines and damage to the Braza brand. |
| Some examples of data that should be classified as Confidential: personal data of clients, personal data of employees, medical data of employees. |
4. Security
Access to data must be carried out in accordance with our User Cybersecurity Policy.
Appropriate security methodologies must be applied according to the data classifications in order to safeguard the security, reliability, quality and integrity of the data.
Stored data must be protected with appropriate tools, and physical access must be restricted to authorized personnel only. Access to data in Braza's repositories (Databases, Data Lake, etc.) must be stored in a way that allows access control only to authorized individuals.
This policy applies to data in any format (paper, digital, or audiovisual), whether stored in files, physical documents, electronic documents, emails, electronic transactions, data stored in databases, maps, plans, photographs, or sound and video recordings.
Data-related incidents should be handled in accordance with our Cybersecurity Incident Response Plan.
5. Access Control
The "Need to Know" principle should always be applied, meaning that access to data or information should be restricted to those who legitimately need this data or information to perform their function or work.
System Access Control – fundamental to ensuring the security and integrity of systems and must be aligned with our Identity and Access Management Procedure.
6. Quality and Integrity
Data users must ensure that appropriate procedures have been followed to guarantee the quality and integrity of the data they access.
Data changes must have a log trail, and all accesses must be auditable.
Data should only be collected for legitimate uses and to add value to Braza's business. Extraction, manipulation, and reporting must be done in alignment with and with the intention of providing support to the business.
Where appropriate, any data shared externally to Braza should be verified by the “Data Steward” to ensure that quality, integrity, and security will not be impacted.
7. Life Cycle
1- Retention
Data will be maintained and deleted as documented in our Data Processing Policy.
2- Copies
Refrain from creating unnecessary copies/duplicates of information. To ensure compliance with data protection regulations and maintain an adequate level of security, we need to control our "Data Sources". Data duplication hinders this process and increases our risk and exposure.
3- Data Privacy Requests
Any data-related requests can be sent to dataprivacy@braza.com.br. Some examples of requests are:
Questions/Clarifications/Guidance
Reporting a Risk or Incident
Data Deletion Requests
4- Data Deletion
It will be documented and carried out in accordance with our Privacy Policy, Data Processing Policy, and in accordance with current data protection regulations (LGPD, GDPR, etc.) and financial regulations (BACEN, FCA, etc.)
The deadlines defined by the regulations (LGPD, GDPR, etc.) for the response will be observed.
8. Data Sharing
Information sharing must be carried out using the methods authorized by the company for Internal, Restricted or Confidential data:
SharePoint/OneDrive – the preferred method to consider as it allows controlling access to the file only for authorized users.
Teams – used for sharing files with corporate users.
Email – can be used as a last resort, where the other two channels are not possible, with the following recommendation: for external sharing, the file must be shared with a password, and the password must be sent to the recipient via a different channel.
Avoid sending Restricted/Confidential data in the body of emails for internal communications.
Refrain from sending Restricted/Confidential data in the body of emails for communication with external recipients.
Information sharing should be done following the same "Need to know" principle described in item 6 of this policy, restricting sharing only to necessary data.
If you have any questions or need clarification, please contact us dataprivacy@braza.com.br.
Distribution of Braza's internal, restricted, or confidential data through personal channels is not authorized (WhatsApp, personal email, Instagram, Facebook, LinkedIn are some examples of personal channels that should not be used for corporate data traffic).
9. Exceptions
Any exception to the policy must be approved by the IT/Corporate Data area in advance.
10.Non-compliance
An employee who has violated this policy may be subject to disciplinary action, up to and including termination of employment.
11. Reviews
Reviews of this policy will take place at least annually to ensure that it meets the security requirements of Braza and the market.
12. Acronyms and Abbreviations
LGPD – General Data Protection Law
GDPR - General Data Protection Regulation – Regulation equivalent to LGPD for European countries
FCA – Financial Conduct Authority – Regulatory institution of the financial market in the United Kingdom
BACEN – Central Bank of Brazil
Author: |
| Reviewer: |
[Digital Signature] |
| [Digital Signature] |
Filipe Ricetti Barbosa de Oliveira CORPORATE DATA |
| Igo Miranda da Fonseca IT GOVERNANCE |
Approver: |
| Approver: |
[Digital Signature] |
| [Digital Signature] |
Eder Nicolau Cardoso HEAD OF IT INFRASTRUCTURE |
| Thiago César de Oliveira Rodrigues HEAD OF IT |

+44 (0) 203 206 1551