LGPD Implementation in Notary Offices: Rules and Data Protection
LGPD implementation in notary offices harmonizes personal data protection with mandatory public registry disclosure and the perpetuity of public books.
Última atualização:
Por Editorial Team of the 5th Notary Office of Recife — Redação jurídica assistida por IA · 5º Tabelionato de Notas de Recife
Note: This content describes Brazilian notary and registry law.
This article answers
- How does the LGPD implementation in notary offices work?
- What personal data can notary and registry offices collect and process?
- How should notary offices issue certificates while maintaining public disclosure and data protection?
- What information security measures are mandatory for notary and registry offices?
- Can citizens request the deletion of their personal data from public registries?
In summary
- The LGPD implementation in notary offices harmonizes the Lei Geral de Proteção de Dados Pessoais (LGPD — General Data Protection Law, Lei nº 13.709/2018) with the mandatory public disclosure of notary and registry acts.
- Data collection by extrajudicial offices is grounded in compliance with legal obligations and the regular exercise of public functions Lei nº 8.935/1994, art. 1º.
- Access to certificates remains public as a general rule, but providing sensitive or protected data requires a reasoned request or court order.
- Deleting records from official books is prohibited to ensure legal certainty and the perpetuity of public archives.
How does the LGPD implementation in notary offices work?
LGPD implementation in notary offices is the adaptation process of notary offices (tabelionatos) and registries (registros) to the rules of Lei nº 13.709/2018 (Lei Geral de Proteção de Dados — LGPD). The main objective is to protect citizens' fundamental rights of freedom and privacy during the provision of extrajudicial services.
Notary and registry offices perform a delegated public service through their titleholders Lei nº 8.935/1994, art. 1º. For this reason, LGPD implementation in notary offices differs from the private sector. Data processing in notary offices does not depend on prior user consent when the purpose is the drafting of an act performed in the exercise of a legal duty.
The Conselho Nacional de Justiça (CNJ — National Council of Justice) regulated the parameters of this adaptation through consolidated provisions Provimento CNJ nº 149/2023, Livro I. These rules define the responsibilities of delegates regarding storage, access management, and cybersecurity routines for internal systems.
To organize public service without compromising daily work routines, office management uses formal tools. You can understand how these steps are operationalized by reading our article on how to structure SOPs and internal processes in notary offices.
What personal data can notary and registry offices collect and process?
The notary or registry office can collect and process all personal data necessary for qualifying parties and identifying assets. This collection includes full name, marital status, occupation, CPF number (Individual Taxpayer Registration), RG number (Identity Card), and residential address.
The legal basis for this collection is compliance with a legal obligation by the notary (tabelião) or registrar (oficial registrador) Lei nº 8.935/1994, art. 6º. Citizens cannot refuse to provide the information required by law for the execution of a notary or registry act.
LGPD implementation in notary offices requires that collection follow the principle of minimization. Attendants collect only data strictly essential to the act. Requests for additional information without legal or procedural purpose are expressly prohibited.
In the processing of data concerning minors or vulnerable persons, reinforced protection is adopted. In these cases, the office stores only what is strictly necessary to qualify legal representatives or preserve the rights of legally incapacitated individuals.
How should notary offices issue certificates while maintaining public disclosure and data protection?
The issuance of certificates must reconcile the principle of public disclosure with LGPD rules. Any person may request a certificate of a public act without demonstrating a specific interest, provided the act is not under court seal or special restrictive rule.
To meet the requirements of LGPD implementation in notary offices, extrajudicial offices adopt traceability controls. Requesters of full-text certificates (certidões de inteiro teor) or searches in data indexes must identify themselves at the time of the request.
You can consult additional details on certificate types in the text on full-text certificate. Confidential information, such as adoptions or paternity investigations under court seal, is provided only through a specific certificate authorized by judicial decision.
The use of computerized systems allows recording who requested the information, when the request occurred, and what data was made available. This traceability ensures transparency and prevents unauthorized use of personal data by third parties.
What information security measures are mandatory for notary and registry offices?
Information security measures in notary and registry offices encompass physical, administrative, and technological safeguards. These actions prevent data leaks, unauthorized access, and accidental loss of official books and digital archives.
Cybersecurity governance is regulated by the Conselho Nacional de Justiça (CNJ) within the scope of the extrajudicial forum Provimento CNJ nº 149/2023, Livro II. Offices are required to maintain backup routines stored off-site and with data encryption.
Among the main technological requirements of LGPD implementation in notary offices, key elements include:
- Individualized access control through strong passwords and two-factor authentication.
- Continuous monitoring of networks and servers with audit log recording.
- Security incident response plan and immediate communication to competent authorities.
- Anonymization or pseudonymization of data in software testing environments.
When an office detects a security incident that poses relevant risk to data subjects, the person in charge must notify the Corregedoria-Geral de Justiça (Internal Affairs Office of Justice) and the Autoridade Nacional de Proteção de Dados (ANPD — National Data Protection Authority). Rapid identification is an essential element of notary governance.
In addition to database security, offices use instruments such as the notary certificate of fact (ata notarial) to authentically record facts from the world wide web. Learn more in our guide on notary certificates of fact and digital evidence.
Can citizens request the deletion of their personal data from public registries?
Citizens cannot request the deletion of their personal data contained in acts recorded in official books. Public disclosure, legal certainty, and the perpetuity of public archives prevent the erasing of data from public registries.
The Lei Geral de Proteção de Dados Pessoais expressly provides that the right to deletion does not apply to cases where storage is necessary for compliance with a legal or regulatory obligation by the controller. The operation of extrajudicial offices strictly falls under this regulatory exception Lei nº 8.935/1994, art. 1º.
If a subsequent change in data occurs (such as a change in marital status or surname correction), the correct procedure is making a marginal annotation (averbação) alongside the original act. The primary record remains preserved to maintain the history of legal relationships.
The data subject's right is restricted to updating or correcting inaccurate data. Requests for anonymization or blocking are allowed only for secondary data kept for administrative purposes at the service counter, with no connection to official notary and registry books.
Document checklist
To request public service in compliance with LGPD rules, present the following documentation:
- [ ] Official photo ID of the applicant (RG, CNH — Driver's License, or professional ID).
- [ ] Active CPF (Individual Taxpayer Registration) card of the interested party.
- [ ] Updated proof of residence (issued within the last 90 days).
- [ ] Reasoned written request, when the certificate contains personal data subject to restricted access.
- [ ] Power of attorney with specific powers, if the request is made through a legal representative.
- [ ] Term of acknowledgment regarding personal data processing at the service counter (provided by the notary office).
In practice
Case 1: Certificate request involving confidential Civil Registry data
A citizen visited the Civil Registry of Natural Persons (Registro Civil das Pessoas Naturais) to request a full-text birth certificate of a family member. The attendant verified that the original entry contained an annotation regarding an adoption proceeding. Under safety rules resulting from LGPD implementation in notary offices, the full-text certificate could not be issued directly at the counter. The applicant was informed of the need to present an authorization from the competent corregidor judge. The procedure preserved the family's right to privacy and fulfilled court seal requirements.
Case 2: Updating registration data in a deed at the Notary Office
A user identified a typo in her surname in a public deed of purchase and sale executed ten years prior. She requested complete erasure of the old document based on the LGPD right to deletion. The notary explained that notary books cannot have pages deleted due to the legal duty of preservation Lei nº 8.935/1994, art. 1º. To resolve the issue, a notary deed of rectification was executed, annotating the correction without erasing the original history. The act maintained the integrity of the notary archive and guaranteed data correction.
Common mistakes
- Requiring prior consent to perform a notary act: This is a conceptual error. Notary offices process data based on compliance with legal obligations and the exercise of delegated public functions Lei nº 8.935/1994, art. 1º. Requiring a consent form to draft a deed or registration is unnecessary.
- Refusing to issue a certificate under generic justification of LGPD application: The principle of public disclosure of public registries remains fully applicable. The office cannot refuse to provide a standard certificate without specific legal justification.
- Fulfilling requests for definitive deletion of acts from notary books: Acts recorded in official books are perpetual. The head of the office cannot erase information from entries under claims of the right to be forgotten.
- Failing to log the identity of those searching office indexes: Issuing certificates and conducting archive searches must maintain internal auditability logs. The office must keep records identifying who requested the information.
- Collecting unnecessary data at the service counter: Requesting personal data unrelated to the notary act violates the principle of minimization. Extrajudicial offices must restrict collection to data prescribed by applicable regulations.
Legal basis
- Lei nº 8.935/1994, art. 1º — Defines the purpose of notary and registry services as guaranteeing public disclosure, authenticity, security, and effectiveness of legal acts Lei nº 8.935/1994, art. 1º. Planalto
- Lei nº 8.935/1994, art. 6º — Establishes the duties of notaries in exercising their public function Lei nº 8.935/1994, art. 6º. Planalto
- Provimento CNJ nº 149/2023, Book I — Regulates general provisions and management of extrajudicial services nationwide Provimento CNJ nº 149/2023, Livro I. CNJ Portal
- Provimento CNJ nº 149/2023, Book II — Defines management, information security, and governance parameters applicable to notary and registry services Provimento CNJ nº 149/2023, Livro II. CNJ Portal
- Lei nº 13.709/2018 (LGPD), art. 23 — Governs personal data processing by public legal entities and delegates of public services. Regulatory note: Provision not included in original data excerpt, but active and applicable. Planalto
- Lei nº 6.015/1973, art. 16 — Governs the principle of public disclosure of public registries and legal exceptions. Regulatory note: Provision not included in original data excerpt, but active and applicable. Planalto
Frequently asked questions
How does the LGPD implementation in notary offices work?
LGPD implementation in notary offices establishes security and access control standards for personal data. The procedure reconciles compliance with legal duties and the principle of public disclosure of public registries.
What personal data can notary and registry offices collect and process?
Offices collect and process data strictly necessary for drafting public acts and registrations, based on the legal basis of compliance with legal and regulatory obligations.
How should notary offices issue certificates while maintaining public disclosure and data protection?
Issuing certificates follows the principle of public disclosure, but requires identification of the applicant in specific cases. Sensitive and confidential data are protected by court seal or judicial authorization requirements.
What information security measures are mandatory for notary and registry offices?
Offices must adopt tiered access control, encrypted storage, audit log recording, and continuous staff training in data governance.
Can citizens request the deletion of their personal data from public registries?
No. Public registries serve the purpose of perpetuity and legal certainty. Deleting data recorded in official books is prohibited, as the legal duty to preserve acts prevails.
FAQ
How does the LGPD implementation in notary offices work?
LGPD implementation in notary offices establishes security and access control standards for personal data. The procedure reconciles compliance with legal duties and the principle of public disclosure of public registries.
What personal data can notary and registry offices collect and process?
Offices collect and process data strictly necessary for drafting public acts and registrations, based on the legal basis of compliance with legal and regulatory obligations.
How should notary offices issue certificates while maintaining public disclosure and data protection?
Issuing certificates follows the principle of public disclosure, but requires identification of the applicant in specific cases. Sensitive and confidential data are protected by court seal or judicial authorization requirements.
What information security measures are mandatory for notary and registry offices?
Offices must adopt tiered access control, encrypted storage, audit log recording, and continuous staff training in data governance.
Can citizens request the deletion of their personal data from public registries?
No. Public registries serve the purpose of perpetuity and legal certainty. Deleting data recorded in official books is prohibited, as the legal duty to preserve acts prevails.
Does the notary office need citizen consent to execute a notary act?
No. Personal data processing carried out by notary and registry services is performed to comply with legal or regulatory obligations and the regular exercise of public functions (art. 7, II, and art. 23 of the LGPD).
How is incorrect data rectified in the notary office?
If there is inaccurate data in a notary or registry record, the original text is not deleted. A notary rectification deed or marginal annotation is performed, preserving the public history.
What is the role of the CNJ in adapting notary offices to the LGPD?
The Conselho Nacional de Justiça issues unified national guidelines, such as Provimento CNJ nº 149/2023, regulating cyber controls, log retention periods, and information security rules.
What happens in case of a security incident involving data at the notary office?
In the event of a leak or unauthorized access that could pose a risk to data subjects, the delegate must notify the Corregedoria-Geral de Justiça and the ANPD, triggering the damage mitigation plan.
Does data of minors receive special treatment in the notary office?
Yes. The strict minimization rule applies. Only data strictly required by registry rules to qualify legally incapacitated individuals and their representatives is collected and stored.
What is the difference between service counter data and official book data?
Data collected in purely administrative counter routines (such as ticket queue numbers) do not form part of public books and may be deleted. Acts recorded in notary books are perpetual.
Can anyone request a certificate of a third party's notary act?
Yes, the principle of public disclosure guarantees anyone the right to request a certificate. However, formal identification of the applicant and adherence to legal court seal exceptions are required.
Base legal
- provimento_cnj 149 2023 — Provimento CNJ nº 149/2023
- provimento_cnj 149 2023 — Provimento CNJ nº 149/2023
- lei_federal 8.935 1994 — Lei nº 8.935/1994
- lei_federal 6.015 1973 — Lei nº 6.015/1973
- lei_federal 13.709 2018 — Lei nº 13.709/2018 (LGPD)
- lei_federal 8.935 1994 — Lei nº 8.935/1994
Próximos passos
Serviços do Tabelionato · gestão cartorária · Ver todos os conteúdos