Information Security Policy
We at Lefosse Advogados (“Lefosse” or “we”) recognize that information is an essential asset for the development of our activities and for maintaining the trust of our clients, partners, professionals, and other related parties.
Accordingly, we have established this Information Security Policy (“Policy”) to explain, in a simple, transparent, and clear manner, how we protect the information under our responsibility, in compliance with applicable legislation and best security practices.
This document is also available in PDF format. Click here to access it.
1. Definitions
Information
Any data, document, or content, regardless of the means of storage or transmission.
Information asset
Resources used to store, process, or transmit information, including systems, equipment, and documents.
Lefosse
Means Lefosse Advogados.
Users
Individuals who access or use Lefosse’s information, including partners, lawyers, professionals, third parties, and business partners.
Security incident
An event that compromises or may compromise the confidentiality, integrity, or availability of information.
Policy
Means this Information Security Policy, intended to ensure the protection of information used at Lefosse.
2. Purpose
This Policy aims to establish the guidelines adopted by Lefosse to protect its information, ensuring:
- Prevention of unauthorized access, loss, or improper alteration.
- Continuity of the law firm’s operations.
- Compliance with applicable legislation, including the Brazilian General Data Protection Law (Law No. 13,709/2018).
- Preservation of institutional trust and reputation.
3. Scope
This Policy applies to all users who have access to Lefosse’s information, including:
- Partners, lawyers, and professionals;
- Service providers and third parties;
- Business Partners and suppliers;
It applies to all environments and means of information processing, both physical and digital.
4. Information security principles
Confidentiality
Ensuring that information is accessible only to authorized individuals.
Integrity
Ensuring the accuracy and completeness of information and protecting it against improper alterations.
Availability
Ensuring access to information whenever necessary by authorized users.
These principles structure the management of information security risks and guide the controls adopted by Lefosse.
5. How we protect Information
- Access control based on need-to-know;
- Authentication mechanisms and system protection;
- Classification and proper handling of information;
- Protection of data at rest and in transit;
- System monitoring and identification of suspicious activities;
- Backup procedures and business continuity plans;
- Continuous risk assessment.
6. Responsibilities
Information Security is everyone’s responsibility.
(i) Lefosse
- Establish security controls and policies;
- Promote training and awareness;
- Continuously monitor and review its practices.
(ii) Users
- Use information securely and responsibly;
- Comply with this Policy;
- Report incidents or suspected breaches.
7. Incident management
Lefosse adopts procedures for the identification, assessment, and response to information security incidents.
When applicable, relevant incidents may be reported to competent authorities and affected parties, in accordance with the law.
8. Information sharing
Information is shared only when necessary for the development of Lefosse’s activities and subject to appropriate security measures.
When applicable, contractual obligations are established to ensure information protection.
9. Legal compliance
Lefosse complies with applicable legislation on information security and personal data protection, including the Brazilian General Data Protection Law.
Security measures are adopted to protect information against unauthorized access and accidental or unlawful events, as required by law.
10. Questions
In case of questions or requests related to this Policy, please use the contact channels available on the Lefosse website.
11. Updates to this Policy
This Policy may be updated periodically by Lefosse. The updated version will be made available on the firm’s website.