Flexible Work and Electronic Monitoring Policy
Technical-operational instrument aligned with Brazil's LGPD (Law 13,709/2018)
- Public document
- Effective: June 2026 · Next review: June 2027
- Approved by: Board of Directors + DPO
Courtesy translation. The official version of this document is the Portuguese original, published on gricco.com.br; in case of divergence, the Portuguese text prevails. Read the original (Portuguese)
TITLE I — FUNDAMENTALS
Chapter I — Subject Matter
Art. 1. This Policy establishes the technical, legal and operational guidelines for the adoption of Flexible Work (full or hybrid remote work) at GRICCO and governs the processing of personal data arising from the electronic monitoring of work activities, in strict compliance with Law 13,709/2018 (LGPD), Law 14,442/2022 (CLT arts. 75-A to 75-F), the Brazilian Internet Civil Framework (Marco Civil da Internet, Law 12,965/2014), art. 5, X, of the Federal Constitution and the settled case law of the Superior Labor Court (TST) on monitoring.
Chapter II — Scope
Art. 2. This Policy applies to all GRICCO employees hired under the CLT, interns and young apprentices who perform their activities, in whole or in part, under a Flexible Work arrangement, in any of the following modalities:
- I) Full remote work (home office), pursuant to art. 75-B of the CLT;
- II) Hybrid arrangement (partly on-site and partly remote);
- III) Temporary work from another location, at the initiative of the employer or of the employee, duly authorized.
Sole paragraph. It also applies, where relevant, to on-site employees with respect to the processing of personal data arising from the use of corporate systems, tools and equipment.
Chapter III — Legal and Regulatory Foundations
Art. 3. This Policy observes, without prejudice to other applicable rules:
- I) Federal Constitution, art. 5, X, XII and LXXIX, and art. 7, XXII (risk reduction);
- II) General Data Protection Law (Law 13,709/2018), in particular arts. 6 (principles), 7 (legal bases), 11 (sensitive data), 18 (data subject rights), 37 to 40 (governance), 41 (DPO), 46 to 49 (security and incidents);
- III) CLT, in particular arts. 74 (working-hours control), 75-A to 75-F (remote work), and art. 482 (employee duties);
- IV) Law 12,965/2014 (Brazilian Internet Civil Framework);
- V) Resolutions and Guides of the ANPD, in particular: the Information Security Guide for Small Processing Agents, the Guide on the Processing of Personal Data by SMEs and Resolution CD/ANPD No. 2/2022;
- VI) Case law of the TST on corporate monitoring (in particular RR-613/2000-013-10-00.7) and of the STF (Federal Supreme Court) on privacy in the workplace;
- VII) ISO/IEC 27001:2022 (ISMS), ISO/IEC 27701:2019 (Privacy Information Management), ISO 37301:2021 (Compliance);
- VIII) Code of Ethics GRICCO-GOV-001, Internal Regulations for Employees GRICCO-GOV-003 and Integrated Policies GRICCO-POL-001.
Chapter IV — Definitions
Art. 4. For the purposes of this Policy, the following definitions are adopted, in addition to those of art. 5 of the LGPD:
- I) "Personal Data" — any information relating to an identified or identifiable natural person;
- II) "Sensitive Personal Data" — racial or ethnic origin, religious belief, political opinion, trade union membership, data concerning health or sex life, genetic or biometric data (LGPD art. 5, II);
- III) "Data Subject" — the natural person to whom the personal data relate; in the context of this Policy, in particular the employee;
- IV) "Processing" — any operation carried out with personal data (collection, use, access, storage, deletion, etc.);
- V) "Legal Basis" — the hypothesis authorizing the processing, pursuant to arts. 7 and 11 of the LGPD;
- VI) "Controller" — GRICCO, responsible for decisions regarding the processing;
- VII) "Processor" — a monitoring software or service provider that carries out processing on behalf of GRICCO, bound by a contract containing LGPD clauses;
- VIII) "Data Protection Officer (DPO)" — the person appointed by GRICCO as the communication channel with data subjects and the ANPD;
- IX) "RIPD" — Data Protection Impact Report (LGPD art. 38);
- X) "Monitoring Software" — a technological tool used to verify compliance with working hours, productivity, information security and conformity with internal rules, comprising screen-capture, activity-logging, application-monitoring, DLP and access-log functionalities.
TITLE II — PRINCIPLES OF THE POLICY
Art. 5. The processing of personal data within the scope of this Policy fully observes the ten (10) principles of art. 6 of the LGPD:
- I) PURPOSE — processing for legitimate, specific and explicit purposes communicated to the data subject, with subsequent incompatible processing prohibited;
- II) ADEQUACY — compatibility of the processing with the purposes communicated;
- III) NECESSITY — limitation to the minimum necessary to achieve the purposes, covering only data that are relevant, proportionate and not excessive (data-minimization principle);
- IV) FREE ACCESS — guarantee to the data subject of easy and free-of-charge consultation on the form, duration and entirety of the data;
- V) DATA QUALITY — accuracy, clarity, relevance and currency;
- VI) TRANSPARENCY — clear, accurate and easily accessible information on the processing carried out;
- VII) SECURITY — technical and administrative measures to protect against unauthorized access and accidental or unlawful destruction, loss, alteration, communication or dissemination;
- VIII) PREVENTION — measures to prevent the occurrence of harm;
- IX) NON-DISCRIMINATION — prohibition of processing for discriminatory, unlawful or abusive purposes;
- X) ACCOUNTABILITY — demonstration of the adoption of effective measures capable of evidencing observance of and compliance with data protection rules.
Art. 6. In addition, this Policy adopts the following principles of its own:
- I) PROPORTIONALITY — the degree and granularity of monitoring must be strictly proportionate to the actual risk of the role and to the Company's legitimate interests;
- II) DIGNITY AND PRIVACY — preservation of the employee's dignity and private life, with monitoring that intrudes upon the personal or intimate sphere prohibited (Federal Constitution art. 5, X);
- III) QUALIFIED TRANSPARENCY — prior, clear and express communication of everything that is monitored, before processing begins;
- IV) PRIVACY BY DESIGN AND BY DEFAULT — default configuration of minimization and privacy in the tools adopted;
- V) REVERSIBILITY — possibility of deactivating, adjusting or discontinuing processing upon a substantiated request from the data subject or a recommendation from the DPO.
TITLE III — MODALITIES, ELIGIBILITY AND EQUIPMENT
Chapter I — Modalities
Art. 7. The recognized modalities of Flexible Work are:
- I) FULL REMOTE (HOME OFFICE) — activities performed entirely outside the Company's premises;
- II) SCHEDULED HYBRID — defined minimum on-site attendance (e.g. 2 or 3 days/week), with a predictable calendar;
- III) ON-DEMAND HYBRID — predominantly remote, with on-site presence at the manager's request for meetings, training or events;
- IV) TEMPORARY — one-off, justified adoption, at the initiative of the employer (business continuity, emergency) or of the employee (health reasons, significant family reasons).
Chapter II — Initiative
Art. 8. The modality may result from:
- I) A DECISION BY GRICCO — implementation by management act, with minimum prior notice of fifteen (15) days (CLT art. 75-C, § 2), except in a documented health or operational emergency;
- II) A REQUEST BY THE EMPLOYEE — formal request to leadership and HR, subject to discretionary approval by the Executive Board, observing the objective criteria of art. 9.
Chapter III — Eligibility
Art. 9. The objective criteria for assessing eligibility for Flexible Work are:
- I) A role compatible with remote performance, according to the eligibility matrix maintained by HR;
- II) Performance rated as satisfactory over the last six (6) months (except by substantiated exceptional decision);
- III) Completion of the probationary period (45+45 days);
- IV) Approval in the ergonomic and environmental safety checklist (Annex II);
- V) The employee's availability to attend on-site meetings when necessary;
- VI) Adhesion to the Flexible Work Agreement with Specific Consent for Data Processing (Annex I).
Chapter IV — Equipment Provided by GRICCO
Art. 10. GRICCO shall provide the employee in Flexible Work, upon signature of a Receipt, Custody and Return Form (Annex III of GRICCO-GOV-003), with:
- I) A corporate notebook, with operating system, antivirus, VPN, productivity tools and monitoring software pre-installed;
- II) Basic peripherals (mouse, keyboard, headset with microphone);
- III) An authentication token or MFA (multi-factor authentication) for access to systems;
- IV) Logical access to the systems, e-mail and collaboration platforms required for the performance of the role.
§ 1. The employee is PROHIBITED from using personal equipment for GRICCO activities, in line with art. 42 of GRICCO-GOV-003, except under exceptional, documented authorization that may be revoked at any time.
§ 2. The installation or modification of software on corporate equipment may only be carried out by the authorized IT team.
§ 3. All content stored on corporate equipment is considered work material belonging to GRICCO.
Chapter V — Reimbursement of Expenses
Art. 11. The following extraordinary expenses directly linked to the performance of remote work are reimbursable, upon presentation of valid receipts and a consolidated monthly report:
- I) A proportional share of the electricity bill, calculated on the basis of an objective methodology communicated by HR;
- II) A proportional share of the broadband internet service, upon presentation of the invoice;
- III) Consumable office supplies (toner, paper, pens), up to established monthly limits;
- IV) Extraordinary expenses previously approved by the manager.
§ 1. Reimbursed amounts are INDEMNIFICATORY in nature and do not form part of remuneration for any purpose (CLT art. 75-D).
§ 2. Reimbursement shall be credited within thirty (30) days of approval of the expense report.
§ 3. Converting salary into reimbursement, or using reimbursement to disguise a salary component, is prohibited.
TITLE IV — ELECTRONIC MONITORING
Chapter I — Declaration of Technologies, Purposes and Legal Bases
Art. 12. In observance of the principles of transparency (LGPD art. 6, VI) and accountability (LGPD art. 6, X), GRICCO expressly declares, in the table in art. 13, which monitoring technologies it adopts, for which purposes, under which legal bases and for which retention periods.
Art. 13. Consolidated Table of Personal Data Processing through Electronic Monitoring:
| Purpose | Technology / Data | LGPD Legal Basis | Retention |
|---|---|---|---|
| Working-hours control and electronic timekeeping | Login/logoff records, clock-in/clock-out entries, geolocation (connection IP only) — precise location outside work is prohibited | Art. 7, II (legal obligation — CLT art. 74) + Art. 7, V (performance of a contract) | 5 years (CLT art. 11; CTN art. 174 — labor limitation period after Constitutional Amendment 28/2000) |
| Productivity measurement | Periodic screen capture (intervals ≥ 10 min), active applications, idle time, aggregate keyboard/mouse counts (no keylogging) | Art. 7, V (performance of a contract) + Art. 7, IX (legitimate interest, with balancing test and RIPD) | Screenshots: 30 days with automatic purge. Aggregate metrics: 12 months |
| Information security and DLP | VPN logs, antivirus, corporate e-mail monitoring (metadata), Data Loss Prevention, exfiltration alerts | Art. 7, IX (legitimate interest: protection of trade secrets, client data, LGPD) | Logs: 6 months (LGPD art. 16) | Incident alerts: 5 years |
| Incident investigation | Detailed log audit, content of corporate (non-personal) communications, event reconstruction | Art. 7, IX (legitimate interest) + Art. 7, VI (regular exercise of rights in judicial/administrative proceedings) | For the duration of the proceeding + applicable limitation period (5 years as standard) |
| Compliance with regulatory obligations | Records required by Regulatory Standards (NRs), ISO certification bodies, client audits | Art. 7, II (legal/regulatory obligation) + Art. 7, V (performance of a contract with the client) | As required by regulation, minimum 5 years |
| Videoconference communications | Webcam and microphone activated ONLY during meetings, with the employee's knowledge. Recording only with express prior notice | Art. 7, V (performance of a contract) + Specific consent (Art. 7, I) for recording | Recorded meetings: 90 days (unless for a specific documentary purpose) |
§ 1. The table above is a material part of this Policy. Any change in technology, purpose, legal basis or retention shall require: (a) an update of this Policy; (b) the preparation or revision of the RIPD; (c) prior communication to employees thirty (30) days in advance; (d) renewal of the Adhesion Agreement (Annex I).
§ 2. Use of the technologies for purposes other than those declared is prohibited, under penalty of invalidating the legal basis and rendering the Company liable.
Chapter II — Absolute Prohibitions
Art. 14. The following conduct is prohibited, under any circumstances and by any GRICCO agent, in the exercise of monitoring:
- I) Accessing the camera or microphone of corporate equipment OUTSIDE corporate meetings held with the employee's express knowledge;
- II) KEYLOGGING (capturing keystrokes), which could reveal passwords, the content of personal messages or sensitive data;
- III) Monitoring personal communications, even when accessed on corporate equipment (personal e-mail, private social media, personal messaging apps), except for generic detection for security purposes (alert without reading content);
- IV) Real-time geolocation outside working hours or outside corporate activities;
- V) Collecting biometric data without specific consent and a legitimate purpose (LGPD art. 11);
- VI) Collecting data on health, sexual orientation, religious belief, trade union membership, political opinion or racial origin (LGPD art. 11) without a specific and proportionate legal basis;
- VII) Sharing monitoring information with unauthorized third parties, except by court order or legitimate request from a competent authority;
- VIII) Solely automated decision-making affecting the employee, without the right to review by a natural person (LGPD art. 20);
- IX) Using collected information for discriminatory, abusive or retaliatory purposes;
- X) Monitoring during meal and rest breaks, rest periods between shifts, weekly rest, vacations, leaves and outside contracted working hours.
Sole paragraph. Violation of these prohibitions entails administrative, civil and criminal liability, without prejudice to the sanctions of the Code of Ethics and of arts. 42 to 52 of the LGPD (fine of up to 2% of revenue, capped at BRL 50,000,000.00 per infraction).
Chapter III — Access Governance
Art. 15. Access to data collected through monitoring shall observe the principles of least privilege and segregation of duties, according to the following access matrix:
- I) DIRECT MANAGER — access to aggregate productivity and working-hours metrics for their team; access to individual screenshots without substantiation is prohibited;
- II) HUMAN RESOURCES — access to working-hours data, compensatory time bank, absences and medical certificates;
- III) COMPLIANCE AND IT — access to security logs, DLP and incident alerts, for audit purposes;
- IV) DPO — broad access, for the purpose of overseeing compliance with the LGPD;
- V) EXECUTIVE BOARD — indirect access, through consolidated HR/Compliance reports, except in a formal investigation;
- VI) DATA SUBJECT (EMPLOYEE) — access to their own data, upon request to the DPO, within 15 days (LGPD art. 19).
Sole paragraph. All access shall be recorded in an immutable audit log, retained for twelve (12) months, for accountability purposes and any investigation.
Chapter IV — Processors and Sub-processors
Art. 16. The engagement of monitoring software providers (LGPD Processors) shall observe:
- I) Data protection due diligence, including assessment of certifications (ISO 27001, ISO 27701, SOC 2);
- II) Mandatory LGPD contractual clauses: purposes, controller's instructions, security, confidentiality, retention, deletion, audit, incident notification within 24 hours, prohibition of use for the processor's own purposes;
- III) Server location: preference for servers in Brazil; international transfers only to countries with an adequate level of protection or under standard contractual clauses approved by the ANPD (LGPD art. 33);
- IV) Prohibition on the Processor using the data for AI model training, commercial profiling or any commercial purpose of its own.
TITLE V — DATA SUBJECT RIGHTS, RIPD AND INCIDENTS
Chapter I — Data Subject Rights
Art. 17. The employee, as the data subject, is guaranteed, at any time, the rights set out in art. 18 of the LGPD:
- I) CONFIRMATION of the existence of processing;
- II) ACCESS to the data, in simplified format (immediate response) or in full (clear and complete statement within 15 days — LGPD art. 19);
- III) CORRECTION of incomplete, inaccurate or outdated data;
- IV) ANONYMIZATION, BLOCKING or DELETION of unnecessary or excessive data, or data processed in non-compliance;
- V) PORTABILITY to another provider, subject to ANPD regulations;
- VI) DELETION of data processed on the basis of consent (save where retention is required by law);
- VII) INFORMATION on the public and private entities with which GRICCO has shared data;
- VIII) INFORMATION on the possibility of withholding consent and the consequences thereof;
- IX) WITHDRAWAL of consent, where applicable;
- X) REVIEW of automated decisions affecting their interests (LGPD art. 20).
Art. 18. The exercise of these rights shall be free of charge and handled by the DPO (dpo@gricco.com.br), within the following time limits:
- I) Confirmation of existence and simplified access: immediate;
- II) Full access, rectification, deletion, portability: within fifteen (15) days of the request;
- III) Automated decisions: review within 15 days, with an explanation of the criteria used.
Sole paragraph. Withdrawal of consent or objection to processing based on legitimate interest may entail a review of the feasibility of continuing the Flexible Work arrangement, given the technical impossibility of remote performance without minimum monitoring, in which case an on-site alternative shall be offered, without any punitive character.
Chapter II — RIPD — Data Protection Impact Report
Art. 19. A DATA PROTECTION IMPACT REPORT (RIPD/DPIA) has been prepared, on the basis of art. 38 of the LGPD and the methodology recommended by the ANPD, covering:
- I) A description of the types of data collected;
- II) The methodology used for collection and for ensuring information security;
- III) An analysis of the safeguards adopted;
- IV) An assessment of the risks to the rights and freedoms of data subjects;
- V) The mitigating measures adopted.
Sole paragraph. The RIPD shall be reviewed annually or whenever there is a material change in technologies, purposes, legal bases or identified risks, kept in the custody of the DPO and made available to the ANPD upon request.
Chapter III — Incident Management
Art. 20. A security incident involving personal data (improper access, leak, unauthorized alteration, unavailability) shall be handled in accordance with the following response procedure:
- I) IMMEDIATE DETECTION AND CONTAINMENT — by IT and the DPO;
- II) RISK ASSESSMENT — within 24 hours, with severity classification;
- III) NOTIFICATION TO THE ANPD — within a reasonable period (ANPD guidance: up to 3 business days), where the incident may give rise to significant risk or harm (LGPD art. 48);
- IV) NOTIFICATION TO AFFECTED DATA SUBJECTS — where significant risk/harm is established;
- V) RECORDING AND LESSONS LEARNED — documentation in the Incident Inventory maintained by the DPO;
- VI) REVIEW OF CONTROLS — implementation of corrective measures and update of the RIPD.
Sole paragraph. An employee who identifies a potential incident must immediately notify the DPO (dpo@gricco.com.br) and technical support, within a maximum of 24 hours of becoming aware of it, failing which this shall constitute an aggravating factor in the determination of liability.
Chapter IV — Communication to the Employee
Art. 21. Before the processing of monitoring data begins, GRICCO shall make available to the employee:
- I) This Policy and its Annexes;
- II) The Flexible Work Adhesion Agreement with Specific Consent (Annex I);
- III) The Specific Privacy Notice for Monitoring (Annex II);
- IV) Training on the LGPD, the purposes of monitoring and the exercise of rights;
- V) A direct communication channel with the DPO for clarifications.
TITLE VI — OHS, INFORMATION SECURITY AND DUTIES
Chapter I — Health and Safety in Remote Work
Art. 22. In line with art. 75-E of the CLT and NR-17 (Ergonomics), GRICCO shall observe the following:
- I) Written guidance on the precautions to be taken to avoid occupational illnesses and accidents;
- II) Collection of a statement of responsibility in which the employee undertakes to follow the instructions (Annex II);
- III) Provision of an ergonomic support channel;
- IV) Promotion of a mental health program aligned with ISO 45003:2021;
- V) Recognition that an occupational accident occurring as a result of work activity during remote work is equivalent to a conventional occupational accident (Law 8,213/1991).
Chapter II — Information Security
Art. 23. The employee in Flexible Work shall mandatorily observe the following:
- I) Keep the equipment locked when away from it, even for a short period;
- II) Not share credentials, tokens, MFA or any authentication mechanism;
- III) Use the corporate VPN exclusively for access to systems and data;
- IV) Not store corporate data in personal cloud services (personal Google Drive, iCloud, personal Dropbox);
- V) Not print, photograph or copy confidential data without a documented operational need;
- VI) Perform security updates when requested by IT;
- VII) Immediately report any suspected incident to the DPO and IT.
Chapter III — Specific Duties of the Employee
Art. 24. The specific duties of the employee in Flexible Work are:
- I) To fully comply with the contracted working hours, punctually;
- II) To maintain an appropriate environment, free from excessive noise and from elements that compromise confidentiality;
- III) To attend meetings with the camera on when expressly requested, with breaks respected;
- IV) Not to allow family members or third parties to access corporate equipment or systems;
- V) To report any supervening impossibility or inadequacy to the manager and HR.
TITLE VII — SANCTIONS, GOVERNANCE AND FINAL PROVISIONS
Chapter I — Sanctions for Non-Compliance
Art. 25. Non-compliance with this Policy, by an employee or a manager, shall be subject to the Penalty Matrix in Annex I of GRICCO-GOV-003, in particular:
- I) Failure to comply with working hours, improper absence and low delivery — minor to moderate sanctions;
- II) Use of personal equipment for corporate activity, data misappropriation, violation of security rules — serious sanctions;
- III) Willful violation of the LGPD by a manager (improper access, disclosure, retaliation) — most serious sanction, with possible dismissal for cause, without prejudice to civil and criminal liability.
Chapter II — Governance of the Policy
Art. 26. Governance structure:
- I) CONTROLLER — GRICCO Soluções Integradas Ltda;
- II) DATA PROTECTION OFFICER (DPO) — dpo@gricco.com.br, with authority to receive communications from data subjects and the ANPD and to provide internal guidance on the practices to be adopted regarding data protection (LGPD art. 41);
- III) COMPLIANCE — responsible for training, periodic audits and first-line incident management;
- IV) IT — responsible for the technical implementation of the tools, privacy-by-default configuration, management of processors and incident response;
- V) HR — responsible for processing adhesion agreements, communications to employees and management of related labor matters;
- VI) EXECUTIVE BOARD — ultimately responsible for approving the Policy and for its annual review.
Chapter III — Effectiveness, Review and Final Provisions
Art. 27. This Policy enters into force on the date of its approval and shall be reviewed every twelve (12) months, or immediately in the event of:
- I) A change in monitoring technology, purpose or legal basis;
- II) A relevant legislative change (LGPD, CLT, ANPD resolution);
- III) A material incident;
- IV) A recommendation from internal or external audit or from the ANPD.
Art. 28. This Policy is hierarchically subordinate to the Code of Ethics (GRICCO-GOV-001) and to the Internal Regulations for Employees (GRICCO-GOV-003), which shall prevail in the event of an interpretive conflict, always subject to the primacy of mandatory legal rules (LGPD, CLT) and of the applicable collective bargaining agreement (CCT/ACT).
Art. 29. Cases not covered herein shall be decided by the Executive Board, after consulting the DPO.
Macaé/RJ, June 2026.
Chief Executive Officer — GRICCO
Data Protection Officer (DPO)
ANNEXES
ANNEX I — Flexible Work Adhesion Agreement with Specific LGPD Consent
I, [full name], CPF [______________], employee of GRICCO Soluções Integradas Ltda. in the role of [position], hereby declare that:
- 1) I have read in full and understood Policy GRICCO-POL-002 and its Annexes, as well as the Internal Regulations for Employees GRICCO-GOV-003;
- 2) I adhere, of my own free will, to the Flexible Work arrangement in the modality [full remote / hybrid, X on-site days], starting on [__/__/____];
- 3) I declare that my remote work environment is adequately prepared in terms of ergonomics, connectivity, lighting, privacy and security, in accordance with the checklist in Annex II;
- 4) I HAVE RECEIVED EXPRESS AND SPECIFIC INFORMATION on the electronic monitoring of work activities performed on corporate equipment, in accordance with the table in art. 13 of this Policy, and am aware of the technologies, purposes, legal bases and retention periods;
- 5) I acknowledge that processing takes place primarily on the basis of the hypotheses of art. 7, II, V and IX of the LGPD (legal obligation, performance of a contract and legitimate interest), and that I SPECIFICALLY CONSENT to the purposes for which art. 7, I, of the LGPD is the applicable basis (notably the recording of meetings and screen capture of windows that may contain incidental personal data);
- 6) I am aware of my rights as a data subject (LGPD art. 18) and of the DPO channel (dpo@gricco.com.br) for exercising them;
- 7) I undertake to use EXCLUSIVELY the equipment provided by GRICCO for work activities, respecting the Company's intellectual property;
- 8) I acknowledge GRICCO's right to revoke this arrangement upon 15 days' notice (CLT art. 75-C, § 2) and my right to object/withdraw, subject to the possibility of returning to on-site work.
Place: ____________________ Date: ____/____/______
[Employee's signature]
ANNEX II — Specific Privacy Notice for Monitoring
In compliance with art. 9 of the LGPD, GRICCO informs, in clear and accessible language:
- a) CONTROLLER: GRICCO Soluções Integradas Ltda, CNPJ 53.765.584/0001-52;
- b) DATA PROTECTION OFFICER (DPO): dpo@gricco.com.br;
- c) PURPOSES, TECHNOLOGIES, LEGAL BASES AND RETENTION: as per the table in art. 13 of this Policy;
- d) SHARING: only with contracted Processors (software providers), under mandatory LGPD clauses; with public authorities upon legitimate request; commercial use prohibited;
- e) INTERNATIONAL TRANSFER: preference for servers in Brazil; international transfers only with the safeguards provided for in art. 33 of the LGPD;
- f) SECURITY: encryption in transit (TLS 1.2+) and at rest (AES-256), MFA, segregation of duties, audit logs;
- g) DATA SUBJECT RIGHTS: as per art. 18 of the LGPD, handled within 15 days;
- h) COMPLAINTS: may be addressed to the DPO or directly to the ANPD (www.gov.br/anpd).
ANNEX III — Ergonomic and Safety Checklist for the Home Work Environment
- 1) Height-adjustable chair, with adequate backrest and lumbar support;
- 2) Desk at a compatible height, with space for keyboard, mouse and forearm rest;
- 3) Monitor positioned at eye level, at arm's length;
- 4) Adequate natural or artificial lighting, with no glare on the monitor;
- 5) Quiet environment, with privacy for confidential calls;
- 6) Stable internet connection (broadband, minimum 50 Mbps recommended);
- 7) Corporate equipment connected via VPN, MFA enabled, antivirus up to date;
- 8) Location free of unauthorized persons with a view of the screen or within earshot of calls;
- 9) Voltage stabilizer or UPS to prevent session loss and equipment damage;
- 10) Smoke detectors and a fire extinguisher recommended in the environment.
Signature of conformity by the employee, with the possibility of an audit upon scheduling and consent.
ANNEX IV — Executive Summary of the RIPD
Summary of the findings of the Data Protection Impact Report (RIPD/DPIA):
Scope) Electronic monitoring of employees in Flexible Work
Number of data subjects) To be determined according to adhesion (potentially: all employees)
Data categories) Identification, working hours, activities on equipment, corporate communications, IP/approximate geolocation, screenshots, aggregate metrics
Sensitive data) Not intentionally processed. Possible incidental occurrence in screenshots — addressed through minimization and automatic purge
Identified risks) (R1) Inadvertent capture of third parties' personal data; (R2) Improper access by managers; (R3) Leak via Processor; (R4) Discriminatory use; (R5) Perception of invasive surveillance
Mitigating measures) Minimum screenshot intervals (≥10 min); purge after 30 days; segregation of access; LGPD clauses with Processors; prohibition of automated decisions; training; DPO channel; annual review
Residual assessment) Acceptable risk, subject to full observance of this Policy
Decision) Approved by the DPO on [date], with mandatory review in 12 months
ANNEX V — Request and Approval Procedure
- 1) The employee submits a formal request to the manager and HR (standardized digital template);
- 2) The manager issues a technical opinion within 5 business days (compatibility of the role and performance);
- 3) HR validates eligibility (probationary period completed, no active disciplinary measures);
- 4) Compliance/IT validate the feasibility of equipment, VPN and monitoring tools;
- 5) The DPO validates the LGPD compliance of the proposed arrangement;
- 6) The Executive Board decides within 15 business days, with reasons;
- 7) If approved, signature of the Adhesion Agreement (Annex I) and the Equipment Receipt Form;
- 8) Start of the modality according to the approved schedule.
ANNEX VI — Specific Regulatory Basis
- I) Law 13,709/2018 (LGPD), arts. 5, 6, 7, 11, 18, 33, 37 to 41, 46 to 49;
- II) Decree-Law 5,452/1943 (CLT), arts. 74, 75-A to 75-F, 482;
- III) Law 14,442/2022 (Remote Work — amendment of the remote work regime in the CLT);
- IV) Law 12,965/2014 (Brazilian Internet Civil Framework);
- V) Federal Constitution, art. 5, X, XII and LXXIX;
- VI) ANPD Resolutions and Guides in force;
- VII) Precedents (Súmulas) and Decisions of the TST on corporate monitoring (in particular on corporate e-mail);
- VIII) ISO/IEC 27001:2022; ISO/IEC 27701:2019; ISO 37301:2021;
- IX) Code of Ethics GRICCO-GOV-001; Internal Regulations for Employees GRICCO-GOV-003; Integrated Policies GRICCO-POL-001.
GRICCO Ethics Channel.
Confidentiality guaranteed, no retaliation. Reach Compliance or our Data Protection Officer (DPO).