- PURPOSE
The purpose of the policy set forth herein (the “Information Security Policy,” or, simply, the “Policy”) is to define the principles and guidelines for information security, with the aim of protecting the organization, its clients, and the general public.
- DEFINITIONS
“Associate” means any attorney who is an associate of Pinheiro Guimarães, pursuant to Articles 39 and 40 of the General Regulation of the Statute of the Practice of Law and the Brazilian Bar Association, enacted by the Federal Council of the Brazilian Bar Association (Conselho Federal da OAB), under the powers conferred by Articles 54(V) and 78 of Law No. 8,906, dated July 4, 1994.
“Client” means any individual or legal entity (including its partners, directors, representatives, attorneys-in-fact, service providers, and advisors) that engages, has engaged, or may engage any services provided by Pinheiro Guimarães.
“Personnel” means the Partners, Associates, Employees, Interns, and Vendors, collectively.
“Employee” means any employee hired by Pinheiro Guimarães under an employment agreement governed by Brazil’s Consolidation of Labor Laws (Consolidação das Leis do Trabalho – CLT).
“Intern” means any student contracted by Pinheiro Guimarães pursuant to Brazilian Law No. 11,788, dated January 25, 2008.
“Vendors” means any individual (other than a Partner, Associate, Employee, or Intern) or legal entity engaged by Pinheiro Guimarães to act on behalf of or in the interest of Pinheiro Guimarães, such as accountants, technology service providers, and partner law firms.
“Pinheiro Guimarães” means Pinheiro Guimarães e Meissner Sociedade de Advogados.
“Partner” means the attorney who holds an equity interest in Pinheiro Guimarães pursuant to its Articles of Association (Contrato Social).
- SCOPE
This policy applies to all Personnel, Interns, and Vendors of the Pinheiro Guimarães firm.
- REFERENCES
- Brazil’s General Data Protection Law (Lei Geral de Proteção de Dados – LGPD);
- General Data Protection Regulation (GDPR);
- Code of Conduct and Ethics;
- Business Continuity Policy;
- ABNT NBR ISO/IEC 27001:2022;
- ABNT NBR ISO/IEC 27701:2019;
- NIST (National Institute of Standards and Technology) Framework.
- PRINCIPLES
Information security is defined herein as the preservation of the following core principles:
Confidentiality: Ensuring that information remains accessible only to authorized individuals for the required period necessary;
Availability: Ensuring that information is accessible to authorized individuals whenever needed;
Integrity: Ensuring that information remains complete, accurate, and unaltered, and preventing any improper modification or destruction, whether unauthorized or accidental, throughout its lifecycle.
- GUIDELINES
Information is a valuable asset of the utmost importance to Pinheiro Guimarães, vital to the success of its business, and therefore requiring adequate protection.
Information security involves implementing measures to protect the ownership, confidentiality, availability, and integrity of information, regardless of the form or medium in which it exists. This is intended to protect against various threats, objective of preventing use that may be improper, inadequate, illegal, or inconsistent with internal policies and procedures. To this end, the following guidelines must be observed.
6.1 OWNERSHIP, MONITORING, AND CLASSIFICATION OF INFORMATION
All information generated by Personnel covered by this Policy, whether in physical or digital format, is considered the exclusive property of Pinheiro Guimarães. This includes information made available by third parties in an authorized manner, which must be used strictly to meet business objectives.
The equipment, communications systems, and IT systems of Pinheiro Guimarães are subject to monitoring. It is important to emphasize that any personal information processed through these means or otherwise provided to Pinheiro Guimarães will be subject to such monitoring. That monitoring is known to all Personnel.
A method must exist to classify information according to its level of confidentiality and criticality for the business of Pinheiro Guimarães. All information must be saved in the document management system, organized by client and matter. Each matter must be assigned to a Partner who is formally designated as responsible for authorizing access to the information under his or her responsibility.
Information must be duly protected and labeled, following the information security guidelines of Pinheiro Guimarães at all stages of its lifecycle, including its: creation, being accessed, handling, storage, reproduction, transportation, and disposal.
6.2 ACCESS AND IDENTITY MANAGEMENT
Access to the information and technology environments of Pinheiro Guimarães must be for personal use, controlled according to classification, and reviewed periodically so as to be made available only to authorized individuals with the permissions necessary for the performance of their duties.
Sharing of access credentials is strictly prohibited, underscoring the critical importance of individual accountability when using these resources.
6.3 DISPOSAL OF INFORMATION
Information must be disposed of using measures that render recovery impossible, based on its physical or digital format. Information must be disposed of in accordance with minimum legal or regulatory retention periods, as well as its necessity for the business or the relevant area, whichever is longer.
6.4 VENDORS AND EXTERNAL PARTIES
Contracts entered into with service providers that have access to the information, systems, or environment of Pinheiro Guimarães must include clauses ensuring compliance with information security and confidentiality requirements, and rules as well as establish penalties in the event of noncompliance.
6.5 BUSINESS CONTINUITY
The business continuity plan of Pinheiro Guimarães establishes and maintains a strategic and operational framework designed to manage and respond to disruptions in the processes that support the operations of Pinheiro Guimarães.
- RESPONSIBILITIES
The success and effectiveness of the Information Security Policy of Pinheiro Guimarães depend on the active collaboration and understanding of all members of the organization. This document sets forth the core responsibilities regarding the management, implementation, and adherence to information security policies.
7.1 PERSONNEL
Personnel must:
- Comply with information security rules;
- Protect information against unauthorized access, modification, destruction, or disclosure;
- Ensure that technological resources, information, and systems at their disposal are used solely for business purposes;
- Comply with laws and regulations governing intellectual property;
- Not discuss, reference, or share confidential matters in public settings or unsecured areas;
- Not share confidential information of any kind;
- Promptly report to the Compliance Committee any non-compliance with or violation of this Policy or its rules and procedures.
7.2 MANAGERS
Managers must:
- Establish rules and procedures relating to information security, addressing the ownership and use of information, access and identity management, and information security incidents;
- Ensure compliance with this Policy or its rules and procedures;
- Ensure that contracts entered into with service providers that have access to the information, systems, or environment of Pinheiro Guimarães include provisions ensuring compliance with information security and confidentiality rules, as well as establishing penalties in the event of noncompliance;
- Communicate, promote, reinforce, and guide the team regarding security practices, processes, and system access.
7.3 COMPLIANCE COMMITTEE
The Compliance Committee is responsible for:
- Approving the Information Security Policy and any revisions thereto;
- Proposing improvements to information security.
- FINAL PROVISIONS
The foregoing provisions shall apply immediately to all of Pinheiro Guimarães as of the
publication of this Policy. All members of the organization must familiarize themselves with and fully comply with these provisions, contributing to the effective implementation of the practices and principles set forth herein.
Last Updated: July 1, 2026
Approved by: Compliance Committee