Some information is usually treated as strictly operational in day-to-day business: phone numbers, addresses, contact details. The STJ (Brazil's Superior Court of Justice), however, has reaffirmed a relevant point: when such data is improperly made available in databases, the legal impact can be immediate, including the recognition of presumed moral damages.
In REsp 2.201.694/SP, the Third Panel held that the improper disclosure of personal information to third parties, especially without prior notice to the data subject and without consent where required, violates personality rights and gives rise to moral damages in re ipsa. In practical terms, the logic is objective: proof of actual harm (such as "humiliation" or "suffering") is not required; it is enough to demonstrate the act of improper disclosure.
What Happened
The case involves a consumer who claimed that a database manager had allowed access to information such as phone number, address and income. The claim sought: (i) an end to the disclosure and (ii) compensation.
One detail helps to understand the scope of the decision: at first instance the claim was dismissed, and the TJSP (São Paulo State Court of Appeals) upheld that conclusion. At the STJ, however, the opinion of Justice Nancy Andrighi (rapporteur for the judgment) prevailed by majority, recognizing that improper disclosure, under these conditions, violates personality rights and gives rise to presumed moral damages.
Why This Decision Matters for Your Business
The judgment carries two messages that help translate the topic from "legal" into "business" terms, especially in B2B ecosystems:
1. Do Not Confuse "Credit Scoring" with "Database"
The STJ distinguishes the discussion on score/credit scoring (Repetitive Theme 710/Súmula 550, the court's settled case law on credit scoring) from the central point here: the sharing/provision of registration data from a database. This distinction matters because it changes the legal framing and, with it, the obligations, limits and safeguards expected in the processing.
2. Registration Data Can Also Give Rise to Presumed Moral Damages
Even when the information is not "sensitive", the court treated improper disclosure as sufficient to establish the violation and support moral damages in re ipsa. In other words, the risk lies not only "in the category" of the data, but in the way it is accessed, exposed and made available.
"The central point is not 'sensitive vs. non-sensitive data'. It is the legal limit of access and the purpose: when registration data is made available to those who should not access it, the court presumes the damage, because of the insecurity arising from the exposure itself."
What May and May Not Circulate in This Ecosystem
To make the topic more concrete, the decision helps draw a boundary around what this type of structure may make available, in the context analyzed:
| Status | Type of Data | Condition |
|---|---|---|
| ✅ Allowed | Credit score | May be made available to third parties without prior consent |
| ✅ Allowed | Credit history | May be made available with the specific authorization of the registered individual |
| ❌ Not allowed | Phone number, address, payment history | Must not be released to consulting companies |
What the Decision Ordered in the Specific Case
In addition to ordering the cessation of the disclosure of the data to consulting third parties (subject to the exceptions within legal limits), the defendant was ordered to pay R$ 11,000.00 in moral damages.
Why This Should Be on Every Business Leader's Radar
Because the problem here is not necessarily a hacker attack. It is something more routine, and therefore more frequent: who has access to the data, how that access is granted and what partners are able to consult. The risk may arise from the operation itself, from the way the company shares, integrates and "opens up" information to third parties.
In practice, this decision translates into four areas of impact:
- Financial: If the damage is presumed, it becomes simpler to turn a disclosure/access failure into compensation, which tends to increase the volume (and predictability) of disputes.
- Reputation: The argument "no harm was proven" loses strength when the damage is recognized from the very fact of improper exposure.
- Contracts and partnerships: In B2B chains, risk is rarely "contained" within a single player. Those who buy, integrate or resell data solutions may be held accountable under liability, audit, recourse and even termination clauses.
- Operations: The topic bears directly on access control, logs, query traceability, API governance and partner permission management.
Practical Checklist: If You Do Any of the Following, Take Note
You are likely to be more exposed if you:
- Offer solutions that depend on database queries (credit, validation, enrichment, anti-fraud, KYC/KYB)
- Sell or consume data enrichment (phone number/address/estimated income) as a differentiator
- Share registration data with "consulting partners" without a clear matrix of purpose, legal basis and authorization
- Cannot quickly answer: where the data came from, to whom it went, when it was consulted and on what grounds
How to Address the Risk Efficiently (Without Stalling the Business)
- Map the disclosure points (API, portal, batch, integrations).
- Validate the "legal menu" of what is provided and under which legal hypothesis (with special attention where there is a link to the positive credit registry).
- Strengthen third-party governance: purpose, access limits, audit, logs, retention and notification obligations.
- Apply minimization and necessity: does the partner need "the data itself" or only a result/indicator?
- Prepare evidence: keep documentation and audit trails ready to demonstrate compliance (this is often decisive in disputes).
In your operation, is registration data treated as a detail or as an asset that, if poorly governed, becomes a liability?

