DPO Privacy
DPO Privacy
PlatformSolutionsAI governancePlansContentAbout us
PTENES
Book a demo
Book a demo
PlatformSolutionsAI governancePlansContentAbout usBook a demo
HomePublicationsLGPD
LGPD

Brazil's STJ: Improper Sharing of Phone Numbers and Addresses May Give Rise to Presumed Moral Damages

Brazil's Superior Court of Justice (STJ) reaffirmed that the improper disclosure of registration data such as phone numbers and addresses in databases, without the data subject's consent, violates personality rights and gives rise to moral damages in re ipsa, with no need to prove actual harm.

M
Maria dos Santos
February 27, 202612 min read

Some information is usually treated as strictly operational in day-to-day business: phone numbers, addresses, contact details. The STJ (Brazil's Superior Court of Justice), however, has reaffirmed a relevant point: when such data is improperly made available in databases, the legal impact can be immediate, including the recognition of presumed moral damages.

In REsp 2.201.694/SP, the Third Panel held that the improper disclosure of personal information to third parties, especially without prior notice to the data subject and without consent where required, violates personality rights and gives rise to moral damages in re ipsa. In practical terms, the logic is objective: proof of actual harm (such as "humiliation" or "suffering") is not required; it is enough to demonstrate the act of improper disclosure.

What Happened

The case involves a consumer who claimed that a database manager had allowed access to information such as phone number, address and income. The claim sought: (i) an end to the disclosure and (ii) compensation.

One detail helps to understand the scope of the decision: at first instance the claim was dismissed, and the TJSP (São Paulo State Court of Appeals) upheld that conclusion. At the STJ, however, the opinion of Justice Nancy Andrighi (rapporteur for the judgment) prevailed by majority, recognizing that improper disclosure, under these conditions, violates personality rights and gives rise to presumed moral damages.

Legal reference: The decision reinforces a relevant line of reasoning: in databases governed by the Positive Credit Registry Law (Law 12.414/2011), the "menu" of what may be provided is restricted, and going beyond those limits tends to have consequences, including in terms of liability for damages.

Why This Decision Matters for Your Business

The judgment carries two messages that help translate the topic from "legal" into "business" terms, especially in B2B ecosystems:

1. Do Not Confuse "Credit Scoring" with "Database"

The STJ distinguishes the discussion on score/credit scoring (Repetitive Theme 710/Súmula 550, the court's settled case law on credit scoring) from the central point here: the sharing/provision of registration data from a database. This distinction matters because it changes the legal framing and, with it, the obligations, limits and safeguards expected in the processing.

2. Registration Data Can Also Give Rise to Presumed Moral Damages

Even when the information is not "sensitive", the court treated improper disclosure as sufficient to establish the violation and support moral damages in re ipsa. In other words, the risk lies not only "in the category" of the data, but in the way it is accessed, exposed and made available.

"The central point is not 'sensitive vs. non-sensitive data'. It is the legal limit of access and the purpose: when registration data is made available to those who should not access it, the court presumes the damage, because of the insecurity arising from the exposure itself."

What May and May Not Circulate in This Ecosystem

To make the topic more concrete, the decision helps draw a boundary around what this type of structure may make available, in the context analyzed:

Status Type of Data Condition
✅ Allowed Credit score May be made available to third parties without prior consent
✅ Allowed Credit history May be made available with the specific authorization of the registered individual
❌ Not allowed Phone number, address, payment history Must not be released to consulting companies
Attention: This framing shifts the discussion from "what type of data is it?" to the question that actually reduces risk: what is the limit of access, who may consult what, for what purpose and under what condition?

What the Decision Ordered in the Specific Case

In addition to ordering the cessation of the disclosure of the data to consulting third parties (subject to the exceptions within legal limits), the defendant was ordered to pay R$ 11,000.00 in moral damages.

Why This Should Be on Every Business Leader's Radar

Because the problem here is not necessarily a hacker attack. It is something more routine, and therefore more frequent: who has access to the data, how that access is granted and what partners are able to consult. The risk may arise from the operation itself, from the way the company shares, integrates and "opens up" information to third parties.

In practice, this decision translates into four areas of impact:

  1. Financial: If the damage is presumed, it becomes simpler to turn a disclosure/access failure into compensation, which tends to increase the volume (and predictability) of disputes.
  2. Reputation: The argument "no harm was proven" loses strength when the damage is recognized from the very fact of improper exposure.
  3. Contracts and partnerships: In B2B chains, risk is rarely "contained" within a single player. Those who buy, integrate or resell data solutions may be held accountable under liability, audit, recourse and even termination clauses.
  4. Operations: The topic bears directly on access control, logs, query traceability, API governance and partner permission management.

Practical Checklist: If You Do Any of the Following, Take Note

You are likely to be more exposed if you:

  • Offer solutions that depend on database queries (credit, validation, enrichment, anti-fraud, KYC/KYB)
  • Sell or consume data enrichment (phone number/address/estimated income) as a differentiator
  • Share registration data with "consulting partners" without a clear matrix of purpose, legal basis and authorization
  • Cannot quickly answer: where the data came from, to whom it went, when it was consulted and on what grounds

How to Address the Risk Efficiently (Without Stalling the Business)

  1. Map the disclosure points (API, portal, batch, integrations).
  2. Validate the "legal menu" of what is provided and under which legal hypothesis (with special attention where there is a link to the positive credit registry).
  3. Strengthen third-party governance: purpose, access limits, audit, logs, retention and notification obligations.
  4. Apply minimization and necessity: does the partner need "the data itself" or only a result/indicator?
  5. Prepare evidence: keep documentation and audit trails ready to demonstrate compliance (this is often decisive in disputes).
Practical solution: Platforms such as DPO Privacy centralize the mapping of data sharing, access control, audit trails and compliance evidence, making it possible to respond quickly and securely to scenarios such as the one analyzed by the STJ.

In your operation, is registration data treated as a detail or as an asset that, if poorly governed, becomes a liability?

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstration
STJMoral DamagesRegistration DataLGPDCase LawData Sharing
Share
M
Maria dos Santos
Digital Law and Data Protection Specialist
  1. What Happened
  2. Why This Decision Matters for Your Business
  3. 1. Do Not Confuse "Credit Scoring" with "Database"
  4. 2. Registration Data Can Also Give Rise to Presumed Moral Damages
  5. What May and May Not Circulate in This Ecosystem
  6. What the Decision Ordered in the Specific Case
  7. Why This Should Be on Every Business Leader's Radar
  8. Practical Checklist: If You Do Any of the Following, Take Note
  9. How to Address the Risk Efficiently (Without Stalling the Business)

Discover the platform

Centralize all data and privacy governance in one place.

Schedule a demo

Related articles

LGPD
February 20, 202612 min

Complete Guide to the LGPD in 2026: What Changes for Companies

The new ANPD guidelines for 2026 bring significant changes for companies of all sizes. Learn about the new governance requirements, the updated penalties and how to prepare for intensified inspections.

M
Maria Fernanda Costa
Head of Governance and Privacy

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstrationExplore features
Back to publications
DPO Privacy

Privacy and personal data protection governance platform for managing compliance with the LGPD (Brazilian General Data Protection Law) and the GDPR.

Platform

  • Modules
  • AI governance
  • Data and Technology
  • Enterprise
  • Plans
  • Security

Company

  • About us
  • Contact

Resources

  • Content
  • Help Center
  • Frequently asked questions

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© 2026 DPO Privacy · All rights reserved · Made in Brazil

Developed bysyntez