São Paulo State Confirms: Personal Data of 28,000 Citizens Compromised
RIO DE JANEIRO, BRAZIL – The São Paulo State Secretariat of Culture confirmed that a “technical fault” had exposed data of 28,000 people, including ID, CPF and proof of address.
The failure was found in the ProAC (Cultural Incentive Program) system and involved information sent between 2015 and 2018. The body opened an inquiry to determine what happened.

According to the Congresso em Foco website, the ProAC system exposed data from approximately 28,000 people who requested financial support from the Secretariat of Culture.
To enroll in the program, candidates need to prove that they live in the state of São Paulo and have worked in the cultural area for at least two years.
This system, which has not yet adopted the HTTPS protocol, serves to collect proof of address and ID and CPF images. The files are saved with sequential numbers for identification: in other words, by having the exact URL, changing this number is enough to access the documents of all candidates, with no need to log in.
“Each candidate has two identifiers, in this case, a sequential and predictable order, which allows the download link to be recognized and the files downloaded from the platform,” explains Congresso em Foco.
“In other words, by changing the sequence, one can access data on almost 30,000 registrants.”
Secretary of Culture “regrets technical failure”
The Secretariat of Culture has been approached several times since Monday, October 21st, but it only replied on Thursday night; in the meantime, the ProAC system remained online, exposing the candidates’ data.
In a statement, the secretariat “regrets that a technical failure by the previous management has exposed personal data of applicants registered in pre-2019 ProAC editions”.
The company in charge of the system was notified and, by determination of Secretary Sérgio Sá Leitão, an inquiry was opened “to ascertain responsibility for the incident”, in addition to a preliminary procedure for “identification of any failures in the system”.
The LGPD (General Law on Data Protection) only enters into force in 2020. It establishes that in the event that personal data is exposed or leaked by a public body, it will be up to the ANPD (National Data Protection Authority) to take the “appropriate measures”.
The body will be linked to the Office of the Presidency.
“I am afraid that with the LGPD in force, little will change,” says lawyer Danilo Doneda, professor of Civil Law at the Instituto Brasiliense de Direito Público (IDP- Brazilian Institute of Public Law), to Congresso em Foco. “The law was introduced in a weakened form and nothing guarantees that the regulating body within the Presidency’s structure will perform its control and penalty enforcement duties over these ‘failures'”.
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error
LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.
Read More from The Rio Times