Introduction to LGPD and Tuya's Commitment
This white paper outlines how Tuya Inc. adheres to Brazil's General Data Protection Law (Lei Geral de Proteção de Dados - LGPD). It details Tuya's commitment to data privacy and security, its strategies for compliance, and the measures taken to protect personal data.
Tuya's Role and Shared Responsibility
The document explains Tuya's dual role as both a data controller and a data processor under LGPD. It emphasizes a shared responsibility model where Tuya provides robust security and privacy features, while customers are responsible for managing and securing their own data and applications built on the Tuya platform.
Security, Privacy, and Certifications
Tuya implements comprehensive security and compliance strategies, including technical and management measures. The company has a dedicated security and compliance team and conducts regular security assessments. Tuya holds various international certifications demonstrating its commitment to data protection and security, such as:
- ISO/IEC 27001:2022
- ISO/IEC 27017:2015
- ISO/IEC 27701:2019
- CSA STAR
- SOC 2 Type II & SOC 3
- ISO 9001:2015
- CCPA Verification Report
- GDPR Verification Report
For more information on vulnerability reporting, visit Tuya SRC.
Supporting Customer LGPD Compliance
Tuya provides features and guidance to help customers meet LGPD requirements. This includes clear privacy policies, data handling protocols, and support for data subject rights. Tuya ensures its services are designed with "Privacy by Design" principles.
Conclusion
Tuya is dedicated to offering secure, reliable, and compliant IoT services. The company continuously monitors and adapts to evolving privacy regulations, ensuring its platform and solutions support customer compliance with global data protection laws like LGPD.