Privacy and Personal

Data Protection

We strive to ensure the personal data processing activities in a transparent, ethical and secure way. These processing activities are carried out fairly and lawfully, based on laws, internal rules and best market practices.

Learn more about our governance and the actions we take to protect the privacy and safeguard of the personal data of everyone who has contact with us.

Privacy and Personal Data Protection Governance Program

Personal data processing guidelines are enforced through a governance program based on three pillars: guidance, supervision and execution.

Guidance

1. Mapping of activities involving Personal Data

2. Privacy and Personal Data Protection notices (“P&PD Notice”)

Supervision

3. Consent management

4. Third party management

5. P&PD incident management

Execution

6. Data subject rights

7. Minimization, retention and deletion of personal data

8. Education and training

Our principles

We follow seven principles to keep personal data safe:

1

Data minimization and necessity

We only collect data that is necessary and useful for each purpose.

2

Purpose

We always have a reason that justifies the collection of personal data.

3

Accuracy

We keep personal data up to date and accurate.

4

Transparency

This page and the P&PD Notices reflect our reasons for processing personal data.

5

Security

We implement best practices regardig information security and privacy.

6

Non-discrimination

Personal data will never be used to discriminate against anyone.

7

Free access

Users are free to contact us to understand how we process their personal data or to manage their preferences.

Glossary

Understand some important terms

Personal data
Sensitive personal information
Personal data subjects
Processing activity
Controller
Processor
Autoridade Nacional de Proteção de Dados – ANPD (“Brazilian Data Protection Authority”)
Data Protection Officer (DPO)
Legal bases
Consent
International data transfer

Your rights

Know your rights as a personal data subject

1
Confirmation of processing and access

Right to know whether or not Suzano processes your personal data and to have access to what type of data is processed.

2
Sharing
information

Right to know what personal data is shared, with whom and how.

3
Not consent or revoke consent

You do not need to allow the processing of your personal data and you can revoke your consent whenever you want, as long as the legal bases for processing your data is Consent.

4
Correction and deletion

Right to have your personal data corrected, updated or deleted.

5
Anonymization and restricting processing

Right to have your personal data anonymized or restrict its processing.

6
Data portability

Right to request your personal data to be shared with other institutions.

What personal data do we use?

At Suzano, we only use information that is necessary to carry out our activities and for the express purposes previously defined for each situation.

Personal data we use include:

ID
E-mail
Job title
Bank information
Address
Religious beliefs
Political opinion
Health information
Biometric information
Racial/ethnic origin

Frequently asked questions

How long does Suzano keep the personal data?
Where is the personal data stored?
How does Suzano colletct the personal data?
Who owns the personal data obtained by Suzano?
How does Suzano process minor's personal data?
How does Suzano protect the personal data?

Privacy and Personal Data Protection notices

These documents show the data we collect in different situations. To learn more, download the PDFs.

Talk to the Data Protection Officer (DPO)

Would you like to exercise your rights as a personal data subject, learn more about this topic, or report a security incident involving personal data? Fill out the P&PD Form to speak to the DPO.

Can we help?

Search for answers to your questions in our Frequently Asked Questions section.
 If you prefer, get in touch via the Contact Us section.