Chuu Valverde França Advogados
← Insights

Corporate Employment Law · July 2026

Forwarding corporate e-mails to a personal account: dismissal for cause and the LGPD

Brazil's 4th Region Labor Court upheld the dismissal for cause of an employee who forwarded around sixty confidential corporate e-mails to his own personal account. Understand what supported the dismissal, why the information security policy decides these cases, and where the company's liability under the LGPD comes in.

Forwarding work e-mails to a personal inbox is a quiet and common practice. It is usually justified as convenience, a way to get ahead on tasks outside the office. A recent ruling shows the point at which this conduct stops being a habit and starts breaking the contract, and what separates a dismissal that holds up from one that is reversed.

The case

An auto parts salesperson forwarded around sixty corporate e-mails, containing confidential company information, to his personal e-mail account. During the proceedings, he admitted the conduct.

The 3rd Panel of the Regional Labor Court of the 4th Region upheld the dismissal for cause applied by the company, confirming the ruling of the 25th Labor Court of Porto Alegre. The grounds were article 482 of the Brazilian Labor Code (CLT), items "b" (misconduct), "g" (breach of company secrecy) and "h" (act of insubordination).

The reporting judge, Justice Marcos Fagundes Salomão, recorded that the conduct made the employer's business vulnerable and violated the Brazilian General Data Protection Law (LGPD).

This is a second-instance decision, still subject to appeal to the Superior Labor Court.

What actually supported the dismissal

The most useful point for the employer is not the outcome, but what existed before the incident.

The employee had signed an acknowledgment, commitment and responsibility form containing a confidentiality clause, and was aware of the company's access and information security rules. There was, therefore, a written rule, previously communicated and formally accepted.

That documentary basis is what turns objectionable conduct into demonstrable serious misconduct. The same conduct, in a company with no signed form and no previously disclosed security policy, would hardly sustain the most severe penalty available under an employment contract. The element that allows one to state that the employee knew, in advance, that the conduct was prohibited would be missing.

The defenses that did not prevail

The employee raised three arguments, all rejected:

  • That the penalty was disproportionate and discriminatory. The volume and repetition of the forwarding ruled out the reading of an isolated slip.
  • That the documents were not confidential. The documentary evidence produced in the record indicated otherwise.
  • That the forwarding resulted from a system failure. The quantity and consistency of the messages were not compatible with a technical failure, and the employee's own admission removed support from the argument.

The procedural lesson is straightforward: in leak cases, documentary evidence usually decides, because the corporate system itself records the conduct.

The data protection layer

Here lies the point that goes unnoticed in day-to-day management, and that considerably increases the company's exposure.

When corporate data leaves through the door of a personal e-mail account, this is not merely a breach of contractual trust. If that content contains personal data of clients, suppliers or other employees, the company acts as the controller of that data, under article 5, VI, of the LGPD, and it is the company that answers to data subjects and to the National Data Protection Authority.

The LGPD requires the controller to adopt security measures capable of protecting data against unauthorized access and leak situations (article 46). Once a security incident with relevant risk is established, a duty to notify the authority and the data subjects also arises (article 48). The agent is liable for damages arising from processing carried out in breach of the law (article 42).

Note the asymmetry: the employee answers at the level of the employment contract, through termination for cause. The company, at the regulatory level, answers for the data that was allowed to leave. That is why controlling the outflow of information is not only disciplinary management, it is also compliance.

What the company should have in place before an incident

What decides these cases is built long before the leak:

  • A written information security policy, with clear rules on the use of corporate e-mail, personal devices and the handling of files.
  • A signed acknowledgment and confidentiality form, with evidence that the employee received, read and accepted the rules.
  • Periodic communication and training, documented. A rule that exists only on paper, and was never disclosed, weakens any later penalty.
  • Proportionate technical controls, such as restrictions on external forwarding, information classification and log retention, always with transparency regarding monitoring of the corporate environment.
  • An incident response plan, defining who investigates, within what deadline, and how the notification required by the LGPD is decided.
  • Proportionality in the response. Dismissal for cause is the extreme measure. The volume, the nature of the data and the existence of prior warnings are all part of the analysis.

How the firm works on this

Drafting information security policies and confidentiality undertakings, investigating incidents involving data, and defending companies in claims discussing dismissal for cause based on breach of confidentiality are part of the firm's corporate employment law practice, in interface with the data protection area. Each case, however, depends on its own circumstances, facts and documents.

Conclusion

The decision confirms what practice already suggested: forwarding confidential corporate content to a personal account may constitute grounds for dismissal for cause, and an admission combined with documentary evidence makes that conclusion difficult to reverse.

For the company, however, the relevant message is a different one. The dismissal held up because a previously communicated policy and a signed undertaking existed. Without that basis, the same facts would produce a fragile dismissal and, even so, a data protection incident for which the company would still answer.

An information security policy also governs the employment contract. It is what supports the penalty afterwards and what helps protect the company under the law that holds it accountable for the data.

Reference basis for review

  • CLT, article 482, items "b", "g" and "h" (misconduct, breach of company secrecy and act of insubordination).
  • Law 13,709/2018 (LGPD), article 5, VI (definition of controller).
  • LGPD, article 42 (liability for damages arising from non-compliant processing).
  • LGPD, article 46 (duty to adopt security measures against unauthorized access and leaks).
  • LGPD, article 48 (notification of security incidents to the national authority and to data subjects).
  • Decision of the 3rd Panel of the Regional Labor Court of the 4th Region, case 0020205-62.2025.5.04.0123, reporting judge Justice Marcos Fagundes Salomão, a second-instance decision subject to appeal.
  • Brazilian Bar Association Rule (Provimento OAB) No. 205/2021, to maintain the informative nature of this content.

Content for informational purposes only. It does not constitute legal advice, an offer of services or a promise of results. Actual analysis depends on the facts, the documents and the context of each case.