Summary
The OXXO case highlights how external criminal violence in the place of work can become a corporate and occupational risk when recurring incidents interact with vulnerabilities created by the business model. OXXO is a popular chain of convenience stores open 24/7. After more than 1,000 robberies and thefts recorded in 2024, the Labor Court of Campinas ordered the company OXXO to pay R$ 2 million in collective moral damages and to adopt stronger security, reporting, and employee-support measures. Critics argue that the decision risks transferring part of the State’s public-security responsibility to private employers and may impose costly or disproportionate requirements. However, the court emphasized OXXO’s 24-hour operations, reduced overnight staffing, repeated incidents, and documented psychological harm as evidence of a foreseeable and structural risk. The case therefore reinforces the importance of the Duty of Care owed by the employer to its employees as a corporate standard, requiring companies to identify foreseeable threats, adopt proportionate preventive controls, and integrate security into operational planning. For businesses, this approach also strengthen compliance, reduce employee exposure, and limit potential legal, financial, and reputational damage.
This Content Is Only For Subscribers
To unlock this content, subscribe to INTERLIRA Reports.
Robberies, Thefts and a Court Decision
On August 25, the Labor Court of Campinas ordered OXXO, a convenience-store chain, to pay R$ 2 million in collective moral damages for allegedly failing to adequately protect employees exposed to repeated robberies and other criminal incidents. The decision resulted from a public civil action filed by the Labor Prosecution Office (MPT).
Beyond the financial penalty, the ruling imposed nationwide operational requirements aimed at reducing employee exposure to violence. OXXO must maintain a visible physical-security presence during night shifts at medium- and high-risk stores. At other locations, the company must adopt protective measures such as bullet-resistant service windows, security airlocks, security booths, or panic buttons connected to a monitoring center.

The decision also established stricter post-incident procedures. A Work-Related Accident Report (CAT) must be issued by the first business day following a robbery, threat, or violent incident, even when the affected employee does not require medical leave. The company must also provide victims with free medical, psychological, and legal assistance, including support when reporting incidents to the police.
In addition, OXXO must revise and continuously update its Risk Management Program (PGR) and corresponding Action Plan, prioritizing collective protection measures and formally incorporating the level of external violence to which employees may be exposed.
Although the ruling remains a first-instance decision and is subject to appeal before the Regional Labor Court (TRT-15), the case has generated concern among business executives, legal departments, and corporate-security professionals. More importantly, it has intensified a broader debate over where the State’s responsibility for public security ends and the employer’s responsibility for workplace safety begins.
That distinction has significant implications beyond the convenience-store sector. If recurrent external criminal violence can become an occupational risk under certain operational conditions, companies may need to reconsider not only their security expenditures but also how business-model decisions themselves influence employee exposure and potential legal liability.
Arguments Against the Decision
Critics argue that the ruling risks transferring part of the State’s responsibility for public security to private employers. From this perspective, armed robberies committed by third parties are manifestations of urban crime rather than hazards inherently produced by retail activity. Although companies must identify foreseeable risks and maintain safe working conditions, opponents contend that employers should not become guarantors against every consequence of criminal violence occurring in and around their establishments.
They also emphasize that the company itself is a victim of criminal activity, sustaining property losses, business disruption, insurance costs, and reputational damage while employees may simultaneously suffer threats or physical harm. Holding the employer liable for repeated criminal acts, critics argue, risks imposing responsibility on one victim for failures originating primarily in the public-security environment.
A second concern relates to the proportionality and effectiveness of the security measures required. Night guards, reinforced barriers, panic systems, and access-control measures may reduce certain vulnerabilities, but critics argue that some controls could create additional risks. In particular, the presence of armed private security personnel in small retail stores could potentially escalate a robbery into an armed confrontation, increasing the consequences for employees, customers, and security personnel.

From a security-management perspective, opponents therefore argue that controls should result from technical, location-specific risk assessments rather than from generalized requirements. Store location, operating hours, incident history, staffing, surrounding crime patterns, and the effectiveness of existing controls should all influence the appropriate security model.
Finally, critics warn about the economic consequences of extending similar obligations across the retail sector. Extensive private-security requirements could significantly increase operating costs, particularly for low-margin businesses, independent retailers, and smaller companies. In high-crime areas, this could contribute to shorter operating hours, store closures, higher consumer prices, reduced investment, and job losses.
The criticism therefore centers on a fundamental question: how far must an employer go to mitigate foreseeable criminal exposure before corporate security begins to substitute for the State’s constitutional public-security function? Opponents favor clearer legal standards defining proportionate employer obligations according to business size, operating model, location, working hours, and demonstrated risk.
The Court’s Rationale: Foreseeable Risk and Employer Responsibility
The court’s reasoning, however, did not rest solely on the existence of urban crime. Instead, it focused on the interaction between repeated criminal incidents and specific characteristics of OXXO’s operating model.
Judge Karine Vaz de Melo Mattos Abreu highlighted the company’s large-scale structure, the location of stores in areas with different security conditions, their easy public access, and the presence of cash and products commonly targeted during robberies, like alcoholic beverages and tobacco.
The 24-hour operating model is particularly relevant. According to the case record, many stores operated late at night with only one employee and without permanent on-site security support. For the court, these conditions created a structural vulnerability exceeding the ordinary exposure of some other retail businesses. Because the model was replicated across multiple locations, the issue was interpreted not simply as localized criminality but as a recurring exposure partly shaped by operational decisions.
The volume of incidents reinforced this interpretation. Recorded robberies, thefts, mass-looting episodes, and break-ins in São Paulo stores increased from 320 cases in 2023 to 1,053 in 2024, with additional incidents reported during early 2025. The scale and recurrence of these events made the threat increasingly foreseeable rather than exceptional.

Another central issue was the nature of the security controls already in place. OXXO reported using a monitoring center, smart safes, surveillance cameras linked to public-security agencies, periodic patrols, police cooperation, crisis procedures, and employee training. Nevertheless, the court concluded that the existing system placed substantial emphasis on protecting property and responding to incidents rather than sufficiently reducing employee vulnerability.
The MPT also identified shortcomings in post-incident procedures. Workers were reportedly instructed to assess material losses and independently register incidents, while a comparison with Social Security data revealed employee absences associated with mental and behavioral disorders for which required Workplace Accident Reports had allegedly not been issued.
Reports from the Occupational Health Reference Center further described employees diagnosed with Post-Traumatic Stress Disorder following violent robberies. According to the case material, some relied on the public health system without adequate employer assistance, while internal incident documentation focused substantially on stolen cash and merchandise.
The distinction is critical. The ruling concerns recurrent incidents interacting with a systematic operational vulnerability, rather than employer liability arising from a single unpredictable robbery. In the court’s interpretation, measures designed primarily to limit financial losses did not sufficiently address the physical and psychological exposure experienced by workers.
Accordingly, the decision established that the State’s constitutional responsibility for public security does not eliminate the employer’s separate obligation to protect workers within the workplace. The court’s position was not that OXXO should replace public policing, but that it should adopt reasonable self-protection, organizational, occupational-health, and security measures within areas under its control.
Duty of Care: Connecting External Violence to Corporate Responsibility
This is where the Duty of Care owed by the employer to its employees provides a useful framework for understanding the dispute. The concept refers broadly to an organization’s obligation to exercise reasonable care to prevent foreseeable harm to employees, encompassing physical safety, security, health, and psychological well-being.
Applied to the OXXO case, the Duty of Care does not imply that a company must eliminate urban crime or guarantee that no employee will ever become the victim of a robbery. Rather, the relevant question is whether the organization has reasonably identified foreseeable exposure and taken proportionate measures within the areas it can control.
That distinction is particularly important because companies directly determine many of the conditions that influence employee vulnerability. They decide where stores operate, whether they remain open overnight, how many workers are present, how cash is handled, how customers enter the premises, what physical barriers are installed, how the employee is instructed to react to a criminal act, how incidents are reported and monitored, and what assistance is provided after a violent event. Public police forces respond to crime and enforce criminal law, but they do not design or manage these elements of the workplace.
Consequently, physical and technical security measures may not be sufficient. Cameras, smart safes, monitoring centers, alarms, and police cooperation can be valuable controls, but their effectiveness remains limited.
The Duty of Care owed by the employer to its employees therefore requires a shift from predominantly reactive security toward risk management. Companies should assess the threat profile of individual locations, examine incident patterns and operating hours, understand workforce exposure, select proportionate controls, train employees, and regularly determine whether those measures remain appropriate. This Duty of Care also extends the issue beyond the Security Department. Repeated external violence can affect occupational health, labor relations, legal liability, employee retention, productivity, reputation, and business continuity. Managing such exposure therefore requires coordination between Security, Human Resources, Legal and senior leadership.



