Journal

Other

The General Data Protection Act (LGPD) is already in effect, and now what?

If you or your company still don't take LGPD seriously, it's time to adjust, so you don't have to pay a fine later. Although it is worth it, sanctions are not beginning to apply until next year. But it's good to get into everything and how to apply it in practice. That's it [...]

· · 8 min read

The General Data Protection Act (LGPD) is already in effect, and now what?

If you or your company still don't take LGPD seriously, it's time to adjust, so you don't have to pay a fine later. Although it is worth it, sanctions are not beginning to apply until next year. 

But it's good to get into everything and how to apply it in practice. That's what I'm going to show you in this article:

In force since 18 September, the General Data Protection Actsanctioned by the federal government, determines that companies and public agencies will have to make it very clear to users in Brazil how the collection, storage and use of personal data will be done, among other details. 

With some exceptions, the data subject will have the power to consent to use it or not and may also request the deletion of the information if necessary. 

If for some reason the law is broken, companies will be warned and fined. The penalty application for those who disobey the new rules was postponed to August 2021.


Read also


And the punishment is no joke: fines can reach up to 2% of the company's revenue, under the limit of up to R $ 50 million. 

LGPD states that it does not matter whether the headquarters of an organization or its data center are located in Brazil or abroad: if there is the processing of content of people, Brazilian or not, who are in the national territory, the law must be complied with. 

It also determines that data can be shared with international bodies and other countries, provided that this occurs from safe protocols and/or to comply with legal requirements.

Consent for data use

Another essential element of LGPD is consent. That is, the consent of the citizen is the basis for personal data to be processed. 

It is possible to treat data without consent if this is indispensable to: comply with a legal obligation; execute public policy provided by law; conduct studies by research agency; execute contracts; defend rights in process; preserve the life and physical integrity of a person; protect actions taken by health professionals; prevent fraud against the holder; protect credit; or meet a legitimate interest, which does not undermine fundamental rights of the citizen.

Automation with authorisation

The law also provides several guarantees. The user may request that his data be deleted, revoke consent, transfer data to another service provider, among other actions. 

Data processing should be done taking into account some questions, such as purpose and need, which must be previously agreed and informed.

For example, if the purpose of a treatment, performed exclusively in an automated way, is to build a profile (personal, professional, consumer, credit), the person should be informed that he can intervene, requesting a review of this procedure by machines.

DPD and treatment agents

For the law to “hold”, the country will have the National Personal Data Protection Authority, ANPD. The institution will monitor and, if the LGPD is not executed, penalize. In addition, the ANPD will of course have the tasks of regulating and guiding, preventively, how to apply the law. Citizens and organizations can collaborate with the authority.

But it is not enough for the ANPD – which is in formation. 

That is why the General Personal Data Protection Act also provides for data processing agents and their functions in organizations: 

  • The controller, making decisions on treatment; 
  • The operator, which carries out the treatment on behalf of the controller; 
  • The foreman, which interacts with citizens and national authority (and may or may not be required, depending on the type or size of the organization and the volume of data processed).

Focus management

There is another item that could not be left out: the management of risks and failures. This means that those who manage personal database will have to draw up governance standards; adopt security preventive measures; replicate existing good practices and certifications in the market. You will also have to draw up contingency plans; audit; resolve incidents with agility. 

What to do in practice?

In addition to the treatment agents mentioned above, other actions should be planned thinking about how to adjust to LGPD. 

Data audit is fundamental

Your company's auditors will be responsible for examining the system by analyzing the data storage, historical, access logs and shared settings.

Auditing is important to leave nothing behind serving to verify the security of the system data regarding access control, backups and recovery plan, as well as analyzing the profile of the stored data as to its quality, integration and processing.

Review data security policies

To be in agreement with LGPD, it is important to review the company's data security policies, as there are always threats of malicious software.

Strengthening the security of systems and guiding employees about the data security procedures to be adopted is a great strategy.

It is recommended to draw up the company's data security policies containing information on the conditions of installation of equipment, access restrictions, appropriate procedures, control, etc. and share them with all the people in the organization for greater engagement in information security.

Review your contracts

Contract review is one of the most important items of the new law. It is necessary to adapt this document to meet the confidentiality, transparency and freedom standards of users.

According to LGPD, the contract must make clear for what purposes the personal data will be used, as well as information on the processing of data as to its duration, shared use, controller identification and responsibilities of the processing agents.

It is necessary to remember that the document should provide for data collection and portability to other servers, as guaranteed by law.

Privacy Policy

You still don't have a privacy policy for your business? Put it in your plan right now! 

The more transparent and appropriate LGPD is your company in the use of user data and information, the more security you will have to avoid future problems. 

Creating a privacy policy is not such a complicated thing and it has many tips on the internet for you to inspire and use as a reference. If you already have, try to update according to the new requirements. 

Authorisation for the use of cookies

Does your website already have a pop-up or banner that alerts you about the use of cookies when accessing the content of the pages? It is another important item that should be taken into consideration. 

Cookies are identifiers that can be generated or collected from the browser or device you use in order to provide a page for you to access or identify your browsing profile.

Ease the exit

Avoid difficulties for the user or lead cancel a subscription, unregister from an email list or even stop receiving communications from your company. Hidden buttons and unintuitive processes and ineffective processes are common practices to make it difficult to leave a Lead. That shouldn't happen again.

Make it clear to people that they have the right to withdraw their consent at any time and how to do so. From the General Data Protection Act, withdrawing consent should be as easy as it was to provide it.

Conclusion

As you have noticed so far, in addition to dedication of personnel, financial effort is also needed, which given the current pandemic scenario, has become an aggravating to achieve compliance with the law. 

That's why I'm hitting the key that you or your company should start this adaptation process as soon as possible. Understand that the sooner the company starts the survey, the sooner it will be able to initiate actions that will positively impact the increase in the required maturity level.

To close the matter, there are two important points to be highlighted: 

  • The law affects companies of all sizes, from law firms, medical offices, real estate and self-employed professionals of various segments, even public departments. 
  • The fact that the ANPD sanctions can only be applied from August 2021, will not prevent the application of penalties by other bodies, such as the Public Prosecutor or Procon, based on the rights of the holders, since the Law will be in force.

Did you like this article, have any questions or suggestions? Comment down.

See you in the next post! 

Gustavo Trentini · Nacionalvox

Let's talk

What is your next move?

Tell Nacionalvox what your company wants to transform.

Let's talk