Skip to Content

One year of LGPD: what has already changed in companies?

August 28, 2019 by
One year of LGPD: what has already changed in companies?
Kleber Leal by Zamak Portal
In 2018, then-President Michel Temer signed the General Data Protection Law, also known as LGPD. However, the law will only come into effect on August 16, 2020, in less than a year. Are companies already prepared to adapt to the new rules? Today, the situation of Brazilian companies across different sectors can be divided into two scenarios: data mapping and the implementation of new routines and practices in handling this information. According to the vice president of Gartner, there are no cases yet of companies that have already implemented actions to comply with the LGPD. However, the financial and retail sectors are in an advanced process to finalize the transition. Implementation The delay in implementing the standards set by the new law is due to the wait for some important LGPD definitions, as well as the approval of the National Data Protection Authority (ANPD). The original LGPD text included the authority, but it ended up being excluded from the proposal signed by Temer. In December of last year, near the end of his term, Temer recreated the ANPD through a provisional measure that could only become permanent if approved by the National Congress. This happened only in July of this year. Now, the Senate needs to choose five directors for the data authority. Officially, the government has no nominations for the positions yet. Data Protection Officer Another important change resulting from the approval of the LGPD was the selection of the data protection officer (DPO). In general terms, this professional will serve as the link between the company and the ANPD, providing information and even reports on data processing. With less than a year until the law is implemented, it is important to define the profile of this professional within companies. Some opt for individuals linked to the legal area (lawyers, for example), while others prefer an executive from the Information Technology area. However, ombudsmen are also taking on this role since they have experience in the field and handle company and employee data. Source: Consumidor Moderno

Frequently asked questions

What is Brazil's LGPD and when did it take effect?

Brazil's LGPD (General Data Protection Law) was signed into law in 2018 by then President Michel Temer and was set to take effect on August 16, 2020. The law created new requirements for how companies collect, handle and protect personal data.

Why was LGPD implementation delayed at companies?

The delay stemmed from companies waiting on key definitions in the law and on the formal approval of Brazil's National Data Protection Authority (ANPD), which had been left out of the bill Temer originally signed. He later recreated the ANPD by provisional measure, but it only became permanent once Congress approved it in July, and the Senate still had to appoint the authority's five directors.

Who should take on the data protection officer (DPO) role under LGPD?

The data protection officer (DPO) acts as the link between a company and the ANPD, providing information and reports on how personal data is processed. According to the article, some companies assign the role to legal professionals such as lawyers, others to IT executives, and ombudsmen have also taken it on because they already handle company and employee data.

One year of LGPD: what has already changed in companies?
Kleber Leal by Zamak Portal August 28, 2019
Share this post
Tags
Archive