Publications

How to make the most of the time for entering in compliance with LGPD

How to make the most of the time for entering in compliance with LGPD

10/3/2019

Less than a year remains until the General Data Protection Law – LGPD, there is not time to lose: everyone needs to know the personal data flows within its structure and adjusting it to LGPD.

This newsletter aims to outline a project of compliance with the law and point directions to the creation and implementation of a data governance program.

Although the efforts necessary for a company to comply with LGPD are influenced by a series of factors that vary between companies, a compliance project has mainly two fronts, both essential for achieving and maintaining compliance: (1) changing the company’s culture; and (2) revision of internal documents, policies and procedures.

It is recommendable that the company creates a multidisciplinary group, with members of different areas, to guide the compliance project, so that all the areas collaborate to the compliance process and it considers all area’s particularities.

Changing the company’s culture aims to internalize practices related to data privacy and make it a natural characteristic of the company’s functioning, being transparent with clients, employees, the authority and society.

The start point for companies’ document revision is getting to know all the personal data it holds and process, how they are processed and for which purpose. From this knowledge, companies must evaluate what must be adapted to observe the law’s principles and the data subject’s rights and adopt appropriate measures and create internal proceedings that observe the principles, requirements and rights established by LGPD.

In order to achieve this, it is necessary to educate the employees on the law, its role and importance within the company and train them to abide by the company’s internal proceedings. The trainings and education shall be directed to all the hierarchical levels of the company so that the compliance project has the most efficacy possible.

Once the company is compliant, it reaches the final phase of the project, maintaining the compliant status and the multidisciplinary group that guided the compliance process shall remain active to update the data governance structure resulting from the compliance project.

Finally, companies must implement system and network security measures in order to assure that all the compliance measures are not easily overruled through an unprotected system. The process of compliance with LGPD shall be seen as an opportunity to strengthen the information security within companies.

Related Posts
Tags