Overview
Personal data protection and privacy have gained prominence in the activities of companies and organizations in the most diverse sectors of industry. Best practices associated with the use of artificial intelligence, behavioral advertising, security incidents, Privacy by Design, digital compliance, cybersecurity, among others, have become keywords in a complex regulatory environment.
In Brazil, the General Data Protection Law – LGPD (Law No. 13,709/2018) governs the relevant procedures to be adopted by data controllers and data processors for the protection of personal data. Enacted in August 2018, the Law entered into force on September 18, 2020 and, since August 2021, sanctions and fines can be imposed by the Brazilian authorities to processing agents.
Since 2022, data protection has become part of the set of fundamental rights provided for in the Brazilian Constitution, offering greater legal certainty for citizens in the exercise of their rights and predictability for obligations on the part of controllers and processors.
The Brazilian data privacy legal framework has a concrete impact on the daily lives of individuals and companies, particularly considering:
- The complexity of matters related to personal data processed (collected, stored, manipulated, shared, transferred internationally);
- The sectorial and organizational aspects of the industry involved in the analysis and its activities in Brazil and abroad;
- Continuous demand to demonstrate data compliance to customers, visitors, employees, service providers, suppliers, insurance companies, as well as to governmental, regulatory, and judicial authorities;
- The sanctions and fines currently in force provided for by the LGPD and subject to the supervisory powers exercised by the National Data Protection Authority (the ‘ANPD’), in addition to its regulatory activities.
L.O Baptista´s Privacy and Data Protection team has highly qualified and seasoned privacy professionals who are prepared to advise companies in this procedure, which requires the mapping of the entire flow of personal data within the company and with its service providers and suppliers and the of internal procedures for compliance with the LGPD.
The performance of data privacy compliance related tasks by L.O. Baptista also covers data processing through internet applications and social networks by the company; analysis of gaps in communication and storage activities, drafting and validation of reports and institution of data policies, as well as effective control mechanisms so that the deadline for compliance is used efficiently.
Advice on privacy and protection of personal data
Our experience has shown us that the mapping and assessment phases are essential pillars to support a data privacy adequacy project in Brazil, but they are not the only ones. Sometimes critical business issues need to be prioritized.
For this reason, L.O. Baptista provides clients with dynamic advice and for this reason, L.O. Baptista provides clients with dynamic advice and interdependent work scopes, according to the client’s needs, with the aim at generating perfect synergy.
Scopes
- Mapping for inventories of personal data circulating in the areas and assessment of the processing of personal data carried out;
- Identification of Gaps (Gap Analysis) of activities and operations with personal data and resulting risk, from a legal point of view;
- Advice on regulatory impacts and risks to the business, along with recommendations for mitigating such risks;
- Structuring of Governance in Data Protection and Privacy, and drafting of an Action Plan for Data Controllers;
- Training and awareness projects for teams, management positions, business partners;
- Drafting of legal documents, including contracts with suppliers, clients, partners, and employees;
- Development of data policies and guidelines for sectors, departments, and specific demands;
- Update of Maturity Reports, Audits, and Project Recycling;
- Advice on the drafting and validation of Data Protection Impact Reports (RIPD) for risky activities to companies;
- Advice on security incidents for the preparation of impact reports and petitions to the National Personal Data Authority;
- Legal assistance for the application of privacy by design principles in new products, services and solutions;
- Drafting and legal review of client’s data instruments and policies, privacy safeguards, and plans for privacy defenses in commercial agreements;
- Consultancy in selection processes for appointment of the Data Protection Officer (DPO) and advice on the activities carried out by DPOs within this role[1];
- Advice on procedural issues and transactions related to international transfer of data, designing and validation of standard contractual clauses SCCs and sectorial compliance in multiple jurisdictions (European Union/GDPR, United Kingdom, Asia, and Americas);
- Advice on the drafting of technical documents and conceptual notes, contributions, and subsidies in public consultations, and gathering of specialized opinions for submission before Brazilian and foreign regulatory authorities;
- Advice to clients on plans for notifying personal data security incidents and disputes relating to information security;
- Representation of our clients in administrative proceedings before regulatory authorities, the National Data Protection Authority (‘ANDP’), in addition to legal proceedings, with strategic theses with general repercussions;
Further materials, publications and legal guides developed by Privacy and Data Protection Team at LO Baptista are available .
Team
(…)
[1] L.O. Baptista does not provide the service of Data Protection Officer/DPO as a Service, as it understands that the basic premise of the DPO function is independence in the decision-making process. In this case, the legal advice provided by L.O. Baptista works as a support to the Data Protection Officer/DPO, thus allowing the absence of conflicts of interest.