Starting this month, it is expected that fines resulting from violations of the General Data Protection Law can finally be applied. Until now, due to a bureaucratic issue with the ANPD (National Data Protection Authority), these fines could not yet be enforced.
According to the announcement regarding the local authority's agenda, the resolution allowing the sanctions to be applied is still scheduled to be published in October.
Since Provisional Measure No. 1.124/22 was published, there has been an expectation about when the ANPD The National Data Protection Authority, now a special type of federal agency, could begin its work of enforcing the law. It seems the wait is finally over.
ANPD is already processing internal investigations into infractions.
According to lawyer Daniel Faidiga: “The legal and administrative security of the agency has become a priority. ANDP has been structuring itself to respond to infractions in a more expeditious and focused manner, and is close to finalizing the regulations for sanctions and methodologies that establish the dosage and calculation of fines. Therefore, being deficient in this adaptation could result in sanctions of significant value.”
The expectation is that, now that it will be possible to application of fines and sanctionsfor companies to truly become aware of the importance of being compliant with the LGPD (Brazilian General Data Protection Law)Because, in addition to the fact that disagreements pose a risk to the company's image, they represent an even greater risk to customers who, besides becoming vulnerable, also lose trust in the companies to which they have given their personal information.
"The transformation of ANDP into a special autonomous agency threatens those who are careless and confidently believe that LGPD is overrated, and that mere adjustments to contractual clauses, without specialized legal guidance, would eliminate any and all risk.""Daniel points out."
Data Protection Officers (DPOs) need to review privacy policies.
The lawyer also points out the need for companies to appoint their data protection officers and that they review and update the privacy policiesFurthermore, it also highlights how necessary it is for companies to provide proper training to their employees.
"It is also necessary to appoint a DPO (data protection officer), a professional responsible for the relationship between data subjects, regulatory bodies, and the company, as well as having a privacy channel for receiving requests from data subjects, bringing greater transparency and avoiding possible red flags in internal and, especially, external audits.""says Daniel."
Finally, it is worth highlighting that any company caught in violation of the regulations may face sanctions ranging from a warning to a fine of up to 2% of the company's revenue, or ultimately, the blocking of data or suspension of the company's data processing activities for six months.
“It is necessary to invest in raising employee awareness and properly training the team on security devices. It is also essential that everyone signs a confidentiality agreement. Employees know that if data is leaked, they can be dismissed, even for just cause.”"That's all," concludes Daniel Honório, data manager at Link Certificação Digital.



















