Through informal conversations, exchanges of experiences, and life lessons, I've noticed that many projects aimed at adapting companies to the General Data Protection Law end without any prospect of further development as a privacy and data protection program.
Basically, by force of law, the project is contracted to: map personal data processing activities, identify operating systems, what is shared with which third parties, conduct structural and procedural risk analysis, launch some brief updates, write a policy, implement a cookie banner, and appoint a data protection officer. Interviews, dozens of files, and delivery do not guarantee compliance with the regulation. If "guarantee" is already a very strong word in any context, here, a project is definitely not capable of maintaining compliance.

Transforming an adaptation project into a program that is part of an organization's value chain means transforming the twenty-five percent of law into one hundred percent of continuous management. I realize and argue that, often, the problem lies in the absence or distance, as a rule of the Portuguese language, of the subject from the predicate. In this specific case, the one who gave birth to Matthew is not always the one who maintains and nurtures him, except in very rare exceptions.
It's not at all simple to envision the next steps and move forward. It's not always just about technology, but always about people. People are always the weakest link when it comes to risks and vulnerabilities, but here, they are the strong point. In fact, they are even the secret. It is people with a very holistic vision who can handle the interdisciplinary nature of the agenda, who can identify program gaps, measure maturity, generate action plans for themselves and other business areas of the company, evaluate clauses, point out requirements, assign legal basis, generate impact reports, review and generate new activity mappings.
If one swallow doesn't make a summer, a single professional also cannot maintain or improve compliance. If a team isn't enough, a committee will suffice. But always with a leader who has a vision of governance, of the need for other complementary areas of expertise, such as legal, processes, risks, information security… The LGPD (Brazilian General Data Protection Law) is complex but doesn't have to be difficult; it needs to be well implemented, well managed, and well conducted in its multiple facets.
A privacy program is like a noble sentiment that needs to be nurtured and cared for every day so that it doesn't die of starvation. It is alive and must reflect organizational changes.
Resist the fallacies of cookie-cutter recipes and always invest in people.
Have you already adapted to the LGPD (Brazilian General Data Protection Law)? Then read on and demystify the... best practices for consent management in this blog post.
{:} {: en}Through informal conversations, exchanges of experiences, and life lessons, I've noticed that many projects aimed at adapting companies to the General Data Protection Law end without any prospect of further development as a privacy and data protection program.
Basically, by force of law, the project is contracted to: map personal data processing activities, identify operating systems, what is shared with which third parties, conduct structural and procedural risk analysis, launch some brief updates, write a policy, implement a cookie banner, and appoint a data protection officer. Interviews, dozens of files, and delivery do not guarantee compliance with the regulation. If "guarantee" is already a very strong word in any context, here, a project is definitely not capable of maintaining compliance.

Transforming an adaptation project into a program that is part of an organization's value chain means transforming the twenty-five percent of law into one hundred percent of continuous management. I realize and argue that, often, the problem lies in the absence or distance, as a rule of the Portuguese language, of the subject from the predicate. In this specific case, the one who gave birth to Matthew is not always the one who maintains and nurtures him, except in very rare exceptions.
It's not at all simple to envision the next steps and move forward. It's not always just about technology, but always about people. People are always the weakest link when it comes to risks and vulnerabilities, but here, they are the strong point. In fact, they are even the secret. It is people with a very holistic vision who can handle the interdisciplinary nature of the agenda, who can identify program gaps, measure maturity, generate action plans for themselves and other business areas of the company, evaluate clauses, point out requirements, assign legal basis, generate impact reports, review and generate new activity mappings.
If one swallow doesn't make a summer, a single professional also cannot maintain or improve compliance. If a team isn't enough, a committee will suffice. But always with a leader who has a vision of governance, of the need for other complementary areas of expertise, such as legal, processes, risks, information security… The LGPD (Brazilian General Data Protection Law) is complex but doesn't have to be difficult; it needs to be well implemented, well managed, and well conducted in its multiple facets.
A privacy program is like a noble sentiment that needs to be nurtured and cared for every day so that it doesn't die of starvation. It is alive and must reflect organizational changes.
Resist the fallacies of cookie-cutter recipes and always invest in people.
Have you already adapted to the LGPD (Brazilian General Data Protection Law)? Then read on and demystify the... best practices for consent management in this blog post.
{:}



















