Every company that handles personal data needs to comply with the General Data Protection Law (LGPD), which has been in effect since last year. With the new law, every organization must adopt measures to protect personal data and ensure that every citizen has rights over their information.
In banking institutions, this means that customer information needs to be protected against leaks, especially when it comes to credit cards, transactions, CPF numbers (Brazilian tax identification numbers), etc. It is also the right of every person not to be bothered with calls offering financial services, nor to receive unauthorized SMS messages.
On May 11th, Privacy Tools held an online event with several prominent figures in the financial market to share their experiences with the LGPD (Brazilian General Data Protection Law) in practice. Check out the main insights:
- Privacy and customer service go hand in hand: Mariana Caparelli (Head of Privacy and Data Protection and DPO at Nubank) spoke about the importance of the relationship with data subjects and preventing them from having doubts about privacy. "Something that Nubank has always upheld is excellence in customer service," she added.
- Transparency with customers: Paulo Tavares (Lawyer, Senior Information Security Analyst at EBANX) recommends paying attention to basic aspects such as the purpose of data collection, supplier assessment, and the principle of transparency. "Sharing with your users which suppliers you share information with" is also advice from the EBANX analyst.
- Process standardization: Marcelo Menezes (Project Manager at the Bank of the State of Sergipe), regarding data portability between institutions, reinforced: "when a standard is created and followed by everyone, it's good for everyone."
- Get to know the suppliers: Tavares also mentioned the importance of knowing about the data collection, processing, and disposal processes of financial institutions' suppliers, as well as the security procedures they use.
- Financial institutions have already taken the lead: Mariana recalled that, in order to comply with Central Bank regulations, Nubank already had a plan for incident cases, so it didn't only start thinking about privacy when the LGPD (Brazilian General Data Protection Law) came into effect.
- It's important to have evidence.Menezes, in his speech during the event, reinforced the importance of accurate evidence to know what happened in the event of any incident. In other words, it is important to have records of each stage of data processing.
- The entire team needs to be aligned.According to Tavares, having a team that spreads the word about safety within the company is important. Gamifying this knowledge could be a solution.
- Response to two regulatorsIn the event of incidents involving personal data, there are two authorities involved: the ANPD (National Data Protection Authority) and the Central Bank. Mariana revealed that it is still unclear what institutions should do in these cases, and they are still awaiting guidance on incident management. "The Impact Assessment Report is also something that needs to be regulated and will provide a bit more security," she added.
The chat, which was led by Privacy Tools CFO Daniela Duarte, lasted 1 hour and can be viewed at [link/website address]. Privacy Tools YouTube channel.



















