Summary of the last Privacy Tools event: LGPD in the new government

Estimated reading time: 4 minutes

Summary

Did you miss our last free live event? Check out the description of some of the highlights from the live stream here!

Immediately after the guests' introductions, Aline Deparis, CEO of Privacy Tools, posed the following question to the guests: "After four years of the LGPD (Brazilian General Data Protection Law), how do you view the adaptation of federal agencies and the way in which the data of millions of Brazilians is handled?"

Public institutions also need to comply with the LGPD (Brazilian General Data Protection Law). Data subjects do not have the option of not providing their data to public institutions. Graziela Kleinubing commented on the difficulties she sees in organizations.

Adaptation in public bodies

“I see a very large gap in the adequacy of public bodies, not only federal ones, but also state and municipal ones – which, as we know, especially the municipal ones, have many difficulties. […] Public administration as a whole already has many challenges. […] We see an even greater challenge for public managers to adapt to this. In addition to all these [problems], we have to think about the difficulty of hiring qualified professionals many times. […] There are excellent, highly qualified professionals on the market, but we still don't have enough professionals to meet the entire market demand.”

Graziela is a DPO certified by ECPC-B from Maastricht University in the Netherlands. She teaches LGPD (Brazilian General Data Protection Law) courses at UNISUL and holds a Master's degree in Public Policy Management.

Next, immediately after Graziela finished speaking, she turned to Isabella, DPO of the Boticário Group, who continued to respond and add to the context.

Isabella spoke about her experience as a DPO (Data Protection Officer) at one of the major Brazilian cosmetics companies and how the issue is being handled. She also discussed how compliance must involve a cultural shift, with transparency in treatment.

Data Ethics

“The LGPD [Brazilian General Data Protection Law], it's just one, although it's the most important, but it's only one of the laws that should support privacy professionals. And considering that we recently changed the name of our area at Grupo Boticário, it's no longer 'privacy.' It's 'data ethics.' I want to process personal data. I must process personal data, and I think this change in mindset should also occur within federal and municipal agencies, within the public sphere – which is precisely to stop viewing the issue of data privacy as something inherent to fines, inherent to sanctions. […] The adaptation project begins precisely with a cultural change. It begins with professionals understanding – from the public or private sphere – that data will indeed be processed; it doesn't need to be hidden. It will continue in our daily lives, but it will be processed ethically and securely.”

Then it's Gutierrez's turn. The secretary-general of the LGPD business forum, political scientist, government affairs and public policy executive, researcher, and professor, he comments on how organizations treat these issues and what digital transformation should look like.

As a possible solution, Andriei highlights interoperability, which is the existence of two components of a system, developed with different tools from different vendors, that may or may not work together. The systems can exchange data to achieve expected results. Transparency, one of the principles of the LGPD (Brazilian General Data Protection Law), is also mentioned.

data governance

“Privacy, data governance, information security, [all of them] have to be at the top of the organization's digital transformation strategy. I think this is also increasingly valid in the public sector. […] It is extremely important to have, on the same scale, with the same weight and the same degree of importance at the top, empowered in the structure, – data interoperability and transparency.”

After the three guests spoke, Arthur P Sabbat, Director of the Board of Directors of ANPD, joined the conversation, and some points were highlighted regarding trends for 2023:

Evolution of dosimetry and the LGPD in the new government

Sentencing guidelines are the calculations used to determine the appropriate punishment for a crime. The body responsible for regulating sentencing guidelines and the application of administrative sanctions is the National Data Protection Authority (ANPD). Arthur Sabbat updated the guests on the situation.

Arthur P Sabbat: “What is the current status of the dosimetry [of data enforcement]? It is currently with our specialized federal prosecutor's office, which should soon issue an opinion on the final version of this draft. This draft will then be updated. The Secretary-General will randomly select one of the ANPD directors to be the rapporteur for this regulation. I believe that by mid-February this regulation should be public… It is a truly complex regulation; it has become quite dense, and it establishes the levels, parameters, and criteria that will determine for the ANPD the severity of a violation. Without criteria for the severity of a violation, it is impossible to assess whether an LGPD violation will have a greater or lesser impact on the holders of personal data.”

According to a publication on gov.br, where the Dosimetry Regulation is published, it is clear that the ANPD aims to build a model for applying sanctions that induces appropriate behavior in accordance with the LGPD, rewarding virtuous regulated entities, those who comply with the regulation, offering guidance and promoting awareness. 

Continuing his speech, Arthur emphasizes: “The ANPD (National Data Protection Authority) should establish regulations for the recognition of good practices, rules of good practice by public and private controllers. The ANPD has to establish these regulations. We haven't done that yet, but it's on our agenda. Just as we will resolve and settle aspects related to sensitive personal data, when it comes to biometric data… The ANPD has a clear duty to discuss this.”

A question regarding data processing involving small and medium-sized enterprises (SMEs) is posed to Gutierrez. The search for professionals in this area can be a challenge for SMEs. The role of a Data Protection Officer (DPO) in such a company and the need for more public policies were used as a reference.

Question: How can the government foster collective development in the medium and short term to ensure data adequacy?

Andriei Gutierrez's second statement: […] The challenge for these people is immense. You're going to hire a DPO, a privacy officer, for a small or medium-sized company, and not even the owner earns what the DPO earns in a large company. […] I think we need to work hard to have these public policies to encourage this.

To watch the entire live stream, go to: https://www.youtube.com/watch?v=i8HkAUp3sAM&t=1242s

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also