Data Protection: Provision published to ensure compliance by registry offices.

Estimated reading time: 2 minutes

Summary

The document, which aims adapting notary offices to the LGPD (Brazilian General Data Protection Law)This corrects some flaws from a preliminary version that had been published previously, although it has not yet managed to clarify certain doubts regarding some procedures.

The General Data Protection Law came into effect two years ago, but there is still much to be done before we can truly celebrate the maturity of the privacy and data protection landscape, which is only just beginning in the country.

There is still a lot of work ahead. 

There are several gaps that will be filled over the years. However, things are happening. 

An example of this is that, a few months after the National Justice Inspectorate conducted a public consultation, it was published... Provision 134/22 which establishes the guidelines that must be followed by registries from the entire country.

Key points about the document

Among the key points of the document, we can list:

  • Governance

The Provision establishes guidelines to be followed regarding personal data governanceIt also establishes the technical procedures and measures that must be adopted, such as the implementation of technical and administrative measures aimed at protecting personal data, the creation of an Internal Privacy and Data Protection Policy, and the review of contracts.

In the pursuit of compliance, it will be necessary to redesign internal processes, changing behaviors, investing in technologies, and constantly updating the team, in order to maintain more adequate management of the data processed on-site.

  • DPO appointment

The data protection officer, or DPOThe notary public is an indispensable figure in the context of privacy and data protection, and their presence is also mandatory in notary offices.

According to the Provision:

"Article 10. A person in charge of processing personal data must be designated, in accordance with the provisions of Article 41 of the LGPD…".

  • Data mapping

Among the procedures outlined in the Provision, the following stands out: data mapping personal. 

According to Article 7 of the Provision:

"§ 2 The person responsible for the extrajudicial service may use forms and computer programs adapted to each specialty of service for recording the flow of personal data, covering all phases of its life cycle during processing, such as collection, storage and sharing, eventually made available by professional associations of notaries and registrars."

Furthermore, data mapping should be carried out annually or whenever necessary, which will require greater organization on the part of the registry offices.

The Provision, despite still having several areas for improvement, represents progress towards adapting registry offices throughout the country to... General Law of Data ProtectionBecause, as places where the daily flow of personal data is absurdly large, leaving them without guidelines to operate within the law would be completely out of context.

The LGPD (Brazilian General Data Protection Law) is here to stay, showing that Brazil is not playing around when it comes to protecting personal data.

The complete document with all the guidelines can be viewed at the following link: https://atos.cnj.jus.br/files/original1413072022082563078373a0892.pdf

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also