LGPD: Manage supplier risk

Estimated reading time: 2 minutes

Summary

Is your company in the process of adapting to the LGPD (General Data Protection Law)? In addition to considering the protection your company will provide for the personal data of customers and employees, it's necessary to pay attention to how suppliers handle this information.

Let's say your company is a client of a marketing agency that has the names, emails, and phone numbers of its clients to send content and advertising: this agency also needs to be in compliance with the LGPD (Brazilian General Data Protection Law) so that its clients are safe!

Similarly, a logistics company also has access to various data, such as names, addresses, and purchases made by its customers. Do they implement preventative measures to ensure this information is not leaked?

For your company to be more compliant with the new law, your suppliers also need to be. First of all, however, you need to "take a snapshot" of your current situation. Do you know how many suppliers share your data with and in what way?

 

Study the lifecycle of personal data.

 

To understand the risk posed by third parties regarding your customers' information, you need to perform Data Mapping. This process will allow you to visualize the entire path taken by the information: how it is collected, how it is processed, how it is shared, and how it is discarded.

This way, you'll quickly see how many companies share this data with and then evaluate, on a case-by-case basis, how well data is protected in that business relationship.

with the tool Data Mapping from Privacy ToolsYou have control over the risks of the operators who process personal data. You can also conduct diagnostic interviews and monitor the maturity level of each supplier, perform an assessment, and record the results. due diligence.

 

Have a plan for incident scenarios.

 

Even if you use the right tools and have good control over the flow of personal data, the risk exists, and you need to have an action plan prepared for such situations. With the LGPD (Brazilian General Data Protection Law) in effect, you need to report to the ANPD (National Data Protection Authority), so your company's DPO/Data Protection Officer needs a clear direction to follow.

To help your organization in this process, the module of Privacy Tools Incident Management It automates alerts regarding violations of privacy and data protection laws, allowing for a quick response and the provision of appropriate notifications.

The tool also allows you to identify which data was affected by a breach, how it is used, who has access to it, and how it flows, among other functionalities. This is strategic information in the investigation of a data breach.

It is also possible to identify the path of an incident and, in this way, demonstrate compliance with audits by needing to retrace steps to detail situations and correct configurations.

Take your free trial and experience firsthand the tools that will make it easier to comply with the LGPD (Brazilian General Data Protection Law) and minimize risks with your suppliers! Click here and register.

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also