Table of Contents
Are you still lost on the subject of data protection and new legislation? This post is a guide for you to understand what the General Data Protection Law is, to know if your company should comply, and how you can act to protect the data of your customers and employees in practice.
GDPR: The General Data Protection Law
The LGPD regulates the processing of personal data, from collection to deletion.This will require companies to change their culture regarding how they have previously handled the personal data of data subjects. The law includes a list of rights for data subjects that must be observed, especially when it involves advertising and the use of contact information.
Today, data is considered more valuable than oil. Coupled with this overvaluation, we have had numerous scandals involving the misuse of data and violations of privacy, which has forced the adoption of more effective measures to guarantee the protection of this data.
Concern for the personal data of owners and users has never been a priority, which makes this journey of adapting to the new law even more complex. Therefore, it is essential for companies to use disruptive solutions to automate processes, making them simpler.
Penalties for violations of the law
The LGPD (Brazilian General Data Protection Law) stipulates the following penalties for companies that fail to comply with it:
- Administrative warning;
- A daily or total fine of up to 2% of total revenue, limited to R$ 50 million per infraction;
- Publicizing information – risk to image;
- Obligation to repair any damage caused as a result of improper data handling.
To whom does the law apply?
The LGPD applies to any company that collects, stores, or processes personal data.Regardless of the medium, the country of their headquarters, or the country where they are located, provided that this personal data was collected in Brazil.
The amount of data stored or the company's segment are not factors that influence the duty to protect data.
First steps towards compliance.
One approach that helps in this process is Data Mapping, since the premise is that what you can't see, you can't protect.
Mapping provides a greater understanding of how data moves through the organization. Since companies need to understand what data they are collecting, how they are using it, and with whom they are sharing it to improve data protection, it is an important initial step in the compliance journey.
Another important step is fulfilling the duty of transparency. This means informing the user about how this data is processed, its purposes, duration, and other information regarding its use. This can be done by developing policies aimed at providing the user with visibility into this data collection and processing.
In this way, everyone who accesses your website or portal can learn about how this data is collected and used. There are different types of policies which may be present on a website, but the main and essential ones are: Privacy Policy (or security terms and conditions), Cookie Policy, and Terms of Use.
There should also be a banner on the website allowing users to give or withhold consent for the collection of data by [the company/service]. Cookies.



















