LGPD puts unprecedented pressure on companies' technology leaders
In effect in Brazil since September 2020, the General Data Protection Law (LGPD), Brazil's data protection law, created a series of rules for companies, and it has now entered a new phase.

In effect in Brazil since September 2020, the General Data Protection Law (LGPD), Brazil's data protection law, which created a series of rules for companies that, in one way or another, process data, entered a new phase this past August. From now on, the sanctions set out in the law for companies that did not properly prepare to protect their data and ended up suffering leaks will begin to be applied. In the case of a small or medium-sized company, the heavy fines stipulated by the law can, in extreme cases, lead to the business shutting down.
Popular wisdom in our country says that “Brazilians leave everything to the last minute,” and this case is no different. A survey conducted by BluePex in July, with around a thousand SMEs, showed that only 4% of them claim to be fully compliant with LGPD rules. In other words, 96% are racing against the clock, or already dealing with the damage. It's time to wake up to the problem.
This scenario, which can be catastrophic for companies, has become a nightmare for the people responsible for information technology at SMEs. Unlike large corporations, where there are bigger, better-prepared teams, compliance rules, and greater organization around information security, at smaller businesses handling this “seven-headed monster” called LGPD is seen as “the IT guy's responsibility.”
Figures from the same survey conducted by BluePex show the scale of this problem: 37% of those companies, that is, more than a third of them, believe that LGPD compliance is exclusively the responsibility of the Information Technology department.
This shows a significant lack of understanding of the aspects of this crucial legislation: since data permeates practically every area of a modern organization (such as HR, customer service, marketing, legal, finance, etc.), it is natural that those responsible for these areas should also be involved and share responsibility for the compliance process.
Of course, IT will also play a leading role in this process, responsible for conducting and implementing all the necessary security procedures in the collection, storage, and processing of digital information and data. But this “burden” can in no way be transferred 100% onto technology professionals.
But how do you change company leadership's thinking on this? Looking for reliable technology partners and information security services that can help the company through this process and show senior management the scale of LGPD's impact across the different areas is, in my opinion, the best way forward.
Leaving “the IT guy” with full responsibility for compliance with the new law is a major mistake that many companies are making. Not because these professionals lack competence, but because of the obvious need for the whole company to be involved for this process to succeed. Ignoring this can prove very costly down the road.
Translated from the Brazilian Portuguese original · Read the original