How to use Brazil's LGPD for compliance and innovation?
The past few months have been a period of adaptation, at this early stage of enforcement of Brazil's General Data Protection Law (LGPD), with authorities now taking action.

The past few months have been a period of adaptation, at this early stage, in August, of the enforcement of administrative sanctions under the General Data Protection Law (LGPD), that is, the genuine and legitimate action of the public authority on the matter.
In this context, it is necessary for off-the-shelf experts to stop buying into the fast-food notion that the LGPD is a piece of legislation full of countless prohibitions and lacking practical instruments for solving problems. Another notion from the canned-goods sector is the perception that Brazil's National Data Protection Authority (ANPD), Brazil's data protection authority, will act with extreme patience, passively waiting for companies to adopt compliance practices.
Extremes are expired products that need to be promptly discarded. The urgent need of this moment is to deconstruct myths about the LGPD and data protection that have so far been widely spread.
The digitalization of supply chains, the transition of operations from the physical to the virtual environment, and the intense awareness of the use of technologies guided by a Data Driven approach have made the use and importance of data in business operations take on proportions of necessity and speed previously unimaginable.
Thus, the LGPD follows the example and structure of most privacy laws by bringing rules aimed at ensuring the adoption of new governance practices, cybersecurity, and the organization of the system for intercepting and massively collecting data. The stance of the compliance officer for this Law should be to interpret its precepts under the aegis of technological neutrality and a global system of best practices.
With this foundation, one should not focus on prohibition itself when there is the opportunity to understand new technologies and tools that can be applied to the business so that what is already being done can be done more securely and efficiently. The roles of the CISO (Chief Information Security Officer), the CIO (Chief Information Officer), and the DPO (Data Protection Officer) intersect precisely in this work.
The interoperational dialogue between these managers of the company's Information Security and Privacy should always aim to build new solutions and processes capable of continuing to generate revenue, while also analyzing the environment in which the activity takes place in order to minimize risks, mitigate vulnerabilities, and adopt the technological resources and procedures that will ensure security.
From a privacy standpoint, in this field, the concern should be to adapt the process so that it collects the minimum amount of data possible and more efficiently achieves the objectives intended by the purpose developed in the risk analysis. The Law should, therefore, be an engine of creativity and possible innovations in the model of how the activity is carried out.
The organization of suitability by financial institutions follows the creative approach model presented. The process for verifying a client's suitability for an investment portfolio collects a set of data that will generate new information regarding profile, risk appetite, and loss tolerance. The activity is highly regulated and necessary to minimize losses and improve the level of personalization in the relationship between client and financial institution.
Another interesting example is the activity some retailers use of collecting personal data to obtain an individualized consumption profile. With this personalization, the data subject would receive offer communications based on their potential individual interest.
The trade-off, in this case, is extremely positive for both parties, since among the many benefits we can cite is a business relationship with greater personalization and increased purchasing potential. Again, the concern for this activity should always be with aspects of the applied information security measures and the practices of minimization and purpose adherence in data collection.
To identify the weaknesses and risks of the company's activities, it is essential that the "DPO, CIO and CISO" group have as its main roadmap the joint effort of creating a governance plan to promote a culture of security in which prohibition and punishment give way to a space of flexibility, creativity, and adoption of new technologies. All of this to ensure the proposed balance between security, privacy, and revenue generation.
Estimates from Verizon, in its 2020 Data Breach Investigations Report, indicate that 17% of all data breaches that occurred in 2020 were caused by human error or inappropriate behavior, such as the use of real data in development environments or the accidental storage of confidential data in public or open environments. This scenario can end up costing companies billions, since IBM's 2020 average estimate for the cost of a data breach was $4.24 million per incident, a significant 10% increase compared to the previous year's estimate.
The same reasoning can and should be applied to the ANPD's enforcement activities. The draft resolution on the Authority's monitoring activities presents a formula of enforcement by cycles and classification into indicative tiers, a mechanism similar to what already occurs in the regulatory activities of the financial market.
The pedagogical orientation will not remove the possibility of sanctions, given that the work within a Monitoring Cycle will be to individualize the perception of a company's level of privacy compliance using as many specific elements about the business structure as possible.
The regulatory draft of the ANPD's Enforcement Regulation reflects the aforementioned image of a phased approach. The Authority, drawing on the experience of other enforcement and class-action entities, such as the actions of CADE, Brazil's antitrust authority, the financial market, and conduct adjustment agreements in collective litigation, will initially present compliance and remediation measures before moving forward with sanctioning administrative proceedings.
The manager will need to understand that the Authority will use risk management and the promotion of a data protection culture as premises for its enforcement activities, aiming at a balance between revenue generation and self-regulation on privacy matters.
The aforementioned Draft Resolution explicitly states that the application of a sanction will be preceded by a remediation phase or a compliance plan, and that failure to comply with the measures set out in this plan will lead to an escalation of the regulatory body's actions and the adoption of punitive instruments such as fines or the prohibition of carrying out the data processing activity.
Thus, viewing the law merely as a list of individual prohibitions will expose you to two highly sensitive risks, both with significant financial loss: the impact of losing agility and decision-making capacity in your business activities, or non-compliance with the aforementioned global aspects of privacy and data protection, which will eventually culminate in a fine imposed by the Authority.
The fundamental advice for the coming months is continuous adaptation. Just as in nature a change in the ecosystem forces species to adapt their habits and behaviors in order to survive, companies need to replicate this flexibility to avoid the extinction of their business.
Translated from the Brazilian Portuguese original · Read the original