The General Data Protection Law was created in 2018 and, on August 14, 2023, completed five years.
During this period, it is evident how many transformations have emerged, mainly regarding the way companies collect and use data.
With a series of privacy measures adopted, the numerous impacts on the corporate landscape reinforce the concern for the security of data subjects in an increasingly digitalized world.
In today's article, we at CodeBlog present a brief overview of the main changes motivated by the General Data Protection Law. Read on and learn about the innovations on this subject.
The Impacts of the General Data Protection Law
The General Data Protection Law (LGPD) came into force in September 2020 and brought with it the promotion of greater awareness of the importance of privacy and the rights of data subjects.
Since then, the National Data Protection Authority (ANPD) has observed an increase in demand for transparency and accountability in the corporate landscape. As a consequence, many companies have started to redouble their attention when dealing with the personal data of customers, employees, partners, and suppliers.
In addition, there was also an increase in the adoption of new practices and technologies to facilitate business compliance with the LGPD, such as, for example, the implementation of privacy policies and procedures, employee training and capacity building, and the application of new resources focused on information security, such as cloud computing, artificial intelligence, and machine learning.
It is important to emphasize that the LGPD establishes fines and sanctions for companies that do not comply with its determinations and do not maintain compliance.
Penalties can include fines of up to 2% of the company's gross revenue, limited to BRL 50 million per infraction, as well as other sanctions, such as publishing the infraction and prohibiting the processing of the data.
The change in data processing:
The General Data Protection Law directly impacts how organizations operating in Brazilian territory process personal data. According to the rules, it is up to companies to:
(1) be more transparent and conscious alert regarding the use of personal data of their clients, partners, and users;
(2) adopt protection and security mechanisms, preventing data leaks and breaches;
(3) adopt measures that allow data subjects to have control and access to their own information.
Due to the requirements, companies started requesting the consent of data subjects before collecting, storing, or using their personal information.
This measure provided users with greater control over their data, allowing them to choose the info they wish to share, as well as knowing how it is used and handled.
Furthermore, data subjects have the guaranteed right to access, correct, or even request the deletion of their data when they deem it necessary. These changes represent a significant advance in collection transparency, privacy protection, and citizens' rights in the digital environment.
A reflection on rights and laws
Undoubtedly, the introduction of the LGPD has reinforced the concern of businesses to adopt good practices and adapt to the standards to process collected data and info with full compliance.
It is worth mentioning that, according to Law 13,709/2018 (LGPD), processing involves the processes of data collection, storage, sharing, among others.
Even though this adaptation is, in a way, an action arising from the fear of suffering penalties by the National Data Protection Authority (ANPD), the search for compliance with applicable legislation and the transformations generated in relation to transparency and reliability are undeniable.
In this scenario, it is important to highlight that the LGPD had the GDPR (European Regulation) as a major reference. However, it is not a simple task to adapt an entire population based on customs and rules established in other countries, with different lifestyles, cultures, social aspects, and behaviors. This is evident in relation to European culture, which has some points completely unrelated to the Brazilian people.
In national territory, many people share their CPFs, or even their biometric personal data, which is highly sensitive, in exchange for product discounts or to participate in loyalty clubs.
On the other hand, Europeans are much more reserved and tend to preserve their personal information as much as possible.
With these examples, we can see how long the road ahead still is, especially to educate and raise awareness among the population about the value of their data.
After all, it is also the consumers' responsibility to act to increase the security and effectiveness of the regulations.
Anyway, did you like discovering the main impacts promoted by the five years of LGPD?
If this article was useful to you, share the content on your social networks and bring this information to more people who might be interested.
Moreover, keep an eye on the CodeBit Blog. We'll have news here soon.
Warm regards, and see you in the next post!




