Although the General Data Protection Law (LGPD) was sanctioned in 2018, due to the pandemic, the law was only set to take effect in May 2021. However, since the MP (Provisional Measure) that was passing through the federal senate was not finalized, the Data Protection Law came into force in the month of August 2020. Normally, the period granted for application is considerably long, precisely so that companies have enough time to adapt.
However, due to the new coronavirus pandemic, this transition has been slower than expected, and because of this, the application of sanctions was postponed to August 2021.
But, in short, regardless of the extension of the implementation deadline, the fact is that companies need to be aware of all the changes imposed to ensure the successful installation of the LGPD.
Therefore, in the following post, CodeBlog presents everything you need to know about the LGPD.
Check it out!
What is the General Data Protection Law?
Without a doubt, the immense importance of personal data in the modern economy is undeniable. After all, this information allows for forecasting, consumption profile analysis, creation of personalized advertisements, and much more.
Therefore, it is fundamental to have a law focused on regulating the processing of personal data by companies.
Currently, more than 120 countries have data protection laws – these rules, besides preventing the misuse of personal reports, also prevent some accidents such as, for example, information leaks.
Very soon, Brazil will be part of this group with the LGPD regulation, which has the following principles:
Ensure greater protection of privacy;
Establish freedom of expression, information, and opinion;
Inviolability of intimacy and image;
Propagate economic and technological development;
Preserve human rights, as well as dignity and the exercise of citizenship.
Furthermore, the LGPD must be applied to all personal data of users located in Brazilian territory, in all cases where the processing takes place in Brazil, and whenever there is an offering of products or services aimed at individuals present in the country.
On the other hand, the General Data Protection Law will not apply to data originating from or destined for other countries, for personal or non-commercial use, journalistic and academic purposes, or in matters of public safety.
What are the principles of the General Data Protection Law?
To ensure information processing, the LGPD establishes 10 principles. They are:
1. Purpose
The processing of personal data can only be established if there are justifiable and explicit purposes for the holder. In other words, it will still be possible to use user data for advertising purposes, provided this is made clear to them.
2. Adequacy
The company cannot state that the data use will be intended for advertising and then direct it to other actions.
3. Necessity
The use or manipulation of personal data must be limited to the fundamental aspects required to achieve the informed purposes.
4. Accessibility
Any data holder must have access to a practical and free consultation regarding the information about their data processing.
5. Quality
Additionally, the data holder must be guaranteed that their data is correct, precise, and constantly updated according to the purpose of the treatment.
6. Transparency
The holder will have the right to check if their information is accurate and accessible both during the processing and in relation to the processing agents.
7. Protection
Personal data protection measures must be applied to protect information from unauthorized access and prevent possible loss and alterations.
8. Prevention
Preventive measures must also be adopted to avoid the occurrence of damage.
9. Security
No personal data may be used for discriminatory or abusive purposes.
10. Responsibility
Companies must adopt measures to prove the application of data protection standards.
How to adapt to the LGPD?
Indeed, there are several factors necessary for organizations to comply with the LGPD.
The first of them is, without a doubt, clarification of the purpose of the collected data. To do this, it will be necessary to collect only information essential to the business and offer simple options for holders to delete information they do not wish to share.
Moreover, because adapting requires numerous changes, ideally, it should be established gradually.
Often, adopting a privacy policy may not be enough to guarantee security, therefore, performing a DPIA (Data Protection Impact Assessment) is recommended.
In short, this practice enables the concrete mapping of personal data flow and business processes. From there, it is possible to establish a plan to adapt to the regulations.
In this context, it will be necessary to consult a Data Protection Officer – a professional who works in implementing good practices to ensure compliance with the law in daily business or to look for companies that carry out this verification with responsibility and commitment. These specialists will be responsible for representing the company to the ANPD (National Data Protection Authority), the body that will inspect compliance with the rules.
Furthermore, it will be necessary to invest in cybersecurity and ensure some tools such as antivirus, firewall, etc.
Finally, it must be considered that the data regulation law will be important to consolidate personal data protection and privacy rights.
If there is no adaptation to the law, what will the consequences be?
If a company violates the rules of the LGPD, it may face penalties such as:
- Warning
Receipt of a warning with a deadline set for adopting the correct measures.
- Fine
A fine of up to 2% of the company's revenue, limited to 50 million BRL per infraction.
- Disclosure of the infraction
After investigation and confirmation of the occurrence, the infraction may be made public, compromising the company's reputation.
- Data blocking
The personal data linked to the infraction will be fully blocked until the situation is regularized.
Anyway, did you like this informative article about the LGPD? Have you already started making your adjustments? Stay tuned to CodeBlog, soon we will have plenty of news around here.




