After a long battle, finally, the General Data Protection Law, approved in 2018, entered into force on September 18, 2020. With this, Brazil joined 100 other countries that apply specific regulations with the objective of defining limits and conditions for the collection, storage, and processing of personal information.
In short, Law No. 13.709 employs a set of factors such as defining data categories, establishing data collection and processing, granting rights to information owners, detailing special conditions for sensitive data and segments (such as children), implementing a differentiated regime for the public sector, and including sanctions in cases of violations. But, what does this change in practice? Follow along with us and check it out on the CodeBlog.
Before discovering the practical changes, it is necessary to understand some concepts defined by the LGPD.
Take a look at the glossary and stay on top of the most cited terms within the articles of the law.
Personal data: Any information that can identify a person (name, numbers, addresses, etc.).
Data subject: The owner of the data.
Processing: All operations carried out with personal data.
Controller: Entity that carries out the collection, as well as the processing and storage of personal data.
Processor: Who applies the processing of personal data on behalf of the controller.
Now indeed, do you already know how to identify the nomenclatures and the main agents of the LGPD?
So, check below the main changes determined by the enforcement of the Law.
Organization of information
In fact, one of the main changes caused by the LGPD is the way companies organize their information. This is because, from now on, it will be necessary to meet the following requirements:
Identification of collected data.
Adequate separation and classification (mainly in relation to sensitive data, such as, for example, those collected by health-related companies).
Systematized management of physical and digital data.
For this reason, to adapt to the LGPD, it is essential to invest in a management process for this information. In addition, this is a great time to discard what is no longer useful for your business and manage only the data that your company really needs.
Accountability
In practice, the LGPD requests companies to prove that its regulations are being properly complied with. Therefore, with the Law in force, it is necessary to prepare the so-called "Data Protection Impact Assessment". The document must include the life cycle of personal data processing, as well as indicate the legal basis for authorization of the processing. The implemented data security measures must also be analyzed.
Expansion of territorial scope
One of the biggest changes in the regulatory scope of data privacy caused by the LGPD is the expansion of territorial scope. After all, the law applies to all companies that collect and process personal data collected in Brazil or from Brazilian residents, even if processed abroad.
That is, the collection and processing of personal data by controllers and processors is duly applied, regardless of whether the process is carried out in national territory or not.
Consent
If before, many companies used long terms and conditions that were difficult to read, from now on, the request for consent must be presented in a clear and easily accessible way. In addition, the authorization must be distinguishable from any other topic to facilitate user understanding.
Rights of data subjects
From now on, data subjects are granted four main rights:
1- Breach notification
Notifications in cases of attacks that can cause risks to the rights and freedoms of individuals are mandatory and must be made, first, to the responsible authority.
2- Access
Confirmation by controllers about the processing of personal data is mandatory. In addition, it is necessary to clarify where they are introduced and for what purpose. Controllers must also make a copy of the information available free of charge in an electronic format.
3- Right to be forgotten
The right to be forgotten allows data subjects to request controllers to delete their personal data and consequently stop its processing.
4- Data portability
Finally, the General Data Protection Law grants the right to portability. That is, the right of the subject to receive personal data or request transfer to another service or product provider. In this way, the original controllers and processors have an obligation to stop collection and processing and follow all established criteria for data deletion.
Anyway, do you want to know more about the LGPD? Then, click here
And in case you need to execute the guidelines established by the LGPD, count on Codebit. Keep an eye on the CodeBlog and don't miss any news about the digital universe.
See you soon!




