This is the second paper of the special Joint-Project “Effective Implementation and Regulation Under the New Brazilian Data Protection Law (LGPD)”, by CIPL and CEDIS/IDP.
This project aims to:
- Facilitate information-sharing about the LGPD
- Inform and advance constructive, forward-thinking and consistent LGPD implementation
- Enable the sharing of industry experience and best practices
- Promote effective regulatory strategies concerning the LGPD
This paper suggests the following organizational priorities for LGDP implementation:
- Understanding the LGPD impact on the organization and obtain buy-in from top management
- Designate a person in charge of data protection and identify and engage key stakeholders
- Identify the organization’s processing activities and the data that the organization handles
- Determine the organization’s role and obligations as a controller or operator
- Assess the privacy risks associated with the organization’s data processing
- Design and implement a data privacy management program covering the LGPD requirements
- Define the legal bases for the organization’s data processing activity
- Define technical and organizational measures for effective data security and internal reporting and management of security incidents
- Identify all third parties with which the organization shares personal data and establish a third party management process
- Identify the organization’s cross-border data flows (inbound and outbound) and put in place appropriate data transfer mechanisms and safeguards
- Build effective processes for transparency and data subject rights
- Train employees on LGPD requirements and create an awareness-raising program