The General Data Protection Law (LGPD) completed eight years this Friday, the 14th. This legislation, sanctioned on August 14, 2018, established guidelines for the handling of personal data in Brazil. Although most of its rules came into effect in September 2020, administrative penalties could only be applied starting in August 2021.
View on corporate maturation
Carlos Lima, partner at Failla Lima Riva Advogados, commented to Olhar Digital that this period was characterized by the maturation of companies, albeit unevenly. Initially, many organizations treated the LGPD as a mere formal and legal requirement, focusing on actions such as creating privacy policies, appointing a data controller, reviewing contracts, and data inventory.
In more advanced companies, Lima observed that data protection began to be integrated into technology processes, information security, supplier selection, product development, and risk management. For him, the primary current challenge lies in proving that the implemented mechanisms operate in practice, because, as he emphasizes, 'it is no longer enough to have a privacy program; it is necessary to demonstrate that it works.'
The General Personal Data Protection Law, formally Law No. 13.709/2018, aims to regulate the processing of personal data, including digital data, by public or private entities. Its objective is to safeguard fundamental rights such as liberty, privacy, and full personality development.
The law defines personal data as any information related to an identified or identifiable natural person. It also categorizes sensitive personal data, which includes information such as ethnic or racial origin, religious belief, political opinion, health data, sexual life, genetic and biometric data.
Furthermore, the LGPD establishes principles for the processing of this information, such as purpose, necessity, transparency, security, prevention, and accountability. Data subjects have various rights, including access to their own data, requesting correction of incomplete or outdated information, deletion of data under certain conditions, and knowledge about the sharing of this information.
Difficulties in implementation and oversight
Lima points out that the biggest current barriers lie in the discrepancy between what companies document and what actually happens in data processing operations. Mentioned problems include inventories that do not reflect current systems, defining legal bases generically, and retention policies that do not lead to effective data deletion.
The expert also mentioned obstacles in meeting data subject rights. Some organizations have formal channels to receive requests for access, correction, or information about sharing, but they find it difficult to locate the data and respond appropriately. This difficulty can extend to the data controller, whose function is limited to indicating a contact, without active involvement in governance.
During this period, the National Data Protection Authority (ANPD) intensified its role in oversight and sanction application. The agency approved the regulation of the inspection process and the administrative sanctioning process in October 2021, and in February 2023, the regulation on dosimetry and application of sanctions.
For Lima, these changes have made the requirement for companies to present the controls they claim to possess more tangible. Responding to the authority, enabling the exercise of data subjects' rights, and proving the existence of protection mechanisms have ceased to be mere theoretical issues.
Responsibility in security incidents
The effectiveness of protection measures was also addressed in a decision by the Superior Court of Justice (STJ). In December 2024, the Third Panel judged a case of non-sensitive personal data leakage resulting from a hacker attack. In this case, the court assessed whether the external attack was sufficient to constitute exclusive third-party fault and exempt the company from liability.
According to Carlos Lima, this interpretation reinforces that the mere occurrence of an external attack does not end the discussion about the data controller's responsibility. Lima clarifies that the LGPD does not require a company to prevent all cyberattacks; the focus must be on verifying whether adequate security measures were adopted for the risks and whether the organization can demonstrate this.
Among the factors that, according to the expert, can be considered in an incident are vulnerability management, access controls, credential protection, activity logs, backups, third-party management, and incident response plans. The company's conduct after the attack is also analyzed, covering event investigation, evidence preservation, adoption of measures to mitigate damage, and relevant communications.
Lima emphasizes: 'Therefore, simply saying 'we were victims of hackers' does not end the discussion.' He adds that if there were prior security failures, absence of controls compatible with the risk, or an inadequate response to the incident, the fact that there was an external criminal does not necessarily exclude the organization's responsibility.
Future challenges with Artificial Intelligence
Looking ahead to the coming years, Lima identifies artificial intelligence (AI) as one of the main challenges for data protection. He warns that the use of large databases for training, the collection of information from the internet, the inference of personal characteristics, profile creation, and automated decisions can increase the dimension and complexity of existing problems in the field of data protection.
The expert advises that companies should not wait for specific legislation on AI to start addressing the topic. Whenever an AI application involves the processing of personal data, the LGPD must be considered. Measures suggested by Lima include identifying the tools used, the data processed, the purposes, and the suppliers, in addition to evaluating uses according to the risk level. It is also crucial to analyze the origin and legal basis of the data, applying the principles of minimization and privacy from the design stage, and establishing mechanisms for human supervision and monitoring.
In conclusion, Lima states that 'AI does not eliminate LGPD obligations; on the contrary, it enormously increases the scale and complexity of these obligations.'