Ensuring privacy in the application of the Brazilian general data protection law (LGPD)

Evandro Thalles Vale de Castro, Geovana Ramos Sousa Silva, Edna Dias Canedo · Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing · 2022

Currently, many organizations make use of the personal data of their users. Personal data is the set of information that can lead to the identification of a specific person and, therefore, this information is generally vital for the operations and business continuity of organizations. Consequently, the relevance of adopting methodologies that guarantee the protection and privacy of user information is indispensable to prevent the leaking of sensible information. Therefore, laws were created to establish essential requirements for organizations to provide support and protection to the personal data of users, such as the General European Data Protection Regulation (GDPR) and the Brazilian General Data Protection Law (LGPD). This work aims to develop a framework to support ICT professionals in adapting companies to the requirements demanded by the LGPD. To achieve the purpose, a framework based on the BEST methodology (Business Engaged Security Transformation) was proposed. This framework has a sustainable approach and can be implemented by any organization. A survey was carried out to collect the perception of Information and Communication Technology (ICT) practitioners in relation to adherence to LGPD adaptation actions by organizations. As a result, we identified a weakness in the privacy and information security management methodology implemented in organizations, which, in the future, may result in risks and damage to user information.

Read the paper · More papers on PaperTik