Assessment of Competences for LGPD DPO through ANPD Standard and Information Systems Curriculum
María Manuela Martins, Yuska Paola Costa Aguiar, Juliana De Albuquerque Gonçalves Saraiva · 2025
Context: The General Data Protection Law (LGPD) in Brazil formalized the Data Protection Officer (DPO) role, demanding professionals to ensure compliance, governance, and data security. This emphasizes the alignment between legal, technical, and governance competences, creating a critical need for academic preparation. Problem: The absence of a defined standard for DPO training creates challenges in adequately preparing professionals. Specifically, there is a lack of integration between the competences outlined by the National Data Protection Authority (ANPD) and the Information Systems (IS) programs’ curricula. Solution: This study maps the competences required by the ANPD for DPOs and evaluates the adherence of a public university’s IS curriculum to these competences, grouping them into broader categories to enhance alignment. IS Theory: Grounded in the Competence-Based Theory, the study aligns professional skills with regulatory and organizational demands, through the CHA Theory. Method: Using a qualitative, descriptive approach, the research applied content analysis to IS curricular components and ANPD standards. Competences were categorized and their curriculum coverage assessed. Results: The study identified 12 competences, grouped into 5 categories, with strong emphasis on governance, security, and communication. Gaps in legal and contractual aspects were noted. Contributions to IS: The study offers a framework to align IS curricula with regulatory and professional DPO requirements, supporting academic institutions in integrating multidisciplinary content. Impact on IS: This research bridges the gap between academia and the market, fostering professionals equipped to address challenges in data governance, security, and compliance, strengthening IS programs’ relevance in data protection.