Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue

In order to guarantee the privacy of users’ data, the Brazilian government created the Brazilian General Data Protection Law (LGPD). This article made a diagnostic of Brazilian organizations in relation to their suitability for LGPD, based on the perception of Information Technology (IT) practitione...

Full description

Bibliographic Details
Main Authors: Sâmmara Éllen Renner Ferrão, Artur Potiguara Carvalho, Edna Dias Canedo, Alana Paula Barbosa Mota, Pedro Henrique Teixeira Costa, Anderson Jefferson Cerqueira
Format: Article
Language:English
Published: MDPI AG 2021-04-01
Series:Information
Subjects:
Online Access:https://www.mdpi.com/2078-2489/12/4/168
id doaj-9c24426c37564b8e898aec9cabea633d
record_format Article
spelling doaj-9c24426c37564b8e898aec9cabea633d2021-04-14T23:01:11ZengMDPI AGInformation2078-24892021-04-011216816810.3390/info12040168Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance IssueSâmmara Éllen Renner Ferrão0Artur Potiguara Carvalho1Edna Dias Canedo2Alana Paula Barbosa Mota3Pedro Henrique Teixeira Costa4Anderson Jefferson Cerqueira5Electrical Engineering Department (ENE), Technology College, University of Brasília (UnB), Brasília, DF P.O. Box 4466, BrazilElectrical Engineering Department (ENE), Technology College, University of Brasília (UnB), Brasília, DF P.O. Box 4466, BrazilDepartment of Computer Science, University of Brasília (UnB), Brasília, DF P.O. Box 4466, BrazilInformation Systems (IS), Pioneer Union of Social Integration (UPIS), Brasília, DF P.O. Box 70390-125, BrazilDepartment of Computer Science, University of Brasília (UnB), Brasília, DF P.O. Box 4466, BrazilDepartment of Computer Science, University of Brasília (UnB), Brasília, DF P.O. Box 4466, BrazilIn order to guarantee the privacy of users’ data, the Brazilian government created the Brazilian General Data Protection Law (LGPD). This article made a diagnostic of Brazilian organizations in relation to their suitability for LGPD, based on the perception of Information Technology (IT) practitioners who work in these organizations. We used a survey with 41 questions to diagnose different Brazilian organizations, both public and private. The diagnostic questionnaire was answered by 105 IT practitioners. The results show that 27% of organizations process personal data of public access based on good faith and LGPD principles. In addition, our findings also revealed that 16.3% of organizations have not established a procedure or methodology to verify that the LGPD principles are being respected during the development of services that will handle personal data from the product or service design phase to its execution and 20% of the organizations did not establish a communication process to the personal data holders, regarding the possible data breaches. The result of the diagnostic allows organizations and data users to have an overview of how the treatment of personal data of their customers is being treated and which points of attention are in relation to the principles of LGPD.https://www.mdpi.com/2078-2489/12/4/168Brazilian General Data Protection Lawtreatment of personal datafederal public administrationorganizations private
collection DOAJ
language English
format Article
sources DOAJ
author Sâmmara Éllen Renner Ferrão
Artur Potiguara Carvalho
Edna Dias Canedo
Alana Paula Barbosa Mota
Pedro Henrique Teixeira Costa
Anderson Jefferson Cerqueira
spellingShingle Sâmmara Éllen Renner Ferrão
Artur Potiguara Carvalho
Edna Dias Canedo
Alana Paula Barbosa Mota
Pedro Henrique Teixeira Costa
Anderson Jefferson Cerqueira
Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
Information
Brazilian General Data Protection Law
treatment of personal data
federal public administration
organizations private
author_facet Sâmmara Éllen Renner Ferrão
Artur Potiguara Carvalho
Edna Dias Canedo
Alana Paula Barbosa Mota
Pedro Henrique Teixeira Costa
Anderson Jefferson Cerqueira
author_sort Sâmmara Éllen Renner Ferrão
title Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
title_short Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
title_full Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
title_fullStr Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
title_full_unstemmed Diagnostic of Data Processing by Brazilian Organizations—A Low Compliance Issue
title_sort diagnostic of data processing by brazilian organizations—a low compliance issue
publisher MDPI AG
series Information
issn 2078-2489
publishDate 2021-04-01
description In order to guarantee the privacy of users’ data, the Brazilian government created the Brazilian General Data Protection Law (LGPD). This article made a diagnostic of Brazilian organizations in relation to their suitability for LGPD, based on the perception of Information Technology (IT) practitioners who work in these organizations. We used a survey with 41 questions to diagnose different Brazilian organizations, both public and private. The diagnostic questionnaire was answered by 105 IT practitioners. The results show that 27% of organizations process personal data of public access based on good faith and LGPD principles. In addition, our findings also revealed that 16.3% of organizations have not established a procedure or methodology to verify that the LGPD principles are being respected during the development of services that will handle personal data from the product or service design phase to its execution and 20% of the organizations did not establish a communication process to the personal data holders, regarding the possible data breaches. The result of the diagnostic allows organizations and data users to have an overview of how the treatment of personal data of their customers is being treated and which points of attention are in relation to the principles of LGPD.
topic Brazilian General Data Protection Law
treatment of personal data
federal public administration
organizations private
url https://www.mdpi.com/2078-2489/12/4/168
work_keys_str_mv AT sammaraellenrennerferrao diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
AT arturpotiguaracarvalho diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
AT ednadiascanedo diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
AT alanapaulabarbosamota diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
AT pedrohenriqueteixeiracosta diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
AT andersonjeffersoncerqueira diagnosticofdataprocessingbybrazilianorganizationsalowcomplianceissue
_version_ 1721526939695448064