ANPD Publishes Information Security Guide for Small-Scale Data Processing Agents
- Mirna Conceição
- Oct 7, 2021
- 2 min read
On October 4, 2021, the Brazilian National Data Protection Authority (ANPD) released the first version of its Information Security Guidance for Small-Scale Data Processing Agents, which may be updated and improved whenever necessary.
In accordance with Article 55-J, item XVIII, of the Brazilian General Data Protection Law (LGPD – Law No. 13,853/2019), which allows the ANPD to issue simplified rules and procedures for microenterprises, small businesses, startups, and innovation companies, the Good Practices Guide presents suggestions for administrative and technical information security measures. Its purpose is to provide tools that can help companies begin their process of achieving compliance with the LGPD.
The administrative measures include: (i) an Information Security Policy, even in a simplified form, through the implementation of controls such as backups, password use, access to information, data sharing, software updates, email use, antivirus software, among others; (ii) Awareness and Training for staff, through training programs and awareness campaigns regarding obligations and responsibilities related to the protection of personal data; and (iii) Contract Management, including confidentiality agreements, contracts with suppliers and partners, among others.
The recommended technical measures include: (i) Access Control, to ensure that data is accessed only by authorized individuals; (ii) Security of Stored Personal Data, including collecting only the data actually necessary for the intended processing purpose, as well as ensuring appropriate security settings, backups, and data deletion procedures; (iii) Communication Security, through encrypted connections and network traffic management; (iv) Maintenance of a Vulnerability Management Program, by monitoring new versions and available security patches for all systems and applications; (v) Measures Related to the Use of Mobile Devices, such as the use of multi-factor authentication to access the organization’s devices and information systems; and (vi) Measures Related to Cloud Services, including compliance with international recommendations and information security best practices.
The Guide also includes a practical checklist of the suggested administrative and technical measures, designed to facilitate their implementation by small-scale data processing agents. Although the Guide does not have binding regulatory effect, it represents an important tool for guiding personal data protection practices.
In summary, the suggested measures are relatively straightforward and demonstrate that compliance with the LGPD involves creating a culture of care regarding personal data—a culture that not only needs to be promoted, but can and should be implemented by all companies, regardless of their size.
Access the Guide and Checklist here.



Comments