Privacy Hub by Wrangu –
Solution for Brazil’s LGPD
Your go-to solution for Implementing the LGPD into your organisation
Quick Look: LGPD
The General Data Protection Law (LGPD) passed into Law in Brazil in 2018, after a long period of uncertainty about the effective date of Brazil’s LGPD, Brazil’s Congress on Wednesday (26th August 2020) dramatically approved a last-minute amendment to legislation that accelerated the effective date of the LGPD to immediately take effect, as of August 27 2020.
The LGPD places specific regulatory requirements on organisations operating in Brazil and organisations outside of Brazil who process personal data of individuals located in Brazil. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.
A look into the details of the LGPD articles immediately reveals several requirements of interest such as the rights of holders of personal data which organisations are required to fulfil within 15 days. Organisations are also required to maintain a record of processing activities, send personal data breach notifications to supervisory authorities and impacted data subjects, conduct data protection impact assessments and process personal data with appropriate safeguards.
How to implement LGPD with the Privacy Hub by Wrangu
Automate LGPD processes in 4 modules:
The data subject rights module provides the ability for data privacy teams and personal data holders to raise and manage personal data holder rights requests allowing organisations:
- Capture DSR request details.
- Validate the identity of the personal data holder, agents and personal data holder rights requests.
- Manage 15 days SLA duration.
- Have a consolidated view of all open and closed personal data holder requests received from a particular personal data holder over a given period of time to manage excessive request.
- Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information.
- Request approval from a data controller to process a DSR request when actioning as a processor.
- Confirm with personal data holders how they would like to receive information in response to right to access requests
- Dynamically create tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request
Relevant LGPD Articles:
#5, #7, #8, #9, #10, #11, #14, #16, #17, #18, #19 & #20.
The DPIA module provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a high risk to the rights and freedoms of personal data holders and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:
- Automatic evaluation of DPIA responses with possible concerns raised for consideration.
- Built-in configurable risk calculation engine with risk ratings displays based on responses.
- Facilitate multiple users’ completion of a single DPIA assessment.
- Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.
Relevant LGPD Articles:
#10, #38, #46 & #49
Comprehensive engine enabling the robust documentation of processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:
- Capture of all data sets as specified by Article 37 of the regulation for controller and the operator to keep a record of the operations of treatment of personal data they make, especially when based on legitimate interest.
- Maintain version history for each ROPA record to support auditing and complaints management activities.
- Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
- Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
- Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.
Relevant LGPD Article:
#37
Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the National Data Protection Authority (ANPD) or affected personal data holders. This module also provides
- Standard process to support data gathering to determine if the personal data breach is likely to cause relevant risk or damage to the personal data holders.
- Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
- Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
- Support report creation for notification to the ANPD or communication to affected personal data holders.
- Ready integration with ServiceNow Security Incident Response module.
Relevant LGPD Article:
#48
