Skip to content
Digital curiosities

Key LGPD stakeholders: who is responsible for enforcing and complying with the law

Meet the key stakeholders involved in the LGPD and learn about their respective responsibilities for enforcing the law.

Key LGPD stakeholders: who is responsible for enforcing and complying with the law

The General Data Protection Law (LGPD) is Brazilian legislation designed to guarantee the privacy and protection of citizens' personal data. It establishes guidelines and obligations for the collection, processing, and sharing of personal information by companies and public and private institutions. Several stakeholders play key roles in ensuring the LGPD is effectively enforced and followed. In this article, we introduce the key stakeholders involved in the LGPD and their respective responsibilities.

National Data Protection Authority (ANPD)

The ANPD is the body responsible for overseeing and enforcing the LGPD. Its main duties include:

  • developing guidelines and rules for implementing the LGPD;
  • overseeing compliance and imposing penalties in cases of noncompliance with the law;
  • guiding data subjects, companies, and public authorities on compliance with the LGPD;
  • promoting national and international cooperation on personal data protection.

Data Protection Officer (DPO)

The Data Protection Officer (DPO) is the professional appointed by an organization to act as a point of contact between the company, data subjects, and the ANPD. Their main responsibilities are to:

  • ensure the organization's compliance with the LGPD;
  • advise employees on data protection practices;
  • monitor the implementation of security policies and measures;
  • respond to data subjects' requests and communicate with the ANPD when necessary.

Organizations and companies

Organizations and companies that process personal data are responsible for ensuring their activities comply with the LGPD. To do so, they must:

  • implement data protection policies and practices, including appointing a DPO when necessary;
  • inform data subjects about the collection, processing, and sharing of their personal information;
  • adopt technical and administrative measures to ensure data security;
  • respect data subjects' rights, including access, rectification, erasure, and portability.

Data subjects

Data subjects are the individuals to whom the personal data processed by organizations relates. The LGPD guarantees them the right to:

  • be informed about the collection, processing, and sharing of their personal data;
  • access, rectify, and erase their information;
  • request the portability of their data to another service provider;
  • withdraw their consent to the processing of their personal data.

IT professionals and developers

IT professionals and developers also play a key role in LGPD compliance, as they are responsible for creating and maintaining systems, applications, and infrastructure that process personal data. Their responsibilities include:

  • developing and implementing security solutions to protect stored and processed personal data;
  • adopting secure development practices, such as encryption and anonymization, whenever possible;
  • working with the DPO and other professionals involved in data protection to ensure compliance with the LGPD.

Public authorities and regulators

In addition to the ANPD, other public authorities and regulators may be involved in overseeing and enforcing the LGPD. These bodies may work with the ANPD to ensure compliance with the law and establish specific guidelines for regulated sectors and activities. Some of their responsibilities include:

  • developing specific rules and guidelines for processing personal data in regulated sectors, such as healthcare, education, and telecommunications;
  • overseeing compliance and imposing penalties for violations of the LGPD within their areas of responsibility;
  • working with the ANPD and other entities involved in personal data protection.

Read also: Considerations on the LGPD when building a corporate website