Skip to the content
  • English
  • Portuguese (Brazil)
  • Spanish
  • Home
  • About Us
  • Industries
    • Financial
    • Health
    • Education
    • Industry
  • Solutions
    • Electronic Signature
      • Eval Sign
      • Crypto Cubo
      • Madics Sign
      • Digital Certificate
    • Data Protection
      • Data Protection on Demand – DPoD
      • CipherTrust
    • Payments
      • payShield
      • Crypto Pix
    • Financial
      • Crypto Compe
      • Crypto SFN
    • HSM (Hardware Security Module)
    • Professional Services
  • Resources
    • Blog
  • Career
  • Contact
Menu
  • Home
  • About Us
  • Industries
    • Financial
    • Health
    • Education
    • Industry
  • Solutions
    • Electronic Signature
      • Eval Sign
      • Crypto Cubo
      • Madics Sign
      • Digital Certificate
    • Data Protection
      • Data Protection on Demand – DPoD
      • CipherTrust
    • Payments
      • payShield
      • Crypto Pix
    • Financial
      • Crypto Compe
      • Crypto SFN
    • HSM (Hardware Security Module)
    • Professional Services
  • Resources
    • Blog
  • Career
  • Contact
Search
Close
  • English
  • Portuguese (Brazil)
  • Spanish
Facebook Instagram Linkedin

Tag: lgpd

Categories
Data Protection

How to avoid fraud with data protection and still maintain a good relationship with your customer

  • Post author By Arnaldo Miranda
  • Post date 20 de October de 2020
  • No Comments on How to avoid fraud with data protection and still maintain a good relationship with your customer

A Serasa Experian’s 2020 Global Fraud and Identity Surveyshows that 57 percent of companies are facing increasing losses due to fraud year after year, despite claiming to be able to accurately identify their customers.

The reality shows that three out of five companies said there was an increase in fraud over the past 12 months. In other words, the study done by Serasa Experian shows that companies’ concerns about the increase in fraud persist even with the investments in security and data protection that have been made in recent years.

Furthermore, the average cost of a data breach in 2020 is $3.86 million, according to IBM’s data breach study. Despite the slight drop from 2019 (USD 3.9 million), it is still a very high amount to pay for fraud and its impacts with customers.

But what happens when the companies responsible for protecting our identities and finances are compromised by fraud through cyber attack?

In September 2017, consumer credit agency Equifax admitted its third cyber attack in two years, when hackers exploited a website vulnerability.

Key Facts About the Cyberattack suffered by Equifax

  • Some 143 million US customers have potentially become vulnerable by having their personal data compromised (with 400,000 in the UK);
  • Confidential information (including social security numbers, driver’s license numbers, dates of birth, medical history, and bank account information) was compromised, leaving customers vulnerable to identity theft;
  • Equifax has been criticized for being ill-equipped to manage the breach. It took five weeks to make the violation public, she set up a website for information and a hotline – where customers criticized the lack of information and the long delays;
  • In a notable gaffe, customers were also directed to a fake website in the company’s tweets;
  • Offers of a one-year free credit monitoring and identity theft service were deemed inappropriate;
  • A lawsuit has been filed accusing Equifax of negligence with customer data, with potential cost implications of $68.6 billion.

Consumers whose data has been leaked, stolen, or used in fraud don’t even know that their personal information is at risk for months or even years. But what choice do people have: don’t travel, don’t share, don’t use social media?

Ok, we can make these choices if we need to, but we still need to get health care services, use a bank or a credit union, be insured, or even get our Social Security benefits.

How can companies take the first steps to prevent fraud and data theft?

These are top tips from experts to help you keep your company’s confidential information safe from data thieves.

1. get rid of paper

If you must keep paper files, destroy them as soon as they are no longer needed. In practice, there are nine things that companies must destroy:

  • Any correspondence with a name and address;
  • Luggage tag;
  • Travel Itineraries;
  • Extra boarding passes;
  • Credit offers;
  • Price list;
  • Vendor payment receipts and paid invoices;
  • Cancelled checks;
  • Receipts.

2. Evaluate which data you most need to protect from fraud

Audit or evaluate your data. Every company is different. Each has different regulations, different types of data, different needs for that data, and a different business culture.

Hire an outside expert to assess what data you have, how you are protecting it (not how you think you are protecting it), and where that data is going.

While you may think it is an unnecessary cost, if you report to customers and prospects that you have done an external data assessment, you may find that it puts you at an advantage over your competitors.

3. Restrict access to your confidential data

Not everyone in the company needs access to everything. Does the project manager need pricing information? Does the seller need information about the operations? By restricting the data to which each person has access, you limit your exposure when an employee decides what they want to steal or when the employee’s account is compromised by an outsider.

4. Apply internal and external data privacy controls

Make sure that third parties and service providers contracted by your company follow the same strict data privacy controls that you implement in your own organization.

Audit them periodically to ensure compliance with your security standards.

5. Use strong passwords to protect computers and devices

Make it difficult for third parties to access your company and employees’ devices and computers if they are lost or stolen by protecting them with strong passwords and enabling remote wiping on all devices.

6. Install or enable a firewall

Even small companies with only a few employees have valuable data that needs to be protected. Make sure you have a firewall installed to prevent strangers from accessing your company’s network.

7. Secure your wireless network

Use a strong password and encryption and security to hide your wireless network from strangers. Don’t let neighbors or passersby get into your network or even see that it exists. You are just creating problems.

8. Combat fraud and maintain good customer relations in accordance with LGPD

Adhering to the core principles of the General Data Protection Act (LGPD) and preventing fraud and still having good customer relations can go hand in hand.

Minimizing the amount of personal data collected, anonymizing that data, and adopting privacy by design principles will not only ensure that your customers’ right to data privacy is preserved, but will also help mitigate your risks from an LGPD perspective.

9. Data minimization

Whether or not you rely on legitimate interest to acquire data, you should collect only the minimum data necessary to achieve your goal.

If you can fight fraud with only the least amount of non-direct identifying information it will be better. That will mean less data to protect later.

10. Anonymization

Make sure that all data is protected using tokenization or encryption.

In addition to increased security, a clear benefit is that mandatory breach reporting requirements are significantly reduced for anonymized data, as the risk of harm to the data subject is greatly reduced as long as the key is not compromised.

11. Privacy by design

Make data privacy an integral part of your organization’s thought process at all levels.

Make it a habit for all departments to ask questions about what data you need, how you will protect it, and whether or not you need consent. Not to mention that a well thought out privacy strategy will likely create a better user experience.

And don’t forget the authentication! Tampered and stolen credentials are a real threat to the security of your users’ data. This threat vector makes stronger authentication an essential component in fighting fraud and defending your users’ right to data privacy.

How EVAL can help your company fight fraud

EVAL has solutions for application encryption, data tokenization, anonymization, cloud protection, database encryption, big data encryption, structured and unstructured file protection on file server and cloud, and key management to meet different demands in the area of data security.

These are solutions for business to be compliant and protected against data leakage.

About Eval

EVAL has been developing projects in the financial, health, education and industry segments for over 18 years. Since 2004, we have offered Authentication, Electronic and Digital Signature and Data Protection solutions. Currently, we are present in the main Brazilian banks, health institutions, schools and universities, and different industries.

With value recognized by the market, EVAL’s solutions and services meet the highest regulatory standards of public and private organizations, such as SBIS, ITI, PCI DSS, and LGPD. In practice, we promote information security and compliance, increase companies’ operational efficiency, and reduce costs.

Innovate now, lead always: get to know Eval’s solutions and services and take your company to the next level.

Eval, safety is value.

  • Tags data protection, frauds, lgpd

Categories
News and Events

Suddenly LGPD: 10 questions and answers your company needs to know to meet the requirements of the Data Protection Act

  • Post author By Arnaldo Miranda
  • Post date 2 de September de 2020
  • No Comments on Suddenly LGPD: 10 questions and answers your company needs to know to meet the requirements of the Data Protection Act

It may seem controversial to imagine that suddenly the General Law of Data Protection (LGPD), will come into force throughout the country. After all, Law No. 13,709/2018, which defines the new legislation, was sanctioned on August 14, 2018, establishing an 18-month adaptation period, scheduled to begin in 2020.

However, the law went through postponements in the same year it was to take effect (2020), and then it was expected to be extended to 2021 due to the COVID-19 pandemic.

But, between comings and goings in the National Congress and presidential approvals and vetoes, we are expecting the Law to come into effect at any moment. Unfortunately, these changes generate a lot of instability regarding the new legislation and a risk that can directly impact the main objective of the law: the protection and privacy of Brazilians.

In addition to the definition (or lack of clear definition), of the effective date of the LGPD, the Federal Government has recently established the structure of the National Data Protection Authority (ANPD)the body responsible for overseeing the protection of personal data, elaborating guidelines for the National Policy on Personal Data Protection and Privacy, inspecting and applying sanctions in cases of non-compliance with the legislation, among other duties defined in Law 13,709.

Expectations aside, companies and organizations need, more than ever now, to be prepared for the requirements that will soon be imposed by data protection law. Despite all this transition period, there are still questions about the LGPD that companies need to understand in order to comply with the new legislation.

To help clarify the main doubts, we have put together a list of the most important questions and answers so that you can adapt the LGPD to your business.

Questions and answers about LGPD that your company needs to know to comply with the data protection law

Although there is no universal checklist applicable to all cases, some problems arise more frequently than others. And these questions and answers about the LGPD will be relevant for years to come, as the new legislation has no expiration date.

#1. Are you a data controller or data processor – do you determine the purposes and means of the processing of personal data or do you process personal data on behalf of another party?

Answering this question is crucial to determining the scope of your obligations under data protection law. Of all the questions and answers about the LGPD, this one will probably guide you to most of the actions that need to be taken going forward.

Data controllers decide what data is collected, for what purpose, how it is processed, and for how long. This means that you are responsible for fulfilling a wide range of obligations, such as protecting the data, meeting the objectives of, for example, data minimization and processing transparency. You are also the one who has the obligation to respond to and facilitate the exercise of the data subject’s rights.

On the other hand, if you are a data processor, you process data on behalf of a controller and only within the scope that it has determined. Therefore, you cannot make decisions about what personal data is processed and how. Your primary duty is to protect the data you process from unauthorized access, modification, etc.

#2. Do you perform all processing activities yourself or do you use third-party processing services, such as server rental?

If you use a third-party processing service, you must enter into a specific written agreement (including in electronic form), which should regulate in particular the object and duration of the processing, the nature and purpose of the processing, the types of personal data and categories of data subjects, and the obligations and rights of the controller.

Remember that even if you do not process the data yourself, you are still responsible for the processing. Choose only those companies that guarantee to implement appropriate technical and organizational processing measures to meet the requirements of the LGPD and ensure data protection.

The set of questions and answers about the LGPD also apply to third-party companies.

#3. Who can access your company’s personal data? Are there different levels of access for different positions?

The fact that you, as the controller or processor, have the right to process the data does not mean that all your employees can access it – it should only be the people whose position within your company requires that they have these rights.

Remember to specify the scope of the authorization – what kind of data they can access (e.g. customer data, employment-related data) and what they can do with the data. Some people will need to have full access, including the right to enter, modify or delete the data, while for others just the right to view the data will be sufficient.

#4. Is all the data you collect really necessary for the purpose of your processing?

One of the main rules of personal data protection is data minimization. It obliges the controller to limit – by default – to the minimum necessary the amount of personal data collected, as well as the extent of its processing, the period of its storage, and its accessibility.

Remember to take this into account when auditing your databases and when designing new data flows (creating forms, making decisions about activity tracking, etc.).

#5. How is the collected data used – what is the purpose of processing personal data?

Data may only be processed for specified, explicit, and legitimate purposes and may not be processed in a way incompatible with those purposes.

# LGPD 6. Do you collect sensitive data – such as health records, data on racial or ethnic origin, religious or philosophical beliefs, etc.?

Processing sensitive data is prohibited by default and can happen only in specific circumstances described in the LGPD, so a general recommendation would be to avoid processing such data altogether. If this is not possible, seek legal advice to identify remedies that provide a legal basis for processing such data.

#7. Have you checked whether there are processes in your company that require a data protection impact assessment to be performed?

Such an assessment must be carried out in the case of processing that – taking into account its nature, scope, context and purposes – is likely to result in a high risk to the rights and freedoms of individuals, in particular due to the use of new technologies.

It may be necessary in specific cases, including:

  • The systematic and comprehensive assessment of personal aspects relating to natural persons that is based on automated processing, including profiling, and upon which decisions that produce legal effects on the natural person or significantly affect him/her are based.
  • The processing of sensitive data on a large scale.
  • The systematic monitoring of a publicly accessible area on a large scale.

#8. How will the right to data portability be handled? In what format will the data be provided to the data subject or to another controller at the data subject’s request?

The right to data portability can be exercised if the data subject has provided data to a controller. The processing is performed by automated means and is based on one of the following legal bases – the data subject’s consent or a contract to which the data subject is a party.

It allows the data subject to request a copy of their data in a structured, common, and readable format. The LGPD does not provide further specifications of this format, so it is up to the controller to choose it, keeping in mind that the data subject may request that the data be transmitted directly to another controller.

#9. How can a user request access to his/her data, including receiving a copy of his/her personal data being processed? Will this process be conducted manually or automatically? In what format will the copy be provided?

The data subject may ask the controller for a copy of his or her personal data being processed. When this right is exercised for the first time, the controller must provide this copy free of charge, but in case of further requests, the controller may charge a reasonable fee based on administrative costs.

Unless otherwise requested by the data subject, if the request is made by electronic means, the information must also be provided in electronic format.

In preparing for the data subject to exercise their data rights, the controller must ask itself a handful of important questions, the most important being:

  • How the request can be made – using a dedicated website, with a request form and instructions, or perhaps, for example, by e-mail;
  • This process will be conducted either manually or automatically;
  • In the first case, there are enough trained personnel to handle the incoming workload;
  • The existing procedures and organizational means allow such requests to be met without undue delay.

#10. Will data be shared with third parties, including within your group? When, how, on what legal basis?

When you are the data controller, sharing data with other entities can take two forms:

  • The processing will be carried out on your behalf, you specify its purpose, duration, the obligations of the processor, and so on – in this case you need to conclude a contract regulating all these issues with the processor, and you do not have to ask the data subject for his or her consent to do so;
  • Your company loses control over the data it shares and its processing, and the recipient becomes an independent controller of that data – in which case you will need a legal basis for sharing personal data (e.g. consent from the data subject specifying with whom you share the data and for what purpose).

Questions and answers about the LGPD that went beyond the basic concept

Basic questions like “What is LGPD?”, ” What is personal and confidential data?”, “When does LGPD go into effect?” have been left out to show that data protection law is directly linked to your company’s business processes, and therefore the goal of data protection law implementation should be something more in-depth.

This means that questions and answers about the LGPD should focus on tools, features such as the adoption of electronic signatures, encryption, training, among other points that were not portrayed in our list. It is necessary to go further.

With a little over a year to go, companies need to keep an eye on the next steps of the General Data Protection Law. That is, the execution of the necessary compliance actions before the LGPD went into effect.

Companies like EVAL help you implement your strategy to meet expected requirements before LGPD takes effect with solutions to assess risks, enforce policies, protect data, respond to incidents and requests, and prove compliance.

EVAL can help your company unify business operations with data protection and security, enabling risk measurement across the organization to assist in implementing a comprehensive LGPD compliance plan.

About Eval

EVAL has been developing projects in the financial, health, education and industry segments for over 18 years. Since 2004, we have offered Authentication, Electronic and Digital Signature and Data Protection solutions. Currently, we are present in the main Brazilian banks, health institutions, schools and universities, and different industries.

With value recognized by the market, EVAL’s solutions and services meet the highest regulatory standards of public and private organizations, such as SBIS, ITI, PCI DSS, and LGPD. In practice, we promote information security and compliance, increase companies’ operational efficiency, and reduce costs.

Innovate now, lead always: get to know Eval’s solutions and services and take your company to the next level.

Eval, safety is value.

  • Tags general data protection law, lgpd
  • Home
  • About Us
  • Industries
  • Solutions
  • Resources
  • Career
  • Contact
  • Home
  • About Us
  • Industries
  • Solutions
  • Resources
  • Career
  • Contact
  • English
    • Portuguese (Brazil)
    • Spanish

Posts recentes

  • [Retrospectiva] Cybersecurity in 2022: A year of great challenges and opportunities for companies
  • On Black Friday, protect your e-commerce against fraud
  • CISOs: key areas to protect your company against cyber attacks
  • How to set up an efficient digital workflow
  • Contract automation: security guarantee for your business

Comentários

No comments to show.

Arquivos

  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • June 2022
  • January 2022
  • October 2020
  • September 2020
  • February 2020
  • November 2019
  • August 2018
  • June 2018
  • June 2017

Categorias

  • Data Protection
  • Digital Signature
  • Electronic Signature
  • News and Events
  • Uncategorized
  • About Us
  • Financial
  • Solutions
  • About Us
  • Financial
  • Solutions
  • Blog
  • Career
  • Contact
  • Blog
  • Career
  • Contact

Where We Are

Rua Paulistânia, nº 381, 2º andar,
Sumarezinho
São Paulo - SP,
ZIP CODE:05440-000

Contact

(11) 3670 - 3825
(11) 3865 - 1124
[email protected]

Facebook Instagram Linkedin
logo-tales-azul
pci-logo-teal
keyfactor-logo
logo-valid-certificadora-digital
google-safe-browsing
Privacy Policy

Copyright © 2023, EVAL TECNOLOGIA EM INFORMÁTICA. All rights reserved - CNPJ 05.278.889/0001-97