Objective: The general objective of the study is to analyze which technical and administrative measures are necessary for accounting organizations to comply with the provisions of the LGPD, with this general objective being divided into three specific objectives: a) identify the technical and administrative measures relevant to the LGPD; b) establish privacy policies on the data made available and c) define the stages of technical and administrative measures so that organizations comply with the provisions of the Law. Theoretical Framework: This topic presents the main concepts and theories that underpin the research. The General Data Protection Law - LGPD (LAW 13.709/2018) stands out, providing a solid basis for understanding the context of the investigation. Method: The methodology adopted for this research is applied, descriptive, bibliographical and documentary, with a qualitative approach. The unit of analysis was 5 managers from 5 for-profit organizations located in the northwest region of RS during the month of May 2023. Data collection was carried out through bibliographic, documentary and interview research, using documentary and descriptive analysis techniques. Results and Discussion: The findings indicate that criteria adopted for the protection of people's data were defined for the companies surveyed, considering the administrative department of the companies, where data considered sensitive is handled, divided basically into three sectors: Accounting sector, Tax sector and Human Resources sector and Personnel Department. It was found that there is a need to implement technical and administrative measures in the processes and invest in training on the subject within the organizations, in order to avoid infractions and fines as punishment for non-compliance with the provisions of the General Data Protection Law. In the discussion section, these results are contextualized in light of the General Data Protection Law - LGPD (LAW 13.709/2018), highlighting the implications and relationships identified. Possible discrepancies and limitations of the study are also considered in this section. Research Implications: The practical and theoretical implications of this research are discussed, providing insights into how the results can be applied or influence practices in the field of the General Data Protection Law - LGPD. These implications may include the deepening of knowledge, as well as from a practical point of view, since it offers a concrete solution to a specific demand of the company investigated in this study. Originality/Value: This study contributes to the literature by discussing the topic General Data Protection Law - LGPD (LAW 13.709/2018. The relevance and value of this research are evidenced by providing guidance to organizations on how to prepare the Privacy Policy and Contingency Plan, with the purpose of adapting to the LGPD.
Read full abstract