and to mitigate problems in the LGPD implementing
model. The investigation and the anticipation, with
possible improvements in these limiting aspects, au-
tomatically reflect the process implementing of per-
sonal data protection, reducing the conflicts of inter-
est in the Federal Public Administration. These lim-
itations are not, therefore, an instrument of decision,
but an instrument that help the LGPD implementing
process.
6 CONCLUSIONS
In this article, we present a proposal for an LGPD im-
plementation process, according to LGPD guidelines,
developed by the FPA to support the agencies under-
standing data privacy requirements, that must compli-
ance with LGPD during implementation by agencies.
The proposed process model can be adopted by
any federal public administration agency and/or pri-
vate organizations. As future work, we intend to ap-
ply the model proposed in other agencies, with differ-
ent contexts, with the aim of adapting / evolving the
process to a more representative model.
ACKNOWLEDGEMENTS
The authors would like to thank the support of
the Brazilian research, development and innova-
tion agencies CAPES (grants 23038.007604/2014-
69 FORTE and 88887.144009/2017-00 PROBRAL),
CNPq (grants 312180/2019-5 PQ-2, BRICS2017-591
LargEWiN, and 465741/2014-2 INCT in Cybersecu-
rity) and FAP-DF (grants 0193.001366/2016 UIoT
and 0193.001365/2016 SSDDC), as well as the co-
operation projects with the Ministry of the Econ-
omy (grants DIPLA 005/2016 and ENAP 083/2016),
the Institutional Security Office of the Presidency of
the Republic (grant ABIN 002/2017), the Adminis-
trative Council for Economic Defense (grant CADE
08700.000047/2019-14), and the General Attorney of
the Union (grant AGU 697.935/2019).
REFERENCES
Acquisti, A., Brandimarte, L., and Loewenstein, G. (2015).
Privacy and human behavior in the age of information.
Science, 347(6221):509–514.
Agostinelli, S., Maggi, F. M., Marrella, A., and Sapio, F.
(2019). Achieving GDPR compliance of BPMN pro-
cess models. In CAiSE Forum, volume 350 of Lec-
ture Notes in Business Information Processing, pages
10–22, https://doi.org/10.1007/978-3-030-21297-1 2.
Springer.
Alexe, I. (2019). The role of the data protection officer in
respect of the rights of the data subject. RRDA, 1:23.
Ataei, M., Degbelo, A., and Kray, C. (2018). Privacy theory
in practice: designing a user interface for managing
location privacy on mobile devices. Journal of Loca-
tion Based Services, 12(3-4):141–178.
Bax, M. P. and Barbosa, J. L. S. (2020). Proposta de mecan-
ismo de consentimento na lei geral de protec¸
˜
ao a da-
dos - LGPD (consent mechanism proposal in LGPD).
In ONTOBRAS, volume 2728 of CEUR Workshop
Proceedings, pages 316–321. CEUR-WS.org.
Bernardes, M. B., de Andrade, F. P., and Novais, P. (2020).
Data protection in public sector: Normative analysis
of portuguese and brazilian legal orders. In World
Conference on Information Systems and Technologies,
pages 807–817. Springer.
BRASIL (2019). Decreto n
´
umero 10.046 de outubro de
2019. Di
´
ario Oficial da Uni
˜
ao - Sec¸
˜
ao 1, 1:1–5.
BRASIL (2020). Guia de boas pr
´
aticas – lei geral
de protec¸
˜
ao de dados (lgpd). Comit
ˆ
e Central de
Governanc¸
˜
a de Dados. Secretaria de Governo Digi-
tal, 1–65.
Canedo, E. D., Calazans, A. T. S., Masson, E. T. S., Costa,
P. H. T., and Lima, F. (2020). Perceptions of ICT
practitioners regarding software privacy. Entropy,
22(4):429.
Carauta Ribeiro, R. and Dias Canedo, E. (2020). Using
mcda for selecting criteria of lgpd compliant personal
data security. In The 21st Annual International Con-
ference on Digital Government Research, dg.o ’20,
page 175–184, New York, NY, USA. Association for
Computing Machinery.
Chamikara, M. A. P., Bert
´
ok, P., Liu, D., C¸ amtepe, S. A.,
and Khalil, I. (2020). Efficient privacy preservation of
big data for accurate data mining. Inf. Sci., 527:420–
443.
da Silva, M. V. V., da Luz Scherf, E., and da Silva, J. E.
(2020). The right to data protection versus “security”:
Contradictions of the rights-discourse in the brazilian
general personal data protection act (lgpd). Revista
Direitos Culturais (Cultural Rights Review), 15(36).
Diamantopoulou, V., Androutsopoulou, A., Gritzalis, S.,
and Charalabidis, Y. (2020). Preserving digital pri-
vacy in e-participation environments: Towards GDPR
compliance. Inf., 11(2):117.
Kitchenham, B. and Pfleeger, S. L. (2002). Principles of
survey research. ACM SIGSOFT Software Engineer-
ing Notes, 27(5):17–20.
Lachaud, E. (2020). Iso/iec 27701: Threats and opportuni-
ties for gdpr certification. Available at SSRN, 1:1–23.
Lindgren, P. (2020). The impact on multi business model
innovation related to GDPR regulation. In HICSS,
pages 1–8, http://hdl.handle.net/10125/64279. Schol-
arSpace.
Lu, Y. and Li, S. (2020). From data flows to privacy is-
sues: A user-centric semantic model for representing
and discovering privacy issues. In HICSS, pages 1–10.
ScholarSpace.
Proposal of an Implementation Process for the Brazilian General Data Protection Law (LGPD)
29