INTERVIEW

João Miranda de Sousa, of Garrigues: “Today, it is no longer enough simply to master specific areas of law”

INTERVIEW

Mafalda Barreto, of Gómez-Acebo & Pombo: “Clients no longer look only for lawyers; they look for strategic partners”

Cyntia Menezes, from Font Advocats, and Carlos Sáiz, from Cumplen, analyze the evolution of data protection in Latin America over the last 10 years

By Heidi Maldonado
May 16, 2022 | By Heidi Maldonado

Recently, in this same space, we discussed the metaverse revolution: normative, legal, and regulatory challenges. Today, together with Cyntia Menezes, associate lawyer at Font Advocats, and Carlos Sáiz, president of Cumplen and partner at Ecix Group, we analyze the evolution of data protection in Latin America, focusing the discussion on how, following the entry into force of the European Union’s General Data Protection Regulation (GDPR), a new season of legislative changes began in many countries.

We also learned, from their experiences, what the biggest problem is with data privacy laws in Latin America, and the specialists also specified what companies that want to work in the metaverse should take into account in terms of data protection.

How has data protection evolved in Latin America over the past 10 years?

Cyntia Menezes: “Over the last decade, we have seen significant developments in data privacy regulation in Latin America. The first countries to legislate on this matter, before the wave of legislation in the last decade, were Chile (1999) and Argentina (2000), but from 2010 onwards, we began to see broader efforts in the region, with the enactment of specific laws in Mexico (2010), Peru (2011), and Colombia (2012), for example. Other countries, such as Brazil, had legal provisions on data protection scattered across different legislation (consumer protection, regulation of internet services, and civil and criminal codes, for example), but with the entry into force of the European Union’s General Data Protection Regulation (GDPR), a new wave of legislative changes began in the region.”

This situation arises from the breadth and complexity of the GDPR, which inspires legislative changes worldwide, but also from its extraterritorial nature. Countries that trade with the EU—and in Latin America, all do—were forced to adapt to continue operating in the European market. This entailed a race, both to adapt existing laws to the new criteria and to create a new legal framework. All of this led countries that lacked specific privacy laws to develop their own new regulatory frameworks; this is the case in countries like Brazil, Bolivia, and Ecuador, for example. Likewise, countries that already had regulatory frameworks (Chile and Argentina) are also seeking to update or replace them to adapt to the new GDPR criteria.

Carlos Sáiz: “It has evolved a lot. We have seen how several countries have approved their own regulations, aware of the need to regulate the protection of a key right in the digital society we live in. The approval of the General Data Protection Regulation in Europe in 2016, and its full application since 2018, has been a very important lever for data protection worldwide, as many national regulations have aligned their own legal systems with the principles and methodologies of the European Regulation.”

What are the challenges and opportunities for the coming years in the area of data protection?

Cyntia Menezes: “The most important thing to understand is that the problem of personal data protection doesn’t end with the enactment of a regulatory framework. When we talk about personal data, we must bear in mind that we live in a society profoundly marked by constant technological developments and by an increasingly data-dependent economy (the concept of the “data economy”). The combination of these two factors will require a state of almost constant vigilance, not only on the part of civil society but also of public administrations.”

Given this scenario, the main challenges we highlight are the growing volume of data generated by citizens (a volume that always tends to increase) which causesData management is becoming increasingly difficult for both companies and the data subject (the individual). Furthermore, we encounter a lack of transparency in the systems of large corporations.Technology companies that make it very difficult for the average citizen to clearly understand how their data is being processed (and whether their rights are being respected), and that also hinder the work of oversight and control by regulatory agencies; or thejurisdictional problems of international data transfers.”

Carlos Sáiz: “The great challenge of data protection is that it is necessary to protect personal information regardless of whether it is verbal, on paper, or digital in its different versions or technologies. The challenge is to be able to implement appropriate security policies in a digital transformation environment that has been accelerated by the pandemic in all organizations. We must adapt and work to correctly analyze the risks to which information is exposed and ensure that data is protected in those technologies and trends that are already a reality and that have a certain degree of complexity: Cloud, social networks, blockchain, facial recognition, AI, edge computing, the metaverse, etc.”

What do you think is the biggest problem with data privacy laws in Latin America?

Cyntia Menezes: “The main problem is not exactly in the legal framework, whatever it may be (no legal framework is perfect), but in the capacity of public administrations to manage, oversee and enforce the law.In particular, public administrations need to go beyond the strictly bureaucratic function and work to create an environment of equal conditions between two parties whose power imbalance is gigantic: the private citizen and big tech. This should be the effort: to level the playing field between the small and the large.”

Carlos Sáiz: “The approval of laws and the recognition of the right to data protection is the first step, but there are two key issues for effective respect for privacy: 1) the establishment of a strong Supervisory Authority with adequate resources, capable of serving citizens, proposing guidelines and best practices for companies and public administrations, with investigative and sanctioning powers, and knowledge of the technological advances being incorporated into our daily lives; and 2) fostering a privacy culture at all levels, both among citizens to make them aware of their rights, and among managers, company employees, and public officials to raise awareness of the need to apply work methods and data processing diligently and in compliance with regulations. Organizations need qualified professionals and appropriate technology to implement a privacy compliance system where data processing is controlled according to legal criteria.”

The arrival of the metaverse and the rise of fintech bring with them a series of privacy challenges that may involve the creation of new data protection laws or the adaptation of existing ones. How do you see the landscape?

Cyntia Menezes: “As we have said before, with the entry into force of the GDPR, the current regulatory landscape is already changing. New technologies and new digital business models will have to adapt to existing regulations and develop their processes accordingly. It is to be expected, obviously, that these new business models and future technological advances will present challenges within the existing regulatory framework, but, more than legislative changes, what we will begin to see more frequently are the actions of regulatory agencies/public administrations in the interpretation and application of the existing framework, in addition to judicial decisions. Specifically in the area of data protection, this is what we expect to see in the medium term.”

However, all these new technologies and the growing concentration of power in big tech companies are leading to the development of a regulatory framework for technology that, onceOnce in force, it could significantly change the current landscape. The European Parliament, for example, is currently discussing a series of proposed Regulations on Artificial Intelligence, Digital Services, and Digital Markets—to name a few—which it intends to adopt in the next two years and which will surely lead to legislative changes around the world, just as happened with the GDPR. We understand that, at this time, these are the most significant legislative changes we can expect.”

Carlos Sáiz: “Data protection is very cross-cutting, and ultimately, many of the processes of organizations, both public and private, involve data processing. I believe we are not moving towards a model of specific regulations that partially or sectorally govern data protection issues, but rather towards general rules that implement the main values of data protection and, subsequently, towards a model of sectoral self-regulation through best practices and standards that detail more specific measures applicable to specific processing activities (financial, telecommunications, utilities, etc.). Some of these tools are Codes of Conduct or so-called “Binding Corporate Rules” for corporate groups with international data transfers.”

What should companies that want to work in the metaverse take into account in terms of data protection?

Cyntia Menezes: “First and foremost, they must understand that the metaverse is not an “unregulated” space, or one not subject to any jurisdiction. However sophisticated the system may be, it remains a space for interaction between people, and is therefore subject to the rules and laws applicable to the entire digital environment. In particular, companies must make efforts to ensure respect for the rights and freedoms of individuals, informing them clearly and simply about their rights and responsibilities and about internal rules for using the system. They must also implement efficient customer service processes and ensure a technologically secure environment, paying special attention to protecting minors and vulnerable groups.”

Carlos Sáiz: “The metaverse is a new digital scenario where the user will have an immersive experience whose action will generate a multitude of new data for the companies that manage that metaverse (because there will be many) and for the companies that sell products and/or services in the metaverse (digital stores).

Companies operating in the metaverse must: a) conduct a risk analysis and data protection impact assessment prior to launching their service or product, b) clearly define the legal basis for data processing, design appropriate policies and procedures, and clearly request appropriate customer consent, ensuring its traceability is fully managed, c) process data for commercial purposes correctly and in accordance with legal principles, d) implement the necessary security measures to prevent data breaches, e) sign appropriate confidentiality agreements with any third parties involved in processing customer data, and f) conduct audits and monitoring to verify that all data processing is carried out in accordance with their policies, procedures, and the applicable regulations.

Related Articles

Editar Imagenes de Higthligths

You are not permitted to submit this form!







    Editar Imagenes de Higthligths

    You are not permitted to submit this form!

    Editar reconocimientos - Latin Lawyer

    Contenido Reconocimiento Latin Lawyer*

    Editar reconocimientos - Leaders League

    Contenido Reconocimiento Leaders League*

    Editar link equipo

    Editar Oficinas

    Editar de highlight

    Editar reconocimientos - Legal 500

    Contenido Reconocimiento Chambers*

    Editar Reconocimientos - Chamber

    Contenido Reconocimiento Chambers*

    Editar Banner

    Selecciona un Banner*

    Editar reconocimientos

    Editar reconocimientos

    Contenido Reconocimiento Interno*

    Editar resumen

    Editar sectores de actividad

    Sectores de Actividad*

    Editar áreas de practica

    Areas de practica*

    Editar tag

    Tags*

    Edita otros datos de interés

    You are not permitted to submit this form!

    Editar logo

    You are not permitted to submit this form!

    Editar datos de firma