Incident Response Plan Aligned with the LGPD Standard
The organization maintains structured procedures for the prevention, detection, containment, investigation, and handling of security incidents involving personal data, in compliance with the principles and obligations set forth in the Brazilian General Personal Data Protection Law (Law No. 13.709/2018 aka LGPD) and other related information security standards.
1. Incident Detection and Identification
The institution continuously monitors its systems, databases, and technological assets to identify unauthorized access, intrusions, leaks, or any event that could compromise the integrity, confidentiality, or availability of personal data. Once an incident is detected, a preliminary classification is performed, taking into account the nature, potential impact, category of affected data, and risk to data subjects.
2. Immediate Containment
Upon confirmation of the incident, emergency containment measures are adopted, including isolating compromised systems, suspending suspicious credentials, blocking irregular connections, and applying additional security controls. These actions aim to halt ongoing unauthorized access, mitigate damage, and preserve evidence necessary for investigating the facts.
3. Analysis and Investigation
The organization conducts a technical and legal investigation of the incident, adhering to practices for evidence preservation and chain of custody. Logs, audit trails, access records, and other elements are analyzed to identify the event's origin, the attack vector, the scope of the compromise, and the personal data involved. The risk to data subjects is also assessed in accordance with the criteria set forth in Art. 48 of the LGPD.
4. Threat Eradication
Following the investigation, measures are implemented to eliminate the incident's root cause, including removing malicious code, remediating exploited vulnerabilities, reconfiguring systems, and strengthening authentication and access control policies. The aim is to ensure that no persistence mechanisms or vulnerabilities remain that could lead to further incidents.
5. Recovery and Restoration
Once eradication is complete, the affected systems are restored using intact and verified backups. Operations resume gradually and under monitoring, ensuring the environments are secure and that there is no significant residual risk to data subjects.
6. Communication and Notification
The organization communicates internally with the relevant departments and, where applicable, notifies the National Data Protection Authority (ANPD) and the affected data subjects, in accordance with Article 48 of the LGPD. The notification includes a description of the nature of the personal data involved, the technical and security measures adopted, the risks associated with the incident, and the steps taken to mitigate its effects.
7. Post-Incident Review
Following the resolution of the incident, a post-event analysis ("post-mortem") is conducted to identify failures, vulnerabilities, and opportunities for improvement. Internal procedures are updated, security controls are reinforced, and training is provided to the teams involved, ensuring the continuous evolution of personal data governance and the prevention of recurrence.