The Law No. 13,709/2018, known as the General Data Protection Law (LGPD), defines a series of requirements for the processing of personal data. The research investigates the initiatives of two private, non-profit higher education institutions, Universidade FUMEC and Pontifícia Universidade Católica de Minas Gerais, based in Belo Horizonte (Minas Gerais, Brazil), to adapt to the LGPD. Specifically, it analyzes the use of information technology governance and data governance standards or frameworks, and the results obtained. The research is exploratory and descriptive, with a qualitative approach. For the multi-case study, in addition to documentary research, semi-structured interviews were carried out with the Data Protection Officer (DPO) and the Information Technology Manager. The ITIL framework was found to be used, but even when applied in a limited way, it provided a solid process and knowledge base for information technology governance operations. Data governance is still little used, pointing to the need to implement it in order to better manage the volume of information. There is consensus among the DPOs that compliance with the LGPD is an ongoing process and requires updates and improvements.
Keywords:
Data protection; Right to privacy; Universities; Data governance; Information technology governance