Privacy and personal data protection: new ESG parameters.
The last few decades have brought accelerated growth and change across all sectors of the economy. New industries, business models, and forms of investment emerge ever more rapidly in the context of globalization and new technologies. Hand in hand with these phenomena, there has also arisen a greater awareness of and concern for the impacts that both companies and consumers generate on the environment and on society at a global level.
Today, both consumers and investors look beyond the financial aspect when selecting new suppliers or business opportunities, so that, in seeking clients or capital, companies must demonstrate that their projects have a better track record than those of their competitors in terms of sustainability, encompassing environmental, social, and corporate governance (ESG) aspects. While the vast majority of consumers prefer to acquire products or services from companies that promote individual or collective well-being, an investor bets on companies that follow ESG criteria, interpreting them as a measure of legal and reputational risk. While it is true that the concept of ESG is broad and encompasses various parameters within its three principal categories (Environmental, Social, and Corporate Governance), ESG should not be regarded as a set of static categories, but rather should include new parameters and concepts that evolve in accordance with the interests that hold the greatest value for a given society. For this reason, the safeguarding of privacy and the protection of personal data should be regarded as a new parameter in the fulfillment of ESG criteria. While the economy in which the concept of ESG arose was based on fossil-fuel industries and the transformation of physical resources, the present and future economy is digital in character, since it is built upon the analysis and exchange of information. Some authors consider that data is the new oil; in that sense, the ESG approach, centered on commitment and social well-being, must contemplate its protection as a central issue. This being so, within which ESG category might the protection of such data fall, and in what manner could it be exercised within the framework of our law and everyday life? In accordance with the accountability standards used by most companies committed to ESG criteria, privacy and data protection is included within the social category. This classification is apt owing to the closeness between personal data and access to financial services, telecommunications, mobility, and medicine, so that the breach of a single database could have truly massive effects and harm entire communities. Likewise, it could expose any responsible company to countless fines and class and individual lawsuits (not to mention the damage to its reputation). In a data economy, any company lacking a clear strategy to defend this asset would suffer the consequences of such an omission, both public and commercial. Therefore, the protection of personal data is a social and extra-legal concept, since it affects both the various interest groups and the company itself. Our country's legal system underscores the social relevance of privacy and the protection of personal data. The Mexican Constitution considers both concepts to be human rights, and contemplates a regulator empowered to guarantee their observance. Various secondary laws require both public- and private-sector subjects to inform those individuals whose data they hold about the conditions of the processing of such data, urging them to request their prior consent, as well as to report any breach of their personal information. These laws make express reference to the fundamental concepts of ESG, by establishing that those who process personal data must respect principles of loyalty and responsibility toward the respective data owners. A second facet of ESG with regard to the protection of personal data and privacy is the corporate governance category. In order for the social commitment made by a company as the party responsible for processing not to remain indeterminate or be limited to the drafting of privacy notices or codes of conduct, the compliance and security measures set forth by law must be put into practice. In fact, an individual or department within the company is required who is effectively empowered and trained to carry out these tasks and to promote the proper use of the information subject to processing. Although the obligations established in this regard under Mexican legislation are limited, since they comprise only the designation of a person in charge of responding to requests related to personal data, the measures adopted by various companies, whether voluntarily or on the basis of foreign legislation, are positive indicators of the relevance that the protection of personal data has acquired. Among these measures are the designation of executives specifically charged with reviewing compliance with the applicable regulations on privacy; the dissemination of internal materials and policies to train company personnel in the correct and minimal processing of personal data; and the engagement of suppliers specialized in the secure processing of information. With so many measures and agents involved in the personal data ecosystem, it is understandable why the protection of personal data generates concern. Although this subject is relatively new within the concept of ESG, the safeguarding of the information of clients, suppliers, and investors has had to be integrated suddenly into companies, since various organizations have experienced negative effects from failing to address this issue, which manifest themselves in the now well-known breaches of personal data or data breaches. On average, each of these incidents has cost North American companies between 3 and 7 million dollars in the short term. However, the damage generated by breaches such as those suffered by Equifax, Facebook, Target, or Marriott does not stop there. As with ESG, the effects can be multidisciplinary, encompassing class actions, government sanctions, and damage to public relations and to their clients that would be very difficult to quantify. Likewise, the general public's awareness of the value and the dangers involved in the processing of their personal data is increasing. This is demonstrated by the fact that recent reforms to allow private financial-sector entities and government agents to collect personal data on a massive scale have faced serious questioning. For the reasons set out above, it is evident why any company should focus on avoiding these risks and incidents, and the reason why it would be attractive for its executives and investors to do so, even if it meant going beyond legal compliance. In a context such as the one we are currently living in, it is easy not only to explain the appearance of the criteria of privacy and personal data protection within the ESG accountability scheme, but also to predict that such matters will soon occupy a central place in the planning and life of companies. Is yours prepared? For additional information on the subject of this note, please contact our experts: Luis Burgueño, Partner: +52 (55) 5258-1003 | lburgueno@vwys.com.mx Gloria Martínez, Counsel: +52 (55) 5258-1016 | gmartinez@vwys.com.mx Rubén Villegas, Associate: +52 (55) 5258-1003 | rvillegas@vwys.com.mx

