top of page

SFTP-SSH and Compliance with the LGPD (General Personal Data Protection Law)

​

File transfer can constitute a high-risk activity regarding compliance with new personal data protection requirements, as discussed below.

​

Based on these principles, we consider that security and compliance risks in the standard z/OS FTP environment arise from the absence of:

​

<> encryption: in transfers lacking SFTP support, file transmissions occur in plaintext (unencrypted) and are vulnerable to breaches using various simple technologies. The exposure of personal data would constitute a serious violation of the LGPD.

 

<> automation: repetitive file transfer requirements increase process complexity in most FTP environments, exposing companies to the risk of human error and data loss. Automating file transfer workflows provides a governance mechanism that facilitates the mitigation of data loss risks and penalties associated with non-compliance.

 

<> visibility: FTP servers lack the visibility and logging capabilities necessary for LGPD compliance. Logs must be tamper-proof and auditable regarding when a file is transferred, whether it was received correctly, and whether or not it was subsequently discarded.

 

<> scalability: IT teams develop scripts to automate file transfer activities. As needs grow, the complexity of maintaining these scripts increases, potentially introducing unwanted security vulnerabilities.

What are the risks?

From a security perspective, the data transmitted is at risk because it is vulnerable to the following conditions: interception and theft, unauthorized access, delivery to an unintended recipient, or handling errors when processed at the destination.

Scenarios:

  • Data files sent via standard FTP are not encrypted and are rarely discarded when they become unnecessary;

  • Anonymous FTP mode, outdated security patches, and other vulnerabilities, such as decentralized control over permissions, expose user credentials, making it easier for hackers to gain access.

  • Desktop users may send personal data through insecure means, such as email or cloud-based file-sharing services;

  • The absence of audit trails creates loopholes for unauthorized transfers or failures.

Up to this point, we have listed elements that require careful attention regarding the external transfer of personal data files, in preparation for compliance with the LGPD (Brazilian General Data Protection Law), but...

What does Workers Informática offer the Brazilian market in terms of compliance with the LGPD (Brazilian General Data Protection Law), especially regarding the use of secure FTP in the z/OS environment?

 

SDS's VFTP-SSH solution provides secure FTP on z/OS and other platforms, which can help in the process of complying with current regulatory standards, such as the LGPD (Brazilian General Data Protection Law).

We believe it is highly advisable to plan ahead to meet the compliance requirements of the new law, which will ensure improved overall security of the environment, reduce the threat of breaches, avoid severe sanctions, and prevent exposure of the company and associated business costs.

It operates within the z/OS environment, protecting, managing, authenticating, automating, and encrypting FTP traffic without requiring changes to JCL.

It provides a comprehensive audit trail that complies with current regulations.

​

All FTP traffic can be dynamically converted to SFTP or redirected via an SSH tunnel, with native support for SFTP, SSH, and FTPS.

​

Management is handled through a web interface, providing detailed, real-time, end-to-end visibility of FTP traffic.

​

VFTP-SSH operates in compliance with SAF (RACF, ACF2, and Top Secret), verifies the integrity of transferred files, and can automate jobs and transfers using FCL (FTP Control Language).

​

VFTP-SSH is a secure FTP solution offering enhanced usability, SAF integration, and encryption—all in compliance with industry security policies.

Copyright © 2026 Workers Informática Ltda

  • Facebook
  • Twitter
  • LinkedIn
bottom of page