LGPD · BRAZIL'S DATA PROTECTION LAW
The initial assessment is the easy part, and it is where most projects both start and finish. What decides whether your company can answer a customer or the regulator two years later is who keeps the inventory current, who revisits the legal bases when the business changes, and who answers data subjects on time. That is what this page is about.
The LGPD is a law, and interpreting it is legal work. DM11 runs the project with a digital law specialist alongside the management specialist, because splitting those two apart is what produces a handsome project that will not survive an inspection. Where the goal also includes a document issued by a third party, the ISO 27701 page explains that route.
Who runs the project
Data protection specialists certified by EXIN (DPO, PDPP and PDPF)
Legal advisory in privacy and digital law
ISO/IEC 27001 Lead Auditor certified by BSI
17 years of governance, risk and compliance
WHAT THE LAW REQUIRES
Law 13.709/2018 reaches any company processing personal data in Brazil, and a company processes personal data if it has employees, customers or individual suppliers. It lists no technology and no controls: it lists principles, data subject rights and responsibilities. In practice that means the company chooses how to comply, and has to be able to demonstrate what it chose, when it decided, and why.
There is no minimum revenue and no headcount below which the law stops reaching you. What does exist is a simplified regime from the Brazilian data protection authority for small-scale processing agents, which reduces formality in some obligations without removing any of them. A small company has less paperwork to produce, not fewer duties.
The most common and most expensive mistake is treating consent as the default. The law provides ten legal bases, and consent is one of them, almost always the most fragile for a business process, because it can be withdrawn at any moment and takes the processing down with it. Choosing the right basis per processing activity is the decision that most reshapes the project, and it is a legal decision.
The law requires you to appoint an officer for personal data processing and to publish their identity and contact details. It can be someone internal with the role formalised, or an outsourced service. What does not work is a name in the website footer with no process behind it, because data subjects write to it and the clock starts running.
Worth settling early, because it shapes what the company has to produce. The law itself is not certifiable, and what demonstrates compliance is dated evidence: an inventory of processing activities, a recorded legal basis, an impact report where the law requires one, records of data subject requests answered, and proof the governance works. When a customer wants a document issued by a third party, and European customers usually do, the route is ISO 27701, and the material built here carries into that project intact.
WHO USUALLY GETS IN TOUCH
The LGPD rarely reaches the agenda out of conviction. It reaches it because somebody outside asked, or because something happened.
A large customer, a bank, an insurer or a foreign company sent a form with dozens of questions and a short deadline. Answering it without a basis produces two bad outcomes: an optimistic answer that will not survive the next audit, and a missing answer that stalls the contract.
A leak, ransomware, or an email that went to the wrong list. The question that appears immediately is whether the regulator and the data subjects have to be notified, and that is a terrible decision to make in a hurry, with no inventory and no plan defined beforehand.
A sale, a funding round or a new shareholder. Privacy has become a due diligence checklist item, and a personal data liability has shown up as a price reduction in real transactions. Here the deadline comes from somebody else's calendar, and it does not negotiate.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
E-commerce
The company had put a consent notice at every collection point and considered the matter closed. When deletion requests started arriving, it discovered the same tick box supported order delivery, invoicing and billing, and that honouring a request to the letter would break the operation.
We redid the analysis activity by activity, with legal alongside. Much of what sat under consent had a better basis available: performance of a contract for delivery, a legal obligation for invoicing, documented legitimate interest for fraud prevention. Consent stayed where it genuinely is the right basis, which is marketing communication.
Deletion requests stopped being a crisis and became a process. And the marketing base shrank far less than the team feared, because almost everything else had never depended on consent to begin with.
Recruitment services
The company held CVs, test results and interview notes for everyone who had ever applied, with no retention period and no criteria. Nobody had decided to keep them permanently: there had simply never been a decision to delete, and the volume built up over years.
We set retention periods by type of information, with legal assessing what has to stay for statutory reasons and what only existed out of convenience. We implemented the deletion, and the hard part was not technical: it was agreeing what to do with an interviewer's subjective notes, which are personal data and which the team did not see that way.
The archive shrank considerably, and with it the size of any future incident. Data that no longer exists cannot leak, and that was the cheapest risk reduction in the whole project.
Manufacturing
Dozens of suppliers touched the company's personal data, from payroll to benefits, from the time clock system to the training platform. No contract carried a data protection clause, and nobody could say which of them stored information outside the country.
We established who touches what and classified by risk, rather than treating all forty as equals. The few critical ones got a full contractual review and verification of where the data sits. The rest went into a standard addendum with a deadline, and procurement started requiring the clause before signature.
The gain was not only legal. Mapping the suppliers, the company discovered three systems contracted by individual departments, never routed through IT, processing employee data. Two were shut down.
HOW WE RUN IT
Legal and management run together from day one, not in sequence. A project driven only by legal produces an opinion nobody operates, and one driven only by technology produces controls with no legal basis behind them. The two readings have to meet on every processing activity.
We establish the processing activities by business process, with the people who operate them rather than only those who coordinate, because the official spreadsheet almost never matches practice. We record origin, purpose, who has access, where it goes, how long it stays and which suppliers touch it.
An inventory of processing activities by business process
The personal data flow, including transfers to third parties
A list of suppliers with access, classified by risk
Identification of what counts as sensitive personal data
Delivery milestoneInventory approved by the departments that own the processes, not only by IT.
With legal, we set the legal basis for each processing activity and record the reasoning. We assess the risks to data subjects, which are not the same as information security risks, and produce an impact report where the law or the risk calls for one.
A recorded and justified legal basis per processing activity
A legitimate interest assessment wherever that is the chosen basis
A data protection impact report, where applicable
A privacy policy and notices rewritten to match what the company actually does
Delivery milestoneA legal basis defined for 100% of inventoried activities, with legal in agreement.
We implement with your team what holds the decision up day to day: access on a need basis, retention and deletion by data type, clauses in third-party contracts, and the data subject request process, with a channel, a deadline, a record and a standard response.
A data subject request process, with a deadline and a record
A retention and deletion policy, implemented rather than only written
Data protection clauses reviewed in third-party contracts
The data protection officer formalised and their contact published
Delivery milestoneFirst cycle of data subject requests answered on time, with a complete record.
This is the phase that separates compliance from a report. We define who reviews what and how often, train the people who operate, and rehearse an incident, so the decision to notify the regulator and the data subjects gets made with a plan in hand rather than in a panic.
A review routine defined, with an owner and a frequency
A personal data incident response plan, rehearsed
Training for the departments that handle the most personal data
A report for leadership, with whatever remains open written down
Delivery milestoneIncident rehearsal completed, with the notification decision taken inside the plan.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. The first conversation is usually enough to separate the two cases that come up most: the company that has never done anything, and the company that ran a project years ago and did not maintain it. The second is almost always closer than it thinks, and sometimes further away.
An operation with half a dozen systems is one project. One with dozens of suppliers and departments buying tools on their own is another, and much of the time goes into discovering what exists before anything can be decided.
With an internal candidate available, the role is formalised quickly. With nobody, the choice between appointing internally and contracting the service has to be made early, because the officer takes part in the project rather than arriving once it is finished.
Compliance is enough to answer a customer or the regulator with your own evidence. Where there is an intention to certify privacy later, we organise the material in ISO 27701's shape from the start, which costs little now and saves an entire project later.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
The law itself is not certifiable, and it is worth knowing that before contracting anything, because the term circulates widely in the Brazilian market. What demonstrates compliance is evidence: a current inventory, a recorded legal basis, a working data subject request process, and governance you can prove with a dated document. If what you need is a document issued by a third party, to answer a customer or a regulator, the certifiable privacy standard is ISO 27701, and this compliance work is precisely its foundation.
Bring us the questionnaire or the contract clause. We will tell you what already exists in your company that answers it, what is genuinely missing, and in what order it makes sense to resolve, without turning this into a two-year programme.