Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. LGPD · BRAZIL'S DATA PROTECTION LAW
  3. LGPD compliance

LGPD · BRAZIL'S DATA PROTECTION LAW

Compliance that is still standing after the project ends

The initial assessment is the easy part, and it is where most projects both start and finish. What decides whether your company can answer a customer or the regulator two years later is who keeps the inventory current, who revisits the legal bases when the business changes, and who answers data subjects on time. That is what this page is about.

Talk to a specialistSee the other standards

The LGPD is a law, and interpreting it is legal work. DM11 runs the project with a digital law specialist alongside the management specialist, because splitting those two apart is what produces a handsome project that will not survive an inspection. Where the goal also includes a document issued by a third party, the ISO 27701 page explains that route.

Who runs the project

  • Data protection specialists certified by EXIN (DPO, PDPP and PDPF)

  • Legal advisory in privacy and digital law

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • 17 years of governance, risk and compliance

WHAT THE LAW REQUIRES

A law of principles, enforced through dated evidence

Law 13.709/2018 reaches any company processing personal data in Brazil, and a company processes personal data if it has employees, customers or individual suppliers. It lists no technology and no controls: it lists principles, data subject rights and responsibilities. In practice that means the company chooses how to comply, and has to be able to demonstrate what it chose, when it decided, and why.

It applies at any size, with no floor

There is no minimum revenue and no headcount below which the law stops reaching you. What does exist is a simplified regime from the Brazilian data protection authority for small-scale processing agents, which reduces formality in some obligations without removing any of them. A small company has less paperwork to produce, not fewer duties.

The legal basis comes before consent

The most common and most expensive mistake is treating consent as the default. The law provides ten legal bases, and consent is one of them, almost always the most fragile for a business process, because it can be withdrawn at any moment and takes the processing down with it. Choosing the right basis per processing activity is the decision that most reshapes the project, and it is a legal decision.

The data protection officer has to exist and be findable

The law requires you to appoint an officer for personal data processing and to publish their identity and contact details. It can be someone internal with the role formalised, or an outsourced service. What does not work is a name in the website footer with no process behind it, because data subjects write to it and the clock starts running.

How compliance is proved

Worth settling early, because it shapes what the company has to produce. The law itself is not certifiable, and what demonstrates compliance is dated evidence: an inventory of processing activities, a recorded legal basis, an impact report where the law requires one, records of data subject requests answered, and proof the governance works. When a customer wants a document issued by a third party, and European customers usually do, the route is ISO 27701, and the material built here carries into that project intact.

WHO USUALLY GETS IN TOUCH

Three situations where the conversation starts

The LGPD rarely reaches the agenda out of conviction. It reaches it because somebody outside asked, or because something happened.

A privacy questionnaire arrived

A large customer, a bank, an insurer or a foreign company sent a form with dozens of questions and a short deadline. Answering it without a basis produces two bad outcomes: an optimistic answer that will not survive the next audit, and a missing answer that stalls the contract.

There was an incident, or nearly one

A leak, ransomware, or an email that went to the wrong list. The question that appears immediately is whether the regulator and the data subjects have to be notified, and that is a terrible decision to make in a hurry, with no inventory and no plan defined beforehand.

Due diligence is coming

A sale, a funding round or a new shareholder. Privacy has become a due diligence checklist item, and a personal data liability has shown up as a price reduction in real transactions. Here the deadline comes from somebody else's calendar, and it does not negotiate.

STORIES

Three situations we have already worked through

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.

E-commerce

Everything rested on consent

Situation

The company had put a consent notice at every collection point and considered the matter closed. When deletion requests started arriving, it discovered the same tick box supported order delivery, invoicing and billing, and that honouring a request to the letter would break the operation.

What we did

We redid the analysis activity by activity, with legal alongside. Much of what sat under consent had a better basis available: performance of a contract for delivery, a legal obligation for invoicing, documented legitimate interest for fraud prevention. Consent stayed where it genuinely is the right basis, which is marketing communication.

Outcome

Deletion requests stopped being a crisis and became a process. And the marketing base shrank far less than the team feared, because almost everything else had never depended on consent to begin with.

Recruitment services

Candidate data kept since forever

Situation

The company held CVs, test results and interview notes for everyone who had ever applied, with no retention period and no criteria. Nobody had decided to keep them permanently: there had simply never been a decision to delete, and the volume built up over years.

What we did

We set retention periods by type of information, with legal assessing what has to stay for statutory reasons and what only existed out of convenience. We implemented the deletion, and the hard part was not technical: it was agreeing what to do with an interviewer's subjective notes, which are personal data and which the team did not see that way.

Outcome

The archive shrank considerably, and with it the size of any future incident. Data that no longer exists cannot leak, and that was the cheapest risk reduction in the whole project.

Manufacturing

Forty suppliers with access and no clause

Situation

Dozens of suppliers touched the company's personal data, from payroll to benefits, from the time clock system to the training platform. No contract carried a data protection clause, and nobody could say which of them stored information outside the country.

What we did

We established who touches what and classified by risk, rather than treating all forty as equals. The few critical ones got a full contractual review and verification of where the data sits. The rest went into a standard addendum with a deadline, and procurement started requiring the clause before signature.

Outcome

The gain was not only legal. Mapping the suppliers, the company discovered three systems contracted by individual departments, never routed through IT, processing employee data. Two were shut down.

HOW WE RUN IT

From mapping to governance that sustains itself

Legal and management run together from day one, not in sequence. A project driven only by legal produces an opinion nobody operates, and one driven only by technology produces controls with no legal basis behind them. The two readings have to meet on every processing activity.

  1. 01

    Mapping: where personal data enters, moves and leaves

    We establish the processing activities by business process, with the people who operate them rather than only those who coordinate, because the official spreadsheet almost never matches practice. We record origin, purpose, who has access, where it goes, how long it stays and which suppliers touch it.

    • An inventory of processing activities by business process

    • The personal data flow, including transfers to third parties

    • A list of suppliers with access, classified by risk

    • Identification of what counts as sensitive personal data

    Delivery milestoneInventory approved by the departments that own the processes, not only by IT.

  2. 02

    Legal basis, risks and what the law requires on record

    With legal, we set the legal basis for each processing activity and record the reasoning. We assess the risks to data subjects, which are not the same as information security risks, and produce an impact report where the law or the risk calls for one.

    • A recorded and justified legal basis per processing activity

    • A legitimate interest assessment wherever that is the chosen basis

    • A data protection impact report, where applicable

    • A privacy policy and notices rewritten to match what the company actually does

    Delivery milestoneA legal basis defined for 100% of inventoried activities, with legal in agreement.

  3. 03

    Controls, contracts and data subject requests

    We implement with your team what holds the decision up day to day: access on a need basis, retention and deletion by data type, clauses in third-party contracts, and the data subject request process, with a channel, a deadline, a record and a standard response.

    • A data subject request process, with a deadline and a record

    • A retention and deletion policy, implemented rather than only written

    • Data protection clauses reviewed in third-party contracts

    • The data protection officer formalised and their contact published

    Delivery milestoneFirst cycle of data subject requests answered on time, with a complete record.

  4. 04

    Governance, an incident rehearsal and maintenance

    This is the phase that separates compliance from a report. We define who reviews what and how often, train the people who operate, and rehearse an incident, so the decision to notify the regulator and the data subjects gets made with a plan in hand rather than in a panic.

    • A review routine defined, with an owner and a frequency

    • A personal data incident response plan, rehearsed

    • Training for the departments that handle the most personal data

    • A report for leadership, with whatever remains open written down

    Delivery milestoneIncident rehearsal completed, with the notification decision taken inside the plan.

HOW LONG IT TAKES

The mapping is predictable. The rest depends on the size of the mess.

We do not publish a standard timeline, because a published timeline turns into a promise. The first conversation is usually enough to separate the two cases that come up most: the company that has never done anything, and the company that ran a project years ago and did not maintain it. The second is almost always closer than it thinks, and sometimes further away.

How many systems and suppliers touch personal data

An operation with half a dozen systems is one project. One with dozens of suppliers and departments buying tools on their own is another, and much of the time goes into discovering what exists before anything can be decided.

Whether someone can take on the officer role

With an internal candidate available, the role is formalised quickly. With nobody, the choice between appointing internally and contracting the service has to be made early, because the officer takes part in the project rather than arriving once it is finished.

Whether the destination is compliance alone or certification too

Compliance is enough to answer a customer or the regulator with your own evidence. Where there is an intention to certify privacy later, we organise the material in ISO 27701's shape from the start, which costs little now and saves an entire project later.

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

The law itself is not certifiable, and it is worth knowing that before contracting anything, because the term circulates widely in the Brazilian market. What demonstrates compliance is evidence: a current inventory, a recorded legal basis, a working data subject request process, and governance you can prove with a dated document. If what you need is a document issued by a third party, to answer a customer or a regulator, the certifiable privacy standard is ISO 27701, and this compliance work is precisely its foundation.

Received a privacy questionnaire and unsure where to start?

Bring us the questionnaire or the contract clause. We will tell you what already exists in your company that answers it, what is genuinely missing, and in what order it makes sense to resolve, without turning this into a two-year programme.

Talk to a specialist

Comparisons on this subject

  • ISO 27701 vs LGPD
  • GDPR vs LGPD
See all 13 comparisons