The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
LGPD · BRAZIL'S DATA PROTECTION LAW
The initial assessment is the easy part, and it is where most projects both start and finish. What decides whether your company can answer a customer or the regulator two years later is who keeps the inventory current, who revisits the legal bases when the business changes, and who answers data subjects on time. That is what this page is about.
The LGPD is a law, and interpreting it is legal work. DM11 runs the project with a digital law specialist alongside the management specialist, because splitting those two apart is what produces a handsome project that will not survive an inspection. Where the goal also includes a document issued by a third party, the ISO 27701 page explains that route.
Who runs the project
Data protection specialists certified by EXIN (DPO, PDPP and PDPF)
Legal advisory in privacy and digital law
ISO/IEC 27001 Lead Auditor certified by BSI
17 years of governance, risk and compliance
WHAT THE LAW REQUIRES
Law 13.709/2018 reaches any company processing personal data in Brazil, and a company processes personal data if it has employees, customers or individual suppliers. It lists no technology and no controls: it lists principles, data subject rights and responsibilities. In practice that means the company chooses how to comply, and has to be able to demonstrate what it chose, when it decided, and why.
There is no minimum revenue and no headcount below which the law stops reaching you. What does exist is a simplified regime from the Brazilian data protection authority for small-scale processing agents, which reduces formality in some obligations without removing any of them. A small company has less paperwork to produce, not fewer duties.
The most common and most expensive mistake is treating consent as the default. The law provides ten legal bases, and consent is one of them, almost always the most fragile for a business process, because it can be withdrawn at any moment and takes the processing down with it. Choosing the right basis per processing activity is the decision that most reshapes the project, and it is a legal decision.
The law requires you to appoint an officer for personal data processing and to publish their identity and contact details. It can be someone internal with the role formalised, or an outsourced service. What does not work is a name in the website footer with no process behind it, because data subjects write to it and the clock starts running.
Worth settling early, because it shapes what the company has to produce. The law itself is not certifiable, and what demonstrates compliance is dated evidence: an inventory of processing activities, a recorded legal basis, an impact report where the law requires one, records of data subject requests answered, and proof the governance works. When a customer wants a document issued by a third party, and European customers usually do, the route is ISO 27701, and the material built here carries into that project intact.
WHO USUALLY GETS IN TOUCH
The LGPD rarely reaches the agenda out of conviction. It reaches it because somebody outside asked, or because something happened.
A large customer, a bank, an insurer or a foreign company sent a form with dozens of questions and a short deadline. Answering it without a basis produces two bad outcomes: an optimistic answer that will not survive the next audit, and a missing answer that stalls the contract.
A leak, ransomware, or an email that went to the wrong list. The question that appears immediately is whether the regulator and the data subjects have to be notified, and that is a terrible decision to make in a hurry, with no inventory and no plan defined beforehand.
A sale, a funding round or a new shareholder. Privacy has become a due diligence checklist item, and a personal data liability has shown up as a price reduction in real transactions. Here the deadline comes from somebody else's calendar, and it does not negotiate.
Translation
Brazilian data protection compliance is the name given to five different jobs. Whoever asks rarely knows which one they need, and finding that out is the first thing we do, because the wrong scope is expensive on both sides: either you pay for work nobody asked for, or you miss the thing that would have unblocked the deal.
| What reaches you | What it means | What changes in the work |
|---|---|---|
| “We need to be compliant with the LGPD” | A request with no scope. Compliance for the whole company, for one product, or only for what touches the data of the customer who is asking. | The conversation starts with which of the three. Doing the whole company when one contract is stuck spends months in the wrong place. |
| “A customer sent a privacy questionnaire” | Third-party due diligence. They do not want a programme: they want evidence that their data is handled with method. | Short and focused work. Map what that customer touches, write what is missing, and answer with evidence rather than promises. |
| “We need to appoint a data protection officer” | The law requires the name to be public. What it does not say is that the role is work every month. | Appointing is the easy part. The work is the data subject channel, the response deadline, every new contract and every new system. It can be taken on as a service. |
| “We had an incident and do not know whether to notify” | Real urgency, short window. Whether to notify depends on the risk to the data subject, and that call has to be made and recorded. | Incident response comes first, with the decision documented. The programme follows, and comes out better for what was learned. |
| “A European customer asked for guarantees on personal data” | GDPR enters the conversation. This is usually where a certificate answers better than a dossier. | The route changes: compliance work becomes the base for ISO 27701, and everything built here carries into that project. |
| “We want an opinion on the legal basis we chose” | This is not compliance work. It is legal advice, and DM11 does not provide it. | We say so in the first conversation. DM11 has digital law specialists on the team and still keeps the roles apart: we organise the operation, counsel decides what is lawful. |
None of this is price. Each of those lines is a different size of job, which is why the conversation starts with which one is yours.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
E-commerce
The company had put a consent notice at every collection point and considered the matter closed. When deletion requests started arriving, it discovered the same tick box supported order delivery, invoicing and billing, and that honouring a request to the letter would break the operation.
We redid the analysis activity by activity, with legal alongside. Much of what sat under consent had a better basis available: performance of a contract for delivery, a legal obligation for invoicing, documented legitimate interest for fraud prevention. Consent stayed where it genuinely is the right basis, which is marketing communication.
Deletion requests stopped being a crisis and became a process. And the marketing base shrank far less than the team feared, because almost everything else had never depended on consent to begin with.
Recruitment services
The company held CVs, test results and interview notes for everyone who had ever applied, with no retention period and no criteria. Nobody had decided to keep them permanently: there had simply never been a decision to delete, and the volume built up over years.
We set retention periods by type of information, with legal assessing what has to stay for statutory reasons and what only existed out of convenience. We implemented the deletion, and the hard part was not technical: it was agreeing what to do with an interviewer's subjective notes, which are personal data and which the team did not see that way.
The archive shrank considerably, and with it the size of any future incident. Data that no longer exists cannot leak, and that was the cheapest risk reduction in the whole project.
Manufacturing
Dozens of suppliers touched the company's personal data, from payroll to benefits, from the time clock system to the training platform. No contract carried a data protection clause, and nobody could say which of them stored information outside the country.
We established who touches what and classified by risk, rather than treating all forty as equals. The few critical ones got a full contractual review and verification of where the data sits. The rest went into a standard addendum with a deadline, and procurement started requiring the clause before signature.
The gain was not only legal. Mapping the suppliers, the company discovered three systems contracted by individual departments, never routed through IT, processing employee data. Two were shut down.
SELF-ASSESSMENT
The first four questions classify your case, because being a controller, a processor or both changes almost everything. The other sixteen measure what exists and is still standing. The full result appears on screen, with a score for each area. We do not ask for your email to show it. This measures management and evidence; it is not a legal reading of the law and it does not replace your counsel's analysis.
WHO DOES WHAT
The law requires a data protection officer, and requires the name to be public. What it does not say is that the role is continuous work: subject requests, incidents, every new contract, every new system. It is where most programmes stop after the assessment.
HOW WE RUN IT
Legal and management run together from day one, not in sequence. A project driven only by legal produces an opinion nobody operates, and one driven only by technology produces controls with no legal basis behind them. The two readings have to meet on every processing activity.
We establish the processing activities by business process, with the people who operate them rather than only those who coordinate, because the official spreadsheet almost never matches practice. We record origin, purpose, who has access, where it goes, how long it stays and which suppliers touch it.
An inventory of processing activities by business process
The personal data flow, including transfers to third parties
A list of suppliers with access, classified by risk
Identification of what counts as sensitive personal data
Delivery milestoneInventory approved by the departments that own the processes, not only by IT.
With legal, we set the legal basis for each processing activity and record the reasoning. We assess the risks to data subjects, which are not the same as information security risks, and produce an impact report where the law or the risk calls for one.
A recorded and justified legal basis per processing activity
A legitimate interest assessment wherever that is the chosen basis
A data protection impact report, where applicable
A privacy policy and notices rewritten to match what the company actually does
Delivery milestoneA legal basis defined for 100% of inventoried activities, with legal in agreement.
We implement with your team what holds the decision up day to day: access on a need basis, retention and deletion by data type, clauses in third-party contracts, and the data subject request process, with a channel, a deadline, a record and a standard response.
A data subject request process, with a deadline and a record
A retention and deletion policy, implemented rather than only written
Data protection clauses reviewed in third-party contracts
The data protection officer formalised and their contact published
Delivery milestoneFirst cycle of data subject requests answered on time, with a complete record.
This is the phase that separates compliance from a report. We define who reviews what and how often, train the people who operate, and rehearse an incident, so the decision to notify the regulator and the data subjects gets made with a plan in hand rather than in a panic.
A review routine defined, with an owner and a frequency
A personal data incident response plan, rehearsed
Training for the departments that handle the most personal data
A report for leadership, with whatever remains open written down
Delivery milestoneIncident rehearsal completed, with the notification decision taken inside the plan.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. The first conversation is usually enough to separate the two cases that come up most: the company that has never done anything, and the company that ran a project years ago and did not maintain it. The second is almost always closer than it thinks, and sometimes further away.
An operation with half a dozen systems is one project. One with dozens of suppliers and departments buying tools on their own is another, and much of the time goes into discovering what exists before anything can be decided.
With an internal candidate available, the role is formalised quickly. With nobody, the choice between appointing internally and contracting the service has to be made early, because the officer takes part in the project rather than arriving once it is finished.
Compliance is enough to answer a customer or the regulator with your own evidence. Where there is an intention to certify privacy later, we organise the material in ISO 27701's shape from the start, which costs little now and saves an entire project later.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
The law itself is not certifiable, and it is worth knowing that before contracting anything, because the term circulates widely in the Brazilian market. What demonstrates compliance is evidence: a current inventory, a recorded legal basis, a working data subject request process, and governance you can prove with a dated document. If what you need is a document issued by a third party, to answer a customer or a regulator, the certifiable privacy standard is ISO 27701, and this compliance work is precisely its foundation.
It does. There is no minimum size, and any company with employees already processes personal data. What exists is a simplified regime from the Brazilian data protection authority for small-scale processing agents, easing formality in some obligations. It reduces paperwork, not duty: legal basis, data subject rights and information security all continue to apply in full.
No, and resting everything on consent is the mistake that causes the most trouble later. The law provides ten legal bases, and several suit a business process better: performance of a contract, compliance with a legal obligation, legitimate interest. Consent can be withdrawn at any time, and where it supports something essential, withdrawal takes the operation down with it. Choosing the right basis per activity is a legal decision, and the one that most reshapes the project.
The law requires appointing an officer and publishing their identity and contact details. It can be someone internal, with the role formalised and real time to perform it, or an outsourced service. What does not solve anything is publishing an email address with no process behind it: the moment the contact exists, data subjects write to it, and from then on the response clock is running.
It depends on whether there is relevant risk to data subjects, and that is a terrible assessment to make on the day. Notifying the regulator and the data subjects is required where the incident may cause relevant risk or harm, and the deadline and form follow the data protection authority's regulation, which changes more often than the law does. That is why the decision has to be rehearsed in advance: with an inventory in hand you can say within hours which data was affected, and without one the company spends days finding out.
It helps considerably and it does not cover it. ISO 27001 covers the security side the LGPD also requires, and that evidence carries over almost intact: access control, logging, third-party management, incident response. What it does not cover is the legal core of the law, which is legal basis, data subject rights, purpose and retention. They are different layers, and certified companies are often surprised by how much of that second one is missing.
Bring us the questionnaire or the contract clause. We will tell you what already exists in your company that answers it, what is genuinely missing, and in what order it makes sense to resolve, without turning this into a two-year programme.