LGPD and Data Protection· 16 min read

LGPD for Startups: What to Address Before Launching Your Product

Every startup that collects personal data — and practically all of them do — needs a minimum privacy program in place before opening the product to its first user.

The Lei Geral de Proteção de Dados (“LGPD,” Brazil’s General Data Protection Law, Law 13,709/2018) makes no exception for company size: a startup with fifty users and a startup with five million users are subject to the same obligations. What changes is the actual risk — data volume, data type, presence in regulated sectors — and, with it, the priority of what to structure first.

This article organizes what a startup needs to do before launch, the most frequent mistakes seen in practice, and when a “DPO as a Service” model makes sense. At the end, a section compares LGPD and GDPR side by side — for companies with users or clients in Europe.


TL;DR

  • Law 13,709/2018 makes no exception for startups: every company that processes personal data is subject to the same obligations.
  • Six items make up the minimum viable compliance package before launch: a public privacy policy, a data mapping exercise (RoPA), documented legal basis, a channel for responding to data subjects, a decision on the DPO, and data protection clauses in vendor contracts.
  • The most common mistakes are: using consent as the legal basis for everything, copying a generic privacy policy from the internet, and failing to formalize data processing agreements with vendors.
  • “DPO as a Service” makes sense for startups without an internal privacy structure, companies processing sensitive data at scale, and companies going through due diligence.
  • A Brazilian startup with users in Europe must observe the GDPR (Regulation (EU) 2016/679) simultaneously — the two frameworks have relevant practical differences in legal basis, incident notification deadlines, and penalties.

Updated on 06/17/2026


Table of Contents

  1. The due diligence scare
  2. Minimum viable LGPD: what a startup needs before launch
  3. The 5 most common LGPD compliance mistakes
  4. When “DPO as a Service” makes sense
  5. LGPD × GDPR: what changes for companies with cross-border operations
  6. Talk to a lawyer

The due diligence scare

Illustrative case — hypothetical scenario, created for educational purposes. Any resemblance to real cases is coincidental.

A B2B SaaS startup in the middle of a Series A fundraising round. The lead investor requested a complete data room, including a public and accessible privacy policy, a mapping of personal data processed (RoPA — Record of Processing Activities), evidence of a documented legal basis for each processing purpose, and the formal appointment of a Data Protection Officer (“DPO” — the Encarregado under Brazilian law). The company had none of these documents. It was given 30 days to produce the full set, with legal due diligence conditional on receiving it.

What was missing: the company collected data from end users, employees, and client companies across three different systems, with no central inventory of what data was processed, for what purpose, and under what legal basis. Its contracts with cloud and CRM vendors had no data protection clauses. The privacy policy published on its website had been copied from another product and described features that didn’t even exist.

Within 30 days, an initial mapping of data flows was carried out, a privacy policy reflecting the company’s actual operations was drafted, processor clauses were added to the contracts with the three main vendors, and a “DPO as a Service” was appointed — with the company itself handling the formal notification of the appointment to the ANPD (Autoridade Nacional de Proteção de Dados, Brazil’s national data protection authority). Due diligence was completed with no material findings on data protection.

This case reflects a pattern that comes up frequently: LGPD compliance often starts not as a strategic decision, but as a demand from a third party — an investor, an enterprise client, or an international partner. When the structuring comes first, the company tends to run compliance on its own timeline — not under someone else’s deadline.


Minimum viable LGPD: what a startup needs before launch

Compliance with Law 13,709/2018 doesn’t need to happen all at once. But there’s a set of items that must be in place before any collection of personal data begins — whether that’s the first user signing up or the first employee being hired.

1. A public privacy policy that reflects actual operations

The document needs to describe what the company actually does: what data it collects, for what purpose, how long it’s retained, who it’s shared with, and how data subjects can exercise their rights. A generic policy copied from another product or generated from an unreviewed template creates a double risk: it fails to properly inform the data subject and doesn’t reflect actual operations — which makes it useless as evidence of compliance.

2. Data mapping (RoPA — Record of Processing Activities)

An internal inventory of all personal data flows: what is collected, where it’s stored, who has access, what the legal basis for each processing activity is, and how long the data is retained. The RoPA doesn’t need to be public, but it needs to exist and stay up to date. It’s the starting point for any internal audit and for responding to regulators.

Law 13,709/2018 sets out ten legal bases in Article 7 (for regular personal data) and Article 11 (for sensitive personal data). For each processing purpose, the company needs to identify and document which legal basis applies — and this choice isn’t a minor detail. Using consent where legitimate interest would be more appropriate creates unnecessary management obligations and can jeopardize processing altogether if consent is withdrawn.

4. A mechanism for responding to data subject requests

Article 19 of Law 13,709/2018 sets a 15-day deadline for responding to data subject requests (access, correction, deletion, portability, among others). The company needs an operational process — whether a dedicated email address or a form — that ensures these requests are received and routed within the legal deadline.

5. An appointed DPO — or a documented decision on exemption

Article 41 of Law 13,709/2018 requires the appointment of a Data Protection Officer (the Encarregado). The ANPD may exempt micro and small companies that don’t process sensitive data at scale from this requirement — but the exemption needs to be assessed case by case, and the decision needs to be documented. Not appointing a DPO and not recording why it wasn’t necessary is the worst-case scenario: an absence with no justification.

6. Data protection clauses in contracts with vendors that access personal data

Every vendor that accesses the company’s personal data acting as a processor — cloud providers, CRM platforms, analytics tools, billing partners — needs a contract or contractual amendment with specific data protection clauses (a DPA — Data Processing Agreement). Without this instrument, the company remains responsible for the processing carried out by the processor without having put in place the minimum controls required by Law 13,709/2018.


The 5 most common LGPD compliance mistakes

Consent is one of the ten legal bases set out in Law 13,709/2018 — not the only one, and, in many cases, not the most appropriate. Using consent for processing activities that would have a stronger basis in contract performance or legitimate interest creates unnecessary obligations: the data subject can withdraw consent at any time, and the company must then stop processing. For employee data, for example, consent is rarely the correct basis — the employment relationship involves a power imbalance that undermines the freedom required for valid consent.

2. A generic, outdated privacy policy disconnected from actual operations

Policies copied from other products, generated from generic templates, or drafted at the company’s founding and never updated create a triple risk: they fail to properly inform the data subject, they don’t hold up as evidence of compliance, and, when audited, they reveal practices that differ from what’s written. The policy needs to describe actual operations — including third-party integrations, international transfers, and cookie usage.

3. Vendors accessing personal data without a Data Processing Agreement (DPA)

Every company that hires a vendor with access to the personal data of its users or employees needs a DPA in place. This includes: cloud platforms (AWS, GCP, Azure), analytics tools, CRMs, email marketing platforms, and payment partners. Without a DPA, the company processing the data remains liable for the processing carried out by the vendor without having established the minimum contractual controls.

4. No process for responding to data subject requests

The 15-day deadline under Article 19 of Law 13,709/2018 is objective. Not having an operational process to receive, log, and respond to data subject requests — whether by email, form, or dedicated channel — isn’t just a compliance gap: it’s an incident risk, because lost or ignored requests generate complaints to the ANPD.

5. Treating sensitive data with the same level of caution as regular data

Article 11 of Law 13,709/2018 imposes a stricter legal basis requirement for sensitive data — health data, biometric data, data on racial or ethnic origin, data on religious belief, among others. Health, fitness, HR, or fintech startups that collect this kind of data without identifying the specific legal basis and without adopting additional safeguards (access controls, encryption, anonymization where possible) operate with a heightened risk of penalties and reputational damage.


When “DPO as a Service” makes sense

“DPO as a Service” is a model in which the Data Protection Officer is appointed externally — a lawyer or specialized firm that formally fulfills the obligations of Article 41 of Law 13,709/2018 without joining the company’s payroll.

Situation In-house DPO DPO as a Service
Startup with no internal privacy structure High cost; hard role to fill at early stages Appropriate — formal appointment at variable cost
Company processing sensitive data at scale (health, biometrics, fintech) May be necessary at larger scale Appropriate for early stage — periodic review recommended
Company going through due diligence (Series A onward) Signals maturity Equally valid — what matters is the formal appointment and a functioning channel
Company with an already-appointed in-house DPO Not applicable

The “DPO as a Service” model typically includes: formal appointment with the ANPD, naming a contact person and providing public contact details; a functioning communication channel for data subjects and the ANPD; support for security incidents (notification and response); periodic audits of the privacy program; and guidance on compliance for new products or features.

More concretely, it makes sense for: pre-seed to Series A startups without an in-house privacy specialist; companies that process sensitive data and need a formal appointment ahead of due diligence; and companies that have started operating in regulated markets (health, fintech, education) and need to quickly raise their level of compliance.


LGPD × GDPR: what changes for companies with cross-border operations

When a Brazilian company processes the personal data of EU residents — whether because it has European users or because it works with clients or employees based in Europe — the GDPR (Regulation (EU) 2016/679) applies simultaneously with Law 13,709/2018. The two frameworks share significant common ground, but also have practical differences that need to be factored into the privacy program.

Point LGPD (Law 13,709/2018) GDPR (Regulation (EU) 2016/679)
Consent as legal basis Valid; can coexist with other legal bases Stricter: must be freely given, specific, informed, and unambiguous; withdrawal must be as easy as giving consent
Mandatory DPO Art. 41: mandatory (the ANPD may exempt micro/small companies without sensitive data) Art. 37: mandatory for public authorities, large-scale processing of sensitive data, and systematic monitoring of data subjects
International data transfers Mechanisms: country with an adequate level of protection, standard contractual clauses, or specific safeguards (Art. 33) Mechanisms: European Commission adequacy decision, SCCs (Standard Contractual Clauses approved by the EC), BCRs (Binding Corporate Rules)
Incident notification Deadline: 3 business days from becoming aware (ANPD + affected data subjects) Art. 33 GDPR: 72 hours from becoming aware (supervisory authority); data subjects notified when there is high risk
Administrative penalties Up to 2% of the group’s revenue in Brazil, capped at R$ 50 million per infraction Up to 4% of global annual revenue or €20 million (whichever is higher)

The practical takeaway is this: there’s no need to choose between LGPD and GDPR — the privacy program should satisfy both. Since the GDPR is, in general, stricter on consent, DPO requirements, and penalties, a company that complies with the GDPR tends to already be in compliance with most of the LGPD. The exception is incident notification, where the LGPD has a different deadline (3 business days) than the GDPR (72 hours).

For SaaS startups with clients or users in Europe, international data transfer is a specific point of attention: data belonging to EU residents cannot be transferred to Brazil without a valid mechanism in place. SCCs (Standard Contractual Clauses) are the most common instrument used to govern this transfer in contracts with European clients and vendors.


Talk to a lawyer

If you’re about to launch a product, received a compliance requirement during a due diligence process, or identified gaps in your company’s privacy program, we can review the situation and propose the most appropriate legal path forward.

Talk to a lawyer


Frequently Asked Questions

  1. Do I need a DPO even if my startup is small?

The answer depends on three factors: company size, the volume of data processed, and the type of data.

Article 41 of Law 13,709/2018 requires the appointment of a Data Protection Officer for all controllers and processors of personal data. The ANPD (Autoridade Nacional de Proteção de Dados, Brazil’s national data protection authority) has the authority to exempt certain categories of processing agents from this requirement — and the guidelines published so far indicate that micro and small companies that don’t process sensitive data at scale may be exempted, but the assessment is made case by case.

In practice, there are three situations that make formal appointment advisable regardless of company size: (a) the company processes sensitive data — health, biometric, financial, or children’s data —, (b) the company is fundraising and due diligence will review the privacy program, or (c) the company has clients or vendors that require an appointed DPO as a contractual condition.

“DPO as a Service” fulfills the formal requirement without requiring the company to hire a full-time specialist — which is relevant for early-stage startups.

*This is general information and does not replace consulting a lawyer to review your specific case.*

  1. What’s the difference between LGPD and GDPR for a SaaS startup?

The LGPD (Law 13,709/2018) and the GDPR (Regulation (EU) 2016/679) have a similar structure — both regulate the processing of personal data, establish legal bases, data subject rights, and penalties — but with practical differences that directly affect a SaaS startup’s day-to-day operations.

The differences most relevant to the product:

– **Consent:** under the GDPR, consent must be granular, specific, and as easy to withdraw as it is to give — stricter standards than under the LGPD.
– **Mandatory DPO:** the GDPR (Art. 37) requires a DPO for large-scale systematic monitoring of data subjects and for large-scale processing of sensitive data — thresholds a SaaS startup with a European user base can reach sooner than it might expect.
– **International transfers:** data belonging to EU residents cannot be transferred to Brazil without a valid mechanism. The most common instrument is SCCs (Standard Contractual Clauses approved by the European Commission).
– **Incident notification deadline:** 72 hours (GDPR, Art. 33) versus 3 business days (LGPD). In an incident affecting EU residents, the GDPR’s deadline prevails.
– **Penalties:** the GDPR provides for fines of up to 4% of global annual revenue; the LGPD, up to 2% of revenue in Brazil, capped at R$ 50 million per infraction.

For a startup operating in both markets, one possible approach is to build the privacy program with both frameworks in mind — applying the stricter standard on each point.

*This is general information and does not replace consulting a lawyer to review your specific case.*

  1. What happens if I don’t achieve compliance before launching the product?

Failing to achieve compliance before launch creates risk on three distinct fronts, and they aren’t mutually exclusive.

**Regulatory front:** the ANPD (Brazil’s national data protection authority) can apply the penalties set out in Article 52 of Law 13,709/2018 — a warning, a fine of up to 2% of revenue in Brazil (capped at R$ 50 million per infraction), public disclosure of the infraction, and suspension of the database. Enforcement proceedings can be triggered by a data subject’s complaint, an ex officio investigation, or an incident notification.

**Contractual front:** enterprise clients, distribution partners, and investors check LGPD compliance as a condition of doing business. The lack of a documented privacy program can hold up contracts, delay funding rounds, or trigger indemnification clauses in M&A deals.

**Incident front:** without data mapping, minimum controls, and a response process in place, a company can’t detect a breach quickly, doesn’t know what to report to the ANPD, and has no way to demonstrate that it took reasonable security measures — which makes the liability assessment worse in an enforcement proceeding.

Achieving compliance before launch doesn’t eliminate all risk — no company operates with zero privacy risk — but it lays the groundwork for detecting and responding to problems in a structured way.

*This is general information and does not replace consulting a lawyer to review your specific case.*


This is general information and does not replace consulting a lawyer to review your specific case.


Alessandra De Paula Souza — OAB/PR 31,133 Practice focused on LGPD, data protection, and corporate privacy.

Talk to a specialist

Ready to protect your business?

Book an initial consultation and find out how we can help your business grow securely in Brazil. Professional confidentiality guaranteed.

What to expect from the consultation

  • Legal diagnosis of your company's situation
  • Identification of risks and opportunities
  • Tailored legal strategy proposal
  • Questions answered, no commitment
Professional confidentiality guaranteed under the Brazilian Bar Association (OAB) statute

Request a consultation

Fill in the details below to request a consultation.

Area of interest *(select one or more)
LGPD and Data Protection