LGPD and Data Protection
We serve everyone from startups that need a minimum viable *LGPD* compliance program to companies with cross-border operations aligning *LGPD* with GDPR. DPO as a Service, with a formally designated "Encarregada" (Data Protection Officer).
"*LGPD* compliance is an ongoing program — not a one-time task."Book a consultation
What our work covers
Services and Deliverables
Assessment and Diagnosis
- Data mapping: source, purpose, legal basis, retention
- Identification of gaps relative to the *LGPD* and ANPD regulations
- Risk analysis by operation
- Executive report with a prioritized compliance plan
*LGPD* Compliance
- External Privacy Policy and Internal Data Policy
- Data Processing Agreements (processor-controller)
- Handling of data subject rights (access, deletion, portability)
- Granular consent and legal basis management
DPO as a Service
- Formally designated "Encarregada" (Data Protection Officer, registered with the ANPD)
- Public communication channel and whistleblowing channel
- Light monthly audit and quarterly report
- Security incident response SLA
Incident Response and Cross-Border
- Response plan: notification to the ANPD (72h)
- Forensic investigation and remediation plan
- *LGPD* × GDPR: equivalences and international data transfer
- Standard Contractual Clauses (SCCs) and ANPD adequacy decisions
Who we serve
Who We Serve
Our focus is on startups, scale-ups, and SMBs that need specialized legal advice that is accessible and business-minded.
- Startups that need a minimum viable *LGPD* program for fundraising
- SaaS, e-commerce, and marketplace businesses with data at scale
- Companies that process sensitive data (health, financial, biometric)
- Multinationals with cross-border data processing
FAQ
Frequently asked questions about LGPD and Data Protection
Does the *LGPD* apply to my startup if I don't have paying users yet?
Yes. Law 13.709/2018 (the *LGPD*, Brazil's General Data Protection Law) applies from the moment the company collects any personal data — including waitlist emails, data from validation interviews, and usage metrics from beta versions. The relevant criterion is not revenue or company stage, but the processing of personal data belonging to individuals within Brazilian territory. Being pre-revenue does not exempt a company from the law's obligations.
===FAQ_A_1===
The controller company is obligated to notify the ANPD (Brazil's National Data Protection Authority) and affected data subjects when the incident could cause relevant risk or damage (art. 48, Law 13.709/2018). Notification must occur within a reasonable timeframe — the ANPD has been guiding companies toward 2 to 5 business days for initial notification — and must include the nature of the affected data, the measures taken, and the risks generated. Companies without an incident response plan tend to lose critical time during severity analysis, which can worsen the regulatory assessment.Ler artigo completo
What happens if there's a data breach at my company? ===FAQ_Q_2=== Does my company need a DPO if it processes little data? ===FAQ_A_2=== Law 13.709/2018 does not set a minimum data volume threshold for the obligation to designate a "Encarregado de Dados" (DPO, Data Protection Officer) — the obligation applies to controllers in general. What varies is the complexity of the privacy program required: a company with low data volume and simple operations still needs a DPO, but the scope of work is smaller. The DPO as a Service model exists precisely to match cost to the size of the operation. ===BODY=== ## Services and Deliverables ### Assessment and Diagnosis - Data mapping: source, purpose, legal basis, retention - Identification of gaps relative to the *LGPD* and ANPD regulations - Risk analysis by operation - Executive report with a prioritized compliance plan ### *LGPD* Compliance - External Privacy Policy and Internal Data Policy - Data Processing Agreements (processor-controller) - Handling of data subject rights (access, deletion, portability) - Granular consent and legal basis management ### DPO as a Service - Formally designated "Encarregada" (Data Protection Officer, registered with the ANPD) - Public communication channel and whistleblowing channel - Light monthly audit and quarterly report - Security incident response SLA ### Incident Response and Cross-Border - Response plan: notification to the ANPD (72h) - Forensic investigation and remediation plan - *LGPD* × GDPR: equivalences and international data transfer - Standard Contractual Clauses (SCCs) and ANPD adequacy decisions ## Who We Serve Our focus is on startups, scale-ups, and SMBs that need specialized legal advice that is accessible and business-minded. - Startups that need a minimum viable *LGPD* program for fundraising - SaaS, e-commerce, and marketplace businesses with data at scale - Companies that process sensitive data (health, financial, biometric) - Multinationals with cross-border data processing
The controller company is obligated to notify the ANPD (Brazil's National Data Protection Authority) and affected data subjects when the incident could cause relevant risk or damage (art. 48, Law 13.709/2018). Notification must occur within a reasonable timeframe — the ANPD has been guiding companies toward 2 to 5 business days for initial notification — and must include the nature of the affected data, the measures taken, and the risks generated. Companies without an incident response plan tend to lose critical time during severity analysis, which can worsen the regulatory assessment.
===FAQ_Q_1===
What happens if there's a data breach at my company?Ler artigo completo
Does my company need a DPO if it processes little data?
Law 13.709/2018 does not set a minimum data volume threshold for the obligation to designate a "Encarregado de Dados" (DPO, Data Protection Officer) — the obligation applies to controllers in general. What varies is the complexity of the privacy program required: a company with low data volume and simple operations still needs a DPO, but the scope of work is smaller. The DPO as a Service model exists precisely to match cost to the size of the operation.
The answers above are general information and do not replace consultation with a lawyer for analysis of your specific case.
Talk to a specialist
Ready to protect your business?
Book an initial consultation and find out how we can help your business grow securely in Brazil. Professional confidentiality guaranteed.
What to expect from the consultation
- Legal diagnosis of your company's situation
- Identification of risks and opportunities
- Tailored legal strategy proposal
- Questions answered, no commitment
Professional confidentiality guaranteed under the Brazilian Bar Association (OAB) statute
Request a consultation
Fill in the details below to request a consultation.