Assessment
Technical and legal gap analysis: privacy management maturity, risks across people, processes, and technology, and review of the documentation that legitimizes your data processing.
The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.

DPO BACKOFFICE®: PRIVACY AND LGPD
Brazil's LGPD fines reach up to 2% of annual revenue. DPO Backoffice® puts specialists in digital law, cybersecurity, and governance, risk and compliance (GRC) alongside your Data Protection Officer, who stays in-house, close to the business, and never alone again.
WHAT'S INCLUDED
From the first gap assessment to continuous auditing, with professionals in Digital, Corporate, and Regulatory Law, Cybersecurity, and GRC.
Technical and legal gap analysis: privacy management maturity, risks across people, processes, and technology, and review of the documentation that legitimizes your data processing.
Personal data inventory covering collection, processing, sharing, and transfers, with legal validation of the legal bases and the sensitive points in your data flows.
Technical and legal execution of the compliance plan: information classification, incident response plan, contracts, and policies.
Awareness workshops for employees, managers, and third parties, plus DPO training to produce the data protection impact assessment (the RIPD in Brazil, known elsewhere as a DPIA) independently.
Third-party and processor risk, consent, data subject requests, vulnerabilities, incidents, and continuity: the privacy routine, fully under control.
Double-checking of implementations, security audits of data flows and applications, attack simulation, and periodic reviews of policies and controls.
WHY IT'S DIFFERENT
SELF-ASSESSMENT
Objective questions about your company's privacy routine under Brazil's LGPD: what can be proven today and what exists only in documents. The result shows where the operation stands on its own and where it runs on luck.
It is the first thing the ANPD checks, because it can be checked from the outside. If the published email lands in a mailbox nobody opens, the honest answer is no.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
Without a formal appointment, a published channel and dedicated time, the company has a de facto contact but not a working function, and that is where the authority and data subjects look first. Formalize the appointment, publish the contact on the website and block fixed hours in the calendar. Three cheap moves that change the company's position.
50 to 79
The role exists but competes with the rest of the agenda, and privacy advances at the pace of leftovers. A recurring forum with management, even a lean one, creates traction: deadlines, accountability and a record of decisions.
80 or above
Privacy governance is among the strongest fronts in your answers. The next gain is giving the DPO technical and legal depth: an agenda of prioritized risks and documented decisions, so leadership decides on risk rather than on generalities.
Below 50
Without a record of processing activities, every discussion about legal bases, contracts or incidents starts from zero, because nobody knows for sure what the company processes. Start with the processes touching the most data subjects, such as HR and sales, and accept an incomplete first version. It already changes the conversations.
50 to 79
The inventory exists but is aging, and an outdated inventory gives false confidence: decisions built on it apply to yesterday's company. Assign an owner, a cadence and a trigger: no new process goes live before entering the record.
80 or above
A living inventory in your answers, and that is rare. The next refinement is using it as a decision instrument: cross each flow with its legal basis, retention and vendors involved, so any question about a piece of data has an answer in minutes.
Below 50
Processing without a defined legal basis is the most direct fragility before the law: there is no way to demonstrate the operation is lawful. Walk through the main flows and record the basis for each one. The exercise tends to reveal unnecessary consents and legal obligations nobody had named.
50 to 79
The bases exist, but part of them were chosen by default, and excess consent charges interest: every revocation becomes an operational doubt. A legal review of those choices usually migrates operations to more stable bases, such as legal obligation and contract performance.
80 or above
Legal bases handled with criteria in your answers. The next step is maintenance: revisit the balancing tests when context changes, and make sure new operations are born with a defined basis, not an inherited one.
Below 50
Today, a data subject request would probably enter through the wrong door and run without an owner, with the legal clock ticking. Before any tool, define the flow: where it enters, who answers, in how long. Then simulate a real request and time it.
50 to 79
The channel exists, but answering depends on manual effort, and the hardest right, complete deletion, probably still fails in peripheral systems. Mapping where each piece of data lives is what turns fulfillment from treasure hunt into procedure.
80 or above
Data subject rights with a working flow. The next gain is testing your own service: one simulated request per quarter, deletion included, finds the forgotten system before a real data subject does.
Below 50
An incident involving personal data would find the company deciding everything from scratch, with three business days running. Start with the minimum: who assesses the risk to data subjects, who decides on notification, who signs. Three names in one document already take the decision out of panic.
50 to 79
The plan exists, but the privacy layer is still thin: assessing risk to data subjects is a trainable judgment, and nobody trains during the fire. One tabletop exercise per year, with a data leak scenario and legal counsel in the room, closes that gap at low cost.
80 or above
Incident response with privacy built in, which is what separates responding from improvising. Keep the reasoned record even for cases not notified, and revisit the flow when the authority publishes new guidance. That file is what supports the company under any questioning.
Below 50
Every vendor processing personal data without a proper contract is risk the company carries with nothing in return, because before the data subject the responsibility remains yours. List the vendors with access to personal data and start the addenda with the highest-volume ones. The list tends to be longer than expected.
50 to 79
The main contracts are covered, but assessing new vendors still depends on someone remembering, and international transfers are rarely all mapped. Making privacy a formal step of procurement closes the door new cases come through.
80 or above
Third parties under management in your answers. The next refinement is moving from contract to verification: ask critical processors for periodic evidence of their controls, because a clause transfers obligation, not operational risk.
Your DPO is the one who knows the business. The technical and legal depth comes from the team working alongside them.