The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Proposal
First we find where personal data enters, where it travels and when it should be erased. Then we put in place what the LGPD, Brazil's General Data Protection Law, requires: legal bases, notices, supplier contracts, a channel for data subjects and incident response. And if you prefer, we take the data protection officer seat ourselves: we answer data subjects, deal with the ANPD, Brazil's data protection authority, and keep the programme alive, instead of appointing someone who already holds another job and watching the role die in the first busy week.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
From finding where the data sits to having someone answer for it.
The path has three stations, and you decide where to stop. First we discover where personal data enters, where it flows, who accesses it, and when it should be deleted. Then we fix what the law requires: legal bases, notices, vendor contracts, the data subject channel, and readiness to respond to an incident. And, if you prefer, we take on the role of DPO.
The mapping is done operation by operation, in conversation with each team: the system shows where the data sits, the interview shows why it is processed. Out of that come the processing inventory, the gaps against the LGPD, and the plan in risk order. In the full remediation, we put documents, the data subject channel, and contracts in place, and train the teams with records.
As DPO, DM11 responds to data subjects within the legal deadline, prepares the responses to the ANPD, reviews the program when processing changes, and reports to your leadership in recurring meetings. The law requires a named and published DPO, and appointing someone who already holds another job usually ends with the role abandoned in the first busy week.
On your side, the project needs access to the teams that process data, to vendor contracts, and to whoever owns the systems. Legal responsibility for the processing remains with the controller, and the law does not let you outsource that: what we deliver is the program working and someone answering for it every day.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Data mapping
We find where personal data enters, where it travels, who accesses it and when it should be disposed of.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Privacy implementation
Legal bases defined, documents written, the data subject channel standing, contracts adjusted and the areas trained.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.