The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Privacy and data
From finding where the data sits to having someone answer for it.
The path has three stations, and you decide where to stop. First we discover where personal data enters, where it flows, who accesses it, and when it should be deleted. Then we fix what the law requires: legal bases, notices, vendor contracts, the data subject channel, and readiness to respond to an incident. And, if you prefer, we take on the role of DPO.
The mapping is done operation by operation, in conversation with each team: the system shows where the data sits, the interview shows why it is processed. Out of that come the processing inventory, the gaps against the LGPD, and the plan in risk order. In the full remediation, we put documents, the data subject channel, and contracts in place, and train the teams with records.
As DPO, DM11 responds to data subjects within the legal deadline, prepares the responses to the ANPD, reviews the program when processing changes, and reports to your leadership in recurring meetings. The law requires a named and published DPO, and appointing someone who already holds another job usually ends with the role abandoned in the first busy week.
On your side, the project needs access to the teams that process data, to vendor contracts, and to whoever owns the systems. Legal responsibility for the processing remains with the controller, and the law does not let you outsource that: what we deliver is the program working and someone answering for it every day.
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Data mapping
We find where personal data enters, where it travels, who accesses it and when it should be disposed of.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Privacy implementation
Legal bases defined, documents written, the data subject channel standing, contracts adjusted and the areas trained.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.