The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
LGPD · BRAZIL'S DATA PROTECTION LAW
The initial assessment is the easy part, and it is where most projects both start and finish. What decides whether your company can answer a customer or the regulator two years later is who keeps the inventory current, who revisits the legal bases when the business changes, and who answers data subjects on time. That is what this page is about.
The LGPD is a law, and interpreting it is legal work. DM11 runs the project with a digital law specialist alongside the management specialist, because splitting those two apart is what produces a handsome project that will not survive an inspection. Where the goal also includes a document issued by a third party, the ISO 27701 page explains that route.
Who runs the project
Data protection specialists certified by EXIN (DPO, PDPP and PDPF)
Legal advisory in privacy and digital law
ISO/IEC 27001 Lead Auditor certified by BSI
17 years of governance, risk and compliance
WHAT THE LAW REQUIRES
Law 13.709/2018 reaches any company processing personal data in Brazil, and a company processes personal data if it has employees, customers or individual suppliers. It lists no technology and no controls: it lists principles, data subject rights and responsibilities. In practice that means the company chooses how to comply, and has to be able to demonstrate what it chose, when it decided, and why.
There is no minimum revenue and no headcount below which the law stops reaching you. What does exist is a simplified regime from the Brazilian data protection authority for small-scale processing agents, which reduces formality in some obligations without removing any of them. A small company has less paperwork to produce, not fewer duties.
The most common and most expensive mistake is treating consent as the default. The law provides ten legal bases, and consent is one of them, almost always the most fragile for a business process, because it can be withdrawn at any moment and takes the processing down with it. Choosing the right basis per processing activity is the decision that most reshapes the project, and it is a legal decision.
The law requires you to appoint an officer for personal data processing and to publish their identity and contact details. It can be someone internal with the role formalised, or an outsourced service. What does not work is a name in the website footer with no process behind it, because data subjects write to it and the clock starts running.
Worth settling early, because it shapes what the company has to produce. The law itself is not certifiable, and what demonstrates compliance is dated evidence: an inventory of processing activities, a recorded legal basis, an impact report where the law requires one, records of data subject requests answered, and proof the governance works. When a customer wants a document issued by a third party, and European customers usually do, the route is ISO 27701, and the material built here carries into that project intact.
WHO USUALLY GETS IN TOUCH
The LGPD rarely reaches the agenda out of conviction. It reaches it because somebody outside asked, or because something happened.
A large customer, a bank, an insurer or a foreign company sent a form with dozens of questions and a short deadline. Answering it without a basis produces two bad outcomes: an optimistic answer that will not survive the next audit, and a missing answer that stalls the contract.
A leak, ransomware, or an email that went to the wrong list. The question that appears immediately is whether the regulator and the data subjects have to be notified, and that is a terrible decision to make in a hurry, with no inventory and no plan defined beforehand.
A sale, a funding round or a new shareholder. Privacy has become a due diligence checklist item, and a personal data liability has shown up as a price reduction in real transactions. Here the deadline comes from somebody else's calendar, and it does not negotiate.
Translation
Brazilian data protection compliance is the name given to five different jobs. Whoever asks rarely knows which one they need, and finding that out is the first thing we do, because the wrong scope is expensive on both sides: either you pay for work nobody asked for, or you miss the thing that would have unblocked the deal.
| What reaches you | What it means | What changes in the work |
|---|---|---|
| “We need to be compliant with the LGPD” | A request with no scope. Compliance for the whole company, for one product, or only for what touches the data of the customer who is asking. | The conversation starts with which of the three. Doing the whole company when one contract is stuck spends months in the wrong place. |
| “A customer sent a privacy questionnaire” | Third-party due diligence. They do not want a programme: they want evidence that their data is handled with method. | Short and focused work. Map what that customer touches, write what is missing, and answer with evidence rather than promises. |
| “We need to appoint a data protection officer” | The law requires the name to be public. What it does not say is that the role is work every month. | Appointing is the easy part. The work is the data subject channel, the response deadline, every new contract and every new system. It can be taken on as a service. |
| “We had an incident and do not know whether to notify” | Real urgency, short window. Whether to notify depends on the risk to the data subject, and that call has to be made and recorded. | Incident response comes first, with the decision documented. The programme follows, and comes out better for what was learned. |
| “A European customer asked for guarantees on personal data” | GDPR enters the conversation. This is usually where a certificate answers better than a dossier. | The route changes: compliance work becomes the base for ISO 27701, and everything built here carries into that project. |
| “We want an opinion on the legal basis we chose” | This is not compliance work. It is legal advice, and DM11 does not provide it. | We say so in the first conversation. DM11 has digital law specialists on the team and still keeps the roles apart: we organise the operation, counsel decides what is lawful. |
None of this is price. Each of those lines is a different size of job, which is why the conversation starts with which one is yours.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
E-commerce
The company had put a consent notice at every collection point and considered the matter closed. When deletion requests started arriving, it discovered the same tick box supported order delivery, invoicing and billing, and that honouring a request to the letter would break the operation.
We redid the analysis activity by activity, with legal alongside. Much of what sat under consent had a better basis available: performance of a contract for delivery, a legal obligation for invoicing, documented legitimate interest for fraud prevention. Consent stayed where it genuinely is the right basis, which is marketing communication.
Deletion requests stopped being a crisis and became a process. And the marketing base shrank far less than the team feared, because almost everything else had never depended on consent to begin with.
Recruitment services
The company held CVs, test results and interview notes for everyone who had ever applied, with no retention period and no criteria. Nobody had decided to keep them permanently: there had simply never been a decision to delete, and the volume built up over years.
We set retention periods by type of information, with legal assessing what has to stay for statutory reasons and what only existed out of convenience. We implemented the deletion, and the hard part was not technical: it was agreeing what to do with an interviewer's subjective notes, which are personal data and which the team did not see that way.
The archive shrank considerably, and with it the size of any future incident. Data that no longer exists cannot leak, and that was the cheapest risk reduction in the whole project.
Manufacturing
Dozens of suppliers touched the company's personal data, from payroll to benefits, from the time clock system to the training platform. No contract carried a data protection clause, and nobody could say which of them stored information outside the country.
We established who touches what and classified by risk, rather than treating all forty as equals. The few critical ones got a full contractual review and verification of where the data sits. The rest went into a standard addendum with a deadline, and procurement started requiring the clause before signature.
The gain was not only legal. Mapping the suppliers, the company discovered three systems contracted by individual departments, never routed through IT, processing employee data. Two were shut down.
SELF-ASSESSMENT
The first four questions classify your case, because being a controller, a processor or both changes almost everything. The other sixteen measure what exists and is still standing. The full result appears on screen, with a score for each area. We do not ask for your email to show it. This measures management and evidence; it is not a legal reading of the law and it does not replace your counsel's analysis.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
A low score here means the company answers questions about personal data from the memory of whoever was there, and memory survives neither a change of team nor a customer audit. What is usually missing is not the spreadsheet, it is the conversation with the people who operate: a map drawn only from IT loses the HR form, the marketing mailing list and the after-sales spreadsheet. Start with one department, the one that handles the most personal data, and finish it before opening the second. Record origin, purpose, who has access, where it goes and for how long, even if the first version comes out ugly.
50 to 79
A survey exists, and it describes part of the company or an older version of it. The typical symptom is a spreadsheet from an earlier project that nobody has touched since the new product launched. It is worth less to widen the map now and more to date what already exists: mark which department owns each processing activity and when it was last checked. After that, the predictable hole is whatever was contracted outside IT, and you find it by asking departments what they signed up for on the corporate card, not by looking at the systems inventory.
80 or above
The map exists and keeps up with the operation, and that is what gives the other areas something to rest on. What tends to slip in this band is a purpose written in system language rather than business language: when the purpose says only the name of a module, nobody can judge whether the data still serves it. Rewrite the purposes of the five processing activities involving the most people and test them with somebody from the department, who has to recognise their own process in the sentence.
Below 50
A low score in this domain almost always means one of two things: nothing was recorded, or everything was marked as consent without analysis. Both create the same work later, because the company cannot explain why it processes what it processes. It is worth separating what is yours from what belongs to legal: listing the processing activities, describing each in a sentence and noting who approved it is management work, and it is the input without which no lawyer can decide. Choosing the basis itself is legal analysis, and it gets far cheaper when it arrives with that material ready.
50 to 79
There are records on the main activities, and what is missing is usually the reasoning: the basis appears noted down and nobody can say why it was chosen or who decided. Without that trail, the first question from a customer or a buyer reopens the whole discussion. On the published notice side, the quick test is to read the text next to the inventory and mark every promise the operation does not keep. Fix the discrepancies first, and only then think about improving the wording, because a handsome notice describing a different company counts against you.
80 or above
Records and transparency are aligned, and the company can explain its own decisions. The point to watch in this band is the trigger: a recorded legal basis ages when the purpose changes without anyone saying so, and purposes change with a new product, a new partnership and a new campaign. Agree with legal on a review fired by events rather than by the calendar. On consent, check that a withdrawal really reaches every system, because the point most often left out is the sending tool contracted by marketing.
Below 50
With no officer appointed and no defined route, the data subject request arrives anyway, through ordinary support or through social media, and the clock starts running without anyone noticing. What is usually missing before the name is the decision about authority and time: appointing somebody with no autonomy to ask a department for a deletion creates a post with no function. Decide who it is, formalise it in writing, publish the contact and sketch on one page who does what for access, correction and deletion. It is the cheapest domain to move off zero in this diagnosis.
50 to 79
There is a published contact and requests are handled case by case, which works while the volume is small and fails in the first month three arrive together. What is missing is the record: without it the company cannot prove it answered, and that history is exactly what a customer asks for in due diligence. A shared spreadsheet with the date received, the type of request, the deadline and the answer already covers the essentials. It is also worth writing the standard answer to the two or three most common requests, because that is what keeps each case from becoming a fresh piece of writing.
80 or above
The channel exists, has an owner and leaves a trail. What sets you apart in this band is identifying the requester: honouring a deletion request without confirming the person is who they say they are is the mistake that turns a good process into an incident. Check that the flow covers requests made by a third party, by a lawyer and by a minor's guardian, which are the ones that stall. And test the route from the outside in, writing to your own published contact and timing the answer.
Below 50
This is the domain that best explains why compliance projects age, and a low score here usually comes with a folder of well-written documents. What is missing is not intention, it is a name with a date in somebody's calendar: with no owner and no frequency, the review only happens when a customer asks, and by then it is late. Pick a person, set a frequency the company can actually keep, even if it is twice a year, and list the three triggers that fire a review outside the cycle: a new system, a new supplier, a new product. On training, start with the departments that handle the most data, with a record of who attended.
50 to 79
The review happens when somebody remembers, and the training was a one-off event or an email. In practice that means the company depends on one specific person sticking around, and that is the risk nobody sees until they leave. The concrete step is turning the reminder into a recorded routine and the email into content per department: what HR can and cannot do is different from what applies to sales. An attendance record is not bureaucracy, it is the only evidence the guidance landed.
80 or above
The routine exists and survives people changing, which is what holds the rest of the programme up. The point to watch is the event trigger: a well-run annual review still leaves an eleven-month gap for the supplier who arrived in February. It is worth checking that procurement, IT and product know they have to flag it, and that they do. And it is worth measuring training by behaviour rather than attendance: asking departments what they would do in a concrete case reveals more than any list of signatures.
Below 50
A low score here almost never comes from a decision to keep everything, but from the absence of any decision to delete. The effect is that the size of a future incident grows on its own, month after month, without anyone having chosen it. What is usually missing is the conversation between the people who know what has to stay by obligation and the people who know what exists: start with two or three types where the build-up is obvious, such as candidate CVs and call recordings. Setting a period for a few types and keeping it is worth more than a complete table nobody applies.
50 to 79
There is a rule for some of the data, or there is a table and it is not applied, which is the more frequent case. The distance between the rule and the execution tends to be technical and ownerless: nobody was put in charge of running the deletion. Name the person, set the frequency and record what went and when, because deletion with no record is not evidence. Before that, check that the written rule was validated with legal on what has to stay, so you do not delete what you were obliged to keep.
80 or above
The retention and deletion cycle is defined and it happens. What tends to slip in this band are the copies outside the main route: an extract to a spreadsheet, a test database with real data, an email attachment, and the backup with a longer retention than the policy. None of them shows up in the system, and all of them show up in a leak. Map where data leaves the official system and treat each exit as a destination with a period of its own, including an explicit decision about what to do in the backup.
Below 50
With no clause in the contracts and no idea where the data sits, the company answers for the decision to choose the supplier and can demonstrate nothing about them. What is usually missing first is not the clause, it is the list: who touches your personal data, and to do what. It comes together quickly by crossing accounts payable with the systems in use, and it almost always turns up names IT did not know about. With the list in hand, classify by criticality instead of treating everyone as equal, and start the review with the few that concentrate volume or sensitive data.
50 to 79
New contracts already carry a clause and the past was never revisited, which is the pattern for a company that fixed procurement and stopped there. The risk sits precisely with the older suppliers, who tend to hold the most data. Pick the ten most critical and handle them one by one, with an addendum where appropriate. On where the data sits, ask the supplier in writing which country the information is in and who else reaches it, including their own subcontractors, because that answer is the input legal needs to handle a transfer.
80 or above
You know who touches what, and the contracts keep up. What tends to be missing in this band is the exit: a supplier who ends the contract while keeping access or keeping a copy of the data is the quietest find in this domain. Include confirmation of return or deletion in the termination, with a record. And reassess the critical ones periodically, because a supplier that was small two years ago may have changed infrastructure, country or subcontractor without telling anyone.
Below 50
Broad access and the absence of a plan are the two factors that most increase the size of any incident, and a low score here often sits alongside good infrastructure, because the problem is one of decisions rather than tools. What is usually missing is the simple question never asked: how many people can open the entire customer database or the HR folder. Do that survey first, cut what is left over from a previous role, and record who approved the rest. In parallel, write on one page who assesses the risk to data subjects and who decides on notifying, even if the full plan comes later.
50 to 79
There is access control and the review is sporadic, or there is an incident plan covering the technical side and not the personal data side. They are different gaps with the same origin: security was settled by IT and privacy never joined the conversation. On access review, what is missing is a record of who reviewed and what was removed, without which the review does not count as evidence. On the plan, what is missing is the criterion for assessing risk to data subjects and legal inside the decision, because whether to notify is a business and legal decision, not an infrastructure one.
80 or above
Controlled access and a written plan put the company in a comfortable position for the worst day. The distance left is the rehearsal: a plan never exercised tends to reveal, in the first tabletop, that nobody knows who calls whom outside business hours and that the critical supplier's contact is out of date. Schedule a short exercise with the people who would genuinely take part, including legal and communications, and record what stalled. The result of that rehearsal is worth more than any improvement to the text of the plan.
WHO DOES WHAT
The law requires a data protection officer, and requires the name to be public. What it does not say is that the role is continuous work: subject requests, incidents, every new contract, every new system. It is where most programmes stop after the assessment.
HOW WE RUN IT
Legal and management run together from day one, not in sequence. A project driven only by legal produces an opinion nobody operates, and one driven only by technology produces controls with no legal basis behind them. The two readings have to meet on every processing activity.
We establish the processing activities by business process, with the people who operate them rather than only those who coordinate, because the official spreadsheet almost never matches practice. We record origin, purpose, who has access, where it goes, how long it stays and which suppliers touch it.
An inventory of processing activities by business process
The personal data flow, including transfers to third parties
A list of suppliers with access, classified by risk
Identification of what counts as sensitive personal data
Delivery milestoneInventory approved by the departments that own the processes, not only by IT.
With legal, we set the legal basis for each processing activity and record the reasoning. We assess the risks to data subjects, which are not the same as information security risks, and produce an impact report where the law or the risk calls for one.
A recorded and justified legal basis per processing activity
A legitimate interest assessment wherever that is the chosen basis
A data protection impact report, where applicable
A privacy policy and notices rewritten to match what the company actually does
Delivery milestoneA legal basis defined for 100% of inventoried activities, with legal in agreement.
We implement with your team what holds the decision up day to day: access on a need basis, retention and deletion by data type, clauses in third-party contracts, and the data subject request process, with a channel, a deadline, a record and a standard response.
A data subject request process, with a deadline and a record
A retention and deletion policy, implemented rather than only written
Data protection clauses reviewed in third-party contracts
The data protection officer formalised and their contact published
Delivery milestoneFirst cycle of data subject requests answered on time, with a complete record.
This is the phase that separates compliance from a report. We define who reviews what and how often, train the people who operate, and rehearse an incident, so the decision to notify the regulator and the data subjects gets made with a plan in hand rather than in a panic.
A review routine defined, with an owner and a frequency
A personal data incident response plan, rehearsed
Training for the departments that handle the most personal data
A report for leadership, with whatever remains open written down
Delivery milestoneIncident rehearsal completed, with the notification decision taken inside the plan.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. The first conversation is usually enough to separate the two cases that come up most: the company that has never done anything, and the company that ran a project years ago and did not maintain it. The second is almost always closer than it thinks, and sometimes further away.
An operation with half a dozen systems is one project. One with dozens of suppliers and departments buying tools on their own is another, and much of the time goes into discovering what exists before anything can be decided.
With an internal candidate available, the role is formalised quickly. With nobody, the choice between appointing internally and contracting the service has to be made early, because the officer takes part in the project rather than arriving once it is finished.
Compliance is enough to answer a customer or the regulator with your own evidence. Where there is an intention to certify privacy later, we organise the material in ISO 27701's shape from the start, which costs little now and saves an entire project later.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
The law itself is not certifiable, and it is worth knowing that before contracting anything, because the term circulates widely in the Brazilian market. What demonstrates compliance is evidence: a current inventory, a recorded legal basis, a working data subject request process, and governance you can prove with a dated document. If what you need is a document issued by a third party, to answer a customer or a regulator, the certifiable privacy standard is ISO 27701, and this compliance work is precisely its foundation.
It does. There is no minimum size, and any company with employees already processes personal data. What exists is a simplified regime from the Brazilian data protection authority for small-scale processing agents, easing formality in some obligations. It reduces paperwork, not duty: legal basis, data subject rights and information security all continue to apply in full.
No, and resting everything on consent is the mistake that causes the most trouble later. The law provides ten legal bases, and several suit a business process better: performance of a contract, compliance with a legal obligation, legitimate interest. Consent can be withdrawn at any time, and where it supports something essential, withdrawal takes the operation down with it. Choosing the right basis per activity is a legal decision, and the one that most reshapes the project.
The law requires appointing an officer and publishing their identity and contact details. It can be someone internal, with the role formalised and real time to perform it, or an outsourced service. What does not solve anything is publishing an email address with no process behind it: the moment the contact exists, data subjects write to it, and from then on the response clock is running.
It depends on whether there is relevant risk to data subjects, and that is a terrible assessment to make on the day. Notifying the regulator and the data subjects is required where the incident may cause relevant risk or harm, and the deadline and form follow the data protection authority's regulation, which changes more often than the law does. That is why the decision has to be rehearsed in advance: with an inventory in hand you can say within hours which data was affected, and without one the company spends days finding out.
It helps considerably and it does not cover it. ISO 27001 covers the security side the LGPD also requires, and that evidence carries over almost intact: access control, logging, third-party management, incident response. What it does not cover is the legal core of the law, which is legal basis, data subject rights, purpose and retention. They are different layers, and certified companies are often surprised by how much of that second one is missing.
Bring us the questionnaire or the contract clause. We will tell you what already exists in your company that answers it, what is genuinely missing, and in what order it makes sense to resolve, without turning this into a two-year programme.
Presidência da República, texto consolidado · accessed on
ISO/IEC · ISO/IEC 27701:2025, edição 2, publicada em outubro de 2025 · accessed on
This page is informational and describes how DM11 reads and applies the sources above. It does not reproduce the text of any standard, does not replace reading the official document, and does not replace an audit, a certification, an independent assessment or legal advice. Where a standard requires formal assessment, it is carried out by an accredited body, auditor or assessor, always separate from whoever did the preparation.