Privacy and security need the same map
Brazil’s LGPD establishes principles, rights, and obligations; security provides controls that preserve confidentiality, integrity, and availability. Managing them separately creates gaps between what the organization states and what it can execute.
Begin with processes that use personal data. Identify purpose, data and data subject categories, legal basis, systems, access, disclosures, retention, and disposition. This record guides legal and technical decisions.
- Purpose and necessity
- Legal basis and transparency
- Access and traceability
- Disclosures and contracts
- Retention and disposition
- Incidents and data subject rights
Proportionate, verifiable controls
Least privilege, strong authentication, updates, backups, appropriate encryption, endpoint protection, logs, and awareness provide a foundation. Selection depends on risk and context; evidence shows that a control exists and operates.
A policy should name owners, frequency, and records. 'Perform backups' is an intention. Defining scope, retention, protection, monitoring, and restoration testing creates an operable control.
Risk follows data to vendors
Cloud, support, communications, accounting, and platform providers may process or access data. Assess what is shared, why, where it is stored, which safeguards apply, how incidents are reported, and how data will be returned or deleted at contract end.
Contract language matters, but it does not replace due diligence. Criticality and access should determine assessment depth and monitoring.
Prepare the response before it is needed
An incident plan should connect technology, leadership, legal, privacy, and communications. Define identification, containment, evidence preservation, impact assessment, notification decisions, and lessons learned.
Organizations should track current ANPD incident-notification requirements and maintain reliable information to evaluate relevant risk or harm to data subjects. Tabletop exercises expose decision gaps without interrupting operations.
Accountability is evidence-based governance
Maintain inventories, decisions, risk assessments, training records, contracts, access reviews, tests, and action plans. Useful evidence is current, understandable, and tied to an owner.
Maturity is visible when the organization can answer: what data do we hold, why do we need it, who can access it, how do we protect it, how long do we retain it, and what happens if something goes wrong?
Practical application
Accountability baseline
Use this list as a starting point and adjust it to the organization’s actual risk:
Official sources
External links to official sources. Always consult the current version and your organization’s specific context.
Informational content. It does not replace a specific technical, legal, or regulatory assessment.