01

Privacy and security need the same map

Brazil’s LGPD establishes principles, rights, and obligations; security provides controls that preserve confidentiality, integrity, and availability. Managing them separately creates gaps between what the organization states and what it can execute.

Begin with processes that use personal data. Identify purpose, data and data subject categories, legal basis, systems, access, disclosures, retention, and disposition. This record guides legal and technical decisions.

  • Purpose and necessity
  • Legal basis and transparency
  • Access and traceability
  • Disclosures and contracts
  • Retention and disposition
  • Incidents and data subject rights
02

Proportionate, verifiable controls

Least privilege, strong authentication, updates, backups, appropriate encryption, endpoint protection, logs, and awareness provide a foundation. Selection depends on risk and context; evidence shows that a control exists and operates.

A policy should name owners, frequency, and records. 'Perform backups' is an intention. Defining scope, retention, protection, monitoring, and restoration testing creates an operable control.

03

Risk follows data to vendors

Cloud, support, communications, accounting, and platform providers may process or access data. Assess what is shared, why, where it is stored, which safeguards apply, how incidents are reported, and how data will be returned or deleted at contract end.

Contract language matters, but it does not replace due diligence. Criticality and access should determine assessment depth and monitoring.

04

Prepare the response before it is needed

An incident plan should connect technology, leadership, legal, privacy, and communications. Define identification, containment, evidence preservation, impact assessment, notification decisions, and lessons learned.

Organizations should track current ANPD incident-notification requirements and maintain reliable information to evaluate relevant risk or harm to data subjects. Tabletop exercises expose decision gaps without interrupting operations.

05

Accountability is evidence-based governance

Maintain inventories, decisions, risk assessments, training records, contracts, access reviews, tests, and action plans. Useful evidence is current, understandable, and tied to an owner.

Maturity is visible when the organization can answer: what data do we hold, why do we need it, who can access it, how do we protect it, how long do we retain it, and what happens if something goes wrong?

Practical application

Accountability baseline

Use this list as a starting point and adjust it to the organization’s actual risk:

01Processing and related asset inventory02Privacy notices consistent with practice03Defined roles and owners04Access control and periodic review05Applied retention and disposition06Critical vendor assessment07Exercised incident response plan08Data subject request channel09Recorded evidence and improvement plans

Official sources

External links to official sources. Always consult the current version and your organization’s specific context.

Informational content. It does not replace a specific technical, legal, or regulatory assessment.