Business Law

LGPD in practice: what your company must actually do (and what is myth)

Compliance is not buying a badge: it is organising what the company already does with data.

LGPD in practice: what your company must actually do (and what is myth)
In short

Brazil’s LGPD (Law 13,709/2018) applies to virtually every company processing personal data — including employees and suppliers, not just customers. Compliance is not buying a certificate: it is mapping the data you collect, defining the legal basis for each processing activity, adjusting contracts with processors, having an incident response plan and being able to answer data subjects. The ANPD may fine up to 2% of revenue, capped at R$ 50 million per infringement — but in practice the bigger risk is contractual and reputational.

Need help with your case? Talk to our business law team in São Paulo.

“Does the LGPD apply to my company? It is small and does not sell online.” It does. If the company has employees, keeps CVs, maintains a customer database or handles supplier data, it processes personal data — and falls within the law. Size is not a criterion for application; it is a criterion for proportionality of the measures.

The trouble is that, for many companies, the LGPD has become a mix of panic and package-selling. Some overspend on unnecessary solutions; others skip the basics — which are cheap and remove most of the risk. This article separates what the law actually requires from market myth.

Who the LGPD applies to (and what counts as personal data)

The law covers any operation with personal data — collection, storage, use, sharing, deletion — by an individual or a company, digitally or on paper. Personal data is anything that identifies or makes someone identifiable: name, tax ID, e-mail, phone, IP, geolocation, image.

One category deserves extra care: sensitive data — health, biometrics, genetic data, racial or ethnic origin, religious belief, political opinion, union membership, sex life. Processing it follows stricter rules. Employee medical certificates, for instance, are sensitive data — and many companies keep them in shared folders with no controls.

The biggest LGPD myth is believing everything needs consent. It does not. The law sets out ten legal bases (art. 7), and consent is only one of them — often the worst choice, because it can be withdrawn at any time.

  • Compliance with a legal obligation: keeping employment and tax records required by law.
  • Performance of a contract: using the customer’s address to deliver the product ordered.
  • Legitimate interest: fraud prevention, security, some relationship activities — requires a balancing test and transparency.
  • Exercise of rights in judicial, administrative or arbitral proceedings.
  • Credit protection, among other statutory grounds.

The correct reading is this: asking for consent where a legal obligation or contract performance already applies does not protect the company — it hinders it. The real work is choosing and documenting the right legal basis for each processing activity.

What the company actually needs

  • Data mapping: what data is collected, from whom, why, where it sits, who accesses it and how long it is kept.
  • Records of processing operations (art. 37) — the document that evidences organisation and is the first thing requested in an inspection.
  • A defined legal basis for each activity, with the rationale recorded.
  • A clear, truthful privacy policy (describing what the company actually does).
  • Adjusted contracts with vendors processing data for you — systems, accounting, marketing, cloud — setting out roles and responsibilities.
  • Proportionate security controls: passwords, access profiles, backups, encryption where appropriate.
  • A data subject channel and a process for handling access, correction and deletion requests.
  • An incident response plan, stating who escalates to whom and within what time.
  • A data protection officer appointed — the ANPD relaxes this for small entities, but someone must be responsible.

Data breach: what to do in the first hours

Security incidents happen — including through human error, such as an e-mail sent with the whole list in copy. What separates a manageable problem from a crisis is procedure. The LGPD requires notifying the ANPD and the data subjects where the incident may cause relevant risk or harm, within a reasonable period — and the ANPD has regulated this flow.

In practice: contain the incident, record everything (what happened, when, which data, how many people), assess the risk, notify where due and document the measures taken. In plain terms: the company that records and responds well usually suffers far less than the one that hides.

Sanctions: what the ANPD may impose

  • Warning, with a deadline to remedy.
  • Simple fine of up to 2% of revenue in Brazil in the last financial year, capped at R$ 50 million per infringement.
  • Daily fine, subject to the same cap.
  • Publicising the infringement — often the most painful effect.
  • Blocking or deletion of the data involved.
  • Partial or total suspension of processing activities in the most serious cases.

One risk is often forgotten: beyond the ANPD, there is civil exposure (claims by data subjects), contractual exposure (large clients require LGPD clauses and audits — those without them lose contracts) and action by the Public Prosecutor’s Office and consumer authorities.

Where to start without overspending

Smart compliance is proportionate to risk. A company handling sensitive data at scale is not comparable to a ten-person office with a client list. A realistic roadmap:

  • 1) Map the processing activities (an honest spreadsheet gets you started).
  • 2) Define the legal basis for each and eliminate unnecessary collection — data you do not collect is risk you do not run.
  • 3) Adjust vendor contracts and review internal access.
  • 4) Publish a truthful privacy policy and create the data subject channel.
  • 5) Write the incident plan and train the team (most breaches begin with human error).

A practical example: compliance that saved the contract

A 40-employee services company was put through a large client’s vendor approval process, which required data protection clauses and minimum evidence of compliance. There was no mapping, CVs sat in an open folder, and the HR system contract said nothing about data.

Within a few weeks: mapping completed, access restricted, addenda signed with three vendors, a policy published and an incident plan written. The contract was retained — and, along the way, the company discovered it was still keeping CVs from 2015 for no reason at all. The reason to comply is not always the fine; often it is the client.

Frequently asked questions

Does the LGPD apply to small companies?

Yes. The law does not exempt small businesses: if personal data is processed — including employees, CVs and suppliers — it applies. What changes is proportionality. The ANPD issued simplified rules for small-scale agents, relaxing requirements such as the formal appointment of an officer, and deadlines. The basics still apply: map, have a legal basis, look after security and be able to answer data subjects.

No, and this is the biggest LGPD myth. Consent is only one of the ten legal bases in article 7. Many activities rely on other bases — compliance with a legal obligation (employment records), performance of a contract (delivering a product), legitimate interest (fraud prevention). Using consent where it does not fit actually weakens the company’s position, since it can be withdrawn at any time.

What are the LGPD fines?

The ANPD may issue a warning, a simple fine of up to 2% of the company’s revenue in Brazil in the last financial year, capped at R$ 50 million per infringement, a daily fine, publicising the infringement, blocking or deletion of data and, in serious cases, suspension of processing. In practice, however, the cost that hits companies hardest tends to be contractual (losing clients that require compliance) and reputational.

We had a data breach. Must we notify the ANPD?

Notification to the ANPD and to data subjects is required where the incident may cause relevant risk or harm, within the period set in the regulations. The first step is to contain the incident and record everything: what happened, when, which data and how many people were affected. Then assess the risk and notify where due, documenting the measures taken. Companies that record and respond well typically face lighter consequences.

Where should we start with LGPD compliance?

Start with mapping: what data the company collects, from whom, why, where it sits, who accesses it and for how long. Then define the legal basis for each activity and eliminate unnecessary collection — data you do not collect is risk you do not run. Next, adjust contracts with vendors processing data for you, publish a truthful privacy policy, create the data subject channel and write an incident response plan.

Done well, LGPD compliance is neither an endless project nor a purchased badge: it is organising what the company already does with data, with measures proportionate to real risk. At Falchet e Marques Sociedade de Advogados, a São Paulo firm on Avenida Paulista, we run compliance in stages — from mapping to contracts and the incident plan — focused on what genuinely reduces risk.

Talk to our team on WhatsApp: +55 11 95901-1854 — does your company need to comply, or has a client imposed LGPD requirements? Tell us the scenario so we can map the most objective path.

Renato Falchet
Written by

Renato Falchet

Founding partner at Falchet e Marques (OAB/SP 344.334). Postgraduate in Business Law (FGV) and Succession Law (PUC-Campinas), working in corporate law, contracts and data protection — specialist in estate planning and business succession. Straight to the point, no legalese.

Meet Renato Ask about your case
Newsletter

Enjoyed it? Get the next one
straight to your inbox.

One short summary, once a month. No spam.