Security
Practical LGPD for teams without a dedicated DPO
LGPD without a dedicated DPO starts with inventory, legal basis, access, contracts, and incident routines. Solid basics reduce a lot of risk.
July 22, 2026|6 min read
Start with what exists
LGPD for a company without a dedicated DPO does not begin with a huge document. It begins with knowing which personal data exists, where it is stored, who accesses it, why it is processed, who receives it, and when it should be deleted.
Without that minimum inventory, any policy becomes decorative text. The company cannot respond to data subject requests, assess supplier risk, or communicate incidents clearly.
ANPD already offers a basic path
Brazil's ANPD maintains an information security guide for small processing agents, updated on the government portal in 2025. It covers administrative and technical measures such as security policy, access control, backups, and awareness.
The value is pragmatism. Privacy does not depend only on legal review. It depends on operational routine.
The minimum checklist
List personal data by process: marketing, sales, support, finance, HR, and suppliers. For each process, record legal basis, purpose, system used, owner, retention period, and sharing.
Then review access. Does someone who left the company still have a login? Who uses local spreadsheets? Who exports lists for campaigns? Who sends data by email without need? These simple points often create real risk.
Incidents need routine before the incident
Define who receives alerts, who assesses impact, who communicates with customers, who calls legal, and who preserves evidence. In crisis, a company without routine decides slowly and communicates poorly.
Practical LGPD is repeated discipline, not a one-week project.
Where Diglion comes in
Diglion helps map data, access, systems, and processes to turn privacy into operations. The goal is reducing risk with controls proportional to the company's maturity.
Sources consulted
- ANPD, Guia orientativo sobre segurança da informação para agentes de tratamento de pequeno porte, retrieved 2026-07-22.
- ANPD, Comunicação de incidente de segurança, retrieved 2026-07-22.
Corporate deepfakes: the scam your company has not seen yet
Generative AI security: risks that do not have names yet
Pentest: when to hire and what to expect from the report
Security for IoT devices in operations
Web3 and blockchain: separating hype from real application
Shadow AI: the invisible risk that grows when companies do not guide usage
Next step
Want to turn this topic into a real project?
Diglion helps diagnose the context, design the path, and build technology with product, architecture, and execution moving together.
Talk to a specialist