Privacy and LGPD
LGPD in practice: the technical control that upholds the policy
Almost every company already has a written privacy policy. Few can show, with evidence, where personal data sits, who accessed it and what happens when it leaks. Inove takes care of the technical half of the LGPD (Brazil’s data protection law) — precisely the half that legal cannot produce on its own.
What we handle in privacy
The document belongs to legal. The proof that it is true belongs to IT. These are the fronts that produce that proof.
Where the data sits
Mapping of personal data across systems, databases, files and cloud — including the fileserver nobody has opened in years.
Who accesses it
Role-based access, periodic review and a usage trail. “Only those who need it” must be verifiable, not declared.
Retention and disposal
Data kept past its term is risk with no return. Retention rules applied for real, with a record of the disposal.
Sensitive and special data
Health, biometrics and other special category data demand their own handling — and that is where the fine hurts most.
Third parties and processors
Who processes data on your behalf, under which basis and for how long. A contract without technical control protects nobody.
Incident response
Who detects, who assesses, who notifies and within what time. Rehearsed beforehand, because the legal deadline runs from the event.
How you get off paper
Without an inventory, everything else is intent. The sequence below produces evidence instead of promises.
- 01
Take inventory
Where personal data sits today, in what volume and under whose responsibility. More always turns up than expected.
- 02
Classify
What is personal, what is sensitive and what could already have been disposed of. Classification sets the effort for the rest.
- 03
Apply controls
Access, encryption, retention and logging — deployed where the data sits, not where it would be convenient.
- 04
Prove and repeat
An evidence report and a review routine. Privacy is not a project: it is a state you maintain.
What this prevents
A ready answer for the data subject
An access or deletion request carries a legal deadline. Without knowing where the data sits, the deadline turns into risk.
An incident without improvisation
The worst moment to work out who notifies is during the breach. The procedure exists beforehand.
Reduced exposure
Disposing of old data and cycling access cut legal risk and attack surface at the same time.
Audits without panic
The map, the trail and the disposal records already exist when they are asked for — because they were born during operations.
Related material and reading
Do you know where your company’s personal data sits?
If the answer starts with “I think so”, that is your starting point. Ask for a privacy assessment: inventory, access, retention and a response plan.