Privacy and LGPD

LGPD in practice: the technical control that upholds the policy

Almost every company already has a written privacy policy. Few can show, with evidence, where personal data sits, who accessed it and what happens when it leaks. Inove takes care of the technical half of the LGPD (Brazil’s data protection law) — precisely the half that legal cannot produce on its own.

What we handle in privacy

The document belongs to legal. The proof that it is true belongs to IT. These are the fronts that produce that proof.

Where the data sits

Mapping of personal data across systems, databases, files and cloud — including the fileserver nobody has opened in years.

Who accesses it

Role-based access, periodic review and a usage trail. “Only those who need it” must be verifiable, not declared.

Retention and disposal

Data kept past its term is risk with no return. Retention rules applied for real, with a record of the disposal.

Sensitive and special data

Health, biometrics and other special category data demand their own handling — and that is where the fine hurts most.

Third parties and processors

Who processes data on your behalf, under which basis and for how long. A contract without technical control protects nobody.

Incident response

Who detects, who assesses, who notifies and within what time. Rehearsed beforehand, because the legal deadline runs from the event.

How you get off paper

Without an inventory, everything else is intent. The sequence below produces evidence instead of promises.

  1. 01

    Take inventory

    Where personal data sits today, in what volume and under whose responsibility. More always turns up than expected.

  2. 02

    Classify

    What is personal, what is sensitive and what could already have been disposed of. Classification sets the effort for the rest.

  3. 03

    Apply controls

    Access, encryption, retention and logging — deployed where the data sits, not where it would be convenient.

  4. 04

    Prove and repeat

    An evidence report and a review routine. Privacy is not a project: it is a state you maintain.

What this prevents

A ready answer for the data subject

An access or deletion request carries a legal deadline. Without knowing where the data sits, the deadline turns into risk.

An incident without improvisation

The worst moment to work out who notifies is during the breach. The procedure exists beforehand.

Reduced exposure

Disposing of old data and cycling access cut legal risk and attack surface at the same time.

Audits without panic

The map, the trail and the disposal records already exist when they are asked for — because they were born during operations.

Do you know where your company’s personal data sits?

If the answer starts with “I think so”, that is your starting point. Ask for a privacy assessment: inventory, access, retention and a response plan.