
What this article covers
Compliance starts with understanding which personal data the business uses and why. A privacy notice alone does not organize access, retention or responses to individuals. This roadmap helps create an initial work list that must be adapted to the company’s activities and obligations.
1. Map a real business process
Start with a common workflow such as recruitment, payroll or customer support. Record which data enters, who receives it, where it is stored, who it is shared with and when it is no longer needed. Include spreadsheets, email inboxes and suppliers alongside the main systems.
The deliverable can be a simple table of purposes, data categories, owners, recipients and retention criteria. Validate it with the people who perform the process, not just the technology team.
2. Connect each purpose to a legal basis
Brazil’s LGPD, particularly Articles 6, 7 and 11, distinguishes principles and grounds for processing. Consent is one ground, not universal permission. Sensitive data requires attention to its specific rules.
Document the applicable basis for each purpose and the reasoning supporting that decision. Check the company’s circumstances and any specific rules; small size does not create a general exemption from the law. Uncertain cases require legal analysis of the actual context.
3. Make rights and responsibilities workable
Define a request channel and a person responsible for routing requests. Establish a proportionate way to confirm identity without collecting excessive documents. Record receipt, assessment and response.
- Locate the data before promising access or deletion.
- Consider retention obligations and other people’s rights.
- Agree with suppliers how to carry out requests and communicate incidents.
4. Prioritize controls you can verify
The ANPD security guide for small processing agents is an initial reference for administrative and technical measures. Turn each business priority into an assigned task with evidence of completion.
A first review might cover former employees’ accounts, multifactor authentication, updates, backups and public sharing. Test restoration of a sample and document who to contact during an incident; merely having a backup does not demonstrate recovery capability.
5. Keep the plan current
Bring together the inventory, decisions, notices, relevant contracts and test records. Rank open items by risk and track completion. Revisit the work when a form, supplier or purpose changes.
The compliance checklist helps surface questions; its results are not certification or a legal opinion. GRCtech presents an approach to managing these activities.
