Data Compliance and Governance:
Advice on development, review and implementation of privacy policies, terms of use and governance documents, with analysis of data flows and definition of applicable legal bases. Structuring of programs data protection compliance, adapted to the reality of each organization, including:
- Inventory of personal data processed;
- Preparation of Data Protection Impact Reports (DPIA);
- Review of marketing practices, relationships with customers, suppliers and employees;
- Team training and development.
Audits, Prevention and Crisis Management:
Driving internal and external audits, identifying flaws, implementing action plans, and adopting technical and organizational information security measures. Direct involvement in:
- Incident and data breach management, with legal guidance on notification to the National Data Protection Authority (ANPD), communication to data subjects and containment plan;
- Representation in administrative or judicial litigation resulting from failures in data protection.
International Transfer and Contracts:
Advice on cross-border data operations, with review and preparation of contractual clauses and international transfer agreements, based on:
- LGPD, GDPR, Privacy Shield, Standard Contractual Clauses (SCCs), among others;
- Risk assessment of technology providers, cloud software, and global platforms.
Relationship with Authorities and Regulation:
Monitoring and representation of clients before the ANPD, Public Prosecutor's Office, PROCONs and other inspection authorities, acting in:
- Responses to notifications, infraction reports and requests for clarification;
- Defense in administrative proceedings;
- Conducting compliance processes required by regulatory bodies in specific sectors (financial, health, education, among others).
Whistleblowing and Corporate Ethics Programs:
Implementation and review of anonymous reporting programs (whistleblowing hotlines) in compliance with data protection regulations and compliance guidelines. Legally structured reporting channels that ensure:
- Security and anonymity of whistleblowers;
- Proper treatment of collected information;
- Integration with anti-corruption compliance policies and organizational conduct.