Sandra TemponiAdvocacia

Digital Law · Privacy · LGPD and GDPR

Data protection with legal certainty.

A law practice specializing in Digital Law and Data Protection. Compliance with the LGPD (Brazilian General Data Protection Law, Law No. 13,709/2018) and the GDPR, service as Data Protection Officer (DPO) and legal handling of incidents, for companies that process personal data responsibly.

  • Law No. 13,709/2018 · LGPD
  • Regulation (EU) 2016/679 · GDPR

Privacy is not a form. It is a legal duty, a culture and a matter of proof.

Every processing of personal data requires a legal basis, a purpose and due care. That is what a defensible privacy program demonstrates when someone asks.

Practice areas

The full scope of Digital Law, with a focus on data protection.

  1. I

    LGPD compliance

    From initial assessment to a living program: legal bases, privacy notices and policies, records of processing activities and data protection impact reports.

    LGPD · Arts. 7, 37 and 38
  2. II

    Data Protection Officer (DPO)

    Serving as Data Protection Officer for the processing of personal data: the channel with data subjects and with the ANPD (Brazil's National Data Protection Authority), internal guidance and legal opinions.

    LGPD Art. 41 · Res. CD/ANPD nº 18/2024
  3. III

    GDPR and international operations

    For companies that offer goods or services to individuals in the European Union or monitor their behavior: records of processing activities, data protection impact assessments, EU representative and transfers.

    GDPR · Arts. 3, 27, 30 and 35
  4. IV

    Security incidents

    Legal handling of the incident: assessment of risk or significant harm, notification to the ANPD and to data subjects and, where data of individuals in the European Union is involved, to the competent supervisory authority.

    LGPD Art. 48 · Res. CD/ANPD nº 15/2024 · GDPR Art. 33
  5. V

    Contracts, vendors and transfers

    Data protection clauses, data processing agreements with processors, legal assessment of third parties and international data transfers.

    Res. CD/ANPD nº 19/2024 · GDPR Art. 46
  6. VI

    Data subject rights

    Workflows and responses to requests for confirmation, access, correction, deletion, portability and withdrawal of consent.

    LGPD Art. 18
  7. VII

    Digital Law

    Terms of use, platform policies, e-commerce, the Marco Civil da Internet (Brazilian Internet Civil Rights Framework) and responsible use of artificial intelligence with personal data.

    Law No. 12,965/2014
  8. VIII

    Inspections and administrative defense

    Handling of ANPD requests and inspection proceedings, and defense in administrative sanctioning proceedings.

    LGPD Arts. 52 to 55-K

The firm

Sandra Temponi

Attorney · Privacy and Data Protection · Data Protection Officer (DPO)

A practice dedicated to Digital Law and personal data protection, for companies that process data at scale and need legal certainty to grow.

Privacy as business strategy

Well-kept data turns into the trust of clients, partners and investors. Our work helps your company grow with data, without data protection law becoming a risk or a brake.

Education

  • Residency in Data Protection · Postgraduate program · Privacy Academy · 2023–2024
  • LL.M. in Data Protection: LGPD & GDPR · Postgraduate specialization (lato sensu) · FMP, Fundação Escola Superior do Ministério Público · 2021–2022
  • Digital Law · Postgraduate specialization (lato sensu) · FMP, Fundação Escola Superior do Ministério Público · 2018–2019
  • Bachelor of Laws · FPL Educacional · 2014–2018

Certifications

  • EXIN Data Protection Officer (DPO) · 2023
  • EXIN Privacy and Data Protection Foundation · 2022
  • EXIN Information Security Foundation · 2022

OAB/MG 195.891

Method

Five stages, and the program continues beyond them.

  1. 1

    Legal assessment

    We understand the business, the data it processes and why. Each processing activity is assigned a legal basis, a purpose and a retention period.

  2. 2

    Compliance plan

    Priorities set by risk, with owners and deadlines. No generic template copied from another company.

  3. 3

    Documents and contracts

    Notices, policies, clauses and records drafted for your operations, in the language of the people who will use them.

  4. 4

    Ongoing governance

    An active Data Protection Officer, periodic reviews, team training and responses to data subjects.

  5. 5

    Incident readiness

    A plan set before the incident: who decides, who notifies, what to notify and within what time frame.

Quick check

Six questions to see where your company stands.

Answer candidly. Nothing is sent: the result is shown only to you, on this screen.

  1. Does the company keep a record of its personal data processing activities?

  2. Has a Data Protection Officer been appointed, with a contact channel for data subjects?

  3. Is there an incident response plan that sets out who notifies and within what time frame?

  4. Do vendor contracts include data protection clauses?

  5. Does the company offer products or services to individuals in the European Union?

  6. Have the information security controls been assessed by specialists in the field?

Integrated technical practice

Law with legal professionals. Security with security professionals.

Privacy requires both, and each has its own professional. The firm focuses on the legal aspects. Information security assessments and technical privacy governance are handled by cybersecurity specialists at GRC1, the firm's technical partner. That way, security controls are assessed by people who work in security, not improvised by people outside the field.

The firm

  • Legal bases, legal opinions and legal guidance
  • Contracts, clauses and transfers
  • Data Protection Officer (DPO), data subjects and the ANPD
  • Legal handling of incidents

The technical partner

  • Assessment of risks and security controls
  • Privacy governance with Titan Penelope
  • Discovery of personal data across systems
  • Technical incident response and evidence
Learn about GRC1(opens in a new tab)

Each professional is responsible for their own work. Engaging technical services is independent of engaging the firm.

Privacy in practice

Technology records. The lawyer decides.

In the integrated practice, technical governance relies on Titan Penelope, GRC1's privacy and LGPD platform.

TITAN PENELOPE

Privacy · LGPD from data mapping to the data subject

Penelope, who for 20 years faithfully kept what had been entrusted to her.

  • Record of processing activities built through interviews or from Microsoft Teams meetings, with AI that suggests and people who confirm.
  • Personal data discovery across 12 families of data sources.
  • Data subject portal for 11 request types, in 8 languages, with 3 identity verification checks.
  • Opinions with defined accountability: AI prepares, reviewers analyze and the Data Protection Officer signs.
  • 10 privacy reports prepared with AI support, with a non-AI alternative.
  • Third-party assessment with a 45-question questionnaire.
  • Whistleblowing channel.

The platform organizes and records evidence. Legal decisions rest with the firm.

Experience in privacy governance

Real cases, without exposing those who entrusted them to us.

Privacy programs supported by the technical partner's platform, presented without identifying the companies, as required by professional ethics and by the LGPD itself.

  • Agribusiness industry

    More than one hundred processes with legal bases and retention periods

    Hundreds of processing activities mapped, each with its legal basis, retention period and third parties involved, and the inventory connected to technical monitoring of potential incidents involving personal data.

  • Business group with several companies

    A single inventory for the group

    Data processing across the group's companies brought together on a single platform, with more than one hundred systems and dozens of partners that receive data, vendor assessment with AI-assisted opinions and a whistleblowing channel with anonymous reporting.

  • Pharmaceutical industry

    Record organized by department

    Dozens of processes spread across more than ten departments, with legal basis and retention defined for virtually all of them, and vendor assessment with questions distributed among the vendor's own teams.

  • Technology and software development

    AI-assisted interviews and impact assessments (DPIA/RIPD)

    Record of processing built through dozens of interviews with the business units, conducted with AI support, international transfers identified in most processes, and data protection impact assessments (RIPD) prepared with AI support, a practice already applied across several clients.

  • Human resources

    Sensitive data in plain sight

    The mapping showed that more than half of the processes involve sensitive data, and the activities that call for an impact report were flagged, with systems, data sharing and retention documented.

  • Compounding pharmacy

    Data flow mapped out

    Dozens of processes mapped, one third involving sensitive data, activities requiring an impact report flagged and vendors with international transfers recorded, with the data flow diagrammed on the platform.

Frequently asked questions

What companies ask most often.

Does every company need a Data Protection Officer (DPO)?

The LGPD requires the controller to appoint a data protection officer (Art. 41). Resolution CD/ANPD nº 2/2022 exempts small-scale processing agents from this appointment, provided that they maintain a communication channel with data subjects. Whether a given company qualifies is assessed case by case.

When do the LGPD and the GDPR apply at the same time?

When the company processes data in Brazil and also offers goods or services to individuals in the European Union or monitors their behavior (GDPR Art. 3). In such cases, the privacy program must comply with both regulations, paying attention to differences such as incident notification deadlines and international transfer rules.

What should be done right after a security incident?

Activate the response plan, preserve evidence and assess whether there is risk or significant harm to data subjects. If there is, notification to the ANPD and to data subjects follows LGPD Art. 48 and Resolution CD/ANPD nº 15/2024, which sets a deadline of three business days. Under the GDPR, notification to the supervisory authority must take place within 72 hours (Art. 33).

Why separate legal work from information security?

Because they are different areas of expertise. The lawyer interprets the law and is responsible for legal advice; the security specialist assesses technical controls and produces evidence. Combining the two, each in their own field, results in a defensible privacy program.

Contact

Contact the firm.

Tell us about your company's situation. We will reply through the channel you indicate.

Message on WhatsApp

The button opens your email program with the message ready to send. Nothing is stored on this site.