Digital Law · Privacy · LGPD and GDPR
Data protection with legal certainty.
A law practice specializing in Digital Law and Data Protection. Compliance with the LGPD (Brazilian General Data Protection Law, Law No. 13,709/2018) and the GDPR, service as Data Protection Officer (DPO) and legal handling of incidents, for companies that process personal data responsibly.
- Law No. 13,709/2018 · LGPD
- Regulation (EU) 2016/679 · GDPR
Privacy is not a form. It is a legal duty, a culture and a matter of proof.
Every processing of personal data requires a legal basis, a purpose and due care. That is what a defensible privacy program demonstrates when someone asks.
Practice areas
The full scope of Digital Law, with a focus on data protection.
- I
LGPD compliance
From initial assessment to a living program: legal bases, privacy notices and policies, records of processing activities and data protection impact reports.
LGPD · Arts. 7, 37 and 38 - II
Data Protection Officer (DPO)
Serving as Data Protection Officer for the processing of personal data: the channel with data subjects and with the ANPD (Brazil's National Data Protection Authority), internal guidance and legal opinions.
LGPD Art. 41 · Res. CD/ANPD nº 18/2024 - III
GDPR and international operations
For companies that offer goods or services to individuals in the European Union or monitor their behavior: records of processing activities, data protection impact assessments, EU representative and transfers.
GDPR · Arts. 3, 27, 30 and 35 - IV
Security incidents
Legal handling of the incident: assessment of risk or significant harm, notification to the ANPD and to data subjects and, where data of individuals in the European Union is involved, to the competent supervisory authority.
LGPD Art. 48 · Res. CD/ANPD nº 15/2024 · GDPR Art. 33 - V
Contracts, vendors and transfers
Data protection clauses, data processing agreements with processors, legal assessment of third parties and international data transfers.
Res. CD/ANPD nº 19/2024 · GDPR Art. 46 - VI
Data subject rights
Workflows and responses to requests for confirmation, access, correction, deletion, portability and withdrawal of consent.
LGPD Art. 18 - VII
Digital Law
Terms of use, platform policies, e-commerce, the Marco Civil da Internet (Brazilian Internet Civil Rights Framework) and responsible use of artificial intelligence with personal data.
Law No. 12,965/2014 - VIII
Inspections and administrative defense
Handling of ANPD requests and inspection proceedings, and defense in administrative sanctioning proceedings.
LGPD Arts. 52 to 55-K
The firm
Sandra Temponi
Attorney · Privacy and Data Protection · Data Protection Officer (DPO)
A practice dedicated to Digital Law and personal data protection, for companies that process data at scale and need legal certainty to grow.
Privacy as business strategy
Well-kept data turns into the trust of clients, partners and investors. Our work helps your company grow with data, without data protection law becoming a risk or a brake.
Education
- Residency in Data Protection · Postgraduate program · Privacy Academy · 2023–2024
- LL.M. in Data Protection: LGPD & GDPR · Postgraduate specialization (lato sensu) · FMP, Fundação Escola Superior do Ministério Público · 2021–2022
- Digital Law · Postgraduate specialization (lato sensu) · FMP, Fundação Escola Superior do Ministério Público · 2018–2019
- Bachelor of Laws · FPL Educacional · 2014–2018
Certifications
- EXIN Data Protection Officer (DPO) · 2023
- EXIN Privacy and Data Protection Foundation · 2022
- EXIN Information Security Foundation · 2022
OAB/MG 195.891
Method
Five stages, and the program continues beyond them.
- 1
Legal assessment
We understand the business, the data it processes and why. Each processing activity is assigned a legal basis, a purpose and a retention period.
- 2
Compliance plan
Priorities set by risk, with owners and deadlines. No generic template copied from another company.
- 3
Documents and contracts
Notices, policies, clauses and records drafted for your operations, in the language of the people who will use them.
- 4
Ongoing governance
An active Data Protection Officer, periodic reviews, team training and responses to data subjects.
- 5
Incident readiness
A plan set before the incident: who decides, who notifies, what to notify and within what time frame.
Quick check
Six questions to see where your company stands.
Answer candidly. Nothing is sent: the result is shown only to you, on this screen.
Does the company keep a record of its personal data processing activities?
Has a Data Protection Officer been appointed, with a contact channel for data subjects?
Is there an incident response plan that sets out who notifies and within what time frame?
Do vendor contracts include data protection clauses?
Does the company offer products or services to individuals in the European Union?
Have the information security controls been assessed by specialists in the field?
Integrated technical practice
Law with legal professionals. Security with security professionals.
Privacy requires both, and each has its own professional. The firm focuses on the legal aspects. Information security assessments and technical privacy governance are handled by cybersecurity specialists at GRC1, the firm's technical partner. That way, security controls are assessed by people who work in security, not improvised by people outside the field.
The firm
- Legal bases, legal opinions and legal guidance
- Contracts, clauses and transfers
- Data Protection Officer (DPO), data subjects and the ANPD
- Legal handling of incidents
The technical partner
- Assessment of risks and security controls
- Privacy governance with Titan Penelope
- Discovery of personal data across systems
- Technical incident response and evidence
Each professional is responsible for their own work. Engaging technical services is independent of engaging the firm.
Privacy in practice
Technology records. The lawyer decides.
In the integrated practice, technical governance relies on Titan Penelope, GRC1's privacy and LGPD platform.
TITAN PENELOPE
Privacy · LGPD from data mapping to the data subject
Penelope, who for 20 years faithfully kept what had been entrusted to her.
- Record of processing activities built through interviews or from Microsoft Teams meetings, with AI that suggests and people who confirm.
- Personal data discovery across 12 families of data sources.
- Data subject portal for 11 request types, in 8 languages, with 3 identity verification checks.
- Opinions with defined accountability: AI prepares, reviewers analyze and the Data Protection Officer signs.
- 10 privacy reports prepared with AI support, with a non-AI alternative.
- Third-party assessment with a 45-question questionnaire.
- Whistleblowing channel.
The platform organizes and records evidence. Legal decisions rest with the firm.
Experience in privacy governance
Real cases, without exposing those who entrusted them to us.
Privacy programs supported by the technical partner's platform, presented without identifying the companies, as required by professional ethics and by the LGPD itself.
Agribusiness industry
More than one hundred processes with legal bases and retention periods
Hundreds of processing activities mapped, each with its legal basis, retention period and third parties involved, and the inventory connected to technical monitoring of potential incidents involving personal data.
Business group with several companies
A single inventory for the group
Data processing across the group's companies brought together on a single platform, with more than one hundred systems and dozens of partners that receive data, vendor assessment with AI-assisted opinions and a whistleblowing channel with anonymous reporting.
Pharmaceutical industry
Record organized by department
Dozens of processes spread across more than ten departments, with legal basis and retention defined for virtually all of them, and vendor assessment with questions distributed among the vendor's own teams.
Technology and software development
AI-assisted interviews and impact assessments (DPIA/RIPD)
Record of processing built through dozens of interviews with the business units, conducted with AI support, international transfers identified in most processes, and data protection impact assessments (RIPD) prepared with AI support, a practice already applied across several clients.
Human resources
Sensitive data in plain sight
The mapping showed that more than half of the processes involve sensitive data, and the activities that call for an impact report were flagged, with systems, data sharing and retention documented.
Compounding pharmacy
Data flow mapped out
Dozens of processes mapped, one third involving sensitive data, activities requiring an impact report flagged and vendors with international transfers recorded, with the data flow diagrammed on the platform.
Frequently asked questions
What companies ask most often.
Does every company need a Data Protection Officer (DPO)?
The LGPD requires the controller to appoint a data protection officer (Art. 41). Resolution CD/ANPD nº 2/2022 exempts small-scale processing agents from this appointment, provided that they maintain a communication channel with data subjects. Whether a given company qualifies is assessed case by case.
When do the LGPD and the GDPR apply at the same time?
When the company processes data in Brazil and also offers goods or services to individuals in the European Union or monitors their behavior (GDPR Art. 3). In such cases, the privacy program must comply with both regulations, paying attention to differences such as incident notification deadlines and international transfer rules.
What should be done right after a security incident?
Activate the response plan, preserve evidence and assess whether there is risk or significant harm to data subjects. If there is, notification to the ANPD and to data subjects follows LGPD Art. 48 and Resolution CD/ANPD nº 15/2024, which sets a deadline of three business days. Under the GDPR, notification to the supervisory authority must take place within 72 hours (Art. 33).
Why separate legal work from information security?
Because they are different areas of expertise. The lawyer interprets the law and is responsible for legal advice; the security specialist assesses technical controls and produces evidence. Combining the two, each in their own field, results in a defensible privacy program.
Contact
Contact the firm.
Tell us about your company's situation. We will reply through the channel you indicate.
- Phone and WhatsApp(31) 99595-6481
- AddressAlameda dos Cedros, 110 · Bela Vista
Lagoa Santa · MG