LGPD Consulting: How it works and what tp expect from the project

Understanding how a LGPD compliance consulting service works in practice is what allows you to evaluate proposals carefully, properly oversee the implementation, and determine at the end whether the work was completed thoroughly.

In this article, you will find:

•	What differentiates a serious consulting service from a purely document-based deliverable
•	What the stages of a compliance project are
•	What your company should have at the end of the process
•	How to evaluate a proposal before hiring a consultant

Enjoy the read.

What Does an LGPD Compliance Consultant Actually Do?

There is an important difference between delivering compliance documents and actually building compliance. A project that is limited to producing a privacy policy and a record of processing activities is delivering forms, not compliance.

Compliance requires these documents to reflect what the company actually does with data, and for internal processes to be aligned with what is documented.

The consultant’s role is to build this connection between the company’s actual practices and the requirements of the law, so that the compliance framework can withstand an audit, a data subject complaint, or an inspection by the ANPD.

The Stages of a Compliance Project

A well-structured LGPD compliance consulting project goes through interdependent stages. Skipping any of them compromises the strength of everything that follows.

Data Assessment and Mapping

The first step is understanding the company’s actual situation: what personal data is collected, which systems store it, who has access to it, and which third parties it is shared with.

This assessment, known as data mapping, provides the foundation for all the documents and processes that follow.

Companies that skip this step to move directly into document creation often discover later that their privacy policy does not reflect the actual product and that their record of processing activities is incomplete. Mapping is labor-intensive because it requires going through each area of the company and documenting what actually happens to the data in practice.

Gap Analysis and Action Plan

With the data map in hand, the consultant identifies where current data processing practices are non-compliant and determines the gap between the current state and the appropriate state.

This analysis produces an action plan with defined priorities: what needs to be corrected immediately, what can be addressed throughout the project, and what depends on more complex technical changes.

This document transforms the LGPD, which is extensive and sometimes abstract legislation, into a set of concrete tasks with assigned responsibilities and defined deadlines.

Document and Process Development

Based on the assessment, the consultant develops the documents required by the law: privacy policy, record of processing activities, data processing agreements with processors, DPO appointment, data retention policy, data subject request procedures, and incident notification procedures.

These documents must reflect how the company actually operates. A generic policy or a ROPA completed with approximate information will not adequately support the company during an inspection.

For e-commerce companies, for example, the 12 points that make up a complete compliance program help illustrate the depth of what needs to be covered in each document.

Technical Compliance and Information Security

The LGPD requires appropriate technical security measures to protect processed data. This includes access controls, encryption where applicable, audit logs, and credential management.

A consulting service that does not include this layer delivers only partial compliance.

Environments that have never undergone a technical exposure assessment often reveal, during the compliance project, areas where data is insufficiently protected even when the documentation itself is correct.

Training and Internal Culture

The LGPD depends on people to work effectively. Employees who access customer data, process orders, or administer systems need to understand what they can and cannot do with that information.

Without this layer, even a well-documented process can be violated by an employee who simply did not know there was a rule.

Training also establishes the procedures for handling data subject requests and the escalation process when an incident is identified.

What Your Company Should Have at the End of the Project

A properly completed LGPD compliance consulting project delivers updated documents that are consistent with the company’s actual operations, defined internal processes, a trained team, technical controls that have been implemented or mapped out, and a formally appointed DPO or a documented justification for not appointing one.

More than that, the company needs to know how to maintain compliance over time.

New features, new vendors, and operational changes can alter the company’s data processing activities and require documents and processes to be updated. Companies that develop digital products involving the ongoing processing of third-party data face these changes particularly frequently.

How to Evaluate a Consulting Proposal

When reviewing a proposal, a few questions can help determine whether the scope is appropriate.

Does the project include data mapping, or does it begin directly with document creation? Will the documents be based on the company’s actual operations or on generic templates? Is technical compliance included in the scope? Does the project include employee training?

Proposals that do not answer these questions precisely tend to deliver less than what is actually required. And the cost of redoing a poorly executed compliance process is often higher than doing it correctly from the start.

STWBrasil conducts LGPD compliance consulting projects that include data mapping, document and process development, technical compliance, and team training. If your company has not yet started the process or wants to review what has already been done, talk to our team.

FAQ — Frequently Asked Questions About LGPD Compliance Consulting

How long does an LGPD compliance project take?
It depends on the size of the company and the complexity of its data processing activities. Small organizations with simpler operations may complete the process in two to three months. Larger companies with multiple systems, vendors, and data flows typically take four to eight months to achieve comprehensive compliance.

Does LGPD compliance consulting need to be renewed, or is it a one-time project?
Initial compliance is a project with a beginning and an end, but compliance itself is ongoing. Whenever the company adds new features, hires new vendors, or changes how it processes data, its documents and processes need to be reviewed. An annual review is generally the minimum recommended.

Do small businesses also need LGPD compliance consulting?
The LGPD does not distinguish based on the size of the operation or revenue. Any company that processes the personal data of Brazilian data subjects is subject to the same obligations. The difference is that the scope of the project tends to be smaller, and the cost of compliance is proportionally more accessible.

What happens if a company is audited without being compliant?
The ANPD may impose a warning, a fine of up to 2% of the company’s prior-year net revenue, capped at R$50 million per violation, public disclosure of the violation, and the blocking or deletion of data processed unlawfully. In addition to formal sanctions, the public exposure resulting from an enforcement action can directly affect the company’s reputation among customers and business partners.

Leading company in information security. The digital protection of your company is our priority. We rely on state-of-the-art technology used by highly specialized professionals.

(11) 3939-0827
R. São Bento, 365 – 8o Andar – Centro Histórico de São Paulo, São Paulo – SP,
CNPJ: 05.089.825/0001-48.

Copyright ©️ 2023 – All rights reserved. Check out our  Privacy Policy.