If your organization qualifies as a micro-company, small company, or startup under Brazil's Data Protection Law, you're working under a different compliance framework than larger enterprises. On Jan. 27, 2022, Brazil's Data Protection Agency adopted Resolution ANPD No. 2, which creates simplified obligations for "small-sized processing agents."
This isn't a free pass. It's a streamlined compliance path that reduces administrative burden while maintaining accountability. Below is a template you can adapt to document your simplified compliance program.
Purpose of This Template
This template helps small-sized processing agents under the LGPD demonstrate compliance with simplified obligations under Resolution ANPD No. 2. You'll use it to:
- Document your simplified record of processing operations (Article 37 requirement)
- Define your security incident response procedure
- Establish a simplified information security policy
- Track extended timelines for data subject requests and ANPD responses
The template assumes you've confirmed your organization meets the definition of a small-sized processing agent and you're not conducting high-risk processing operations that would disqualify you from simplified treatment.
Prerequisites
Before you customize this template, verify:
- Entity classification: You qualify as a micro-company, small company, startup, or qualifying legal entity under Brazilian law.
- Processing scope: You're not engaged in high-risk processing as defined by the ANPD (separate guidelines apply to high-risk activities).
- DPO status: You've documented your exemption from appointing a data protection officer under Resolution Article 11.
- Extended timelines: You've communicated internally that your organization has twice the standard response time for data subject requests, security incident notifications, and ANPD information requests.
The Template
Section 1: Simplified Processing Record
Purpose: Maintain a record of personal data processing operations under LGPD Article 37 in simplified form.
PROCESSING ACTIVITY: [Name of processing activity]
DATA CATEGORIES PROCESSED:
- [e.g., Customer email addresses]
- [e.g., Payment transaction records]
- [e.g., Service usage logs]
PURPOSE OF PROCESSING:
[Describe why you're processing this data]
LEGAL BASIS:
[Consent / Contract performance / Legitimate interest / Legal obligation]
RETENTION PERIOD:
[How long you keep this data]
THIRD-PARTY RECIPIENTS:
[List any processors or partners who receive this data]
SECURITY MEASURES:
[Brief description of how you protect this data]
LAST REVIEWED: [Date]
Repeat this block for each distinct processing activity.
Section 2: Simplified Security Incident Response
Trigger: Any security incident that creates risk or relevant damage to data subjects.
Response timeline: Twice the standard notification period, unless the incident poses potential compromise to physical or moral integrity of data subjects or national security.
INCIDENT DETECTION LOG
Date discovered: ___________
Data categories affected: ___________
Estimated number of individuals: ___________
Incident severity (Low / Medium / High): ___________
INTERNAL ASSESSMENT (complete within 48 hours)
□ Scope of breach documented
□ Root cause identified
□ Immediate containment measures applied
□ Risk to data subjects assessed
NOTIFICATION DECISION
□ ANPD notification required: Yes / No
□ Data subject notification required: Yes / No
□ Notification timeline: [Extended timeline applies unless exception noted]
REMEDIATION ACTIONS
1. [Action taken]
2. [Action taken]
3. [Action taken]
FOLLOW-UP REVIEW DATE: ___________
Section 3: Simplified Information Security Policy
Purpose: Establish essential and necessary requirements for processing personal data under Resolution Article 13.
INFORMATION SECURITY POLICY
[Organization name]
Effective date: [Date]
1. ACCESS CONTROL
Who can access personal data: [Define roles]
Authentication requirements: [Password policy, MFA if applicable]
Access review frequency: [Quarterly / Annually]
2. DATA PROTECTION MEASURES
Encryption: [In transit / At rest / Both / None with justification]
Backup procedures: [Frequency and storage location]
Deletion procedures: [How you securely delete data]
3. THIRD-PARTY MANAGEMENT
Processor vetting: [How you evaluate vendors]
Contractual requirements: [Standard data processing terms]
Monitoring: [How you verify processor compliance]
4. INCIDENT RESPONSE
Point of contact: [Name and role]
Escalation procedure: [Internal steps]
Documentation requirements: [Reference Section 2 template]
5. TRAINING
Frequency: [Annual / On-hire / As-needed]
Topics covered: [Data handling, security awareness, incident reporting]
Completion tracking: [How you document training]
Last reviewed: [Date]
Next review: [Date]
Section 4: Data Subject Request Tracker
Timeline: Twice the standard response period for LGPD data subject requests.
REQUEST ID: [Unique identifier]
DATE RECEIVED: ___________
EXTENDED RESPONSE DEADLINE: [Calculate: standard deadline × 2]
REQUEST TYPE:
□ Access to personal data
□ Correction of data
□ Deletion of data
□ Data portability
□ Information about processing
□ [Withdrawal of consent](/glossary/withdrawal-of-consent)
□ Other: ___________
IDENTITY VERIFICATION:
□ Completed [Date: _____]
Method used: ___________
RESPONSE PREPARED:
□ Data located and compiled
□ Legal review completed
□ Response sent [Date: _____]
NOTES:
[Document any complications, exceptions, or follow-up required]
How to Customize It
Processing Record: Start with your three highest-volume data processing activities. Add detail where you're sharing data with third parties or processing sensitive categories.
Incident Response: Adjust severity thresholds based on your data types. If you process financial data or health information, consider lowering your threshold for ANPD notification.
Security Policy: The measures you document should match your actual technical capabilities. Don't promise encryption at rest if you're not implementing it. Better to document a realistic control with a roadmap for improvement.
Request Tracker: If you receive fewer than 10 data subject requests per year, a spreadsheet works. Above that volume, consider a ticketing system that auto-calculates your extended deadlines.
Validation Steps
Classification check: Confirm annually that you still qualify as a small-sized processing agent. Revenue growth or processing expansion may change your status.
Processing record audit: Review your simplified processing record quarterly. Add new activities within 30 days of launch.
Security policy test: Run a tabletop exercise annually to verify your incident response procedure works with your extended timelines.
Timeline compliance: Audit a sample of data subject requests every six months. Verify you're meeting extended deadlines and documenting appropriately.
High-risk assessment: Review the ANPD's guidance on high-risk processing whenever you launch a new product or service. High-risk activities disqualify you from simplified treatment.
This template won't replace legal counsel, but it gives you a documented starting point that reflects the simplified obligations you're actually held to. Update it when your processing changes, and keep evidence that you're following what you've documented.





