Skip to main content
Promotional banner for the pentest readiness checklist
Small-Entity LGPD Compliance TemplateLaws and Regulations
5 min readFor Data Governance Teams

Small-Entity LGPD Compliance Template

If your organization qualifies as a micro-company, small company, or startup under Brazil's Data Protection Law, you're working under a different compliance framework than larger enterprises. On Jan. 27, 2022, Brazil's Data Protection Agency adopted Resolution ANPD No. 2, which creates simplified obligations for "small-sized processing agents."

This isn't a free pass. It's a streamlined compliance path that reduces administrative burden while maintaining accountability. Below is a template you can adapt to document your simplified compliance program.

Purpose of This Template

This template helps small-sized processing agents under the LGPD demonstrate compliance with simplified obligations under Resolution ANPD No. 2. You'll use it to:

  • Document your simplified record of processing operations (Article 37 requirement)
  • Define your security incident response procedure
  • Establish a simplified information security policy
  • Track extended timelines for data subject requests and ANPD responses

The template assumes you've confirmed your organization meets the definition of a small-sized processing agent and you're not conducting high-risk processing operations that would disqualify you from simplified treatment.

Prerequisites

Before you customize this template, verify:

  1. Entity classification: You qualify as a micro-company, small company, startup, or qualifying legal entity under Brazilian law.
  2. Processing scope: You're not engaged in high-risk processing as defined by the ANPD (separate guidelines apply to high-risk activities).
  3. DPO status: You've documented your exemption from appointing a data protection officer under Resolution Article 11.
  4. Extended timelines: You've communicated internally that your organization has twice the standard response time for data subject requests, security incident notifications, and ANPD information requests.

The Template

Section 1: Simplified Processing Record

Purpose: Maintain a record of personal data processing operations under LGPD Article 37 in simplified form.

PROCESSING ACTIVITY: [Name of processing activity]

DATA CATEGORIES PROCESSED:
- [e.g., Customer email addresses]
- [e.g., Payment transaction records]
- [e.g., Service usage logs]

PURPOSE OF PROCESSING:
[Describe why you're processing this data]

LEGAL BASIS:
[Consent / Contract performance / Legitimate interest / Legal obligation]

RETENTION PERIOD:
[How long you keep this data]

THIRD-PARTY RECIPIENTS:
[List any processors or partners who receive this data]

SECURITY MEASURES:
[Brief description of how you protect this data]

LAST REVIEWED: [Date]

Repeat this block for each distinct processing activity.

Section 2: Simplified Security Incident Response

Trigger: Any security incident that creates risk or relevant damage to data subjects.

Response timeline: Twice the standard notification period, unless the incident poses potential compromise to physical or moral integrity of data subjects or national security.

INCIDENT DETECTION LOG

Date discovered: ___________
Data categories affected: ___________
Estimated number of individuals: ___________
Incident severity (Low / Medium / High): ___________

INTERNAL ASSESSMENT (complete within 48 hours)
□ Scope of breach documented
□ Root cause identified
□ Immediate containment measures applied
□ Risk to data subjects assessed

NOTIFICATION DECISION
□ ANPD notification required: Yes / No
□ Data subject notification required: Yes / No
□ Notification timeline: [Extended timeline applies unless exception noted]

REMEDIATION ACTIONS
1. [Action taken]
2. [Action taken]
3. [Action taken]

FOLLOW-UP REVIEW DATE: ___________

Section 3: Simplified Information Security Policy

Purpose: Establish essential and necessary requirements for processing personal data under Resolution Article 13.

INFORMATION SECURITY POLICY
[Organization name]
Effective date: [Date]

1. ACCESS CONTROL
Who can access personal data: [Define roles]
Authentication requirements: [Password policy, MFA if applicable]
Access review frequency: [Quarterly / Annually]

2. DATA PROTECTION MEASURES
Encryption: [In transit / At rest / Both / None with justification]
Backup procedures: [Frequency and storage location]
Deletion procedures: [How you securely delete data]

3. THIRD-PARTY MANAGEMENT
Processor vetting: [How you evaluate vendors]
Contractual requirements: [Standard data processing terms]
Monitoring: [How you verify processor compliance]

4. INCIDENT RESPONSE
Point of contact: [Name and role]
Escalation procedure: [Internal steps]
Documentation requirements: [Reference Section 2 template]

5. TRAINING
Frequency: [Annual / On-hire / As-needed]
Topics covered: [Data handling, security awareness, incident reporting]
Completion tracking: [How you document training]

Last reviewed: [Date]
Next review: [Date]

Section 4: Data Subject Request Tracker

Timeline: Twice the standard response period for LGPD data subject requests.

REQUEST ID: [Unique identifier]
DATE RECEIVED: ___________
EXTENDED RESPONSE DEADLINE: [Calculate: standard deadline × 2]

REQUEST TYPE:
□ Access to personal data
□ Correction of data
□ Deletion of data
□ Data portability
□ Information about processing
□ [Withdrawal of consent](/glossary/withdrawal-of-consent)
□ Other: ___________

IDENTITY VERIFICATION:
□ Completed [Date: _____]
Method used: ___________

RESPONSE PREPARED:
□ Data located and compiled
□ Legal review completed
□ Response sent [Date: _____]

NOTES:
[Document any complications, exceptions, or follow-up required]

How to Customize It

Processing Record: Start with your three highest-volume data processing activities. Add detail where you're sharing data with third parties or processing sensitive categories.

Incident Response: Adjust severity thresholds based on your data types. If you process financial data or health information, consider lowering your threshold for ANPD notification.

Security Policy: The measures you document should match your actual technical capabilities. Don't promise encryption at rest if you're not implementing it. Better to document a realistic control with a roadmap for improvement.

Request Tracker: If you receive fewer than 10 data subject requests per year, a spreadsheet works. Above that volume, consider a ticketing system that auto-calculates your extended deadlines.

Validation Steps

  1. Classification check: Confirm annually that you still qualify as a small-sized processing agent. Revenue growth or processing expansion may change your status.

  2. Processing record audit: Review your simplified processing record quarterly. Add new activities within 30 days of launch.

  3. Security policy test: Run a tabletop exercise annually to verify your incident response procedure works with your extended timelines.

  4. Timeline compliance: Audit a sample of data subject requests every six months. Verify you're meeting extended deadlines and documenting appropriately.

  5. High-risk assessment: Review the ANPD's guidance on high-risk processing whenever you launch a new product or service. High-risk activities disqualify you from simplified treatment.

This template won't replace legal counsel, but it gives you a documented starting point that reflects the simplified obligations you're actually held to. Update it when your processing changes, and keep evidence that you're following what you've documented.

Application Security Isn’t Optional Anymore.

You Might Also Like