LGPD Brazil Software Outsourcing: Executive Due-Diligence Guide

Last Updated: Aug 6, 202611 min readAlexander Lim
 LGPD Brazil Software Outsourcing: Executive Due-Diligence Guide

LGPD compliance in a software outsourcing engagement starts with the real data flows, not a generic clause saying one party is the controller and the other is the operator. Those flows can span customer and employee records, production logs, support and analytics data, credentials, test data, and repository metadata. The provider's legal role can differ across those activities.

The executive task is to map the processing, constrain access, and document instructions. It also requires control over subprocessors and international transfers, an incident clock that leaves the controller time to act, and testable deletion and handover at exit.

Key Findings

  • LGPD scope follows processing and territorial connections, not vendor nationality.

  • Controller and operator roles must be mapped purpose by purpose.

  • Certificates support diligence but do not replace engagement-specific evidence.

  • Incident notice is threshold-based and measured in business days.

  • Deletion and handover controls must cover systems, backups, and subprocessors.

When LGPD applies to outsourced software work

Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), enacted as Law 13,709, can apply based on processing and territorial rules, not simply because the vendor is Brazilian. Article 3 supplies three independent connections to Brazil: the processing takes place in Brazil; the activity offers goods or services to people in Brazil or processes the data of people located there; or the operation involves personal data collected in Brazil. For the collection test, the law looks at where the person was when the data was collected.

This is not a citizenship test. An overseas company can fall within scope when it processes data about people located in Brazil, while the provider's nationality alone doesn't settle the analysis. Apply the test to each operation, including support, telemetry, recruitment, and product analytics.

The Brazil outsourcing shortlist is a starting point for comparing software development companies. Privacy diligence begins after a provider identifies the legal entities, delivery locations, people, systems, and subprocessors that will handle data.

Common outsourced-development data flows include these examples:

  • production database access for incident or migration work;

  • application logs containing identifiers, IP addresses, or user actions;

  • copied production records in development, testing, or analytics environments;

  • customer support tickets and recordings;

  • employee, candidate, payroll, or access-control data;

  • source-control identities, code comments, secrets, and audit trails;

  • observability, error-tracking, CI/CD, cloud, and collaboration platforms; and

  • backups, exports, screenshots, local devices, and temporary debugging files.

Data minimization may remove several flows entirely. Synthetic test data, effectively anonymized data, redacted logs, production break-glass access, masked support views, and client-controlled credentials reduce dependence on contractual promises.

Scale diligence to the data exposure

Not every software vendor needs the same review. A team working only with synthetic test data presents a different exposure from engineers holding privileged production access. Classify the engagement before setting evidence, approval, and contract requirements.

Exposure profileTypical accessMinimum diligenceApproval posture
ContainedSynthetic or effectively anonymized test data; no production, customer-support, or identifiable log accessApproved tool list, production-access denial, test-data method, repository controls, and contractual prohibition on real personal dataDelivery and security owners confirm that the boundary is technically enforced
OperationalLimited personal data in tickets, logs, analytics, or time-bound production supportPurpose and field map, DPA schedule, role-based access, activity logs, subprocessor and transfer register, rights-request test, deletion test, and rapid incident SLAPrivacy, security, legal, and delivery owners accept the documented scope
ElevatedPersistent or privileged production access; sensitive, financial, authentication, child, older-person, or large-scale dataOperational controls plus architecture evidence, penetration-test scope and remediation, RIPD decision, incident exercise, forensic-log export, recovery testing, and executive risk acceptanceNamed executive owner approves residual risk and any exceptions before access begins

These profiles are a procurement framework, not statutory LGPD classifications. A contained label does not remove legal duties, and any change in data, access, purpose, location, or tooling can move the engagement into a deeper review.

Map data processing roles by purpose

The ANPD’s controller and operator guidance treats the roles as factual. The controller makes decisions about processing personal data; the operator carries out that processing on the controller’s behalf and under its instructions. Contract labels help document intent but do not override actual decisions.

A vendor may be an operator for product-hosting support while acting under its own purposes for workforce administration, security records, legal claims, or billing. A buyer can also be an operator for its own customer. A purpose-by-purpose row avoids forcing the entire relationship into one label.

Processing purposeData and subjectsDecision ownerProposed role splitEvidence needed
Product development and testingUsers, customers, client staffBuyer normally defines product purposeBuyer controller; provider operator, subject to factsInstructions, environments, access, test-data method
Production supportUsers and customer recordsBuyer defines service purpose and access conditionsOften buyer controller; provider operatorTicket, break-glass access, logging, approval
Provider workforce administrationProvider employees and contractorsProvider determines employment purposeProvider controller for that purposeEmployee notices, retention, systems, transfers
Security monitoringUsers, client staff, provider staffMay be shared or separately determinedPurpose-specific analysisLog fields, detection purpose, access, retention
Legal claims and complianceRelevant individualsEach party may have its own dutySeparate controller activity may ariseLegal basis, hold process, disclosure rules

If the vendor cannot explain its processing purposes and systems, it isn't ready to sign the DPA.

Role and legal basis answer different questions. The role analysis identifies who decides why and how an operation occurs. The legal-basis analysis explains why that operation is permitted. The controller's legal basis comes from the purpose-specific Article 7 or 11 analysis, regardless of the provider label or the presence of a DPA.

Articles 7 and 11 contain different legal bases for ordinary and sensitive personal data. Consent is one option, not the default answer for every outsourced data flow. The controller needs a purpose-specific analysis, and a provider acting under instructions needs enough information to recognize when a request falls outside the agreed scope.

OperationDecision to documentEvidence to request
Core product or support processingPurpose, data category, Article 7 or 11 basis, role, and instructionProcessing record, product notice, approved data fields, ticket or access route
Testing and analyticsWhether reuse is compatible with the original purpose and whether real records are necessarySynthetic-data method, masking rule, field allowlist, retention period
Security and observabilityExact detection purpose, collected fields, recipients, access, and retentionLog schema, alert workflow, access list, deletion setting
Provider HR, billing, and legal administrationProvider's separate purpose and controller obligationsWorkforce notice, legal-basis record, system and transfer list
AI training or product improvementWhether the new use creates a separate purpose, role, notice, or legal-basis issueApproved-use policy, model and account settings, data-class restriction, decision record

Article 6 turns those decisions into engineering constraints. Purpose and adequacy limit tools and reuse; necessity limits fields and copies; data quality requires accurate, clear, relevant, and current data; transparency keeps notices, subprocessors, and transfer disclosures accurate; security and prevention begin at design; accountability requires evidence that the controls work.

Set the data protection officer (DPO) and escalation path

The encarregado, often called the data protection officer (DPO), is a communication channel among the processing agent, data subjects, and the ANPD. Law 15,352/2026 amended the Article 5 definition so that it now refers to a person indicated by the controller and operator. Article 41 still directs the controller to appoint the encarregado, while Resolution 18/2024 predates that amendment. For each legal entity, document how the current provisions apply to its controller and operator activities and record the appointment or exemption basis. Do not rely on an operator-only label to end the analysis: a vendor may also act as a controller for workforce administration, billing, fraud prevention, or legal claims.

ANPD Resolution 18/2024 governs the function. The ANPD guidance contemplates a natural or legal person, and the appointment can be internal or contracted. A complete appointment record identifies the person, scope, backup arrangements, available resources, direct escalation route, and potential conflicts of interest. Outsourcing the function does not outsource the processing agent's accountability.

Article 41 requires the controller to publish the encarregado's identity and contact information clearly and objectively, preferably on its website; it does not specify a language. Where the service handles people in Brazil, test whether a Portuguese-speaking data subject can find the channel, submit a request, verify identity, receive updates, and understand the answer.

What to put in the data processing agreement

The data processing agreement works only when it reflects the architecture and statement of work. Generic General Data Protection Regulation (GDPR) wording with Brazil added to the definitions isn't enough.

Cover these terms in the schedule:

  1. parties, legal entities, roles, and contacts;

  2. documented processing purposes, applicable legal bases, and instructions;

  3. data subjects, data fields, special or sensitive data, systems, and locations;

  4. approved people, access conditions, authentication, logging, and periodic review;

  5. confidentiality and workforce training;

  6. security controls and evidence obligations;

  7. subprocessor approval, notice, flow-down terms, and objection process;

  8. international-transfer mechanism and change process;

  9. assistance with data-subject requests, risk assessment, regulator contact, and audits;

  10. incident detection, immediate escalation, investigation, evidence, and communication;

  11. retention, legal holds, return, deletion, backups, and certification; and

  12. exit assistance, portability, survival, liability, and conflict order with the main agreement.

Make the instructions operational. “Process data as needed to provide services” gives too little control. Reference the environments, repositories, ticket categories, access groups, and approved tools that turn the instruction into something auditable.

Data security controls for outsourced development

The provider’s actual scope sets the depth of data security diligence needed to protect personal data. A certificate supports the review but does not establish that the delivery team, cloud tenant, code repository, or subprocessor chain in this engagement sits inside the certified boundary.

For software delivery, examine these controls:

  • identity lifecycle, MFA, least privilege, privileged access, and access reviews;

  • client-controlled repositories and cloud accounts where practical;

  • secret storage, rotation, scanning, and prohibition on secrets in source code;

  • endpoint management, encryption, patching, malware defense, and device return;

  • secure development, dependency review, open-source approval, and code scanning;

  • separation of development, test, and production environments;

  • production-access approval, session logging, and break-glass review;

  • log design, monitoring, retention, alert ownership, and evidence export;

  • backup, recovery tests, business continuity, and ransomware preparation;

  • penetration-test scope, remediation evidence, and repeat testing; and

  • incident exercises involving the client, provider, and material subprocessors.

The software outsourcing security review produces scoped evidence and named remediation owners. A questionnaire response alone is weak evidence.

lgpd-brazil-software-outsourcing-certificate-vs-evidence.jpg

Put data privacy controls into the software delivery lifecycle

LGPD article 46 requires security measures from product or service design through execution, and article 49 requires systems to reflect security, good-practice, governance, and LGPD principles. A privacy review performed only before contract signature will miss changes introduced by new fields, integrations, AI tools, support workflows, or delivery locations.

Both controllers and operators must maintain records of their personal data processing activities under article 37. Those records work best as a change-control artifact rather than a static spreadsheet.

Delivery gatePrivacy questionEvidence that survives the meeting
DiscoveryWhich people, purposes, fields, systems, legal bases, roles, countries, and retention periods are involved?Processing inventory and data-flow map
DesignCan fields, copies, identifiers, or production access be removed? Does the risk justify a RIPD?Design decision, minimized schema, risk assessment
Build and testAre real records excluded or masked, and are repositories, secrets, endpoints, and access separated?Test-data record, access configuration, scan results
Release and changeDid a feature alter purpose, fields, subprocessors, countries, permissions, automated decisions, or notices?Approved privacy change record and updated schedules
OperationsCan the team find, correct, export, block, delete, and preserve data while investigating incidents?Rights-request test, deletion test, incident exercise, retained logs

A Relatório de Impacto à Proteção de Dados Pessoais (RIPD) is not automatically mandatory for every feature. Article 38 allows the ANPD to require one, and the statutory definition focuses on processing that may create risks to civil liberties and fundamental rights. Set documented buyer-side triggers for higher-risk changes, then record the processing, safeguards, residual risk, decision owner, and review date.

Subprocessors and software supply-chain access

A provider can expose client data through cloud, observability, support, collaboration, code, AI, payroll, and staffing tools even if the main application runs in the client’s environment.

A current subprocessor register states the legal name, service, purpose, data, location, transfer route, and access. The contract provides advance notice of material changes and a practical objection or remediation route. Flow-down obligations mirror the provider’s own duties to the client.

Generative-AI tools deserve separate attention. Define which source code, prompts, logs, customer data, and credentials may be submitted. The tool register then records the required enterprise controls, model-training restrictions, usage logging, approved account, retention setting, and allowed data class.

International transfers under Resolution 19/2024

LGPD does not impose a general rule that Brazilian personal data must stay in Brazil. International data transfers still require both an applicable Article 7 or 11 legal basis and a valid transfer mechanism; one does not replace the other.

ANPD Resolution 19/2024 regulates adequacy decisions, ANPD standard contractual clauses, equivalent clauses, specific clauses, and binding corporate rules. At the August 3, 2026 primary-source check, the European Union had an ANPD adequacy decision under Resolution 32/2026. The ANPD repository did not show approved equivalent clauses, specific clauses, or binding corporate rules.

“Use SCCs” is therefore incomplete advice. If the parties rely on the ANPD standard contractual clauses, Resolution 19 requires their full, unchanged adoption. Standard clauses issued elsewhere don't become equivalent Brazilian clauses unless the ANPD approves them. For a covered transfer to the European Union, the adequacy decision can supply the transfer mechanism, but the rest of the LGPD analysis still applies.

That status can change. Before publication and signature, recheck the ANPD transfer repository and identify the chosen mechanism in the agreement. The agreement records the exporting party, receiving entity, countries, systems, onward transfers, and mechanism; a general “we comply with international-transfer law” clause leaves those facts unresolved.

Sector rules may add separate hosting or localization constraints for a specific regulated activity. They warrant separate investigation when the article or project names finance, health, government, telecoms, or another regulated context. The transfer schedule should list the exporter, recipient, country, system, data category, mechanism, and effective date.

Data breaches and the three-business-day incident rule

Data breaches are not automatically reportable under LGPD; the threshold still applies. Current ANPD guidance gives a controller the standard period of three business days to notify the ANPD and affected data subjects when an incident may cause relevant risk or damage. Qualifying small processing agents receive double time under Article 14 of Resolution 2/2022, as amended by Resolution 15/2024, while sector-specific law may provide another deadline.

Resolution 15/2024 makes that threshold cumulative. The incident must be capable of significantly affecting data subjects' interests and fundamental rights and involve at least one of these categories: sensitive personal data; data concerning children, adolescents, or older people; financial data; authentication data; data protected by legal, judicial, or professional secrecy; or data processed on a large scale. Those criteria belong in the first incident triage, before a complete forensic report is available.

The threshold and responsible party matter. A generic “24 to 72 hour” summary misstates the LGPD rule, which is threshold-based and measured in business days. Set a much faster provider-to-client notice in the contract, because the controller needs time to collect facts, assess risk, preserve evidence, coordinate communications, and submit a notice if required.

The incident schedule should require the provider to supply these details as they become available:

  • discovery time, occurrence window, systems, locations, and reporting source;

  • affected data, subjects, volume, sensitivity, and protection state;

  • access, exfiltration, alteration, loss, encryption, or unavailability evidence;

  • containment, credential changes, recovery, and business impact;

  • affected subprocessors and their response;

  • logs, images, timelines, indicators, and preserved evidence;

  • risk assessment inputs and potential individual harm;

  • recommended client, regulator, or data-subject actions; and

  • root cause, corrective actions, owners, and dates.

The contract sets immediate escalation for a suspected material event, followed by staged updates as facts develop. Giving the provider the entire external deadline would leave the controller too little time to act.

Resolution 15/2024 also requires the controller to retain a record of security incidents involving personal data, including incidents not reported to the ANPD or data subjects, for at least five years from the record date unless a longer obligation applies. The contract should preserve the provider's evidence and require prompt delivery to the controller; a short vendor log-retention setting otherwise leaves the statutory record incomplete.

lgpd-brazil-software-outsourcing-incident-response-timeline.jpg

Data subjects, data subject rights, and regulator cooperation

Article 18 data subject rights include confirmation, access, and correction. In specified circumstances, they also include anonymization, blocking or deletion. Article 18 also addresses portability, information about sharing, and consent-related rights. Article 20 separately addresses review and information concerning certain solely automated decisions. The DPA assigns clear responsibility for intake, identity verification, system searches, export or correction, blocking or deletion, portability support, and communication. The operator answers a data subject or regulator on the client’s behalf only when law or documented instruction authorizes it.

The 15-day period doesn't apply to every request. Under article 19, confirmation or access is supplied immediately in simplified form, or through a clear and complete statement within 15 days. Other rights follow their applicable legal or regulatory terms. Build the vendor's internal SLA backward from the controller's deadline and leave time for identity checks, legal review, compilation, and communication.

Test whether the vendor can search tickets, logs, backups, development environments, collaboration systems, and subprocessors rather than only the production database. When data has been shared, correction, deletion, anonymization, or blocking may also need to be propagated to other processing agents, subject to the statutory exceptions. Keep the request, identity decision, searches, recipients, response, exceptions, and completion evidence in one case record.

Regulatory cooperation should cover records, evidence, personnel availability, translation, privileged review, communications approval, remediation, and cost. The contract must not prevent either party from fulfilling a legal duty.

Retention, deletion, and exit

Deletion clauses often fail because they ignore backups, local devices, logs, issue trackers, observability tools, and subprocessors. A system-level retention schedule closes that gap.

At exit, require these deliverables:

  • client data and metadata exports in usable formats;

  • repository, ticket, architecture, runbook, and decision-record handover;

  • access revocation for provider personnel and tools;

  • production, test, local, and temporary-copy deletion;

  • backup aging or deletion schedule where immediate deletion is impracticable;

  • subprocessor deletion confirmation;

  • legal-hold exceptions with purpose, access restriction, and destruction date; and

  • signed deletion certification tied to the listed systems.

Client control of repositories, cloud accounts, domains, keys, and CI/CD is preferable where practical, especially during a software vendor handover. The final certificate should enumerate every system and its deletion or backup-expiry date.

Liability, administrative sanctions, and business exposure

LGPD article 52 allows a simple fine of up to 2% of the prior-financial-year Brazilian revenue of the private legal entity, group, or conglomerate, excluding taxes, capped at R$50 million per infraction. Any summary of the fine must retain both the Brazilian-revenue scope and the R$50 million per-infraction cap.

Article 42 separately addresses compensation for material, moral, individual, or collective damage caused by unlawful processing. An operator can be jointly liable when it breaches data-protection obligations or fails to follow the controller's lawful instructions, subject to the statutory exclusions. A contract label, liability cap, or indemnity does not rewrite that statutory allocation or remove a data subject's rights.

The fine is only one administrative exposure. Article 52 also provides for warnings with corrective deadlines, daily fines, publication of a confirmed infringement, blocking or deletion of affected data and, subject to statutory conditions, suspension or prohibition of processing activities. Those remedies can affect service continuity and data availability more directly than the headline fine.

The software outsourcing contract allocates costs, control, and cooperation between the parties without transferring regulatory responsibility.

Contract issueDecision to make before signature
Indemnity and liability capIdentify investigation, notification, restoration, regulator, data-subject, subprocessor, and remediation costs; state any negotiated cap exclusions or separate caps
Cyber and privacy insuranceVerify the insured entity, territory, event definitions, limits, exclusions, retention, and whether regulatory investigation and incident-response costs are covered
Claims and communicationsAssign notice, counsel, evidence preservation, regulator contact, data-subject communication, settlement control, and approval rights
RemediationSet owners and deadlines for containment, corrective work, validation, repeat testing, and delivery of closure evidence
Shared fault and recoveryPreserve cooperation and contribution rights where several controllers, operators, or subprocessors participated in the event

Insurance may fund response costs. Compliance still depends on the underlying controls and conduct. Review the relevant policy wording and exclusions under appropriate confidentiality rather than relying only on a certificate of insurance.

Executive due-diligence questions

During software vendor selection, ask each finalist to answer with documents and demonstrations, not yes-or-no assurances.

Data and roles

A credible answer connects every data purpose to a system and owner.

  • What personal data will your team access, create, infer, copy, or transmit?

  • Which entity decides each purpose, and where do you act under our instructions?

  • Which activities do you perform for your own purposes?

A satisfactory response connects instructions to the controller's documented decisions and demonstrates that rights requests work across the delivery stack.

  • Which Article 7 or 11 basis has the controller recorded for each processing purpose?

  • Which changes trigger a new purpose, legal-basis, notice, or RIPD review?

  • Can you demonstrate a complete access, correction, blocking, and deletion request across systems and subprocessors?

  • Who is the encarregado for each controller entity, and how are requests escalated during absence or conflict?

People, systems, and subprocessors

The legal schedule mirrors the actual delivery stack.

  • Which legal entities, employees, contractors, countries, and tools are in scope?

  • What is the full subprocessor register?

  • Will any public or enterprise AI system receive source code, logs, or personal data?

Transfers and incidents

The provider must identify the mechanism and show that its incident clock leaves the client time to act.

  • Which transfer mechanism applies to each foreign recipient and onward transfer?

  • How quickly will you notify us of a suspected incident?

  • Can you export logs and investigation evidence without a special paid project?

Liability and recovery

The contract defines a workable response when prevention fails.

  • Which privacy, confidentiality, security, and transfer events sit outside the general liability cap or use a separate cap?

  • Which investigation, notification, restoration, claim, and remediation costs does the indemnity address?

  • Does the relevant insurance policy cover the contracting entity, territories, incident types, and response costs in this engagement?

  • Who controls regulator contact, data-subject communications, counsel, evidence, remediation, and settlement decisions?

Exit and proof

The buyer needs to know how data leaves before it enters.

  • Which systems contain our data at exit?

  • How are backups and legal holds handled?

  • What deletion and subprocessor evidence will we receive?

No general LGPD data-localization rule was identified. International transfers require a valid mechanism and documented parties, destinations, systems, and onward transfers. Separate sector rules may apply to a specific regulated activity.

No. The standard thresholded rule gives the controller three business days to notify the ANPD and affected data subjects when the incident may cause relevant risk or damage. Qualifying small processing agents receive double time under Resolution 2/2022, and sector-specific law may set another deadline. Contract the provider to notify the controller much sooner.

Roles follow factual decisions and purposes. A vendor may act as an operator for client-directed product work and as a controller for its own workforce, legal, billing, or security purposes.

A simple fine can reach 2% of prior-year Brazilian revenue of the private legal entity, group, or conglomerate, excluding taxes, capped at R$50 million per infraction. Keep every qualifier.

Compliance depends on more than the signature. The DPA must match actual access, systems, subprocessors, transfer routes, controls, incident handling, retention, and exit. Architecture and operating controls do much of the real risk reduction.

Article 19 gives controllers two response formats for confirmation and access: a simplified response immediately, or a clear and complete statement within 15 days. Other rights have their own applicable rules. Contract the provider to respond early enough for the controller to verify identity, review the result, and meet the correct obligation.

Takeaway

LGPD diligence starts where the boilerplate ends. Match the contract to the real data flow, verify the delivery chain, and demand evidence at every control point—from access to incident response and exit.

Global Software Companies

Global Software Companies maintains sole editorial control over this content. Rankings and analysis are based on our proprietary methodology and are not influenced by company listings, partnerships, or advertising relationships. See our Editorial Policy for more information.

About this article

Alexander Lim

Alexander Lim

Alexander Lim, Founder and CEO of Cudy Technologies, is a serial entrepreneur with extensive experience in the tech industry. He has founded numerous startups and possesses a deep understanding of the software development life cycle process.

How we reviewed this content

This page is reviewed using a consistent editorial process that evaluates company data, service offerings, client feedback, and publicly available information. Content is updated regularly to reflect changes in company profiles, reviews, and market relevance.

Update history

August 4, 2026 — Converted to current article markup
Planned — Initial publication

Read Next

What is Outsourcing Software Development? A Complete Strategic Guide
What is Outsourcing Software Development? A Complete Strategic Guide

The software market is constantly changing with new technologies and innovations. Software infrastructures rely on building tools to create new products, leading to increased options and difficulty for companies with limited resources. Outsourcing can help businesses stay competitive but requires careful consideration of platform, vendor, and quality standards.

Victor JamesJul 28, 2026