CORUZEN
Back to blog

LGPD checklist for small and medium businesses

By CORUZEN Team · Aug 10, 2026 · 3 min read

LGPD checklist for small and medium businesses

Many small and medium businesses treat LGPD (Brazil's data protection law) as a big-company issue — "that's for companies with a legal department." In practice, the law applies regardless of company size, but Brazil's data protection authority (ANPD) created a simplified regime precisely to recognize that a small business doesn't have the same structure as a multinational. This checklist is the realistic starting point.

First: map what the company actually collects

Before any document or policy, you need to know, in fact, what personal data the company handles: customer data (name, email, phone, tax ID), employee data, vendor data, data collected through website forms. Without that mapping, any privacy policy written afterward becomes fiction — describing practices the company doesn't actually follow.

The practical checklist

1. Identify the legal basis for each processing activity. For each type of data collected, which of LGPD's article 7 hypotheses justifies it — consent, contract performance, legal obligation, legitimate interest?

2. Publish a genuine privacy policy. Not a generic template downloaded from the internet — a document that reflects what the company actually does with the data it collects.

3. Establish a contact channel for data subjects. A dedicated email or a responsible person, able to receive and respond to requests for access, correction, or deletion of data.

4. Assess whether you need to formally appoint a data protection officer (DPO). Under ANPD Resolution CD/ANPD No. 2/2022, small businesses with low-risk processing can waive that formal appointment, as long as they keep the contact channel from the previous item genuinely working.

5. Review contracts with vendors who also process data on the company's behalf. Email provider, payroll system, CRM tool — everyone who receives personal data from the company should have data protection clauses in their contract.

6. Train whoever has access to personal data day-to-day. Most data incidents don't come from external attack — they come from operational error: sending a customer spreadsheet to the wrong recipient, leaving access open beyond what's necessary.

7. Have a minimal plan for incidents. It doesn't need to be a 40-page document — there needs to be a clear answer to "what do we do if data leaks," including the deadline and form for notifying affected data subjects and the ANPD when applicable.

What the simplified regime actually waives

It's worth being specific: the ANPD's simplified regime for small businesses doesn't waive LGPD itself — it waives specific formalities, like the mandatory appointment of a DPO, as long as the company maintains an effective communication channel with data subjects. It's not a blanket exemption, it's a targeted flexibility.

The most common mistakes

  • Copying a privacy policy from another company without adapting it. That's already a non-compliance by itself — the policy ends up describing practices that don't match reality.
  • Treating LGPD as a one-time project, done once and forgotten. Compliance is routine, not an event — it needs to keep up with a new vendor, a new form on the site, a new internal tool.
  • Focusing only on the institutional website and forgetting internal processes. An HR spreadsheet, a sales system, WhatsApp with a customer — all of that handles personal data, and all of it needs the same attention the website gets.

Where to go from here

If the company's institutional website already has a contact form or any data collection, it's worth specifically reviewing what LGPD requires in that context — it's usually the most visible (and most auditable by third parties) point of contact between the company and the public.

Want to see this in practice?

Check out CORUZEN SECURITY and see how it solves this in your company's day to day.

Explore CORUZEN SECURITY