LGPD implementation fails most often by ordering, not effort: months on a data map while the site runs consentless trackers and the DPO page returns 404, the two things the ANPD (or a prosecutor, or a Procon) can check before lunch. The roadmap below orders the work by external visibility first, investigation-readiness second, matching how Brazilian enforcement actually arrives.
| Phase | Deliverable |
|---|---|
| 1. Scope | Applicability memo; entity and flow list |
| 2. Visible edge | Portuguese notice, cookie/consent behavior, published DPO |
| 3. Inventory | Data map + lawful-basis register |
| 4. Rights | 15-day DSR pipeline with propagation |
| 5. Paper | Transfer instruments, operator contracts |
| 6. Incidents | 3-working-day ANPD breach runbook |
| 7. Assessments | RIPD set for high-risk flows |
Running the phases
Phase 2 before phase 3 is deliberate. The published encarregado, the Portuguese privacy notice naming real lawful bases, and tracker consent are what outsiders see; they are also what the ANPD’s first fine (Telekall, 2023) punished, no basis, no DPO.
Paper the borders early. If data leaves Brazil, Resolution 19/2024’s Brazilian SCCs had an August 2025 adaptation deadline for existing contracts; new vendor onboarding should demand them by default.
Make breach response Brazilian. Resolution 15/2024’s 3-working-day notification with prescribed content is tighter than most global runbooks assume; pre-draft the ANPD form. Foreign-headquartered companies should pair this with the US-company guide and the LGPD vs GDPR diff to avoid EU-reflex mistakes.
Phase 2’s external evidence, banner behavior, tracker timing, notice links, is exactly what a free scan checks: run one before the ANPD does the equivalent.