The laws

What do GDPR and LGPD ask of engineering?

GDPR Article 25 asks for data protection by design and by default, Article 32 for security appropriate to the risk, and Article 33 for notifying the authority of a breach within 72 hours where feasible. LGPD Article 46 asks for security measures from the design of the product through its execution, Article 48 for communicating security incidents, and Article 49 for systems structured to meet the security requirements.

GDPR makes the measures proportionate to the state of the art, the cost, the nature, scope, context and purposes of the processing, and the risk. Article 32(1) names examples, not a checklist: pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, timely restoration of access, and regular testing of the measures.

LGPD Article 46 §1 lets the national authority set minimum technical standards, considering the nature of the information, the characteristics of the processing and the state of the technology.

How they compare

Where do the two laws differ for engineering?

The engineering is largely the same work. The differences that matter are in the wording of design duties, in who must be told after a breach and when, and in the records each law expects.

Design and default

GDPR Article 25(1) and (2): appropriate measures when the means of processing are determined and during processing, and by default only the personal data necessary for each purpose, in the amount collected, the extent of processing, the storage period and who can access it. LGPD Article 46 §2: the security measures apply from the conception of the product or service through its execution.

Security of processing

GDPR Article 32(1): pseudonymisation and encryption, the ability to ensure confidentiality, integrity, availability and resilience, timely restoration after an incident, and regular testing. LGPD Articles 46 and 47: technical and administrative measures against unauthorized access and against accidental or unlawful destruction, loss, alteration or communication, which keep applying after the processing ends. Article 49: systems structured to meet the security requirements.

Breach notification

GDPR Article 33: the controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours; the processor tells the controller without undue delay; every breach is documented. LGPD Article 48: the controller communicates to the national authority and to the data subject an incident that may cause relevant risk or damage, within a reasonable period the authority defines, describing the data affected, the people involved, the technical measures used, the risks and the measures taken. When the severity is judged, technical measures that made the data unintelligible to unauthorized third parties are taken into account (§3).

Records and impact assessments

GDPR Article 30 requires records of processing activities and Article 35 a data protection impact assessment where the processing is likely to result in a high risk. LGPD Article 37 requires the controller and the operator to keep a record of their processing operations, and Article 38 lets the national authority require an impact report.

What we do not claim

What do we not claim?

We are not a law firm, a data protection officer or a supervisory authority. We give no legal opinion on whether GDPR or LGPD applies to you, and no certificate exists for us to hold.

  • Whether a law applies, your legal basis for processing, data subject requests, international transfers and the appointment of a DPO stay with your company and your counsel.
  • We hold no GDPR or LGPD certification, seal or code-of-conduct adherence. GDPR provides for approved certification mechanisms (Article 42), and we claim none.
  • We have no published GDPR or LGPD programme. The cases linked below show privacy-relevant engineering, such as a consent system, encryption and access control, in other work.
  • We guarantee no outcome of a regulatory inquiry, a data subject complaint or a customer's privacy review.

The measures

Which technical measures does the engineering team build?

Six areas of the two laws land on engineering: privacy by design and by default, security of processing, restore and resilience, testing the measures, detecting and notifying a breach, and the records. For each: what the laws ask, the engineering work, and where we have done it in a published case.

Privacy by design and by default

What it asks of engineeringDoes the product collect and keep only what each purpose needs, and are the safer settings the default?

The engineering: a data inventory per feature, retention that deletes on a schedule instead of keeping data forever, masking of fields that most people do not need to see, and defaults that expose nothing to an unbounded audience (GDPR Article 25(2)). The legal basis for each purpose is your counsel's call.

Where we have done it

Delivered by

No fixed package builds deletion and retention on its own. We scope it in Discovery or with engineers by the hour.

Security of processing

What it asks of engineeringIs personal data encrypted, access-controlled and kept off the open network?

GDPR Article 32(1)(a) names pseudonymisation and encryption, and LGPD Articles 46, 47 and 49 ask for technical measures against unauthorized access. The engineering: TLS in transit, managed keys and encryption at rest, private network paths to data stores, access through your SSO with MFA and least privilege, and secrets in a managed store.

Where we have done it

No fixed package covers encryption and access control on their own. We scope them in Discovery or with engineers by the hour.

Restore and resilience

What it asks of engineeringCan you restore access to personal data in a timely manner after an incident, and has anyone shown it?

GDPR Article 32(1)(b) and (c) ask for ongoing resilience of processing systems and the ability to restore availability and access in a timely manner. The engineering: encrypted, scheduled backups, restore drills and a rehearsed rollback.

Where we have done it

No fixed package covers backups and recovery on their own. We scope them in Discovery or with engineers by the hour.

Testing the measures

What it asks of engineeringIs there a process that regularly tests whether the technical measures work?

GDPR Article 32(1)(d) asks for a process for regularly testing, assessing and evaluating the effectiveness of the measures. The engineering: dependency, secret and container scans on every change with suppressions that expire, automated tests in the pipeline, and gates that stop a release.

Where we have done it

Delivered by

Detecting and notifying a breach

What it asks of engineeringHow fast would you know what was touched, and who tells whom?

GDPR Article 33(3) and LGPD Article 48 §1 list what a notice must describe: the data affected, the people involved, the likely consequences and the measures taken. That depends on records that survive an incident. The engineering: logs and alerts that show who touched what, designed so that personal data does not land in log lines, and a runbook that follows the content the notice needs.

Where we have done it

Delivered by

Records of processing

What it asks of engineeringCan you list what personal data you process, where it flows and why?

GDPR Article 30 and LGPD Article 37 expect a record of processing. The engineering: a data-flow map kept next to the code and generated from the infrastructure definitions, so the record matches what actually runs. The purposes, the legal basis and the impact assessment's judgment are yours.

Where we have done it

Delivered by

How we deliver

How do our packages and engineers deliver it?

Start with a fixed-price package, or hire engineers by the hour. The CI/CD & IaC package builds the pipeline and the infrastructure as code. SRE / Observability Foundations wires the monitoring. QA Automation Foundations puts tests in your CI. Discovery turns your records of processing, your customer's privacy questionnaire or your counsel's list into a roadmap with a backlog.

Pipeline and infrastructure as code

A 2-week build or re-architecture of your CI/CD pipelines and your infrastructure as code. The gates that go into the pipeline, such as a vulnerability scan, are agreed in the SOW.

Delivered by

Logging and monitoring

Metrics, logs and traces wired, 3 SLOs defined, alerts tested until they fire, and a runbook.

Delivered by

Tests on every change

A Playwright suite for your 5 critical flows, running in your CI, with accessibility checks.

Delivered by

From the requirement list to a backlog

Discovery understands your product and its configuration end to end and delivers a roadmap with a backlog, roles, critical changes and needs. Bring your record of processing, your counsel's list or a customer's privacy questionnaire, and we turn it into engineering work.

Delivered by

Engineers by the hour

For the work that continues after a package: Senior USD 45–⁠50 an hour, Lead or Architect USD 55–⁠60, with a 6-month minimum, billed per hour worked. You interview the engineer who will do the work.

Sources

Which texts did we read?

Primary texts, read on 2026-10-09.

  • Regulation (EU) 2016/679 (GDPR) on EUR-Lex: Articles 25, 28, 30, 32, 33, 35 and 42.
  • Lei nº 13.709/2018 (LGPD) on planalto.gov.br: Articles 37, 38, 46, 47, 48 and 49.

Frequently asked questions

Is Clouditive GDPR or LGPD compliant?

Compliance belongs to the organization that decides why and how personal data is processed, and neither law offers us a certificate. We build the technical measures, a DPA is available, and we give no legal opinion on how a law applies to you.

Do you act as our data protection officer or give legal advice?

No. We are not a law firm or a DPO. Whether a law applies, your legal basis and your data subject procedures are for your counsel. We make the systems able to do what they decide.

What does privacy by design mean for an engineering team?

GDPR Article 25 asks for measures at the time you decide how to process and during processing, and for processing only the data necessary for each purpose by default, including how long it is kept and who can reach it. LGPD Article 46 §2 applies security from the conception of the product.

How fast do we have to notify a breach?

Under GDPR Article 33 the controller notifies the authority without undue delay and, where feasible, within 72 hours, and a processor tells the controller without undue delay. LGPD Article 48 sets a reasonable period that the ANPD defines, so check the authority's current regulation with your counsel.

Is a data processing agreement available?

Yes. A data processing agreement (DPA) is available, along with the MSA, SOW and NDA. Security and procurement describes how we contract.

How long does it take to get ready?

It depends on what you already have, and we give no guarantee about a regulatory outcome. A 2-week package builds one area, such as the CI/CD pipeline and infrastructure as code, and Discovery, 1 to 4 weeks, turns the rest into a roadmap.

How does this relate to SOC 2 and the other frameworks?

The engineering overlaps a lot: gated releases, access you can prove, tested alerts and drilled recovery serve several frameworks at once. The compliance engineering page shows which clause of each framework asks for which control.

How do your engineers get access to our systems?

Through your own accounts and identities, with your SSO, your MFA and least-privilege access, revoked when the engagement ends. Every engineer passes a background check before assignment.

Who does the work?

Mat Caniglia leads every project end to end, and the engineers are in LATAM and share your working day. We present candidates within 1 week, and you interview the engineer who will do the work.

Tell us your case.

We reply to every request within 1 business day. We sign an NDA before the call if you ask.