
Risk and Governance · 12 min
AI Governance and Brazil’s LGPD: What to Evaluate Before Contracting a Solution
No tool alone guarantees compliance with Brazil’s LGPD. A guide to evaluating roles, data, risk, integration, monitoring and accountability.
Published on August 12, 2026
CENTRAL THESIS
The promise of compliance by tool versus the responsibility that remains with the organization
Governance as a system of decisions, roles, evidence and limits
This content is informative and does not replace specialized legal advice. The application of LGPD depends on context and must be evaluated by qualified professionals.
This article concerns Brazil’s General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, LGPD), Law No. 13,709/2018. It addresses the Brazilian legal framework; requirements in other jurisdictions may differ. Read the Brazilian law.
Quick answer
An artificial intelligence governance solution does not "guarantee LGPD" by itself. It can support inventory, documentation, controls, monitoring and accountability. Compliance also depends on the purpose of use, the data processed, responsibilities among parties, security measures and organizational decisions. Before contracting, evaluate the governance system, not just the feature list.
The right question does not start with the supplier
Those seeking an AI governance solution often ask directly: which platform or consultancy meets the requirements of Brazil’s General Data Protection Law?
The question is legitimate. The premise needs adjustment.
LGPD applies to the processing of personal data. An AI initiative may involve data from customers, employees, candidates, patients, citizens or partners at different stages. The risk is not only in the model. It also appears in collection, integration between systems, access permissions, secondary use, retention, result review and disposal.
Therefore, a tool may organize controls and still be used in a poorly defined process. A consultancy may propose good practices and still depend on decisions belonging to the data controller. A certificate may demonstrate the existence of a management system but does not automatically make every specific use compliant.
Governance starts before purchase.
What a solution can do, and what remains the company’s responsibility
A platform can maintain inventories, record approvals, track metrics, produce audit trails and gather evidence. A consultancy can help design roles, policies, risk criteria, decision forums and an implementation roadmap. Legal advisory can interpret obligations and evaluate contracts, legal bases and data subject rights.
These contributions complement each other. They are not interchangeable.
- Inventory of AI uses: the solution can record systems, responsible parties, data and purpose. The organization still needs to define what will be inventoried and who is responsible for each use.
- Risk assessment: a method can map impact, probability, reversibility and controls. The organization determines risk tolerance and authorizes, limits or stops use.
- Data protection: technology can offer security, documentation and access management. Purpose, necessity, responsibilities and response to data subjects remain organizational decisions.
- Monitoring: metrics, alerts and logs help track operation. The company decides which deviations matter and who can act on them.
- Compliance: evidence, policies and controls provide support. Responsibility for applicable obligations is not transferred to a dashboard.
Seven criteria before contracting
1. Is the intended use described precisely?
"Using AI in customer service" is too broad. Does the system only suggest responses or speak directly with customers? Does it consult purchase history? Does it record sensitive data? Can it perform actions? A serious assessment must start with purpose, users, affected people and decisions the system supports or makes.
If the supplier starts by demonstrating the tool and cannot help delimit the use, the conversation has not yet reached governance.
2. Is the data flow visible?
The company needs to understand which data enters the system, where it comes from, where it goes, how long it remains and who can access it. This includes integrations with ERP, CRM, HR platforms, cloud services and model providers.
Integration is not only a technical issue. It changes the surface of responsibility.
3. Are roles between parties clear?
Contracts and processes must reflect who decides on processing, who operates on behalf of whom, which third parties participate in the chain and how requests, incidents and changes will be handled. Brazil’s data protection regulator, ANPD, maintains specific guidance on data agents and the data protection officer, and foresees proportional rules for small agents. Proportionality, however, does not mean absence of responsibility.
This analysis requires legal and privacy participation. A commercial webpage does not replace this review.
4. Is control proportional to impact?
Not every AI use requires the same procedure. A feature that organizes internal notes should not receive the same treatment as a system influencing credit, employment, health or access to services.
Good governance differentiates uses by impact, probability of harm, scale, data sensitivity, system autonomy and decision reversibility. The NIST AI Risk Management Framework organizes this discipline into Govern, Map, Measure and Manage functions. The framework itself is voluntary and adaptable. It should not be used as a universal checklist.
5. Is there supervision during operation?
Testing before deployment is necessary but insufficient. Data changes. Models are updated. People find unforeseen uses. Integrations expand system reach.
The contract and operational design should answer:
- which metrics will be monitored;
- which events trigger alerts;
- who reviews results and incidents;
- how often use is reassessed;
- when the system should be limited, suspended or retired.
Monitoring without authority to act becomes late observation.
6. Can the organization produce evidence?
Generic policies have little value when no one can demonstrate how a decision was made. Look for the ability to record responsible parties, criteria, assessments, approvals, versions, tests, exceptions and corrective measures.
ISO/IEC 42001 addresses establishing, implementing, maintaining and continuously improving an AI management system. This logic helps turn intentions into verifiable processes. Adopting the reference or seeking certification does not eliminate the need to analyze legal obligations and risk of each application.
7. Is there an exit plan?
Governance also includes stopping. The company needs to know how to export records, revoke access, delete or return data, replace a supplier and deactivate a system without creating new risks.
A solution difficult to abandon can turn a technological decision into organizational dependency.
LGPD and AI regulation are not the same
LGPD already establishes obligations for personal data processing. Brazil is also discussing specific legislation for artificial intelligence. As of August 2026, Bill 2,338/2023 remains under consideration in the Chamber of Deputies. Therefore, its content should not be presented as current law.
ANPD, in turn, has been addressing the relationship between AI, algorithmic transparency and data protection, including through its regulatory sandbox. This movement reinforces a practical conclusion: waiting for full regulation consolidation to organize responsibilities is a risky choice. It would also be imprudent to treat proposals under debate as already defined obligations.
The responsible path is to work with what already applies, monitor what is changing and keep decisions documented.
How to compare supplier proposals
At the contracting meeting, ask for concrete answers to these questions:
- What governance problem does the proposal solve?
- Does the scope include technology, consultancy, legal, audit or an explicit combination?
- Which deliverables remain under company control?
- How are systems, data, responsible parties and third parties mapped?
- How does the method differentiate low and high impact uses?
- What controls exist before, during and after deployment?
- How are model, data or integration changes evaluated?
- What evidence can be presented to leadership, audit, data subjects and authorities?
- What does the proposal not cover?
- How does knowledge transfer to the internal team work?
The last item deserves attention. Outsourced governance without internal capacity tends to produce dependency, not maturity.
Where dooop fits in
dooop works on designing organizational capacity that connects strategy, leadership, business, people, technology, risk and governance. The starting point is not to sell a platform or issue legal opinion. It is to help the organization make explicit the context, use cases, decision criteria, roles, controls and evolution roadmap.
This work can prepare a more rigorous technology selection, organize conversation between areas and reduce the gap between policy and operation. When the topic requires legal interpretation, independent audit, specialized security or technical implementation, these responsibilities must be clearly assigned to appropriate professionals.
AI governance is not the promise to eliminate uncertainty. It is the ability to know who decides, based on what evidence and with what limits.
Next decision
Before requesting a commercial demonstration, choose a real use case and answer three questions: who can be affected, what data will be processed and who has authority to stop the system.
If these answers do not yet exist, the priority is not to compare dashboards. It is to build the context that will allow choosing the right solution.
Talk to dooop about governance criteria for your organization.
Official sources and references
- ANPD: Resolution CD/ANPD No. 2, January 27, 2022
- ANPD: Regulatory Sandbox for AI and Data Protection
- NIST: Artificial Intelligence Risk Management Framework
- ISO: ISO/IEC 42001:2023, Artificial intelligence management system
- Chamber of Deputies: Bill 2,338/2023 progress
NEXT DECISION
Talk to dooop about your organization’s governance context and criteria
Bring AI governance and LGPD criteria into your organization’s real context.
Content by Danniel Pozza. Registration allows linking this topic to the reader’s journey and tracking interest in the subject.
Sources
- ANPD
- NIST AI RMF
- ISO/IEC 42001
- Chamber of Deputies.
