skill-lgpd-brasil
When To Use
Use this skill when the task involves Brazilian privacy and data protection work, especially:
- Personal data or sensitive personal data processing.
- Privacy notices, cookie banners, consent flows, or preference centers.
- Data subject requests, incident handling, retention, deletion, or audit trails.
- RIPD, processing records, vendor or processor reviews, or international transfers.
- AI, analytics, CRM, support, WhatsApp, email, or admin flows that touch personal data.
Operating Model
- Identify the role model first: controller, operator, sub-operator, joint controller, and encarregado/DPO.
- Build a factual data map before drafting policy text or code.
- Assign a legal basis per purpose; do not default everything to consent.
- Record data categories, purpose, source, sharing, retention, deletion, and access path.
- For high-risk processing, prepare or update a RIPD.
- For incidents, preserve evidence, isolate scope, assess impact, and document notification decisions.
- Verify that the final policy or implementation matches the real system behavior.
Core Artifacts
Recommended LGPD workspace artifacts:
.lgpd/data-map.md.lgpd/processing-record.md.lgpd/legal-basis.md.lgpd/consent-ledger.md.lgpd/privacy-notice.md.lgpd/dsar-playbook.md.lgpd/ripd.md.lgpd/vendor-register.md.lgpd/retention-policy.md.lgpd/incident-response.md
Scope Checklist
- Personal data, sensitive personal data, and children's data.
- Controller, operator, sub-operator, joint controller, and encarregado/DPO.
- Purpose limitation, adequacy, necessity, transparency, security, prevention, non-discrimination, and accountability.
- Rights requests: access, correction, deletion, anonymization, portability, information about sharing, consent revocation, and review of automated decisions.
- International transfers, subprocessors, backups, logs, and retention.
- AI datasets, prompts, transcripts, recordings, embeddings, and training corpora.
Guardrails
- Do not claim legal compliance or certification.
- Do not recommend collecting personal data without a purpose and retention rule.
- Do not store raw personal data in docs, logs, or examples when a redacted identifier is enough.
- Treat consent as revocable and distinct from other legal bases.
- Keep policies aligned with actual product behavior and vendor contracts.
- Escalate to legal counsel for formal notices, contractual language, or regulator-facing decisions.
Validation
- Confirm each processing purpose has a legal basis and retention rule.
- Confirm the privacy notice matches collected fields and third-party sharing.
- Confirm DSAR and consent-revocation flows are testable.
- Confirm incident and transfer controls are documented.
- Confirm telemetry and forms do not leak unnecessary personal data.
Related Skills
gdpr-data-handlinglegal-advisorsecurity-compliance-compliance-checkskill-supabase-rlsskill-saas-security-scanskill-security-hooksskill-unified-analyticsskill-ai-orchestrationskill-google-workspace-syncskill-evolution-api