Why Legal LGPD Compliance Isn't Enough for SaaS and Apps
A privacy policy and a legal opinion won't protect your SaaS, app or platform. Why Brazil's LGPD requires technical measures, and what changes in 2026.
Security researcher and founder of No Vuln

You paid a good lawyer. Your privacy policy is written. Your terms of service are up to date. The cookie banner is live. Your general counsel signed an LGPD compliance opinion. You think you're compliant.
You're compliant with half of the LGPD.
This article explains in detail why legal compliance with the LGPD (Brazil's General Data Protection Law) isn't enough for a SaaS, an app, a digital platform or any business that processes personal data through software — and what's missing. If you're a founder, CEO, CTO or digital business leader operating in Brazil or serving Brazilian users, read to the end.
The LGPD has two axes. Nobody told you that.
Most Brazilian companies treat the LGPD as a legal problem. That makes sense — that's how the market sold “LGPD compliance.” Law firms, outsourced DPOs, governance consultancies. They all sell the same package: policy, contracts, training, legal opinion.
But the law has two axes:
- Legal/administrative axis — Art. 6 (principles), Arts. 7 and 11 (legal bases), Art. 8 (consent), Art. 9 (information to data subjects), Art. 18 (data subject rights). It covers what you tell users and how you organize yourself internally. Policy, contracts, record of processing, DPO. A lawyer handles it.
- Technical axis — Art. 46 (security measures), Art. 47 (the security duty of everyone involved in processing), Art. 48 (incident notification), Art. 49 (systems built to meet security standards). It covers what the system does, not what you say it does. A security engineer handles it.
If you only tackled the legal axis, you're half compliant. Here's what's missing.
What Article 46 actually requires
“Processing agents shall adopt security, technical and administrative measures capable of protecting personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication or any form of inappropriate or unlawful processing.” (unofficial translation)
The key phrase is “technical and administrative.” It's not one thing. It's two dimensions. A privacy policy is administrative. A pentest is technical. The law requires both.
When the ANPD (Brazil's National Data Protection Authority) investigates a breach, it will ask for evidence of both dimensions. When an enterprise customer runs due diligence, it will ask for both. When you file a cyber insurance claim, the insurer will ask for both.
Without technical evidence, you have half.
Why a privacy policy doesn't protect your SaaS
Let's get concrete. Your privacy policy says:
“We implement appropriate security measures to protect your personal data against unauthorized access, alteration, disclosure or destruction.”
Question: how do you know you implemented them?
If I ask for evidence:
- A pentest report from the last 12 months
- A documented incident response plan
- An inventory of who has access to the production database
- Audit logs of who accessed customer personal data in the last 90 days
- A credential and secret rotation policy
- A subprocessor inventory (third parties that receive personal data from you)
- A retention and disposal map by data category
...can you show it?
If you can't, the statement in your privacy policy is literally false for lack of evidence. In an inspection, that's an aggravating factor. It's not “non-compliance out of ignorance.” It's “an unsupported claim.”
A real case: Telekall (R$ 14,400) and enforcement that's ramping up
In July 2023, the ANPD issued its first fine against a private company: two fines of R$ 7,200 each (R$ 14,400 total) against Telekall Infoservice, a micro-business that sold WhatsApp contact lists for a political campaign without a legal basis (source: ANPD). A small amount, but the signal was clear: the ANPD is willing to fine private companies, not just recommend fixes. In 2024, the ANPD issued no fines against private companies — only sanctions against public agencies — but that December it opened inspections against 20 large companies for lacking a Data Protection Officer (DPO) and a channel for data subjects (all of them came into compliance by April 2025). As of January 2026, Telekall remained the only private company ever fined — but it's the enforcement, not the fine amount, that's growing.
Companies still operating on the assumption that “the ANPD doesn't enforce” are working off old information. The reality in 2026 is different.
For SaaS, apps and digital platforms, the risk is higher because:
- Personal data sits in an internet-facing system — that's attack surface
- Processing volume is higher (multi-tenant, built to scale)
- Release velocity is high — bugs reach production fast
- Reliance on third parties (subprocessors, external APIs) spreads the risk
The cost of legal-only compliance (the real math)
In Brazil, companies typically pay:
- Full legal compliance — R$ 15,000 to R$ 60,000 (depending on the law firm and company size)
- Outsourced DPO — R$ 1,500 to R$ 8,000/month
- Training and governance — R$ 5,000 to R$ 20,000
Year-one total: R$ 38,000 to R$ 176,000.
How much of that protects against a technical breach (BOLA, OAuth ATO, SSRF, race conditions, SQL injection)? None of it.
A one-off SaaS pentest in the Brazilian market: R$ 8,000 to R$ 18,000. Ongoing pentesting: varies — monthly or quarterly hour bank, depending on scope. A comparable cost — for complementary, non-overlapping protection.
A company that only does the legal work is paying half the cost, getting half the protection, and staying exposed to the real risk of a technical breach, where the legal work can't help you — because when the breach comes out, the judge asks whether you had adequate technical controls, and you don't.
What's missing on the technical axis (checklist)
To complement legal compliance and satisfy LGPD Arts. 46, 47 and 48, you need technical evidence in 7 areas:
1. Documented pentest
A security assessment in a defined window, by a qualified researcher (not a scanner), with a formatted report covering methodology, findings, severity and a remediation plan. Minimum: once a year.
2. Tested access control
Who has access to what? Is MFA mandatory? Is least privilege applied and validated? Are onboarding and offboarding documented? Are credentials and secrets rotated?
3. Audit logs
Who accessed customer personal data, when, for what reason, with what authentication? How long are the logs retained? How are they protected against tampering?
4. Incident response plan
Documented. Tested. With clear triggers (volume, severity, data category). With a timeline for notifying the ANPD (Art. 48) and data subjects (Art. 48, §1).
5. Subprocessor management
An inventory of third parties that receive personal data from you (cloud, analytics, monitoring, communications, billing). Each one with a signed DPA and periodic review.
6. Encryption
In transit (TLS 1.2+, ideally 1.3). At rest (KMS, envelope encryption). For sensitive data (Art. 11 — health, biometrics) and children's data (Art. 14), an extra layer. Data masking in logs and non-production environments.
7. Team training
Not generic legal training. A technical security mindset: phishing, credential management, secure code, OWASP, least-privilege principles. Your engineering team needs to understand it, not just your legal team.
How to pitch this to your legal team or board
If you're a CTO, founder or technical CEO trying to convince your legal leadership or board that you need a pentest on top of legal compliance, here's a line that works:
“Legal compliance protects us against proceedings over missing documentation. Technical compliance protects us against an actual breach. The ANPD looks at both in an inspection. If we only have one, we're covered against half the risk — and the half we're missing is the one that costs the most when things go wrong.”
Another way to put it:
“A privacy policy is like the sign at a parking garage entrance that says ‘not responsible for theft.’ It doesn't stop theft. It only stops lawsuits. When real data leaks, the sign won't save you — cameras, alarms and locks will. The LGPD works the same way.”
What to do today
- Audit your current compliance. List what you've done on the legal axis and what you've done on the technical axis. If the second list is empty, you know where to focus.
- Request a pentest. Even a simple black-box test (R$ 3,000 to R$ 6,000 in the Brazilian market) gives you a baseline and a report formatted for LGPD Art. 46. See LGPD penetration testing.
- Implement the 7 areas in sequence (pentest → access control → logs → incident plan → subprocessors → encryption → training). A 90-day plan is doable.
- Document it. Without evidence, any control you've implemented is invisible to the ANPD or an enterprise customer. Build the paper trail.
Conclusion
The LGPD wasn't written for lawyers. It was written for companies that process personal data — and modern processing is technical. If your compliance stopped at the legal opinion, you've covered only the half that protects you against documentation proceedings, leaving uncovered the half that protects you against an actual breach.
In 2026, with the ANPD increasingly active and enterprise customers increasingly strict in due diligence, the technical half is no longer optional. Paying two legal consultants doesn't replace one security researcher pentesting your system.
Start with our LGPD penetration testing page for an LGPD-formatted scope, or with SaaS security for a general SaaS security roadmap. To understand what a pentest covers technically, see LGPD Article 46 — 7 technical measures.
Next step
Want to apply this to your system?
No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.