Brazil LGPD Articles 41 + 46-50 Governance and Accountability. Article 41 Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais - Brazilian-specific term for DPO) - mandatory designation by all controllers (default + exceptions per ANPD Resolution CD/ANPD No. 2 of 27 January 2022 - microenterprises + small enterprises + startups + entities not in high-volume processing may exempt with documented procedures). Encarregado must be made known + accept complaints + provide explanations to data subjects + receive ANPD communications + train + advise controller + ANPD notification. Article 50 Good Practices and Governance (Boas Praticas e Governanca) - controllers and processors can formulate Rules of Governance Practices including: privacy policies + sectoral codes of conduct + privacy seals + technical and administrative security measures + business continuity + impact assessments + audits + ROPA + Privacy by Design + Privacy by Default. Article 38 + 32 Data Protection Impact Assessment (RIPD - Relatorio de Impacto a Protecao de Dados Pessoais) - mandatory for high-risk processing + ANPD may require + content includes processing description + risk analysis + mitigation measures. Article 37 Records of Processing Activities (ROPA - Registro de Operacoes de Tratamento) - controllers and processors must maintain. Articles 42-45 Civil Liability Joint and Several for processors and controllers + reverse burden of proof + consumer protection alignment + CDC Codigo de Defesa do Consumidor Law 8.078/1990 cross-references for collective actions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.