Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Privacy and data protection

ISO 27701 vs LGPD

LGPD is Brazilian law: you comply because you must, and there is no such thing as an LGPD certificate. ISO 27701 is the international standard for privacy management, and that one does earn a certificate issued by an external auditor. It does not replace the law, but it is the most recognised way to prove to customers, partners and the regulator that your company handles personal data in an organised way.

Explore DPO BackofficeGo to the comparison

In short

  • LGPD is mandatory for anyone processing personal data in Brazil and is enforced by the ANPD. There is no certificate for it.
  • ISO 27701 is voluntary, certifiable and internationally recognised. It is the proof the law does not issue.
  • Since the 2025 revision, ISO 27701 is a standalone standard and no longer requires ISO 27001 as a prerequisite.
  • Holding the certificate does not shield you from fines, but it shows diligence and organises exactly what the regulator wants to see.

Side by side

The legal obligation and the voluntary proof

What to compareLGPDISO/IEC 27701
What it isBrazil's personal data protection law, Law 13.709/2018.International standard for privacy management, with a certificate.
MandatoryMandatory for anyone processing personal data in Brazil.Voluntary. You adopt it to prove organisation and earn trust.
Earns a certificateNo. Nobody issues an LGPD certificate.Yes, issued by an accredited certification body.
Who enforces itThe ANPD, Brazil's national data protection authority.The certification body, through periodic audits.
What it requiresLegal basis, data subject rights, security, breach notice and accountability.A full privacy management system, with roles, risks and controls.
Depends on another standardNot applicable.No. Since the 2025 revision it can be implemented on its own.
Geographic reachBrazil, including processing done abroad with Brazilian data.International, and supports the laws of many countries.
SanctionUp to 2% of Brazilian revenue, capped at 50 million reais per infraction.Loss of the certificate, with no fine.

ISO 27701 is law neutral: it organises privacy management and you map it to LGPD, GDPR or whichever legislation applies to you.

The obligation already in force

LGPD

In force since 2020, it reaches any company processing personal data in Brazil, from the customer database to the employee time clock. It requires a legal basis for each processing activity, responses to data subject requests, security measures, breach notification and a designated privacy officer. The ANPD enforces, guides and applies sanctions ranging from a warning to a fine of up to 2% of Brazilian revenue, capped at 50 million reais per infraction.

  • Mandatory for anyone processing personal data in Brazil
  • Requires legal basis, data subject rights and a privacy officer
  • Enforced by the ANPD, with defined sanctions
  • Issues no certificate of any kind
The proof the law does not issue

ISO/IEC 27701

It is the international standard that organises privacy management: it defines controller and processor roles, maps processing, assesses risk to data subjects and requires control and continuous improvement. Until 2019 it was an extension of ISO 27001. The revision published in October 2025 turned it into a standalone standard, so a company can now certify privacy without certifying information security first. That cut the cost of entry considerably.

  • Certifiable by an accredited body
  • Independent of ISO 27001 since the 2025 revision
  • Organises privacy roles, risks and controls
  • Recognised internationally, which helps when selling abroad

How they fit together

The standard does not replace the law; it proves the law

LGPD says what you have to guarantee, and does not say how. ISO 27701 delivers exactly that how: the management structure, the records, the risk assessment for data subjects, the process for handling requests and the evidence that all of it genuinely runs. When the regulator or a customer asks how you are organised, that structure is the answer, already written. The certificate does not remove anyone's liability, but it demonstrates diligence, and diligence counts when a sanction is being weighed.

  • The law defines the obligation; the standard organises execution and proof
  • The certificate demonstrates diligence without removing liability
  • One structure serves LGPD, GDPR and other privacy laws

Which case is yours

Where to start

You do not yet know where the personal data lives

Start with mapping and LGPD readiness

Without knowing what you process and under which legal basis, no standard will save you. It is step one on any route.

A customer or partner is asking for proof of privacy

Go for ISO 27701

It is the only privacy certificate that exists and it clears much of the vendor questionnaire in one move.

You sell outside Brazil

ISO 27701 mapped to GDPR

The same structure serves LGPD and European law, without running two parallel programmes.

Numbers that matter

2%

of Brazilian revenue, the LGPD fine ceiling

R$ 50 m

cap per infraction applied by the ANPD

2025

the year ISO 27701 became a standalone standard

How DM11 solves it

LGPD readiness and the ISO 27701 certificate in one piece of work

We map the processing, deliver LGPD readiness and organise that same material in the format ISO 27701 requires. The privacy officer can be ours, through DPO Backoffice, or yours, with our structure behind it.

  • One project delivers both legal compliance and the certificate
  • You get a privacy officer who genuinely acts, not a name in the website footer
  • Data subject requests and breach notices run to a ready process, inside the deadline
  • The same structure serves GDPR when you start selling abroad
Explore DPO Backoffice

Common questions

What people ask before deciding

Answers checked against Law 13.709/2018 and ISO/IEC 27701:2025.

There is not. LGPD is a law, and laws are not certified: they are complied with. Any company selling an LGPD certificate is selling a document with no official standing. What does exist and is recognised is certification to ISO 27701, the international privacy management standard, issued by an accredited certification body.

More questions? Talk to DM11

Prove privacy with the only certificate the market recognises

A short conversation shows where your company stands on LGPD and how far it is from ISO 27701.

Talk to a specialistExplore DPO Backoffice