Firms To Watch: TMT: Cybersecurity and data privacy

Marcio Chaves leads the data privacy practice at Almeida Advogados since his return to the firm in 2020; he has particularly strong experience in the implementation of compliance projects.
Thamilla Talarico  and Thamilla Talarico  lead specialised IP firm Daniel Law ‘s data privacy and cybersecurity practice, which offers a technology and IP perspective on data protection, AI and privacy matters.
Boutique law firm Prado Vidigal Advogados is specialised in digital law, privacy and data protection, and despite its relative youth has already established itself as a strong player in the technology field.

TMT: Cybersecurity and data privacy in Brazil

Mattos Filho

Mattos Filho has established a strong reputation in data protection and cybersecurity in Brazil, offering clients a ‘holistic view‘, with ‘excellent service and quality’. The team covers the gamut of privacy and security matters across a number of industries, including healthcare, insurance, technology, financial services, retail, education and telecoms. While the Brazilian Data Protection Law (LGPD) is key for a lot of clients, the team also advises on regional compliance strategies, undertakes risk assessments, assesses cloud computing issues, and provides counselling on major data incidents and litigation. Within the team, Fabio Ferreira Kujawski is well known for his expertise in the technology space in Brazil, particularly in his transactional and consulting work. Paulo Brancher is also a technology, telecoms and intellectual property expert. Thiago Luís Sombra is also of note within the team, especially in data privacy and cybersecurity matters from a regulatory, liability and contractual perspective and before the courts. The team also boasts strength at the associate level, with Jaqueline Simas de Oliveira praised by clients for her ‘excellent technical knowledge’. Isabela Fernandes is also noted.


‘Proactivity and innovation in solutions.’

‘Quality of service provided is excellent. It has a team with differentiated technical knowledge, but also with market experience. They work with our sense of urgency.’

‘Any question I have, Mattos Filho responds to us in an exemplary way, with a clear rationale and which conveys confidence in the opinion. At the moment, we are working hard on LGPD, but there are other laws/regulations that must be considered and even so, it is easy to bring these points in a clear and concise way.’

‘We worked with Isabela Fernandes Pereira and Paulo Marcos Rodrigues Brancher: Both are open, with a great holistic view of our diverse sector. Very transparent.’

‘The office has excellent service and quality. They are thoughtful and problem-solving.’

‘Paulo Brancher’s team, especially Jaqueline Oliveira, provided services to the company in its LGPD adaptation project. The lawyers involved demonstrated excellent technical knowledge on the matter and, in particular, great availability, cordiality and the response to urgent demands.’

‘Mattos Filho is an exceptional firm on the data protection and privacy front. The office works with the largest technology companies and performs excellent work, especially considering the complexity of the topics and the international context with deep debates on the processing of personal data on several fronts.’

‘Thiago Luís Sombra does an impeccable job in organizing the presented problem and proposing an innovative solution to the debated issue. In addition, Isabela Fernandes and Jaqueline Oliveira stand out; they are very organised, proactive and deliver a very high level of work.’

Key clients






Google Brasil


Credit Suisse


Banco MUFG



United Parcel Services (UPS)

BNY Mellon

Enel Brasil

Prudential do Brasil

Netflix Entretenimento Brasil

Semantix Tecnologia em Sistema de Informação

Match Group

Bayer AG

National Wildlife Foundation (NWF)

The Bumble Group

Work highlights

  • Advised Allianz on the use of legitimate interest to justify certain data processing activities.
  • Advised a company in the technology sector in the context of a security incident that resulted in the compromise of customer information.
  • Advised Arcos Dourados Comércio de Alimentos on various data protection and compliance matters.

Pinheiro Neto Advogados

Pinheiro Neto Advogados’ cybersecurity and data protection group is a popular choice for multinational and domestic clients in the financial services, healthcare and insurance industries. The full-service firm advises and consults on all manner of aspects related to the LGPD with a multidisciplinary approach. Outside of compliance programmes, the team also advises on increasingly complex cybersecurity challenges, assisting clients in managing risk and data breach remediation actions. In particular, social media clients trust the team to advise them in breakthrough matters, such as open banking technology in Brazil. Litigation is another area in which the team shines, representing companies in a number of high-profile cases involving free speech, privacy, and liability for third-party content and disclosure of user data in the Supreme Federal Court. André Zonaro Giacchetta and José Mauro Decoussau Machado are go-to individuals in the team for litigation matters. Larissa Galimberti is a technology transaction and data protection expert, with extensive experience in structuring new products, services and platforms for e-commerce. Ciro Torres Freitas is also highly specialised within the field, and advises some of the top global technology clients. In broader developments, the firm opened a Tokyo office in 2019, which is a strategic advantage for Asia-based clients.


‘For a long time now, Pinheiro Neto’s team have been involved in some of the most relevant tech law issues arising in Brazilian courts, which has an incredibly positive impact in their work handling tech-related litigation and counseling on pre-litigation or regulatory matters.’

‘André Zonaro Giacchetta and Ciro Torres Freitas are readily available should a sensitive issue arise and provide strategic, sensible legal advice in tech law matters.’

Key clients




Mirow & Co. do Brasil

Tiger Global Management






Work highlights

  • Assisted Facebook in a public civil action filed by Instituto Brasileiro de Defesa e Proteção de Dados Pessoais, Compliance e Segurança da Informação – SIGILO.
  • Assists Amazon and AWS in a range of matters related to privacy and data protection, consumer law, IP, e-commerce and other legal fields.
  • Assisted Facebook in several sensitive and complex administrative proceedings initiated by the Public Prosecutor’s Office and consumer protection agencies.


The cybersecurity and data protection department at B/Luz specialises in complex transactions involving technology and innovative businesses. The team advises clients on data protection compliance projects, specialised audits and internal policy development, cross-border data transfers, and data breach and cyber attack incident management. Fernando Bousso  and Pedro Ramos  co-lead the team, which is praised for its ability to ‘quickly adapt’ to its clients’ needs. Bousso is a data protection specialist, regularly assisting clients in their compliance projects. Ramos’s expertise includes media, technology transactions and data protection. The firm also serves as the data protection officer (DPO) for several clients.

Practice head(s):

Fernando Bousso; Pedro Ramos


‘B/Luz Advogados is able to understand not only the issues raised, but also the business environment that involves the requested analyses. As it is a smaller office, it quickly adapts to the needs of our company.’

‘I recommend Fernando Bousso.’

‘Fernando Bousso and Rafael Pessoa are very practical and know our business very well. I feel 100% comfortable working with both of them and turning to them for help from day to day matters to sensitive topics.’

Key clients

Anheuser-Brush Inbev

Grupo Boticário




Grupo Pão de Açúcar



Viacom CBS


Loft Brasil

99 (Didi Chixing)

Azul Linhas Aéreas



Grupo Soma



Arco Educação

Publicis Group

Work highlights

  • Advised TIM on its data protection compliance programme.
  • Advised Rappi in a civil action related to the LGPD, which ruled that Rappi was in compliance with data protection regulations.
  • Advised Boticário with its data protection compliance programme, including the review of procedures and training to its franchise chain.

TozziniFreire Advogados

The cybersecurity and data privacy practice at TozziniFreire Advogados covers contentious and non-contentious data protection issues related to LGPD compliance, data breaches, and administrative and judicial proceedings. The litigation side of the practice regularly handles emblematic issues within the LGDP and internet law space, such as artificial intelligence, and intermediary liability for personal data in instances of illegality online. Marcela Waksman Ejnisman focuses her practice on contracts and advisory work related to data compliance programmes and training. Patricia Helena Marta Martins is a key contact within the team for litigation and administrative proceedings before the courts and regulators. Carla Do Couto Hellu Battilana is also a technology expert, regularly advising on data sharing agreements, data licensing and internal policies for clients. Luiza Sato joined the team from ASBZ Advogados in July 2022, bringing with her expertise across IP, technology and digital law.

Practice head(s):

Marcela Waksman Ejnisman; Patrícia Helena Marta Martins


‘The firm has a team of proactive lawyers, who always seek to understand all the details of the issue presented by the company, when they are called upon, presenting in the end a precise and excellent result.’

‘Extremely dedicated team and subject matter experts. Agility in service. They understand the client’s business vision.’

‘Carla do Couto Hellu Battilana, Tulio Belem de Andrade, and Marcela Ejnisman: I recommend these three practitioners.’

Key clients




Mitre Realty Empreendimentos e participações

Page Group









Aspen Pharma

GoDaddy Serviços Online do Brasil

Lojas Renner



Work highlights

  • Assisting McKinsey with its LGPD data conformity programme, which includes mapping the data processing activities carried out in the company.
  • Assisting Colgate with LGPD compliance, including mapping the data processing activities carried out in the company, and identifying the applicable legal bases, risks and recommendations.
  • Advising BMW on its compliance with LGPD, including the development of the legal structure to introduce connected vehicle services in the Brazilian market.

ASBZ Advogados

ASBZ Advogados‘ cybersecurity and data protection practice advises clients across a diverse range of sectors, including aviation, retail, logistics and technology, in their LGPD compliance projects. In addition to this, the team assists clients in M&A transaction due diligence, and provides representation before administrative and judicial bodies. Guilherme Braguim is a key contact in the team for litigation, leveraging his expertise across IP, internet law and unfair competition. Igor Baden Powell is also of note and is recommended by clients. Since research concluded, Baden Powell has moved to TozziniFreire Advogados - effective as of July 2022.


‘The firm was able to present a well-structured LGPD compliance plan/schedule, allowing the client to have a clear view of pending activities and estimated time for their completion.’

‘ASBZ Advogados demonstrated a lot of knowledge in the area, being able to provide examples of what other companies usually do, which helps a lot in the execution of this type of project.’

‘Igor Powell executed the project very well. He was very agile in deliveries and clarified all doubts satisfactorily.’

Key clients

American Airlines

United Airlines

Air France / KLM


Amanco Wavin


DSM Brasil

Omega Energia







ACSP – Associação Comercial do Estado de São Paulo


Supermercado Big Bom


AGI Brasil


Work highlights

  • Advising on Sascar’s LGPD compliance project and on its new projects involving the processing of data in the rendering of fleet management services.
  • Advising on Mutant’s LGPD compliance project and assisting on several data protection-related issues involving its technological and innovative projects and new companies being acquired.
  • Advising on Omega Energia’s LGPD compliance project and assisting the company with consultancy on data protection-related issues in the energy sector.

Azevedo Sette Advogados

Azevedo Sette Advogados’ cybersecurity and data protection practice sits within the firm’s wider TMT practice group. LGDP compliance programmes, impact assessments and data transfer projects are within the team's purview. The team also advises on internet law, assisting in issues involving provider civil liability, net neutrality, and virtual currency and e-payments related to data privacy and cybersecurity. In addition, the practice group has a civil litigation team, which advises Brazilian and foreign clients in judicial and arbitration contexts. Ricardo Barretto Ferreira Da Silva leads the practice and has extensive experience in the areas of IT, internet and TMT. Lorena Pretti Serraglio is also of note within the team, particularly for compliance programmes and digital law.

Practice head(s):

Ricardo Barretto Ferreira

Key clients

Tempo Assist


Xerox Corporation

Gramado Parks – GPK

Shiseido do Brasil

RHI Magnesita

Talenses Group

Nokia Brasil

Grupo J. Mendes

Torrent Pharmaceuticals


Amazon Web Services

Zambon Laboratórios Farmacêuticos

BFBM – Barroso Fontelles, Barcellos, Mendonça & Associados

Clients turn to BFBM – Barroso Fontelles, Barcellos, Mendonça & Associados’ ‘excellent’ privacy and data department for advice on privacy maters, including LGPD compliance, privacy-related class actions, user privacy, and third-party liability related to data. Eduardo Mendonça has over 15 years of experience in constitutional and digital law, and co-leads the practice alongside André Zanatta and Felipe Monnerat, who are both well versed in regulatory matters and litigation, including data breaches.

Practice head(s):

Eduardo Mendonça; Felipe Monnerat; André Zanatta


‘The Technology, Privacy and Data Protection team is excellent. All extremely qualified, dedicated and know how to reconcile theory and practice to solve complex cases.’

‘Without question BFBM provides exceptional service. They are thorough yet pragmatic, their advice is well-researched and tailored to client needs.’

‘They’re experts in the subject matter. They understand our business. We meet without restrictions by WhatsApp. They offer an affordable price.’

‘In terms of technology, the practice stands out in its client document management, with strict access controls. The team keeps excellent documentation on the projects they do for us, highlighting deliverables and timelines.’

‘André Zanatta brings together extraordinary expertise and business acumen, drawing on a uniquely rich experience in the private sector.’

‘Fernanda Mascarenhas Marques is highly detailed-oriented and knowledgeable about clients’ practical needs.’

‘André Zanata is an attentive, available and dedicated professional who provides his services masterfully.’

‘André Zanatta is a deep expert in the subject. He has developed very simple processes to serve us. He understands our business sensitively. Always helpful. Highly recommended.’

Key clients

Pivo Arte Pesquisa


Hospital Santa Lucia

Trillion Digital Services




STB – Student Travel Bureau

ISIC – International Student Identity Card




McKinsey & Company



ABTG comercio e serviço para o mercado de arte

Silvia Cintra + Box 4

Fortes, D’Aloia e Gabriel

Galeria de arte Luisa Strina

Luciana Brito Serviços e Comércio de Obras de Arte

Gramol Objetos de Arte (Mul.ti.plo)

Mirarte Comércio de Obras de Arte Eireli

Monteze Artes (Arte FASAM Galeria)

Bolsa de Arte de Porto Alegre

Andrea Rehder Arte Contemporânea

BMA - Barbosa, Müssnich, Aragão

The cybersecurity and data protection offering at BMA - Barbosa, Müssnich, Aragão is broad based, covering security breaches such as ransomware, LGPD compliance projects, and data transfers. Clients ranging in size from multinationals to start-ups in the financial services and digital media industries turn to the team, which offers a 24/7 hotline available in instances of critical events. Felipe Palhares heads up the practice, advising on personal data processing in cross-border and domestic transactions, data breaches, and new product and service development. Bárbara de Oliveira Iszlaji is another name to note in the team.

Practice head(s):

Felipe Palhares


‘BMA provides very practical and business-oriented advice. Always very concise and to the point.’

‘I regularly work with Felipe Palhares, who is very responsive, very practical and extremely helpful.’

‘Team assertiveness and quick response time.’

‘Felipe Palhares distinguishes himself from other professionals in the market. Brillant.’

Key clients

Launch Pad Tecnologia, Serviços e Pagamentos (Hotmart)

SITA Inc. do Brasil

Biofourmis Singapore

Comuto Sa (BlaBlaCar)

Seadrill Serviços de Petróleo

Curupira  (Take)


Black & Decker do Brasil



Work highlights

  • Advised Hotmart in developing its intracompany data transfer agreement, which will be used by all subsidiaries of the company around the world.
  • Advised Eletromidia in structuring its privacy programme in order to comply with the LGPD, and in training its staff regarding the policies and procedures developed.
  • Advised ABIOVE in structuring a groundbreaking new project to protect its associates against fraud through creating a database of its clients that was managed by Serasa.

Campos Mello Advogados in cooperation with DLA Piper

Campos Mello Advogados in cooperation with DLA Piper‘s privacy, data protection and cybersecurity practice covers a wide breadth of industries and clients, both domestic and multinational. The team regularly advises clients on LGPD compliance programmes, data transfer agreements, cybersecurity tool development and implementation, and M&A due diligence. Paula Mena Barreto manages the practice and regularly advises clients on privacy policy implementation, as well as data breaches and compliance issues. Also of note within the team are Ana Luisa Bastos Ramos and Vanessa Azambuja, both of whom are well versed in LGPD counselling.

Practice head(s):

Paula Mena Barreto

Demarest Advogados

Demarest Advogados’ multidisciplinary data protection, cybersecurity and technology-oriented practice advises domestic and multinational clients within and outside the technology sector on all aspects of privacy, security incident risk management and AI. The team is led by intangibles, technology, internet law and IP expert Tatiana Campello, alongside Eduardo Magrani, who focuses on data protection and AI. The team’s recent instructions include assisting clients to achieve LGDP compliance, and advising on data privacy matters related to M&A. Since research concluded, Magrani has left to become a consultant at CCA Law Firm in Lisbon, Portugal.

Practice head(s):

Tatiana Campello; Eduardo Magrani


‘Team with very high seniority on the topic addressed.’

‘I recommend both Tatiana Campello and Eduardo Magrini.’

Dias Carneiro Advogados

Dias Carneiro Advogados regularly advises financial institutions, videogame and e-sports companies, schools and public administration bodies, and AI companies in their day-to-day dealings. In addition, the team also assists clients in their LGPD compliance projects, data transfer negotiations, data breaches and data audits. Vanessa Pareja Lerner leads the practice; she has extensive experience in data collection, use and privacy. Also of note in the team is Guilherme Berti de Campos Guidi, whose practice focuses on technology, personal data protection, security matters, and digital health in the fintech, crypto-economics and education-technology industries. Since publication, Guidi has moved to Freitas Ferraz Advogados - effective as of October 2022.

Practice head(s):

Vanessa Pareja Lerner

Key clients

Banco Keb Hana do Brasil

Banco KDB do Brasil

Banco Woori Bank Do Brasil

Cristália Produtos Químicos Farmaceuticos

Echoenergia Participações

Oficial De Registro De Imóveis, Títulos E Documentos Pessoa Jurídica E Registro Civil Das Pessoas Naturais, Interdições E Tutelas De Valinhos São Paulo

Ciena Communications Brasil

Sami Saúde

Companhia Promotora UCI

Monashees Gestão De Investimentos

Work highlights

  • Advised Banco KEB Hana do Brasil on the compliance of its operation with the LGPD and the establishment of a data privacy programme.
  • Advised Echoenergia on the compliance of its operation with the LGPD and the establishment of a data privacy programme.
  • Advised Sami Saúde on LGPD compliance and the establishment of a data privacy programme, in addition to day-to-day data protection matters.

KLA Advogados

The data protection and cybersecurity offering at KLA Advogados is praised for its ‘qualified professionals' and its ability to 'meet all demands regardless of subject’. Well versed in LGPD compliance project implementation across a wide range of industries, including energy, technology, banking and entertainment, the team also advises on data breaches, instances of fraud, data transfers and takedown requests. Ana Carolina Cesar advises on complex regulatory matters and data breach strategy. Vanessa Pirró left the firm, effective March 2022.


‘What makes KLA a unique office is the fact that people are always available to assist us in all matters of the company. Very qualified professionals and an office that can meet all demands, regardless of the subject.’

‘Totally available to the client, it has a sense of urgency, and provides services quickly, practically, objectively and efficiently.’

‘Specifically in the area of data privacy, Ana Carolina Cesar stood out in the assistance provided for the implementation of the LGPD Adaptation Programme, understanding the business and needs of the company, and making herself available for any questions and/or clarifications.’

Key clients


Banco Digimais

Boston Scientific do Brasil

DXC Technology (DXC)

Instituto Unibanco

Associação Japan House

Bain & Company Brazil

Energias de Portugal

QMC Telecom

Cred-System Administradora de Cartões de Crédito

TV Omega

Work highlights

  • Assisted Cinemark with the implementation of a privacy programme.
  • Supporting Bain & Company Brazil in the implementation of its privacy programme in Brazil in accordance with global privacy team guidelines.
  • Assisted DXC with the review and drafting of all relevant documents related to data protection and privacy matters.

Lefosse Advogados

Lefosse Advogados’ data protection team sits within the firm’s wider technology and IP practice, and advises clients on a day-to-day basis regarding their LGPD and cybersecurity needs. The team works in close proximity with other groups within the firm, including M&A and litigation, pooling expertise where needed by clients. The team is led by Paulo Lilla, who has extensive experience in internet law, digital platforms, IT and technology agreements. Senior associate Carla Segala is another key figure in the practice, also advising on matters related to AI, software, privacy and data protection, and outsourcing.

Practice head(s):

Paulo Lilla


‘We were promptly attended to in unusual/emergency situations and the office’s main concern was to meet the client’s urgency before adding to the “time sheet”. We felt totally taken care of since the biggest concern was with the client and not with the value they could receive with the service.’

‘Paulo Lilla and Carla Segala are always available to talk to the client, despite having a very competent team that serves us with mastery.’

Key clients



WTorre (Grupo WTorre)

Panasonic Brasil


Care Plus

Julius Baer Family Office


Porto Seguro

Argo Energia



bp Brasil

Viatris Brazil

Atradius Credito y Caución

Work highlights

  • Advising CISS – a Software-as-a-Service (SaaS) provider of IT solutions for retailers – in technology, data protection and cybersecurity matters.
  • Assisting bp Brasil in the implementation of measures to reach compliance with the Brazilian General Data Protection Law.
  • Assisted Panasonic Brasil in the implementation of measures to reach compliance with the Brazilian General Data Protection Law.

Madrona Fialho Advogados

Madrona Fialho Advogados‘ data protection and cybersecurity practice offers its clients ‘extraordinary dedication’ and ‘innovation’ in advisory work and counselling for LGPD compliance projects. The practice is led by Lucas Spadano, who also heads the firm’s IP and international trade teams; he leverages his expertise in these fields to advise clients in the retail, energy, logistics, healthcare and technology industries. Also of note within the team is senior associate Bernardo Santos, who leads the data protection projects arm of the practice, advising Brazilian and multinational clients on coordinating multi-jurisdictional projects.

Practice head(s):

Lucas Spadano


‘Extraordinary dedication to our teams and staff across the board in terms of innovation, from technologies and people.’

‘Bernardo Santos is a professional who gives everyone confidence, super clear and objective in solving doubts, problems and questions. A true expert in the field.’

Key clients

2w Energia

Andrade Gutierrez Participações

Aperam Inox America Do Sul

Arent Fox

Bh Iluminacao Publica

Brk Ambiental Participacoes

Chemson Polymere – Additive

Cia De Fiacao E Tecidos Cedro E Cachoeira

Clamper Industria E Comercio

Confederacao Nacional Da Industria – CNI

Criteo Do Brasil Desenvolvimento De Servicos De Internet

Csem Brasil

Mundie e Advogados

The data protection and cybersecurity offering at Mundie e Advogados sits within the firm’s wider regulatory and competition group. The team has extensive expertise in advising telecoms providers, FTA broadcasters, pay-TV providers, satellite operators and major international media conglomerates on issues related to LGPD compliance and data breaches. In addition, the team draws on expertise from the firm’s corporate and M&A, private equity and labour practices when advising clients. Elinor Cotait, Beatriz Faustino França, Enrico Romanielo and Ana Claudia Beppu jointly lead the department. Since publication, the entire team left to Veirano Advogados – effective as of January 2023.

Work highlights

  • Advised a global pay-TV company on its data protection compliance programme.
  • Advised a Brazilian streaming service on the implementation of a data protection compliance programme.

Opice Blum e Bruno Advogados Associados

Strong in both advisory and litigation, Opice Blum e Bruno Advogados Associados’ digital law, technology and data privacy group deals with LGPD compliance and adjacent matters, administrative proceedings, data breaches and M&A due diligence. Renato Opice Blum and José Roberto Opice Blum both have extensive expertise in digital law across a wide range of markets. Marcos Bruno is a key contact within the team for matters related to IP, media and e-commerce. Matters of cybersecurity are within the purview of Rony Vainzof, while Caio César Carvalho Lima focuses on privacy and personal data protection. Camilla Jimene and Danielle Serafino are technology governance and tax law experts, and Henrique Fabretti Moraes also has strong expertise in privacy and data protection, and was promoted to partner in 2022.

Practice head(s):

Renato Opice Blum; Marcos Bruno; José Roberto Opice Blum; Rony Vainzof; Caio Lima; Camilla Jimeme; Danielle Serafino


‘The team is made up of people who have high technical and legal knowledge about banking and payment products and services, so that legal opinions, document reviews and recommendations are always based on the best technique and law.’

‘I’d recommend Caio Cesar Carvalho Lima and Florence Dencker Terada.’

‘Law firm specialising in digital law and GDPR.’

Key clients

Grupo Mercado Livre

Grupo Simpar


Bom Trato

Fecomércio São Paolo


Positivo Tecnologia

Cinemark Brasil



Work highlights

  • Represented Grupo Mercado Livre in a lawsuit for moral damages concerning the plaintiff’s data on the client’s platforms.
  • Advised Grupo Simpar on its privacy and data protection programme, and implemented the management of the compliance programme, acting as Data Protection Officer.
  • Advised Bom Trato on its LGPD compliance project.