TMT: Cybersecurity and data privacy in Brazil

Mattos Filho

The data protection and cybersecurity team at Mattos Filho, Veiga Filho, Marrey Jr. e Quiroga Advogados has a breadth of expertise that ensures a steady flow of work from clients in the technology, healthcare, financial services, telecoms, insurance, retail and education sectors. In addition to assisting with the implementation of data protection compliance programmes, the department is also well versed in major data incidents, transnational data transfers and M&A due diligence. Paulo Brancher 'has great knowledge of different areas of law that involve technology and data protection'; Fabio Ferreira Kujawski is another name to note in this space. Ana Carolina Heringer Castellano is seasoned in advising on domestic and cross-border data breaches, while Isabela Fernandes routinely advises high-profile clients on rules introduced by the recent Brazilian Data Protection Law and their implications for digital platforms and new products. Thiago Luís Sombra is also noted by clients for data privacy and cybersecurity matters.


‘The team comes up with innovative solutions looking at the business as a whole. In addition, the service is very close to the client and lawyers really seek to understand the business in order to propose solutions or adjustments. Team members demonstrate that they are following the events, trends and directions of the market, especially considering the issue of data protection.’

‘The firm fields a technical, prepared team that is skilled at dealing with complex and interdisciplinary issues in a unique way. Paulo Brancher has great knowledge of different areas of law that involve technology and data protection; he possesses great presence in meeting, bringing his points across in a clear and direct way.’

‘Readiness to assist us with opinions that bring security regarding LGPD. Paulo Marcos Rodrigues Brancher and Isabela Fernandes Pereira are recommended.’

‘Fast and quality service, with total focus on the client’s needs. Thiago Sombra stands out.’

‘Strong knowledge of data protection laws. The team led by Paulo Brancher is excellent. Fast and responsive service, they always make time to be available, often dealing with complex issues which they are able to handle at short notice.

‘Paulo Brancher is excellent with a sharp mind and an eye for detail. He provides sound legal advice and can be relied on.’

Key clients






Google Brasil


Credit Suisse


Banco MUFG



United Parcel Services

BNY Mellon

Enel Brasil

Prudential do Brasil

Netflix Entretenimento Brasil

Semantix Tecnologia em Sistema de Informação

Match Group


National Wildlife Foundation (NWF)

The Bumble Group

Work highlights

  • Retained by WhatsApp to render legal advice regarding data protection requirements for several products including WhatsApp Business, WhatsApp Shops and WhatsApp Payments.
  • Assisted Luxottica in compliance with the Brazilian Data Protection Laws and an investigation of a data breach.
  • Retained by BNY Mellon to render legal advice regarding data privacy laws and regulations in Brazil, which comprised the production of a comprehensive data privacy compliance programme.

Pinheiro Neto Advogados

Pinheiro Neto Advogados has recently been especially busy advising several clients, particularly in the healthcare, insurance and financial services industries, on different aspects of the recently enacted General Data Protection Law (LGPD), while also assisting others with their increasingly complex cybersecurity challenges, including data breaches and remediation actions. Social media networks also turn to the team for support with litigation involving privacy and free speech rights, intermediary liability for third-party content and disclosure of users' data. Ciro Torres Freitas is the main contact for data protection and cybersecurity matters. His experience covers compliance issues, data security incidents and lawsuits before the superior courts. André Zonaro Giacchetta is another key practitioner.

Work highlights

  • Assisted Amazon and AWS with several consultations regarding Brazilian personal data protection norms, including the review of documents, agreements and procedures to ensure they comply with the Brazilian General Data Protection Law.
  • Represented Facebook in a number of lawsuits filed in Brazil by users affected by actions taken by the company to combat coordinated inauthentic behaviours, seeking the reinstatement of their pages and profiles, and/or compensation for damages.
  • Represents Facebook is a class action recently filed by a pharmacies’ association, seeking to reinstate some accounts of pharmacies that had been deactivated in WhatsApp for violation of its terms and policies.


B/Luz is instructed by a range of prestigious clients operating in the consumer goods, retail, technology, healthcare and financial services sectors, among others. The department acts as data protection officer (DPO) for several clients, assisting them with the development and implementation of their privacy governance programmes. Its practitioners are also equipped to advise on all stages of a transaction, international data transfers, whistleblower’s compliance analysis, e-discovery investigations and data breaches and cyber attacks. Fernando Bousso ‘has exceptional expertise in digital law and related topics’, and routinely assts with compliance projects under the Brazilian Data Protection Law. Other individuals to note include Pedro Ramos – whose areas of expertise include technology transactions and data protection issues – and of counsel Renato Leite Monteiro. Since publication, in March 2022, the team was further strengthened by the arrival of Vanessa Pirró from KLA Advogados.

Practice head(s):

Fernando Bousso; Pedro Ramos; Renato Leite Monteiro


‘The team is extremely experienced in the field and has a good reputation in the market, because it was very competent in hiring (and keeping in the team) professionals with a high level of knowledge of LGPD and compliance matters. They have a deep knowledge of the subjects they work with and a broad vision, so, in cases where the topic is new, they are able to present alternatives.’

‘Fernando Bousso has exceptional expertise in digital law and related topics (software contracts, intellectual property). Furthermore, he is available to assist us whenever necessary, and responds quickly (without losing quality).’

‘The data privacy team has a deep knowledge of the subject, advising clients in a practical and objective way. Fernando Bousso and Rafael Pessoa are always available, respond quickly to queries and understand the client’s business.’

‘Renato Leite Monteiro is an expert in LGDP-related issues and provides objective legal opinions focused on what is relevant to the client.’

‘Fernando Bousso is a valuable asset when it comes to LDPD  projects.’

‘Baptista Luz has been increasingly important to us, as a legal department, as it stands out in the light of the technical knowledge of our products, which ensures that the quality of legal analysis is even higher. Pedro Ramos is recommended.’

Key clients

Arco Educação

Cura Diagnósticos





Japan Tobacco International

Red Bull





Leroy Merlin

Lufthansa Service Holding




AB inBev

Instituto Ayrton Senna

Reclame Aqui


Grupo Arezzo



WildLife Studios



Work highlights

  • Retained by Mercedes-Benz to prepare and implement a robust privacy programme in Brazil.
  • Assisted DASA in all the regulatory and data privacy aspects related to the development of a major chest segmentation tomography platform based on artificial intelligence.
  • Engaged by 99, part of the Didi Chuxing group, to analyse the privacy and data protection risks of a project involving the use of footage from external dashcams to be installed on vehicles used by drivers.  

TozziniFreire Advogados

TozziniFreire Advogados fields a cybersecurity and data privacy practice focused on LGPD compliance, global data breach incidents, and administrative and judicial proceedings. On the contentious front, the team is regularly retained by technology companies in cases involving intermediaries’ liability, data disclosure and right to be forgotten claims. Marcela Waksman Ejnisman advises on contractual issues and LGPD enforcement. Patricia Helena Marta Martins is a key contact for litigation related to data protection and cybersecurity matters, while Carla do Couto Hellu Battilana assists clients with the review of terms of use and privacy policies and issues related to data breaches.

Practice head(s):

Marcela Waksman Ejnisman; Patricia Helena Marta Martins

Key clients













Work highlights

  • Retained as leading litigation counsel for TikTok – ByteDance Brasil, having advised the client on a recent lawsuit alleging that TikTok app collects – without consent – biometric facial data through the app filters.
  • Assisted Decolar with respect to their conformity with the new privacy law in Brazil, LGPD, and in this context, helped it in the mapping of all its data processing activities.
  • Assisted Crédit Agricole bank with its compliance programme for LGPD, including the mapping of all data processing activities, implementation and review of documents and policies, and training.

ASBZ Advogados

With airlines, call centres and logistics and technology companies at the core of the group's client base, ASBZ Advogados excels in LGPD compliance projects, having developed commercial partnerships with leading consultancy firms. The practice also has strength conducting data protection audits in the context of M&A transactions and handling administrative claims. Department head Luiza Sato, who brings together expertise in data protection, IP and digital law, is praised by clients for her 'competence, knowledge and leadership' skills. Guilherme Braguim undertakes mandates pertaining to compliance with data protection legislation.

Practice head(s):

Luiza Sato


‘Agility in response. Assertive, straightforward direction. Luiza Sato is great.’

‘Innovative services, flexibility and objective advice. Our market has very peculiar characteristics and ASBZ knew how to adapt to our reality and deliver what we asked for.’

‘Luiza Sato assisted us, with the support of Igor Baden Powell. Both lawyers were always available and delivered the service according to the schedule stipulated between us. I will definitely recommend Luiza Sato’s services, given her competence, knowledge and leadership in the project.’

Key clients

American Airlines

United Airlines

Air France



Naval Group

Fundação Antônio Helena Zerrener (FAHZ)









Xingu Agri


DSV Panalpina

DSM Brasil


ACSP – Associação Comercial do Estado de São Paulo

Work highlights

  • Conducted Air France/KLM’s LGPD compliance project.
  • Assisted Sascar with the implementation of its LGPD compliance project.
  • Conducted the Associação Comercial de São Paulo’s LGPD compliance project.

Azevedo Sette Advogados

Led by Luiz Augusto Azevedo Sette and IP specialist Ricardo Barretto Ferreira, the data protection team at Azevedo Sette Advogados advises on the mitigation of risks in the context of data breaches, launch of new products and services, and international data transfers. The department - which works under the umbrella of the information technology, media and telecommunications group - has been particularly active assisting Brazilian and foreign companies in relation to compliance with the new obligations imposed by GDPR and LGPD. Lorena Pretti Serraglio is a key individual for LGPD compliance programmes.

Practice head(s):

Ricardo Barretto Ferreira; Luiz Augusto Azevedo Sette

Key clients

Torrent Pharmaceuticals

Electronic Arts

Petronas Lubrificantes

Amazon Web Services

Check Point Software Technologies

JMN Mineração

Talenses Group

Xerox Corporation

Zambon Farmacêutica

Tempo Assist Seguros

Work highlights

  • Advising Amazon Web Services on the processing of employees’ personal data.
  • Assisted Zambon Laboratórios Farmacêuticos with the drafting of a set of data protection agreements with service providers and business partners.
  • Responsible for advising Torrent Pharmaceuticals on compliance with the Brazilian General Data Protection Act.

BMA - Barbosa, Müssnich, Aragão

Leveraging its full-service structure, BMA - Barbosa, Müssnich, Aragão advises on an array of matters in the data protection space. Clients from a variety of sectors - such as financial institutions, digital media companies and start-ups - seek the team's assistance with due diligence in the context of transactions, regulatory issues, contentious matters involving data breaches and LGPD compliance projects. Leading the group is Felipe Palhares, whose key areas of activity include data incidents and the processing of personal data. Vitor Butruce and Felipe Schvartzman are other key contacts in the data privacy, technology and digital business department.

Practice head(s):

Felipe Palhares

Key clients

Airbnb Serviços Digitais

Launch Pad Tecnologia, Serviços e Pagamentos


Amobitec – Associação Brasileira de Mobilidade e Tecnologia

Work highlights

  • Responsible for conducting a comprehensive revision of Hotmart’s terms of service; the company is a Brazil-based digital edtech platform.
  • Advised Smallpdf in connection with the production of valid electronic documents and the provision of valid digital signatures procedures under Brazilian law.

Campos Mello Advogados

Campos Mello Advogados in cooperation with DLA Piper provides a wide range of advice, spanning data protection and cybersecurity regulatory matters, data transfers and M&A due diligence. The team is jointly led by Paula Mena Barreto in Rio de Janeiro and São Paulo-based Ricardo Caiado Lima. Barreto has significant experience in the implementation of privacy policies and management of data breach incidents, while fellow co-head Lima specialises in cybersecurity compliance issues and preventive measures. Data protection and privacy matters are also among Manoela Quintas Esteves‘ areas of expertise; she handles both consulting and contentious matters. In August 2021, Antonio Tovo – who specialises in compliance, cybersecurity and white-collar criminal law – joined the firm.

Practice head(s):

Paula Mena Barreto; Ricardo Caiado Lima

Demarest Advogados

Demarest Advogados ‘provides great quality services related to LGPD and digital law‘. The firm covers all aspects of privacy issues, cybersecurity and data processing matters. Led by the ‘excellentTatiana Campello, the group has been particularly busy advising multinational clients whose businesses depend on the processing and analysis of large volumes of data on the new LGPD. Data privacy due diligence in the context of M&A is another area of focus for the team, which was recently strengthened by the arrival of co-head Eduardo Magrani, who specialises in digital law and AI. Cecília Cunha, who dedicates her practice to technology and data protection, joined from Tocantins & Pacheco Advogados – CTA in November 2020. Since publication, the practice has been strengthened further still with the February 2022 hire of Tomás Paiva, formerly head of TMT and data privacy at Mundie e Advogados.

Practice head(s):

Tatiana Campello; Eduardo Magrani


‘The biggest difference is the active participation of the partners in all phases of the service. Tatiana Campello is recommended.’

‘The work is excellent and the service is very fast. Tatiana Campello is great.’

‘Extensive technical knowledge. Attentive team that provides great quality services related to LGPD and digital law.’

‘Tatiana Campello is excellent.’

Key clients

Mercado Livre Group

Grupo ABC

Dias Carneiro Advogados

Work related to privacy and data protection compliance issues is a standout strength for Dias Carneiro Advogados' department, which acts for clients in the banking, gaming, education, start-up and digital sectors. Its practitioners are particularly skilled in the drafting of privacy policy reviews, structuring of cybersecurity programmes, data transfers and data incidents. Vanessa Pareja Lerner is a key contact for technology, video game, media and entertainment companies seeking advice on data protection matters. She oversees the practice with Eduardo Turkienicz, who regularly advises on the management of compliance risks and privacy issues.

Practice head(s):

Vanessa Pareja Lerner; Eduardo Turkienicz

Key clients

Echoenergia Participações

Monashees Capital

Riot Games

Banco KEB Hana do Brasil

Arquivei Serviços Online

Epic Games

2RM Tecnologia da Informação


Lalamove Tecnologia (Brasil)

Cristália Produtos Químicos

Work highlights

  • Acting for Echoenergia Participações in the structuring of the entire LGPD compliance programme.
  • Advised Cristália Produtos Químicos on the implementation of its LGPD compliance programme.
  • Assisting 2rm Tecnologia da Informação with the structuring of its LGPD compliance programme.

Fialho Salles Advogados

Praised by clients for its 'prompt service, efficiency, assertiveness and innovation', Fialho Salles Advogados handles advisory and compliance work in relation to the recently enacted LGPD. The department, which is led by IP expert Lucas Spadano, is instructed by a sizeable client base of retail, energy, logistics, healthcare and technology companies. 'Standout lawyer' Luiza Tângari is seasoned in data protection matters and IP rights. Bernardo Santos coordinates data protection compliance projects.

Practice head(s):

Lucas Spadano


‘The firm is a huge asset to anybody working with data privacy and cybersecurity issues. Extremely responsive and hard-working in its efforts to achieve clear and practical advice on complex matters.’

‘Standout lawyer Luiza Tangari Coelho is revered as a leader in this practice area within the country and within the region.’

‘In technical terms they are impeccable and have an exceptional strategic positioning. Prompt service, efficiency, assertiveness, innovation. Luiza Tangari is recommended.’

Key clients

2w Energia

Andrade Gutierrez Participações

Aperam Inox America Do Sul

Arent Fox

Bh Iluminacao Publica

Brk Ambiental Participacoes

Chemson Polymere – Additive

Cia De Fiacao E Tecidos Cedro E Cachoeira

Clamper Industria E Comercio

Confederacao Nacional Da Industria – CNI

Criteo Do Brasil Desenvolvimento De Servicos De Internet

Csem Brasil

Dvf Studio


End To End Analytics Consultoria America Do Sul

Evolua Energia Participacoes

Facio Pagamentos

Freixenet Brasil

Geofusion Sistemas E Servicos De Informatica

Innovative Seed Solutions Brasil Sementes Inovadora

Inspira Mudanca Participacoes

Irati Petroleo e Energia

Itatiaia Moveis

Maxmilhas – MM Turismo & Viagens

Meditrina Technology

Meero Do Brasil Servicos

Mrv Engenharia E Participacoes

Nanomark Pesquisa E Desenvolvimento Tecnologico

Pharma E-connection Intermediação e Agenciamento de Serviços e Negócios

Sandvik Mining And Rock Technology

Sano Saneamento E Participacoes

Sao Joaquim Holding & Empreendimentos

Sao Marcos – Saude E Medicina Diagnostica

Scala Data Centers

Slipstream Brazil

Somos Educacao e Participacoes

Spruson & Ferguson Lawyers

Sumup Solucoes de Pagamento

Sunew Filmes Fotovoltaicos Impressos

Sympla Internet Solucoes


The Void

TSA Tecnologia De Sistemas De Automacao

UP Brasil – Policard Systems E Servicos

VR Entreposto de Decoracao e Comercio

Work highlights

  • Assisted BRK Ambiental Participações in the acquisition of various tools that will be used for the processing of employee and customer personal data and/or for privacy management.
  • Advised Pharma e-Connection on the use of a B2B platform which aims to connect medicine sellers and buyers, having assisted with the drafting of the privacy policy and terms of use of the platform.
  • Assists Up Brasil Administração e Serviços with the analysis of the Brazilian General Protection Law, including risk assessment of new and current processes and products, negotiation of data processing agreements, among other areas.

KLA Advogados

KLA Advogados offers ‘partner-led advice’ to domestic and international clients across a range of data protection matters, demonstrating notable strength in the implementation LGPD compliance programmes. Response to data incidents, assistance with the review of privacy policies, risk assessment of new products and regulatory issues involving the processing of personal data are other key areas of activity for the team. Vanessa Pirró coordinates the department, which also includes Ana Carolina Cesar, who often acts for clients in the energy, banking, entertainment and technology sectors in transactional cybersecurity matters and regulatory issues. October 2021 saw the departure of former co-head Tania Liberman. Since publication, Pirró has also left the firm, effective March 2022.


‘Very attentive and committed lawyers. Partner-led advice. Very competent, available and dedicated team. ‘

‘Ana Carolina Cesar is excellent.’

Key clients

Lumiar Educações e Participações

Casa Hacker


Eventbrite Brasil Gestão Online de Eventos

Associação Japan House

Boston Scientific do Brasil



Reclame Aqui

Grant Thornton Brasil


Grupo Shiseido

Instituto Unibanco


Fundação Itaú

Corbion Produtos Renováveis

Vopak Brasil



Work highlights

  • Assisted Cinemark with the implementation of a privacy programme.
  • Advised Associação Japan House on the risks involving the implementation of facial recognition on its premises.
  • Providing data protection advice to Casa Hacker, including the review of the most relevant information on its data processing activities and advice on necessary improvements to meet the requirements of the new Brazilian Data Protection Law.

Lefosse Advogados

The cybersecurity and data protection service offering at Lefosse Advogados was recently bolstered by the arrival of practice head Paulo Lilla and senior associate Carla Segala from Opice Blum, Bruno, Abrusio, Vainzof Advogados Associados. Both practitioners bring a wealth of experience in the fields of data protection regulatory issues, data breaches and cyber law. Besides advising clients on LGPD compliance matters, the department also works in close collaboration with other groups in the firm, including litigation and M&A, making it well placed to assist with due diligence in relation to transactions, and contentious mandates.

Practice head(s):

Paulo Lilla

Key clients

CVC Corp

Grupo GPS

Panasonic Brasil


Fundação do Câncer

PayPal Holdings

Diagnosticos da America

Acesso Digital Tecnologia da Informação

BP Brasil

Conexa Saúde Serviços Médicos



Work highlights

  • Acted as counsel to CVC Corp in the implementation of measures to reach compliance with the Brazilian General Data Protection Law.
  • Assisted Panasonic Brasil with the implementation of measures to reach compliance with the Brazilian General Data Protection Law.
  • Acted as counsel to WTorre in the implementation of measures to reach compliance with the Brazilian General Data Protection Law.

Mundie e Advogados

Mundie e Advogados is equipped to advise a range of clients in Brazil on the implementation of data protection compliance programmes in the wake of the enactment of the LGPD. Leading the department are Elinor Cotait, Beatriz Faustino França, Enrico Romanielo, Ana Claudia Beppu and Tomás Paiva ; the latter is a name to note for high-profile matters involving data privacy and cybersecurity issues. Since publication Paiva has left the firm, effective Febraury 2022.

Practice head(s):

Elinor Cotait; Ana Claudia Beppu; Beatriz França; Enrico Romanielo


‘The team almost uniformly brings together impeccable technical expertise with excellent service and delivery. In addition, the team has a fascinating engagement that is rare to find in large firms. I think there is top-notch managerial work being done behind the scenes, led by Elinor.’

‘Tomás Paiva stands out for his technical knowledge, performance, availability, commitment and courtesy.’

Opice Blum, Bruno, Abrusio, Vainzof Advogados Associados

Offering advisory and litigation services, Opice Blum, Bruno, Abrusio, Vainzof Advogados Associados undertakes work across multiple data protection and cybersecurity issues, including LGPD compliance matters, administrative proceedings, M&A due diligence and data breaches. Renato Opice Blum specialises in digital law and data protection, while IP and media issues are core areas of activity for Marcos Bruno. Rony Vainzof 'has in-depth knowledge' of cybersecurity matters, while mandates pertaining to privacy and processing of personal data are some of José Roberto Opice Blum and Caio Lima's areas of expertise. Camilla Jimene and Danielle Serafino are also noted.

Practice head(s):

Renato Opice Blum; Marcos Bruno; José Roberto Opice Blum; Rony Vainzof; Caio Lima; Camilla Jimeme; Danielle Serafino


‘They are very focused on digital law and that’s the big difference, they go straight to the point.’

‘Enormous dynamism and deep legal vision, knowledge of the reality in other countries. Excellent administrative and academic structure, stimulating the exchange of knowledge between lawyers.’

‘Roni Vainzof has in-depth knowledge of the subject, seeks practical solutions, and possesses a great reputation in the market.’

Key clients

Cinemark Brasil

Multiplus (LATAM)


Positivo Tecnologia

Uniprime Central – Central Interestadual de Cooperativas de Crédito

CardPay Pagamentos

VS Datta Imagem Comércio e Serviços Eireli

Cartório Azevedo Bastos

C6 Bank




Work highlights

  • Provided legal advice to Positivo Tecnologia on its smart home project.
  • Conducted a legal analysis of Cinemark Brasil’s new loyalty programme.
  • Assisted Pipefy in compliance matters regarding the Brazilian General Data Protection Law.