Despite the General Data Protection Law being in effect for eight years, justifications for non-compliance are still frequent.
Credits: Conjur
The LGPD, Law No. 13.709/2018, establishes rules for the processing of personal data, including in digital media. Among the most recurring justifications are: “The law is only for large companies”; “we don’t even process data”; “I only use the name, CPF (Brazilian tax identification number), telephone number, and address of my clients; just the basics.” In 2026, these justifications are still frequently heard. However, all three need to be analyzed in light of the LGPD’s own provisions.
“The law is only for large companies.” First mistake: the law does not state, for example, that it “applies to companies with more than one hundred employees,” “to companies in the healthcare sector,” “only to companies that sell online,” or “to those who sell products or offer services.” On the contrary, the LGPD expressly establishes that it applies to any processing operation carried out by a natural person or by a legal entity under public or private law, regardless of the means, the country of its headquarters, or the country where the data is located.
Therefore, if an operation, business, or company, whether conducted by a natural person or a legal entity, public or private, involves the processing of personal data as defined by law, the LGPD (Brazilian General Data Protection Law) will apply to that activity.
“We don’t even process data.” The initial point to be verified is what is understood by data processing. Often, the layman’s answer is: “It’s when I modify some data. Here we only register and make the sale.”
The law itself defines processing as any operation performed with personal data, such as those relating to the collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction. In other words, when a customer provides their name, CPF (Brazilian tax identification number), and phone number to register or request a quote, data is being collected and received.
When the team enters this information into the sales system, a CRM, or a spreadsheet, processing and storage occur. When, in that same spreadsheet, customers are organized and categorized as “VIP customer,” “inactive,” or “delinquent,” information is classified and organized.
When contact occurs or goods or services are delivered, data is accessed and used. When a customer requests a change of phone number or an update to their registration, data is modified. Furthermore, when a contract ends and, after the applicable period, the company deletes that registration from the database, data is eliminated. All of this constitutes data processing.
Based on this concept, it is quite difficult to imagine a business that does not carry out some type of operation with personal data. The simple fact of having employees, for example, already involves the use of their information for different purposes related to the employment relationship, such as compliance with legal and social security obligations.
Along the same lines, it’s also common to hear: “I don’t even collect CPF numbers, so I don’t need to comply with the LGPD (Brazilian General Data Protection Law).” Personal data is information related to an identified or identifiable natural person. This means that a piece of information, in isolation, does not need to immediately identify someone. Information that can be associated or combined with other information can also allow for the identification of a person.
LGPD doesn’t protect data out of sheer fastidiousness.
Clear examples include full name, CPF (Brazilian tax identification number), and fingerprint. Information such as employee registration number, IP address, GPS data, address, vehicle license plate, and date of birth can also be considered personal data, depending on the context and the possibility of identification. How many times, in a group of people, does someone provide a seemingly random characteristic, and even without saying their name, everyone knows who is being talked about? The logic of identification through a combination of information works similarly.
“I only use my clients’ names, CPF numbers (Brazilian tax identification numbers), phone numbers, and addresses—just the basics!” The third justification, perhaps one of the most common, relates to the trivialization of personal data. But why consider names, CPF numbers, phone numbers, and addresses as “just the basics”?
This information, when gathered and used inappropriately, can represent a significant exposure. The magnitude of this risk can be understood from concrete situations in which criminals use this data to open a digital bank account in the person’s name for use as a “mule account”; transfer a cell phone number to another chip, taking control of a WhatsApp account to solicit money from contacts; fraudulently obtain loans or credit cards; make purchases in the victim’s name; or even personalized scams, in which information such as address and family names are used to lend greater credibility to the approach.
The pattern is evident. To some, this data may seem simple. To a fraudster, however, it can represent a set of information capable of enabling different types of fraud. The LGPD (Brazilian General Data Protection Law) does not protect data out of mere precision; it protects people.
The three justifications used to try to avoid the need for the company to adapt do not withstand an understanding of the basic concepts of the General Data Protection Law. Every company that processes personal data must observe the obligations set forth in the legislation and adopt appropriate measures to protect this information. Continuing to insist on myths that no longer hold up not only means ignoring the requirements of the law, but it can also expose the business to administrative sanctions, including fines that can reach 2% of the business’s revenue (article 52) per infraction committed, in addition to legal action and significant damage to its reputation.
The protection of personal data is an inherent responsibility of organizations. Compliance with the General Data Protection Law should not be understood as a business choice, but as a legal obligation that needs to be incorporated into the processes, decisions, and routines of organizations.
Helena Corrêa Soares
is a lawyer at the law firm Moraes & Gonçalves Advogados, with Executive Certification in Personal Data Protection and Artificial Intelligence Governance from the National Institute for Data Protection (INPD).