Use this guide to build an LGPD evidence file, distinguish it from a under another framework, assign the decision, and preserve the records behind each risk conclusion.
1
Section 1
What should teams decide about RIPD and DPIA Evidence under the Brazil LGPD?
Identify the controller, project or process, purposes, legal bases, data, people, systems, operators, recipients, international transfers, retention, and decision date. Record whether the responds to an ANPD request or to the controller's high-risk assessment. The ANPD recommends preparation before begins, but the LGPD does not impose a universal pre-launch report for every activity.
Until a specific regulation supplies another test, ANPD guidance treats Resolution 2/2022's high-risk criteria as a non-exhaustive screening parameter. That test requires at least one general criterion - large scale or a possible significant effect on interests and fundamental rights - together with at least one specific criterion: emerging or innovative technology, monitoring a publicly accessible area, a decision based solely on automated processing, or sensitive data or data about children, adolescents, or older people.
For example, large-scale health-data processing meets a general and a specific criterion. A solely automated decision that may deny a service also combines a specific criterion with a possible significant effect on rights. A small pilot using innovative technology meets only a specific criterion unless another fact supplies a general criterion, although the controller may still find high risk on other facts because the ANPD screen is non-exhaustive.
Use the term only for a report prepared under another framework or as an internal label. Reuse its evidence where the facts match, then complete the LGPD-specific trigger, legal bases, Article 38 minimum content, rights, transfer, secrecy, ANPD-request, and controller-approval analysis.
Keep the high-risk screen with facts for each Resolution 2/2022 general and specific criterion.
Link data maps, system diagrams, notices, legal-basis analysis, contracts, retention rules, and transfer mechanisms to the report version.
Record consulted parties and material divergent views, including the controller's reason for the selected course.
Keep evidence in a controlled internal file; a public summary may omit protected commercial, industrial, security, or other confidential information.
Who should own RIPD and DPIA Evidence, and what evidence should prove the decision?
The controller owns the and final processing decision. Product and operations supply processing facts; privacy or legal tests purposes, legal bases, necessity, proportionality, rights, and transfers; security supplies threat, control, testing, and incident evidence; operators provide facts within their control; the encarregado should be consulted where designated.
Article 38's minimum evidence is the personal-data types, collection and information-security methodology, and the controller's analysis of measures, safeguards, and risk mitigation. ANPD guidance recommends adding the full lifecycle, purposes, legal bases, affected people, necessity, proportionality, risks, and planned measures.
For each risk, retain the event, cause, affected people, possible harm, existing controls, likelihood, impact, combined effects, chosen treatment, owner, date, test evidence, and residual risk.
For each safeguard, distinguish a planned control from an implemented and verified control.
Record the controller representative who accepts residual risk or requires a change, plus any conditions for launch or continued processing.
Keep stable evidence references so a later reviewer can reproduce the conclusion from the version approved.
Which edge cases should teams check before relying on a RIPD and DPIA Evidence decision?
Do not treat a signed report as proof that its safeguards work. Verify access controls, encryption, deletion, monitoring, rights handling, operator instructions, incident escalation, and other claimed measures against current technical or operational evidence.
A private-sector controller generally need not publish the full or send it to the ANPD without a request. Public bodies must also consider Article 32 and access-to-information and secrecy rules. When publishing a summary, preserve the internal evidence needed for accountability.
Separate legal requirements, ANPD recommendations, internal risk policy, and another jurisdiction's rules.
Do not reuse a group report when the Brazilian controller, purpose, legal basis, people, transfer, or risk differs.
Keep unresolved facts visible and condition approval on their resolution when they could change the result.
Protect security architecture and commercial or industrial secrets while still providing the ANPD-required scope when requested.
How should teams operationalize RIPD and DPIA Evidence with proportionate controls?
Reopen the evidence file when a purpose, data category, affected population, automated decision, technology, operator, destination, retention period, interface, threat, incident, complaint pattern, control result, or rule changes. Keep prior versions and explain what changed.
The final record should state whether processing may proceed, must change, is paused, or should stop. List every required measure, owner, due date, validation method, residual risk, approver, condition, and next review trigger.
Preserve the approved report, evidence index, consultation record, divergent views, risk acceptance, and mitigation verification.
Confirm that production processing still matches the approved data map and purpose.
Track open measures until evidence proves implementation; a planned ticket is not a completed safeguard.
Prepare a protected disclosure copy if the ANPD requests the report, without altering the underlying approved record.