PRIVACY · GDPR · LGPD

Data protection engineered into the way technology works.

A practical knowledge centre for privacy principles in Europe and Brazil, and the engineering practices Feitorix uses to support responsible data handling.

Information, not legal advice

This page provides general information about data protection and engineering practices. It does not constitute legal advice, certification or a claim that every client environment is automatically compliant. Regulatory obligations depend on the specific processing context.

REGULATORY KNOWLEDGE

Two important data protection frameworks.

Feitorix operates with awareness of the European GDPR and Brazil’s LGPD when designing systems that may process personal data.

EU / EEA

General Data Protection Regulation (GDPR)

The GDPR establishes rules for processing personal data in the EU/EEA and places accountability, transparency and protection of individuals at the centre of data processing.

Core principles

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

Data subject rights

Rights include information, access, rectification, erasure in applicable circumstances, restriction, portability, objection and safeguards around automated decision-making.

European Commission — official guidance
BRASIL

Lei Geral de Proteção de Dados (LGPD)

Brazil’s LGPD establishes principles, rights and responsibilities for personal-data processing and is supervised by the Autoridade Nacional de Proteção de Dados (ANPD).

Core principles

  • Purpose, adequacy and necessity
  • Free access and data quality
  • Transparency
  • Security and prevention
  • Non-discrimination
  • Accountability and demonstration of compliance

Data subject rights

Rights include confirmation and access, correction, anonymisation/blocking/deletion in applicable circumstances, portability, information about sharing, consent withdrawal and review of certain automated decisions.

ANPD — data subject rights
PRIVACY ENGINEERING

Turning principles into technical decisions.

Legal compliance cannot be created by a website badge. Good engineering can, however, make privacy obligations easier to implement, evidence and operate.

Data minimisation

Collect and expose only the data needed for a defined business purpose.

Least-privilege access

Design role-based access and limit privileged operations to authorised users.

Auditability

Create traceable records for material actions, changes and security-relevant events.

Retention awareness

Design data lifecycles so retention and deletion rules can be applied deliberately.

Security by design

Use secure defaults, encryption where appropriate, secrets protection and defensive application design.

Rights support

Design data models and workflows that can support access, correction, export and deletion requests where applicable.

TRUST BY DESIGN

Privacy is strongest when it is considered before production.

Explore Trust Center