• About us
  • People
  • Solutions
  • Capabilities
  • Careers
  • Contact us
  • PT

Sign up for our newsletter

Get the latest insights and news. Register your email.

Subscribe

Our units

Berrini Unit - Rua James Joule, 65, 4º andar, Cidade Monções, São Paulo/SP
Paulista Unit - Alameda Joaquim Eugênio de Lima, 680
1º andar, Jardim Paulista, São Paulo/SP
Vila Olímpia Unit - Cubo Itaú - Alameda Vicente Pinzon, 54, Vila Olímpia, São Paulo/SP

Contact us

55 11 4040-9751 - Berrini 
55 11 2189-0061 - Paulista
contato@opiceblum.com.br

© 2025 All rights reserved. Site designed by FutureBrand
  • Privacy policy
  • Ethics channel

Privacy and Data Protection

We advise our clients on all aspects related to privacy and data protection. To this end, we are structured into three main areas:

  • Services for risk analysis, construction of privacy programs, as well as preparation and review of policies and procedures;
  • Services for managing the privacy program, either as an outsourced DPO (DPO as a Service), or support work for the DPO (Data Protection Officer) appointed by the company;
  • Consulting services, review of contracts and documents, and preparation of training and awareness materials.

Services

Projects for adapting to the LGPD (Brazilian General Data Protection Law): we offer consulting for private companies and public bodies, perform maturity diagnostics of personal data governance, and structure governance and compliance programs with the LGPD.

Maturity Audit of the Privacy Program: we align the level of maturity of the organization by applying a privacy framework developed by the firm. This process includes the analysis and validation of the evidence of the privacy program, identification of any inconsistencies, and formulation of recommendations for correction.

Review and preparation of policies and procedures: we provide consulting in the analysis, review, and preparation of various policies and procedures related to data protection, such as: privacy notices, sharing policy, privacy by design procedure, among others.

Personal Data Protection Impact Assessment (DPIA): preparation and review of personal data protection impact assessments, as a way to analyze specific processing activities that may generate risks to civil liberties and fundamental rights of data subjects, pointing out risks and appropriate mitigation measures.

Legitimate Interest Assessment (LIA): preparation and review of legitimate interest assessments, as a way to evaluate the elements that allow its attribution as a legal basis for a specific personal data processing activity.

Due Diligence in privacy and data protection: assessment of companies or assets to identify privacy and data protection risks in the main processes, products, and services targeted by the merger or acquisition (M&A) transaction, giving visibility on: i) serious risks that may compromise the acquirer's business; ii) effort required, time, and resources to correct and/or mitigate identified risks; and iii) any obstacles to the main databases of the target being used by the acquirer.

Cookie compliance: analysis of the website to identify cookies used and their purposes, as well as assessment of legal bases authorizing said cookies and preparation of a notice aimed at transparency to data subjects.

Measurement of the level of transparency: measurement of the level of transparency of our clients's; websites and applications, based on user experience, through a framework developed by the firm. The result of this work is an action plan to correct identified vulnerabilities.

Maturity measurement for incident response: measurement of the level of maturity of an organization to respond to security incidents involving personal data, through a framework developed by the firm. The result of this work is an action plan to correct identified vulnerabilities.

Maturity measurement for fulfilling data subject rights: measurement of the level of maturity of an organization to fulfill data subject rights, through a framework developed by the firm. The result of this work is an action plan to correct identified vulnerabilities.

Outsourced DPO (DPO as a Service): we act as the DPO of our clients, from formal appointment to the proactive management of compliance programs. For the development of this activity, we elaborate a plan with activity milestones for the next two years.

DPO support services: we also act as support to the DPO appointed by the organization. In these cases, we work together with the DPO to prepare the work plan, execute management activities, as well as other consulting activities in privacy and data protection.

Response to data subject rights: guidance, preparation, and/or review of formal responses to be presented to data subjects seeking to exercise their rights.

Mapping review: we review the record of personal data processing activities for validation of the legal basis and updating of information. We also recommend the preparation of Data Protection Impact Assessments.

Measurement of the level of severity in cases of security incidents: preparation of a report to indicate the level of severity of security incidents involving personal data, with a recommendation of communication to the National Data Protection Authority (ANPD) and data subjects.

Review of contracts: construction and review of privacy and data protection clauses for various legal instruments, such as contracts, addenda, data processing agreements, data transfer agreements, and contracts involving international transfer of personal data.

Preparation and review of documents: adaptation of documents to the LGPD and/or other applicable privacy and data protection laws and regulations. Preparation and review of documents, forms, terms of use, consent terms, and other terms for compliance with applicable data protection legislation.

Legal analyses: preparation of legal analyses assessing compliance requirements and any inherent risks to processing activities in light of applicable privacy and data protection laws and regulations, as well as their respective mitigating measures.

Preparation of training and capacity-building materials on privacy and data protection: preparation of guides, presentations, and other materials and documentation for training and awareness of employees, partners, and service providers.

Support in Security Incidents: analysis of security incidents involving personal data, with preparation of an incident score and recommendations regarding the need or not to notify competent authorities and data subjects involved.

Consultations: answering queries and clarifying specific doubts by telephone, email, or participation in meetings or videoconferences.

Our specialist team

Alessandra Borelli

Partner
Image without alt

Camilla Jimene

Partner
Image without alt

Danielle Serafino

Partner
Image without alt

Florence Terada

Partner
Image without alt

Henrique Fabretti

Partner and CEO
Image without alt

José Roberto Opice Blum

Founding Partner
Image without alt

Marcos Gomes da S. Bruno

Partner
Image without alt

Renato Opice Blum

Founding Partner and Chairman
Image without alt

See others practice areas

With rapid advances in algorithms and data processing, AI has impacted various sectors, such as healthcare, finance, and education. However, its increasing adoption raises ethical and legal questions, such as responsibility for automated decisions, data protection, and impacts on the labor market. The discussion about AI is fundamental to ensuring that its development and use are beneficial and equitable for society.

Learn more

Our Corporate and Digital Education team offers exclusive and customized content aligned with the needs of each client to raise awareness among employees and third parties about relevant topics involving Digital Law, Artificial Intelligence, Data Protection, Innovation, etc.

Learn more

Our Digital Tax team provides tax consulting on digital transformation operations, tax impacts on e-commerce, taxation of software, cryptocurrencies, crypto-assets, among others.

Learn more

Prevention and suppression of unlawful acts: suggestions for legal measures in relation to the improper access of personal accounts, creation of fake profiles, unauthorized sharing of photos and videos, among others.

Learn more

The financial and banking markets are constantly transforming thanks to technological advancements, innovation initiatives led by regulators, as well as the needs of customers who consume products and services offered in digital media.

We advise Financial Institutions, Payment Institutions, Credit Cooperatives, Fintechs, Exchanges, Insurers, International Payment Facilitators, Financial Market Associations, Direct Credit Companies, and Peer-to-Peer Lending Companies on various topics addressed by the sector's Regulatory Bodies, in addition to traditional Compliance topics and the development of new projects.

Learn more

The Intellectual Property team offers a full range of legal services related to the acquisition, enforcement, and commercialization of intellectual property and technology assets. Our services include consulting on contracts involving patents, copyrights, trademarks, outsourcing, privacy, and data security.

Learn more

Legal Innovation, Visual Law, Venture Capital & Startups

Aligning the legal field with innovation, the LegalX area develops and applies processes, practices, and solutions for our client's; businesses. Our area is composed of multidisciplinary professionals prepared to redefine the limits of what's possible in the scenario of Law, Technology, and Innovation.

Learn more

Our strategic approach supports our clients in various disputes, including cyber incidents, data class actions, data protection, technology-based solutions and services, and products.
Our Digital Litigation area is composed of three teams divided into service lines, which operate in a multidisciplinary manner: Scale, Special, and Standard.
 

Learn more

In the context of accelerating digital transformation, the interaction between Digital Law and other legal areas, such as Intellectual Property, Contracts, Media, and Entertainment, becomes increasingly evident.

Our TME team has professionals specialized in meeting the specific demands of this scenario, offering robust legal solutions through the preparation and review of contracts, opinions, and project feasibility studies.

We develop work methodologies oriented towards client centrality, addressing the main needs of the market. Our role is to act as partners to clients, helping them to enable businesses with legal security.

Learn more
See all practice areas