School Management
October 08, 2026
Challenges of LGPD in customer service for the construction industry in the Midwest region
Challenges of LGPD in Customer Service in the Civil Construction Sector in the Center-West Region
Juliana Laurindo de Sousa; Gabriela Trindade Pinheiro
DOI: 10.22167/2675-6528-202603082
Article derived from a Course Conclusion Work (TCC), with content based on the student’s original work and adapted to the editorial format of the E&S Magazine with the support of the ResumeAI tool, an artificial intelligence solution developed by Instituto Pecege for textual synthesis and organization.
Summary
The protection of personal data has become a central theme in Brazil after the enactment of the General Data Protection Law (LGPD). The present study aimed to analyze the challenges in applying the LGPD to consumer service processes in the civil construction sector. To this end, a case study was conducted in a company located in the Center-West region of Brazil. The methodology adopted was descriptive, with a quali-quantitative approach, using a structured questionnaire applied to 41 employees who directly handle personal data. Quantitative data were analyzed by descriptive statistics, and open-ended questions were interpreted qualitatively. The results showed a high level of contact with personal data and a perception of risks associated with its processing. The existence of gaps was observed related to the lack of process standardization, use of inadequate tools, absence of specific training, weaknesses in governance, and conflict between commercial goals and legal requirements. It was concluded that the implementation of the LGPD requires more than formal adjustments, demanding integration between governance, technology, and organizational culture, as well as its incorporation as a strategic element for information security and strengthening trust in consumer relations.
Keywords: compliance; civil construction; data governance; LGPD; data protection.
1. Introduction
The protection of personal data has emerged as a central theme in Brazil, driven by the significant increase in the collection and processing of information by companies, as well as by growing consumer awareness about their privacy. In this scenario, the enactment of the General Data Protection Law (LGPD – Law nº 13.709/2018) established clear guidelines for the processing of personal data, reinforcing the need for organizational compliance and guaranteeing rights to data subjects.
The internet, in turn, has consolidated itself as an indispensable tool in modern life, being widely used for various purposes. In 2023, the number of internet users globally surpassed 5.3 billion, with Brazil registering approximately 165 million people with internet access, which corresponds to more than 80% of the population and positions the country as the fifth in the world ranking of users (Statista, 2023). In the civil construction sector, especially in companies that incorporate and market real estate developments, a high volume of personal data from clients, suppliers, and partners is observed, making customer service processes particularly sensitive to LGPD compliance.
Despite the current legislation, the practical implementation of LGPD still reveals several gaps, generating risks of non-compliance, failures in privacy protection, and impacts on consumer trust (Carrilho, 2022). Among the most relevant challenges are the need to review internal data flows, update privacy policies, and train teams to meet new legal requirements. Small and medium-sized enterprises, in particular, face difficulties in understanding and applying LGPD provisions due to limited financial and human resources (Lima, 2024).
An additional challenge lies in the high costs associated with compliance, which involve the implementation of information security tools, the hiring of specialized audits, and the preparation of impact reports. The lack of specialized professionals, such as Data Protection Officers (DPOs), also compromises compliance (Lima, 2024). Furthermore, the limited action of the National Data Protection Authority (ANPD), with a reduced staff and budgetary restrictions, combined with the slowness of investigative processes, generates a perception of impunity that compromises the effectiveness of the legislation (Acioly et al., 2024; Loures, 2024). There is also a significant gap in population digital education, which hinders the full exercise of rights guaranteed by the LGPD, reducing social pressure for compliance (Oliveira, 2023).
Given this context, the investigation into the challenges in applying the LGPD in customer service becomes essential. This study allows for the identification of flaws that can compromise data protection and customer trust, in addition to supporting companies in the civil construction sector in adapting their processes. Understanding these challenges contributes to strengthening legal compliance, improving the compliance culture, and promoting secure and transparent personal information practices, benefiting both organizations and consumers (Boscolo, 2021).
The relevance of this research lies in its ability to offer subsidies for strengthening legal compliance and protecting consumers’ personal data privacy. Thus, the present study aimed to analyze the application of the General Data Protection Law (LGPD) in consumer service processes, through a case study conducted in a company in the civil construction sector, located in the Center-West region of Brazil, seeking to identify gaps and challenges in the practical implementation of the legislation and to subsidize the proposal of improvements.
2. Material and Methods
The present study adopted a quali-quantitative methodological approach, characterized as a descriptive research and a case study, according to the guidelines of Yin (2001) and Gil (2002). This methodological choice aligned with the objective of analyzing the application of the General Data Protection Law (LGPD) in consumer service processes, seeking to identify gaps and challenges in a specific organizational context. The descriptive nature allowed for the systematic survey of the sample’s characteristics, while the quali-quantitative approach enabled a comprehensive understanding of the investigated phenomenon.
The unit of analysis consisted of a company in the civil construction sector, located in the Center-West region of Brazil, which operates in the incorporation and commercialization of real estate developments. The study population comprised a total of 180 employees of the organization. The sample was composed of 41 participants, representing approximately 26% of the total population. A non-probabilistic convenience sample was chosen, defined based on respondent accessibility and specific inclusion criteria.
The inclusion criteria for participant selection were established to ensure the relevance of the collected information. Professionals directly involved in customer service processes and employees who handle personal customer data were included. Additionally, employees were required to have a minimum of six months of experience in the organization, ensuring familiarity with organizational processes and the research context.
The data collection was carried out by applying a structured questionnaire, available in Appendix A of the original work. The instrument consisted of 18 questions, which included open and closed items, organized into sections on participant profile, professional practice, and challenges and gaps related to the LGPD. The profile questions (1 to 8) and some on practice and challenges (9, 10, 12, and 17) were closed, with the latter formulated on a 5-point Likert scale, from 1 (totally disagree) to 5 (totally agree).
The questionnaire was made available in an online format, using the Google Forms platform, between January 13 and 22, 2026. Initially, information was disseminated to collaborators via institutional email, sent in a hidden list to ensure voluntary participation and confidentiality. Participants could fill out the questionnaire at their most convenient time and place, without prejudice to their work activities.
The data analysis was carried out through a quali-quantitative approach, as recommended by Lakatos and Marconi (2017). The quantitative data, from the profile questions and the Likert scale questions, were treated by descriptive statistics. For the profile questions (1 to 8), absolute and relative frequencies were calculated. For the Likert scale questions (9, 10, 12, and 17), measures of central tendency, such as the mean, and dispersion, such as the standard deviation, were used, following the guidance of Field (2009).
The open-ended questions (11, 13, 14, 15, 16, and 18) were subjected to a qualitative analysis of an interpretive nature. This procedure enabled the identification of patterns, recurring perceptions, and critical points expressed by the participants, deepening the understanding of the challenges and gaps in the application of LGPD in consumer service, according to the guidelines of Lakatos and Marconi (2017).
Throughout all stages of the research, ethical principles were rigorously observed. The secrecy and confidentiality of the collected information were guaranteed, and participants were informed about the voluntary nature of their participation. Furthermore, the right to not answer any questions or to withdraw from the research at any time, without the need for justification, was assured, reinforcing the autonomy of the collaborators.
As a limitation of the study, the use of a non-probabilistic sample and the research conducted in a single organization should be highlighted. Although this characteristic restricts the generalization of the results to other contexts, it did not compromise the validity of the analyses performed within the specific scope of the investigated company, providing valuable insights for its scenario.
3. Results and Discussion
The research results revealed a detailed panorama on the application of the General Data Protection Law (LGPD) in customer service processes in a company in the civil construction sector in the Center-West region of Brazil. The analysis of the data, collected through a structured questionnaire applied to 41 employees, allowed for the identification of the main challenges and gaps in the practical implementation of the legislation, as well as the perceptions of the professionals involved. A predominance of daily contact with personal data and a generalized awareness of the risks associated with its processing were observed, although with significant weaknesses in operational and governance aspects.
The sample of collaborators who participated in the study presented a balanced distribution between genders, with 53.6% women and 46.4% men. Regarding age group, the majority of respondents, 31.7%, were between 25 and 34 years old, followed by 22% in the 35 to 44 years and 45 to 54 years age groups. This demographic data indicates that most participants belong to the economically active population, a profile that, according to the Brazilian Institute of Geography and Statistics (IBGE, 2023), is associated with greater labor market insertion and, consequently, more frequent contact with organizational routines.
Regarding the level of education, it was found that 36.6% of respondents had completed undergraduate studies, and 26.8% had postgraduate studies. This predominance of employees with higher education or postgraduate degrees suggests a greater capacity to understand the requirements related to data protection and regulatory compliance, as pointed out by Chiavenato (2014). The literature also reinforces that professional qualification is intrinsically linked to the adoption of good organizational practices and compliance with legal requirements (Gil, 2002), which is a positive factor for the internalization of LGPD principles.
Regarding professional experience, 39% of respondents had more than five years of experience, indicating a consolidated workforce. Another 22% had been working for one to three years, and 19.5% had between six months and one year, or between three and five years. This diversity of experience can influence knowledge and perception levels regarding LGPD practices, as professional experience contributes to the development of skills and decision-making in the organizational environment (Dutra, 2017). The presence of professionals at different career stages can, therefore, generate a variety of perspectives on compliance challenges.
The analysis of the participants’ professional sector revealed a significant concentration in the Commercial and Sales sector, with 31 respondents, representing 75.6% of the sample. The Directorate (General Administration) accounted for 12.2%, and the Legal sector for 4.9%. This distribution highlights the predominance of areas with direct interface with clients and decision-making, characteristics of market-oriented and customer-relationship organizations (Kotler and Keller, 2012). The high exposure of these employees to the processing of personal data reinforces the criticality of LGPD compliance in this organizational context.
Performance, challenges and gaps
The results indicated a high frequency of contact by respondents with personal data, with 95.1% of participants stating they deal with this information daily. Only 2.4% declared dealing with personal data rarely, while the other categories did not show significant representation. This finding underscores that the processing of personal data is an intrinsic and routine part of the operational activities of the vast majority of employees, which increases the importance of robust data protection practices.
The processing of personal data occurs in multiple stages of professional activities, with emphasis on multichannel service, indicated by 56.1% of respondents, highlighting the centrality of direct customer contact. The formalization of contracts (48.8%) and financial profile analysis (46.3%) also stood out, indicating the strategic use of this information. Customer prospecting and registration, with 43.9%, were identified as critical stages, especially at the collection point, where attention to compliance is fundamental to avoid initial risks.
Support activities, such as internal data sharing (29.3%) and compliance with legal obligations (19.5%), although less frequent, represent sensitive points that require strict control. More specific functions, such as payment management (4.9%), indicate a more restricted, but equally critical, use of data. Overall, it is perceived that the risks related to data processing are distributed across various operational stages, with a higher concentration in customer service, registration, analysis, and contract activities, which reinforces the need for adequate controls and organizational practices throughout the value chain.
Regarding the criticality of personal data, financial data was the most pointed out as critical by 58.5% of respondents, followed by registration data (43.9%) and contractual data (31.7%). Credit data (24.4%) was also highlighted, while third-party and location data (7.3%) were less mentioned. This perception may indicate an underestimation of the risks associated with less obvious, but equally sensitive, data categories, highlighting the need for a more comprehensive understanding of the criticality of different types of information.
The analysis of the Likert scale structured questions (Q09, Q10, Q12, and Q17) revealed a tendency of agreement among respondents, with most answers concentrated in the “agree” and “strongly agree” levels. The sample mode of 4 in all questions indicates that “agree” was the most frequent option. This predominance of positive perception suggests that participants have a general alignment regarding personal data protection practices and conditions in the organizational environment, although the depth of this understanding may vary.
In question 09, 82.9% of respondents recognized the existence of procedures that can generate risks to data privacy in their sectors. This high percentage demonstrates significant awareness of the vulnerabilities present in daily operations. However, the perception of the existence of risks does not automatically translate into effective mitigation actions, which may indicate a gap between awareness and the implementation of robust preventive measures, as discussed by Bioni (2020) and Zuboff (2019) on the difference between discourse and practice.
Question 10, which addressed difficulties in complying with LGPD requirements, had 70.7% of participants indicating agreement, although with a greater presence of responses at intermediate levels of the scale. This suggests that, despite the perception of risks, the difficulties in applying LGPD are not uniformly felt or fully recognized. The variability in responses may reflect different levels of engagement with the regulations or the existence of sectors with a greater or lesser degree of compliance, demanding a more granular analysis of critical areas.
In question 12, which questioned the company’s full alignment with LGPD requirements, one of the highest levels of agreement was observed, with 87.8% of respondents positioning themselves at the “agree” and “strongly agree” levels. This high degree of consensus indicates a general perception that the company has not yet achieved full compliance. This perception is crucial because, even with adaptation efforts, the persistence of gaps recognized by employees themselves signals the need for deeper and more comprehensive interventions to achieve effective compliance.
Question 17, which assessed whether the company’s current procedures posed a significant risk to data privacy, also registered high agreement, with 85.4% of participants indicating yes. Although the majority agree, the presence of 14.6% of responses at lower levels suggests the existence of divergent perceptions among employees. These results, taken together, indicate that employees are aware, to varying degrees, of the practices related to the processing of personal data, as well as the associated risks and responsibilities, aligning with studies that highlight the importance of organizational awareness for data governance (Doneda, 2020).
The analysis of the open-ended questions allowed for a deeper understanding of the results, identifying relevant thematic patterns and categories in the participants’ responses. The collaborators’ perceptions were compared with the literature on LGPD challenges and gaps, revealing points of convergence and divergence that enrich the discussion on the effectiveness of data protection in the civil construction sector. This qualitative approach complemented the quantitative data, offering a more holistic view of the challenges faced by the organization.
Process standardization
Respondents pointed to the absence of clear standards among teams and discrepancies in data collection and treatment as a significant challenge. This lack of standardization generates inconsistencies and increases operational risks, making it difficult to uniformly apply LGPD guidelines. The literature, in turn, emphasizes that process standardization is essential to ensure compliance and reduce risks, promoting the security and integrity of personal data (Teffé and Viola, 2020). Inconsistency in practices can lead to protection failures and potential violations of the law.
Training and development
The research highlighted a clear lack of specific training and practical guidance on LGPD for employees. Many professionals feel unprepared to deal with the law’s requirements in their daily routines. Academic literature corroborates this perception, emphasizing that training and capacity building are fundamental for the internalization of data protection within organizations (Pinheiro, 2021). Without a continuous and targeted training program, awareness of LGPD may remain superficial, not translating into effective compliance practices.
Organizational culture
LGPD is perceived by employees as a bureaucratic process poorly integrated into the organizational routine. This formalistic view prevents data protection from being incorporated as a cultural value. Miragem (2021) argues that data protection depends on building a privacy-oriented organizational culture, where compliance is not just a legal obligation, but an intrinsic principle of operations. The absence of a robust privacy culture compromises the effectiveness of data protection policies and procedures.
Governance and control
The results indicated a lack of clear definition of responsibilities and access control to data. This gap in governance can lead to ambiguities about who is responsible for data protection and how access is managed. Pinheiro (2021) emphasizes that structured governance is essential to ensure security and compliance, establishing roles, responsibilities, and control mechanisms. The absence of these elements weakens the organization’s ability to manage risks and respond effectively to security incidents.
Tools and technology
Collaborators reported the use of obsolete systems and informal tools, such as WhatsApp and spreadsheets, for the processing of personal data. These practices significantly increase the risks of information leakage and inconsistency. Technological adequacy is crucial for data control and security, as pointed out by Teffé and Viola (2020). Crespo (2020) adds that the use of outdated and non-integrated systems amplifies the risks of inconsistency and leakage, hindering the proper management of personal data and compromising the effectiveness of protection.
Consumer transparency
A lack of clarity regarding data usage and inadequate communication with consumers was identified. This gap in transparency can undermine data subjects’ trust and hinder the exercise of their rights. Miragem (2021) highlights transparency as a central element in data protection and in building a trusting relationship with the consumer. Clear communication about how data is collected, used, and protected is fundamental for compliance and for the company’s reputation.
Business Goals and compliance
Respondents perceived pressure for commercial results that, in many cases, negatively impacts data protection practices. This tension between sales goals and legal requirements can lead to shortcuts or negligence in compliance. Pinheiro (2021) argues that LGPD compliance should be aligned with organizational strategy, not seen as an obstacle, but as a competitive differentiator. The conflict between commercial objectives and data protection is a significant risk to the effectiveness of LGPD in practice.
Monitoring and auditing
The research revealed the absence of continuous oversight and process review, indicating a weakness in monitoring mechanisms. The lack of internal audits and regular controls prevents proactive identification of failures and correction of deviations. Teffé and Viola (2020) emphasize that internal audits and controls are essential for the effectiveness of the LGPD, ensuring that policies and procedures are followed and that the organization is constantly improving. Without monitoring, gaps can persist and worsen.
Additionally, question 11, which is open-ended, allowed participants to detail procedures potentially incompatible with the LGPD. Informal data sharing, lack of standardization, inadequate document storage, use of personal channels for communication, and lack of training and guidance were mentioned. Excessive data collection, weaknesses in consent, and prioritization of commercial agility over transparency were also pointed out. These findings indicate gaps not only in operations but also in governance, reflecting difficulties in internalizing the norms in daily organizational life, according to Pinheiro (2021).
Question 13 deepened the discussion on inadequate tools, highlighting the use of personal communication applications, spreadsheets without access control, obsolete systems, and poorly organized physical documents. The identified weaknesses included the absence of access control, non-existence of audit trails, lack of integration between systems, and insufficiency of institutional guidance. These results corroborate the literature that points to the absence of adequate technical and organizational controls as one of the main challenges for the effectiveness of data protection (Crespo, 2020).
In question 14, respondents suggested actions to strengthen data protection, such as process standardization, employee training, governance improvement, and modernization of technological tools. Specific proposals included more targeted training, definition of criteria for data collection and processing, and improvement in information control and storage. The importance of aligning business practices with LGPD requirements, with integration between areas and incorporation of compliance into organizational strategies, was also highlighted, in line with Maldonado et al. (2020).
Question 16 revealed high convergence in responses regarding the necessary measures for LGPD compliance, emphasizing employee training, internal audits, adoption of secure technologies, and strengthening institutional support. The recurring demand for training and process review indicates gaps in employee preparation and in the monitoring structure of organizational practices. The need for tools that ensure greater control and security in data processing, as well as continuous support from compliance and legal departments, aligns with literature that highlights the importance of implementing internal control mechanisms and risk management (Frazão and Mulholland, 2019).
Finally, question 18, which requested final comments, brought a more critical perception of the gaps and risks, reiterating the absence of standardization, weaknesses in governance, and risks of undue information exposure. The conflict between commercial goals and compliance practices was again evidenced, indicating that the pressure for results can compromise compliance with LGPD requirements. The need for greater transparency in consumer relations and integration between organizational areas was also highlighted, aligning with literature that points to the effectiveness of data protection as dependent on the construction of an organizational culture oriented towards privacy and the reduction of informational asymmetry in consumer relations (Sarlet, 2018).
In summary, the research results confirmed that, although there is a widespread perception of the importance of personal data protection and the existence of risks, the company studied in the civil construction sector still faces significant challenges in the effective application of the LGPD. The identified gaps in process standardization, employee training, data governance, technological adequacy, and organizational culture indicate that compliance is often treated as a formal requirement, rather than an integrated strategic element. Overcoming these challenges demands a holistic approach that aligns governance, technology, and culture, promoting information security and strengthening consumer trust, as per the central objective of this study.
4. Conclusion
This study aimed to analyze the application of the General Data Protection Law (LGPD) in consumer service processes in a company in the civil construction sector in the Center-West region of Brazil, with the intention of identifying gaps and challenges and supporting the proposal of improvements. It was found that employees maintain a high level of daily contact with personal data and are aware of the risks inherent in its processing. However, significant weaknesses were identified, such as the lack of process standardization, the use of inadequate technological tools, the lack of specific training, and the lack of clarity in data governance. A conflict was also observed between commercial goals and legal requirements, which impacts the effectiveness of data protection practices. The main contribution of this work lies in the explicitation of these gaps, offering subsidies for the organization to strengthen its legal compliance, improve its compliance culture, and promote safer and more transparent practices in the processing of personal information, benefiting both the company and its consumers.
Despite the relevance of the findings, the study presents as limitations the use of a non-probabilistic sample and the research conducted in a single organization, which restricts the generalization of the results to the construction sector as a whole, although it does not compromise the validity of the analyses in the investigated context. It is concluded that the effective implementation of the LGPD in the company demands more than formal adjustments, requiring the adoption of more structured practices that promote alignment between governance, technology, and continuous employee training. Standardization of processes, modernization of technological tools, and strengthening of data governance are suggested, with clear definition of responsibilities and the performance of internal audits. It is recommended that data protection be incorporated as a strategic element, not just a bureaucratic one, for information security and strengthening trust in relationships with consumers. For future studies, it is proposed to expand the research to other companies in the sector, allowing for a comparative analysis and the identification of broader patterns in the application of the LGPD.
Bibliographic References
Acioly, L.H.M.;Silva, M.F.; Monteiro Neto, J.A. 2024. A Emenda Constitucional n° 115 de 10 de fevereiro de 2022 e o enforcement da proteção de dados pessoais no Brasil. Revista de investigações Constitucionais 11(3): e275-e275.
Bioni, B. R. 2020. Proteção de dados pessoais: a função e os limites do consentimento. 1ed. RT, São Paulo, SP, Brasil.
Boscolo, M.J.O. 2021. Uma análise dos efeitos da Lei Geral de Proteção de Dados nas relações de consumo e os parâmetros para o uso de dados pessoais. Monografia em Direito Empresarial. Insper, São Paulo, SP, Brasil.
Carrilho, V.E.F. 2022. Implementação da LGPD em uma empresa do ramo de construção civil em Criciúma/SC. Monografia em Ciência da Computação. Universidade do Extremo Sul Catarinense, Criciúma, SC, Brasil.
Chiavenato, I. 2014. Introdução à teoria geral da administração: uma visão abrangente da moderna administração das organizações. 8.ed. Elsevier, Rio de Janeiro, RJ, Brasil.
Crespo, M. X. F. 2020. Proteção de dados pessoais: fundamentos e desafios na implementação da LGPD. 1ed. Thomsom Reuters Brasil, São Paulo, SP, Brasil.
Doneda, D. 2020. Da privacidade à proteção de dados pessoais. 1ed. Forense, Rio de Janeiro, RJ, Brasil.
Dutra, J.S. 2017. Competências: conceitos, instrumentos e experiências. 2ed. Atlas, São Paulo, SP, Brasil.
Field, A. 2009. Descobrindo a estatística usando o SPSS. 2ed. Artmed, Porto Alegre, RS, Brasil.
Frazão, A.; Mulholland, C. 2019. Proteção de dados pessoais: fundamentos e perspectivas. 1ed. Thomsom Reuters Brasil, São Paulo, SP, Brasil.
Gil, A.C. 2002. Como elaborar projetos de pesquisa. 4ed. Atlas, São Paulo, SP, Brasil.
Instituto Brasileiro de Geografia e Estatística [IBGE]. 2023. Anuário estatístico do Brasil: trabalho e rendimento. Rio de Janeiro, RJ, Brasil. Disponível em: <https://anuario.ibge.gov.br/2023>. Acesso em: 04 fev. 2026.
Kotler, P.; Keller, K.L. 2012. Administração de marketing. 14ed. Pearson Education do Brasil, São Paulo, SP, Brasil.
Lima, J.C. 2024. Lei Geral de Proteção de Dados: desafios e aplicação prática nas organizações. 1ed. Atlas, São Paulo, SP, Brasil.
Loures, M. O. R. 2024. A eficácia da fiscalização e sanção da Lei Geral de Proteção de Dados: propostas de melhoria para a atuação da autoridade nacional de proteção de dados baseadas no modelo francês. Monografia em Direito Digital. Centro Universitário de Brasília, Brasília, DF, Brasil.
Maldonado, V.N.; Blum, R. O. 2020. LGPD: Lei Geral de Proteção de Dados comentada. 1ed. Revista dos Tribunais, São Paulo, SP, Brasil.
Marconi, M.A.; Lakatos, E.M. 2017. Metodologia científica. 7ed. São Paulo, SP, Brasil.
Miragem, B. 2021. Proteção de dados pessoais e defesa do consumidor. 1ed. RT, São Paulo, SP, Brasil.
Oliveira, D.C. 2023. Direitos fundamentais e a era digital: limites no exercício dos direitos fundamentais e sua aplicação na internet. Monografia em Direito. Centro Universitário de Ciências Gerenciais de Manhuaçu, Manhuaçu, MG, Brasil.
Pinheiro, P.P. 2021. Proteção de dados pessoais: comentários à LGPD. 1ed. Saraiva, São Paulo, SP, Brasil.
Sarlet, I. W. 2018. A eficácia dos direitos fundamentais: uma teoria geral dos direitos fundamentais na perspectiva constitucional. 13ed. Livraria do Advogado, Porto Alegre, RS, Brasil.
Statista, 2023. Number of internet and social media users world wides of October 2023. Disponível em: https://www.statista.com/statistics/617136/digital-population-worldwide/. Acesso em: 14 out. 2025.
Teffé, C.S.; Viola, M. 2020. A aplicação da Lei Geral de Proteção de Dados (LGPD) e os desafios regulatórios no Brasil. Revista de Direito Civil Contemporâneo 25: 1-20.
Yin, R. 2001. Estudo de caso: planejamentos e métodos. 2ed. Bookman, Porto Alegre, RS, Brasil.
Zuboff, S. 2019. A era do capitalismo de vigilância. 1ed. Intrínseca, Rio de Janeiro, RJ, Brasil.
Article originating from the Final Course Work of the Specialization in Compliance and ESG of the MBA USP/Esalq
To learn more about the course, click here and access the MBX Academy platform