DPO Privacy
DPO Privacy
PlatformSolutionsAI governancePlansContentAbout us
PTENES
Book a demo
Book a demo
PlatformSolutionsAI governancePlansContentAbout usBook a demo
HomePublicationsData Subject Rights
Data Subject Rights

Data Subject Portal: How to Fulfill Data Subject Rights Under the LGPD

The LGPD (Brazilian General Data Protection Law) grants data subjects a series of rights over their personal data. Learn how to implement an efficient request portal that complies with the legislation.

R
Rafael Oliveira
February 05, 20269 min read

Articles 17 to 22 of the LGPD (Brazilian General Data Protection Law) grant data subjects a series of rights over their personal data, including access, rectification, erasure and portability. Companies need efficient channels to receive and fulfill these requests.

Data Subject Rights Under the LGPD

The LGPD establishes the following rights for personal data subjects:

  • Confirmation of processing: Knowing whether their data is being processed
  • Access: Obtaining a copy of the data processed
  • Rectification: Updating incomplete or outdated data
  • Anonymization: Requesting the anonymization of unnecessary data
  • Portability: Transferring data to another provider
  • Erasure: Requesting the deletion of data processed on the basis of consent
  • Withdrawal of consent: Withdrawing previously given consent
  • Objection: Contesting processing based on legitimate interests

Why Have a Dedicated Channel

The ANPD (Brazilian Data Protection Authority) recommends that companies maintain a specific channel to receive and process data subject requests. A dedicated portal offers:

  1. Complete traceability of requests
  2. Control of response deadlines (15 business days)
  3. Verification of the requester's identity
  4. Recording of evidence of request handling
  5. Generation of reports for audits
Legal deadline: The LGPD requires simplified access requests to be fulfilled immediately and complete requests within 15 business days. Failure to comply may lead to sanctions.

How to Implement the Portal

Essential Requirements

An efficient data subject portal should include:

  • An intuitive form for submitting requests
  • A field for selecting the type of right
  • Identity verification (documents, multi-factor authentication)
  • A secure communication channel between the data subject and the DPO
  • A dashboard for tracking the status of the request
  • Multilingual support where applicable

Best Practices

  • Publish the portal link in the privacy policy and in the website footer
  • Use QR codes on printed materials that collect data
  • Train the service team on LGPD rights
  • Automate deadline notifications to avoid non-compliance
Integrated portal: The DPO Privacy Data Subject Portal module includes identity verification, secure communication with the data subject, a compliance seal, QR code generation and complete traceability, all without the need for custom development.

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstration
Data Subject PortalDSARRightsLGPDRequest Handling
Share
R
Rafael Oliveira
DPO & Compliance Specialist
  1. Data Subject Rights Under the LGPD
  2. Why Have a Dedicated Channel
  3. How to Implement the Portal
  4. Essential Requirements
  5. Best Practices

Discover the platform

Centralize all data and privacy governance in one place.

Schedule a demo

Related articles

Data Subject Rights
March 09, 202612 min

Biometric data and facial recognition: when convenience does not replace necessity, proportionality and governance

Biometric data combines high impact and elevated risk. Learn why technological convenience does not replace the need for robust governance, especially under the new ANPD agenda.

R
Rafael Oliveira
DPO & Compliance Specialist
Data Subject Rights
March 09, 202615 min

Data subject rights and practical governance: why handling a request well takes much more than a service channel

Data subject rights are no longer just a legal topic of the LGPD (Brazilian General Data Protection Law); they have become one of the most sensitive points of data protection governance. Learn why structure and process are essential for a consistent response.

M
Maria Fernanda Costa
Head of Governance and Privacy

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstrationExplore features
Back to publications
DPO Privacy

Privacy and personal data protection governance platform for managing compliance with the LGPD (Brazilian General Data Protection Law) and the GDPR.

Platform

  • Modules
  • AI governance
  • Data and Technology
  • Enterprise
  • Plans
  • Security

Company

  • About us
  • Contact

Resources

  • Content
  • Help Center
  • Frequently asked questions

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© 2026 DPO Privacy · All rights reserved · Made in Brazil

Developed bysyntez