Fermin Piccolo
Founder, Arqueum
Published on · 7 min read
Digital transformation has led most corporate information to be stored in digital repositories, whether in cloud “drives” or in EDM (Electronic Document Management) systems – cloud services or solutions running within the organization’s infrastructure (on-premise). Added to this scenario, and to the enormous amount of data generated every year, the adoption of artificial intelligence (AI), especially generative models, is accelerating in Brazilian organizations.

To get a sense of the order of magnitude of this volume of information, look at the table below and consider that a PDF is typically between 5MB and 50MB and a web page between 2MB and 3MB:
| Unit | Equivalence in bytes | Relation to 1 ZB |
|---|---|---|
| 1 ZB (Zettabyte) | 10²¹ bytes | 1 ZB |
| 1 EB (Exabyte) | 10¹⁸ bytes | 1 ZB = 1,000 EB |
| 1 PB (Petabyte) | 10¹⁵ bytes | 1 ZB = 1,000,000 PB |
| 1 TB (Terabyte) | 10¹² bytes | 1 ZB = 1,000,000,000 TB |
| 1 GB (Gigabyte) | 10⁹ bytes | 1 ZB = 1,000,000,000,000 GB |
| 1 MB (Megabyte) | 10⁶ bytes | 1 ZB = 1,000,000,000,000,000 MB |
Even with this ocean of information, many managers believe that structuring folders and standardizing file names, keeping control in “master spreadsheets” or systems with basic features, is enough to demonstrate compliance with the Brazilian General Data Protection Law (LGPD).
However, the LGPD is built on principles such as respect for privacy, informational self-determination, freedom of expression and technological development. These foundations show that simply organizing documents does not guarantee transparency, security or accountability, and that governance, traceability and control mechanisms must be implemented.
Legal foundations of the LGPD and their implications
The LGPD applies to any data processing operation, including in digital media, and protects fundamental rights such as privacy, honor and image. It establishes principles of purpose, necessity, transparency, security, prevention and accountability. The sanctions provided for non-compliance include warnings, public disclosure of the violation and fines of up to 2% of the company’s revenue, capped at R$ 50 million per violation. The law also provides for the blocking or deletion of data and, in the most serious cases, the suspension of personal data processing activities. This framework shows that information management, and document management in particular, must make it possible to prove compliance, since failures can lead not only to financial penalties but also to reputational damage and the shutdown of activities.
Why organizing folders is not enough
Organizing folders, naming files and classifying them by type and characteristics (taxonomy) are important practices, but they do not meet the LGPD’s compliance requirements. The LGPD Implementation Manual of the State of Paraná explains that becoming compliant requires steps such as mapping the processing of personal data, surveying risks, preparing data protection impact reports, creating privacy and incident-handling policies, appointing a data protection officer, training teams and linking compliance to the LGPD. The document emphasizes that, beyond awareness, governance must involve analysis, planning and control of data use, with periodic assessments to measure the level of maturity and implement improvements.
Another critical point is the classification of information from the standpoint of criticality and confidentiality – not merely simple document classification. The Document Management Manual of the Brazilian Judiciary distinguishes classification for the organization of files from classification related to confidentiality. When classifying a document as confidential, the guidelines of the Access to Information Law and of the LGPD itself must be applied, and the level of confidentiality (top secret, secret or restricted) must be recorded in the computerized document management system. That system must automatically restrict access according to the confidentiality level and keep records, since digital documents require technical mechanisms to ensure these obligations are met. In other words, filing correctly does not eliminate the need for technical access controls, labeling and logs.
Good practices in document management and data governance
Document governance combines processes, people and technology. The Paraná manual points out that implementing the LGPD in public bodies begins with a mapping of personal data to understand the flow, catalog the databases and identify risks. The survey must be documented in electronic systems and updated periodically, serving as the basis for preparing action plans, privacy policies and incident response procedures. The data protection impact report (RIPD) is another essential instrument: it describes the processes that may generate risks, indicates safeguards and must be reviewed whenever changes occur.

The manual of the National Council of Justice reinforces that, when classifying documents as confidential, the body must store them in systems that record the confidentiality level and restrict access according to each level. All actions involving case initiation, processing, data entry, consultation and archiving require their own records and controls, since confidentiality classification is not to be confused with archival classification. This manual also advises that document management policies be integrated with data protection through the joint action of document assessment commissions and data protection committees, ensuring that actions to disseminate and provide access to the collection take LGPD requirements into account.
AI adoption and new risks
Advances in generative AI bring benefits, but they also amplify privacy risks. The technology radar of the Brazilian National Data Protection Authority (ANPD) highlights that the coexistence of personal and non-personal data in the models and the generation of synthetic content increase the likelihood of processing personal data without safeguards, potentially violating the principles of necessity and transparency. Generated content can be indistinguishable from real data and improperly associated with individuals. The document warns that these systems have a low level of transparency because they are complex and opaque methodologies, which demands attention to the LGPD’s principles.
Another excerpt from the radar explains that generative AI systems can generate personal data without having been trained for that purpose and that the broad concept of data sharing covers information submitted by the user, the disclosure of outputs and the reuse of pre-trained models. Users can paste entire documents into the prompt, and outputs can include sensitive personal data. In these circumstances, shifting the responsibility for data protection onto the user is insufficient; it is necessary to establish a chain of responsibility among the processing agents to ensure compliance.
Security concerns are reinforced by international studies. The Amazon Web Services (AWS) white paper Navigating the security landscape of generative AI notes that generative models are reshaping data management but amplify security risks and introduce new attack vectors, such as context window overflows and prompt injections. These systems must be held to the same compliance and regulatory standards as other technologies, and organizations that adopt an agile approach to security will be better positioned.
Shadow AI and the risk of leaks
The popularization of generative tools has resulted in the phenomenon of shadow AI – the use of AI applications by employees without the knowledge or approval of the IT and Corporate Governance teams. Microsoft’s data-leak prevention blueprint defines shadow AI as the use of AI by employees without governance and warns that, if these risks are not addressed, leakage of sensitive data, regulatory non-compliance and reputational damage may occur. The document highlights that the improper use of AI outside the corporate environment can expose confidential information and recommends detecting the use of AI applications, blocking access to unsanctioned tools, labeling and protecting sensitive information, and auditing interactions. This reinforces the importance of offering official AI channels with access policies and monitoring, rather than simply banning use.

Consequences of non-compliance and reputation
Beyond the financial fines already mentioned, the lack of governance can result in the blocking of databases, suspension of processing activities or deletion of data. Data leaks or the misuse of AI also affect the company’s reputation and can translate into a loss of trust from customers and partners. To avoid this damage, it is essential to implement:
-
Data inventory and classification – catalog the types of data processed, assign access levels and apply automated labeling according to the confidentiality level;
-
Traceability and audit trails – record who accesses, changes or shares documents; without logs it is impossible to demonstrate compliance or investigate incidents;
-
Version control and lifecycle management – keep document versions and define retention and disposal periods;
-
Risk management and impact reports (RIPD) – identify risks in processing operations, establish safeguards and periodically review the report;
-
Training and a security culture – train teams in the ethical handling of data and the responsible use of AI. This reduces the risk of shadow AI and other unsafe practices.
Conclusion
Compliance with the LGPD requires more than organized folders or cloud repositories. The law’s legal principles emphasize privacy, transparency and accountability, and its sanctions underscore the severity of violations. Corporate content governance must incorporate proper classification, access restriction, traceability, version control and clear processing policies. Data mapping, risk assessment and the preparation of impact reports are pillars for building compliance programs.
In parallel, the accelerated adoption of AI and the shadow AI phenomenon demand heightened attention: generative models can mix personal data and generate synthetic content that hampers transparency, and unsupervised use of AI can lead to leaks and fines.
By integrating document management and information security with ethical and governance principles, companies reduce risks, protect their reputation and ensure a responsible transition to the age of artificial intelligence.