Data Protection Officer (DPO) Responsibilities and Annual Work Program
Structure the responsibilities, metrics, and annual work program for the Data Protection Officer (DPO) under Brazil's LGPD data protection framework.
Define the DPO's scope of work, legal responsibilities, and a work program that ensures ongoing LGPD compliance.
At a glance
Access
Free prompt
Open to copy without upgrading.
Prompt objective
Define the DPO's scope of work, legal responsibilities, and a work program that ensures ongoing LGPD compliance.
Real use case
EduTech Brasil, an online learning platform with 350,000 enrolled students including minors, appointed their legal manager as DPO while maintaining existing responsibilities. They need a structured program to execute legal obligations without abandoning other duties.
Customize these fields first
Replace the placeholders with your own context before you run the prompt. That usually improves the first output more than adding more instructions later.
Prompt
Structure the responsibilities and annual work program for the Data Protection Officer (DPO) at [COMPANY NAME], operating in the [INDUSTRY] sector, with [NUMBER] registered data subjects.\\\\\\\\n\\\\\\\\n**DPO Profile:**\\\\\\\\n- Commitment: [EXCLUSIVE ROLE / COMBINED WITH OTHER DUTIES / OUTSOURCED (DPO as a Service)]\\\\\\\\n- Reports to: [TITLE/ROLE]\\\\\\\\n- Support team: [NUMBER] people\\\\\\\\n\\\\\\\\n**1) Legal Responsibilities of the DPO (Art. 41, LGPD):**\\\\\\\\n - Accept complaints and communications from data subjects\\\\\\\\n - Receive communications from the ANPD (data protection authority)\\\\\\\\n - Advise employees and contractors on data protection practices\\\\\\\\n - Execute other responsibilities assigned by the controller\\\\\\\\n - Practical detail of each responsibility with processes and SLAs\\\\\\\\n\\\\\\\\n**2) Additional Responsibilities (best practices):**\\\\\\\\n - Oversee the privacy program\\\\\\\\n - Participate in new project reviews (privacy by design โ Art. 46, ยง2)\\\\\\\\n - Lead or oversee Data Protection Impact Assessments (DPIAs)\\\\\\\\n - Monitor LGPD compliance\\\\\\\\n - Manage the register of processing activities (Art. 37)\\\\\\\\n - Serve as point of contact for security incidents\\\\\\\\n - Maintain relationship with the ANPD\\\\\\\\n - Track ANPD regulations and updates\\\\\\\\n\\\\\\\\n**3) Annual Work Program** (12 months):\\\\\\\\n\\\\\\\\n| Month | Primary Activity | Deliverable |\\\\\\\\n|-------|--------------------|-----------|\\\\\\\\n| Jan | [ACTIVITY] | [DELIVERABLE] |\\\\\\\\n| ... | ... | ... |\\\\\\\\n| Dec | [ACTIVITY] | [DELIVERABLE] |\\\\\\\\n\\\\\\\\nInclude:\\\\\\\\n- Data inventory updates (semi-annual)\\\\\\\\n- Staff training (quarterly)\\\\\\\\n- Compliance audit (annual)\\\\\\\\n- Operator contract review (semi-annual)\\\\\\\\n- Incident plan testing (semi-annual)\\\\\\\\n- Executive reporting (quarterly)\\\\\\\\n- Policy updates (as needed)\\\\\\\\n\\\\\\\\n**4) DPO KPIs:**\\\\\\\\n - Average response time to data subject requests (target: < [NUMBER] days)\\\\\\\\n - % of processing activities with documented legal basis\\\\\\\\n - % of staff trained\\\\\\\\n - Number of incidents vs. previous year\\\\\\\\n - Incident detection and response time\\\\\\\\n - DPIAs conducted vs. new projects\\\\\\\\n - Operator contract compliance\\\\\\\\n\\\\\\\\n**5) Independence and Governance:**\\\\\\\\n - Technical autonomy guarantee (no conflicts of interest)\\\\\\\\n - Direct access to senior management\\\\\\\\n - Necessary resources and budget\\\\\\\\n - Protection against retaliation\\\\\\\\n\\\\\\\\n**6) Data Subject Channel:**\\\\\\\\n - Request form (rights under Art. 18)\\\\\\\\n - Service flow with SLA by request type\\\\\\\\n - Response templates for each right\\\\\\\\n\\\\\\\\nBase on LGPD (Arts. 5, 37, 38, 41, and 46), Resolution CD/ANPD No. 18 (small-scale data controllers), and ISO 27701 references.
Open directly in an AI โ the text is pre-filled:
How to use this prompt
- 1Replace the key placeholders first: COMPANY NAME, INDUSTRY, NUMBER, EXCLUSIVE ROLE / COMBINED WITH OTHER DUTIES / OUTSOURCED (DPO as a Service).
- 2Replace any bracketed placeholders like [this] with your own context.
- 3Add extra background information when you want more tailored results.
- 4Combine multiple prompts in one conversation when you need a richer output.
- 5Save your best-performing prompts so they are easy to reuse later.
Next best step
Open the guide first, then branch only if you still need more.
A guide for choosing prompts, tools, courses, and workflows without creating expensive tool sprawl.
If this prompt is close but not quite right, generate variants next. If the job is recurring, move into the course library after the guide.
Related prompts
View allSaaS Licensing Agreement with SLA and Data Protection Clauses
Generates a complete SaaS licensing agreement template adapted to Brazilian law, including SLA terms, data processing, and intellectual property provisions.
Best for
Draft a SaaS service agreement that protects both provider and client, compliant with the Brazilian Civil Code, Internet Framework Law, and LGPD (Brazil's data protection law).
Mutual NDA for Business Negotiations
Creates a robust mutual non-disclosure agreement to protect sensitive information during negotiations between businesses.
Best for
Draft an NDA that protects both parties in commercial negotiations, M&A deals, or strategic partnerships, compliant with Brazilian Civil Code and Industrial Property Law.
Professional Services Agreement with Defined Scope and Scope Creep Protection
Generates a professional services contract with clear scope delimitation, change request mechanisms, and formal acceptance procedures.
Best for
Protect service providers from informal scope expansion (scope creep) by establishing formal change procedures.
Commercial Partnership Agreement (Joint Venture) Between Companies
Draft a commercial partnership or joint venture agreement with clear governance rules, profit-sharing, and exit mechanisms.
Best for
Structure a commercial partnership or joint venture legally, defining responsibilities, investments, governance, and dissolution mechanisms.
Explore other prompt categories
Move sideways into adjacent libraries when the current category is not the full answer.
Free browsing stays open. Premium prompts unlock the reusable workflow layer.
Use the guides and role paths to validate the job first. Upgrade when you want the full prompt text, editable premium prompts, and the surrounding course paths in one place.
Free access
- Browse guides, role paths, and category pages.
- Preview prompts before you decide to upgrade.
- Find the right starting point without friction.
Membership access
- Unlock premium prompts and the full copy text.
- See more workflow paths and course connections.
- Keep the reusable templates in one place.