GDPR and LGPD, put into practice by the person who answers for your compliance
FM brings your company into compliance with GDPR and LGPD, gets it ready for a SOC 2 or ISO 27001 audit when it applies, and keeps it running as your outsourced Data Protection Officer. Led by Michelle G. Andrade.
- certified DPOGDPR, LGPD and ISO/IEC 27701
- certified CISOISO/IEC 27001:2022 Lead Auditor
- verifiable certificationsissued by ITCERTS, verified on credential.net
What reaches you
Compliance Check
A 30-minute initial review to map where your company is exposed in privacy and security, and what comes first. No cost, no strings.
GDPR/LGPD implementation
Policies, legal basis, data flow, consent, data subject rights and incident response, implemented, not just recommended.
SOC 2 / ISO 27001 readiness
Controls, evidence and processes in place to pass the audit, with no surprises when the auditor arrives.
DPO-as-a-Service
FM acts as your outsourced Data Protection Officer: monitoring, responding to data subjects and regulators and keeping compliance alive. Both GDPR and LGPD allow this role to be outsourced.
How it enters your operation
Michelle runs the diagnosis, the remediation and the ongoing operation. You follow along without becoming a standards expert.
Compliance Check
We get to know your operation, map where you are exposed in data and show you what comes first. Free and with no strings.
Remediation plan
We turn the diagnosis into a clear roadmap: what to fix, which controls to implement, scope and timeline. You approve before anything starts.
Implementation
We put the policies, processes and technical controls live, with documentation and training for your team.
Audit and ongoing operation
We prepare your company for a SOC 2 or ISO 27001 audit where it applies, and we run compliance day to day: DPO-as-a-Service, monitoring and incident and regulator response.
- The GDPR and LGPD policies and processes implemented, documented in your company’s name
- The controls and evidence in place for a SOC 2 or ISO 27001 audit, when it applies
- The record of responses to data subjects and regulators, kept by your outsourced DPO
- The remediation plan, with scope and timeline you approved in writing
Scope closes before we start
What is in and what is out comes out of the assessment, in writing, with a price. Anything you ask for later becomes a new scope you approve, never an invoice that shows up at the end.
What we deliver stays yours
Code, documents, domain and accounts sit in your company’s name. If you stop working with FM one day, nothing that is already live goes down with it.
Five questions, and we already start looking at your case
This is not a contact form. Each answer changes the next question, and at the end you get a read of your case on screen.
Takes about two minutes. Nothing to book and nobody to talk to first.
- The read of your caseIt shows up right here when you finish answering, with nobody to wait for.
- What we would switch on firstIn the order that fits your operation, with the reason behind each choice.
- A copy in your inboxTo read again later, with a link back whenever you want it.