Back to homeEffective July 26, 2026
LGPD

LGPD Controls

SOFI Governance helps teams apply access control, masking, lineage, and auditability to private data without creating a new replicated copy of sensitive datasets.

Role in data processing

SOFI Governance is designed to help customers control access to their own data sources. Depending on the deployment and contract, SOFI may act as a service provider or processor for platform metadata, account information, audit data, and support interactions.

Zero-copy access model

SOFI does not require copying customer datasets into a SOFI warehouse. Governed virtual views are evaluated against customer-controlled sources, with policy decisions, masking, and audit events produced in the query path.

Access controls

Customers can configure RBAC, row-level and column-level controls, masking rules, purpose-based policies, tenant boundaries, and audit retention. These controls are intended to support LGPD governance programs but do not replace customer legal review.

Data subject requests

SOFI can help identify where personal data appears through catalog metadata, lineage, and audit records. Exports for DSR workflows can be generated from governed views and audit trails configured by the customer.

Security and retention

Sensitive credentials are encrypted, access is logged, and deployment boundaries can be private VPC or on-premise. Retention periods for audit logs, cache, and metadata are configured during deployment and documented in the customer agreement.

Important note

This page describes product controls and operational posture. It is not legal advice. Customers should validate LGPD obligations with their legal, privacy, and security teams.

LGPD and privacy questions can be sent to contact@sofigovernance.dtsofi.com.