LGPD Controls
SOFI Governance helps teams apply access control, masking, lineage, and auditability to private data without creating a new replicated copy of sensitive datasets.
Role in data processing
SOFI Governance is designed to help customers control access to their own data sources. Depending on the deployment and contract, SOFI may act as a service provider or processor for platform metadata, account information, audit data, and support interactions.
Zero-copy access model
SOFI does not require copying customer datasets into a SOFI warehouse. Governed virtual views are evaluated against customer-controlled sources, with policy decisions, masking, and audit events produced in the query path.
Access controls
Customers can configure RBAC, row-level and column-level controls, masking rules, purpose-based policies, tenant boundaries, and audit retention. These controls are intended to support LGPD governance programs but do not replace customer legal review.
Data subject requests
SOFI can help identify where personal data appears through catalog metadata, lineage, and audit records. Exports for DSR workflows can be generated from governed views and audit trails configured by the customer.
Security and retention
Sensitive credentials are encrypted, access is logged, and deployment boundaries can be private VPC or on-premise. Retention periods for audit logs, cache, and metadata are configured during deployment and documented in the customer agreement.
Important note
This page describes product controls and operational posture. It is not legal advice. Customers should validate LGPD obligations with their legal, privacy, and security teams.
LGPD and privacy questions can be sent to contact@sofigovernance.dtsofi.com.