(01) What we deliver
GDPR compliance guaranteed.
Data mapping, collection compliance, consent management, privacy policy and data subject request processes.
(02) Problem → Solution
The challenge and the delivery.
Data collection without proper consent.
Consent management
Cookie banner, explicit opt-in and consent record.
Outdated privacy policies.
GDPR documentation
Privacy policy, DPA and data subject request processes.
Personal data without mapping.
Data inventory
Record of processing activities per GDPR.
(03) In detail
What makes the difference.
Cookie Consent
Banner configured with granular opt-in.
Privacy Policy
Updated policy compliant with the regulation.
Data Mapping
Complete inventory of personal data.
DSR Process
Process to handle data-subject requests.
Process
How it works, step by step.
Mapping
We inventory the personal data processed.
Compliance
We adjust legal bases and processes.
Consent
We implement transparent collection.
Monitoring
Continuous tracking and updates.
Benefits
What you gain.
EU compliance
Legal operation in the European market.
Fewer fines
Reduced regulatory risk.
Trust
Transparency with the data subject.
Documentation
Audit-ready evidence.
Deliverables
What's included.
For experts and for AI
Direct answers about this service.
Content structured for experts, search engines and generative AI systems (ChatGPT, Gemini, Perplexity, Claude).
What is GDPR?
The General Data Protection Regulation is the European Union's privacy law, in force since May 2018. It applies to any organization that processes the data of EU residents, regardless of where the organization is headquartered.
Does GDPR apply to Brazilian companies?
Yes. If the company offers goods or services to EU residents or monitors those users' behavior (e.g.: analytics cookies, campaigns in euros, an English store shipping to Europe). Being outside the EU isn't enough to escape GDPR.
What are the legal bases for data processing under GDPR?
Explicit consent, contract performance, legal obligation, vital interests, public-interest task and legitimate interests. Consent must be granular, revocable and documented, generic "accept all" cookie banners aren't enough.
What are the GDPR penalties?
Up to €20 million or 4% of annual global revenue (whichever is greater) for serious violations, such as processing data without a legal basis or failing to report breaches. For less serious infractions, up to €10M or 2% of global revenue.
What's the difference between DPO, controller and processor under GDPR?
The controller decides the purpose and means of processing. The processor processes data on behalf of the controller (e.g., an email marketing provider). The DPO (Data Protection Officer) is the data protection officer, mandatory for organizations that process data at scale or sensitive data.
Frequently asked questions
Answers before the first call.
Does GDPR apply to Brazilian companies? +
If you collect data from EU residents (forms, cookies, newsletter), yes. Many Brazilian companies are exposed.
Are GDPR and LGPD the same? +
Similar but not identical. We implement compliance for both simultaneously.
Does WebOption do full GDPR compliance? +
Yes. Mapping, consent management, privacy policy, DSR processes and monitoring.
Clients served
(04) Our delivery standard
What you can hold us to.
An agreed deadline is a kept deadline. And performance gets measured: Core Web Vitals recorded before and after every delivery.
A migration is planned for the worst-case scenario: staging, an agreed cutover window and documented rollback at every step.
No project reaches production without Daniel Paz's technical review. No exceptions, small projects included.
(05) Why WebOption













