Privacy & Data Protection Policy


Privacy & Data Protection Policy


1. Introduction

Caribe Costa (“the Desk,” “I,”) is committed to the highest standards of data privacy. As a Brazilian Legal Desk/Sole Practitioner serving UK Private Wealth firms, international legal firms, private individuals, and fiduciaries, wI operate under a dual-compliance framework: the UK General Data Protection Regulation (UK GDPR) and the Brazilian Lei Geral de Proteção de Dados (LGPD).

2. Data Collected

I strictly adhere to the principle of “Data Minimisation.” I only collect professional information necessary to provide my Strategic Briefings and legal intelligence:

  • Identity Data: Name and professional title.
  • Contact Data: Professional email address and firm name.
  • Technical Data: IP address and browser type (collected via essential cookies for site functionality).

3. Legal Basis for Processing

I process your data under the following legal grounds:

  • Legitimate Interest: To provide the specialised Brazilian legal intelligence you have requested.
  • Contractual Necessity: To perform services under a formal engagement letter.
  • Legal Obligation: To comply with anti-money laundering (AML) and “Know Your Client” (KYC) regulations in both jurisdictions.

4. International Data Transfers (The 2026 Adequacy Agreement)

Under the 2026 UK-Brazil Data Adequacy Decision, personal data flows freely between our UK partners and our Brazilian operations. This recognition of “Essentially Equivalent Protection” ensures that your data receives the same level of security in Brazil as it does in the UK.

5. Data Retention & Security

  • Security: I utilise industry-standard encryption and secure cloud-based repositories (SOC 2 compliant) to protect your professional data.
  • Retention: I retain data only for as long as necessary to fulfil the purposes outlined or to meet statutory legal retention periods (typically 6–10 years for legal files), when and if applicable.

6. Your Rights

Regardless of your location, Caribé Costa Legal UK-Brazil Legal Desk affords you full rights under both GDPR and LGPD, including:

  • Access & Portability: Request a copy of your data in a machine-readable format.
  • Rectification: Correct any inaccurate professional details.
  • Erasure (“Right to be Forgotten”): Request the deletion of your data when it is no longer required for legal or contractual purposes.
  • Objection: Opt-out of receiving our “Strategic Outlook” briefings at any time via the link in our footer.

7. Governance & Contact

For all data-related inquiries or to exercise your rights, please contact our Data Governance lead: Email: rafael@caribecosta.com.br

Subject: Data Subject Request


São Paulo Time London Time