Titulata

Record of Processing Activities

Generated automatically · updated on every scan

Controller
Your Company Ltd.1You enter it once.
Activity
Customer registration2One activity per table with personal data.
Source
prod · ecommerce.customers · 7 columns
Personal data
CPF, e-mail, phone, address3Detected by the scan. No value was read.
Sensitive data
Health (cartao_sus)4Art. 11 — needs a specific legal basis.
Data subjects
Customers5Suggested from the table name.
Legal basis
Art. 7, V — performance of a contract6Your team confirms or corrects it.

This record wrote itself.

Titulata reads the structure of your databases, identifies the personal data and drafts the record of processing activities that Brazilian and Latin American data protection laws require. Your team only reviews and signs.

First scan free · read-only connection · no credit card

How this document was made

  1. Art. 1

    Reading

    We connect to PostgreSQL, MySQL, BigQuery, Snowflake or Databricks with a read-only user and read the schema: tables, columns and types.

  2. Art. 2

    Classification

    Rules built for Latin America — CPF, CUIT, RUT, NIT, CNS — identify each column and the applicable article. Whatever the rules don't recognise can go through an AI review, which you can switch off at any time.

  3. Art. 3

    Drafting

    Each table with personal data becomes an activity in the record. Your team adds purpose, legal basis and retention, marks it reviewed and exports to PDF or Excel.

  4. Art. 4

    Vigilance

    On every new scan the record is compared with the previous version. A new sensitive column triggers an e-mail and webhook alert, and the activity goes back to review.

Sole paragraph. No scan ever erases what your team wrote.

Jurisdictions

Brazil

LGPD — Law 13,709/2018

ANPD

Record of processing operations (art. 37) and a DPO with public contact details (art. 41).

Argentina

Law 25,326

AAIP

Registration of public databases and of private ones that provide reports (art. 21), plus security measures (art. 9).

Chile

Law 19,628 → Law 21,719

Personal Data Protection Agency

Law 21,719 takes full effect on 1 December 2026, with fines of up to 20,000 UTM.

Colombia

Law 1581 of 2012 and Decree 1074 of 2015

SIC

National Database Registry with the SIC for companies with assets above 100,000 UVT (Decree 1074, art. 2.2.2.26.1.2) and fixed deadlines for queries and claims (arts. 14 and 15).

Annex I — What we read and what we never read

✓ We read

  • Table and column names
  • Data types
  • Counts computed inside your database — e.g. “1,204 values shaped like a CPF”

✕ We never read

  • The value of any row
  • Names, documents or any content about your data subjects
  • Nothing leaves your database except column names and numbers

The AI review, when on, only receives column names and counts. It can be switched off for the whole organization, and every report states what was read.

Annex II — Change log

Scan of 26 Sep compared with 19 Sep

+patients.cartao_susnew column · health · critical
↑customers.emailsensitivity medium → high
−orders.courier_cpfcolumn removed

You hear about it the day it happens — not at the next audit.

Pilot program enrolment form

The first companies use Titulata with direct support from the people who built it.

  • 90 days of the Business plan, no card
  • One-to-one onboarding to connect your database
  • 50% off the first year, if you continue
  • In return: two feedback conversations

Data protection officer

Join the pilot →

Legal basis

  1. 1

    Brazil, LGPD, art. 37 and 52. Controllers and processors must keep a record of their processing operations; fines of up to 2% of revenue in Brazil, capped at R$ 50 million per violation.

  2. 2

    Argentina, Law 25,326, art. 21. Public databases and private databases intended to provide reports must be registered with the supervisory body, now the AAIP (Law 27,275, art. 19).

  3. 3

    Chile, Law 21,719. Creates the Personal Data Protection Agency and takes full effect on 1 December 2026; fines of up to 20,000 UTM.

  4. 4

    Colombia, Law 1581, art. 25, and Decree 1074 of 2015. Companies and non-profits with total assets above 100,000 UVT, and public legal entities, must register their databases in the SIC's National Database Registry (Decree 1074, art. 2.2.2.26.1.2).