LGPD Brazil: Complete Guide to Brazil's Data Protection Law
A complete guide to LGPD Brazil: who the law applies to, the 10 legal bases, data subject rights, ANPD penalties, cookie rules, and the steps to comply.
If your website reaches customers in Brazil, LGPD Brazil compliance is not optional, and it does not matter where your servers or offices sit. The Lei Geral de Protecao de Dados (Law No. 13.709/2018) took full effect in September 2020, with administrative sanctions enforceable since August 2021. This guide covers what the law requires, who enforces it, and the concrete steps to bring a website into compliance. It is educational rather than legal advice, so consult a Brazilian-qualified attorney for guidance on your specific processing activities.
What Is the LGPD in Brazil?
The LGPD (Lei Geral de Protecao de Dados Pessoais, Law No. 13.709/2018) is Brazil's comprehensive data protection law, governing how any organization collects, stores, uses, shares, and deletes the personal data of individuals in Brazil. It replaced a patchwork of more than 40 sectoral rules with a single national framework.
Brazil LGPD was signed in August 2018 and became enforceable in September 2020. Sanction powers were delayed until August 1, 2021, giving organizations a grace period that has now long expired. In February 2022, Constitutional Amendment 115 elevated personal data protection to a fundamental right in the Brazilian Constitution.
The law is built on 10 principles set out in Article 6:
- Purpose: processing for legitimate, specific, and explicit purposes stated to the data subject.
- Adequacy: compatibility of processing with the stated purposes.
- Necessity: limiting processing to the minimum data required.
- Free access: easy, free consultation about processing and the data itself.
- Data quality: accuracy, clarity, relevance, and currency of data.
- Transparency: clear, accurate, and easily accessible information about processing.
- Security: technical and administrative measures against unauthorized access.
- Prevention: measures to prevent damage from processing.
- Non-discrimination: no processing for unlawful or abusive discriminatory purposes.
- Accountability: demonstrating effective compliance measures.
Accountability is the one that catches companies out. Under the LGPD, being compliant is not enough. You must be able to prove it with documentation, records, and evidence of the measures you took.
Who Must Comply With Brazil LGPD
Article 3 of the LGPD sets an extraterritorial scope similar to Article 3 of the GDPR. The law applies to any processing operation where:
- The processing operation is carried out in Brazilian territory, regardless of the country where the organization is headquartered.
- The processing activity aims to offer or supply goods or services to individuals located in Brazil.
- The personal data being processed was collected in Brazil, meaning the data subject was in Brazil at the time of collection.
A Shopify store in Austin that ships to Sao Paulo is covered. A SaaS company in Berlin with Brazilian subscribers is covered. A blog that accepts newsletter signups from Brazilian readers and runs analytics on those visits is covered.
Who Is Exempt
Article 4 carves out narrow exemptions. LGPD does not apply to processing carried out:
- By a natural person for exclusively private and non-economic purposes.
- For exclusively journalistic, artistic, or academic purposes (academic use still must respect Articles 7 and 11).
- For purposes of public safety, national defense, state security, or criminal investigation activities, which are governed by separate legislation.
- Of data originating outside Brazil that is only in transit and not shared with Brazilian processing agents.
The "private purposes" exemption is much narrower than people assume. The moment a personal blog runs affiliate links or ads, the non-economic condition fails.
The 10 Legal Bases Under LGPD Brazil
This is where LGPD Brazil diverges most visibly from the GDPR. Article 7 provides 10 legal bases for processing personal data, compared to six under GDPR Article 6:
| Legal basis (Art. 7) | Typical use |
|---|---|
| Consent | Marketing emails, non-essential cookies, optional profiling |
| Compliance with a legal or regulatory obligation | Tax records, employment filings |
| Public administration by the government | Public sector service delivery |
| Studies by a research body | Anonymized research datasets |
| Contract performance or preliminary procedures | Fulfilling an order, account creation |
| Judicial, administrative, or arbitration proceedings | Litigation holds, evidence retention |
| Protection of life or physical safety | Emergency medical situations |
| Health protection by health professionals or authorities | Clinical care, health services |
| Legitimate interests of the controller or third party | Fraud prevention, basic service analytics |
| Credit protection | Credit scoring and reporting |
Choose your legal basis before you start processing, and document that choice. Article 9 obliges you to tell data subjects which basis you rely on, and switching bases after the fact to escape a withdrawn consent is not permitted.
Consent Requirements
When you do rely on consent, Article 5(XII) requires it to be a free, informed, and unambiguous manifestation for a specific purpose. Article 8 adds that consent must be given in writing or by another means demonstrating the data subject's will, and that generic authorizations are void.
Two practical consequences follow. Pre-ticked boxes and bundled consent do not work, and the burden of proving valid consent sits with the controller under Article 8, paragraph 2. Keep timestamped consent records showing exactly what text the person agreed to.
Sensitive Personal Data
Article 5(II) defines sensitive personal data as data on racial or ethnic origin, religious belief, political opinion, trade union or religious/philosophical/political organization membership, health or sex life, and genetic or biometric data. Article 11 restricts processing of this category to specific consent or a short list of exceptions such as legal obligation, life protection, and health protection.
Children's data gets its own rules. Article 14 requires specific and highlighted consent from at least one parent or legal guardian for processing the personal data of children under 12, and controllers must make public the information they require to obtain that consent.
LGPD Data Subject Rights
Article 18 grants nine rights to data subjects, exercisable free of charge at any time upon request:
- Confirmation of the existence of processing.
- Access to the data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in noncompliance with the law.
- Portability to another service or product provider, upon express request.
- Deletion of personal data processed with consent, subject to the retention exceptions in Article 16.
- Information about public and private entities with which the controller has shared data.
- Information about the possibility of denying consent and the consequences of denial.
- Revocation of consent, through a free and facilitated procedure.
Article 20 adds a distinct right to request review of decisions made solely by automated processing that affect a person's interests, including decisions on credit, consumer profile, and personality profile.
Article 19 sets the response deadlines. A simplified response is due immediately, and a full declaration of data origin, criteria used, and processing purpose must be provided within 15 days of the request. That 15-day window is tighter than the GDPR's one-month standard, so build the request-handling process before requests arrive.
ANPD Enforcement and LGPD Penalties
The Autoridade Nacional de Protecao de Dados (ANPD) is Brazil's data protection authority, established by Law No. 13.853/2019 and converted into an autonomous agency in 2022. It issues regulations, investigates complaints, and applies sanctions.
Article 52 lists the administrative sanctions available:
- Warning, with a deadline for corrective measures.
- Simple fine of up to 2 percent of the group's revenue in Brazil for the prior fiscal year, excluding taxes, capped at 50 million reais per violation.
- Daily fine, subject to the same total cap.
- Publicization of the violation once confirmed.
- Blocking of the personal data involved until the irregularity is fixed.
- Deletion of the personal data involved.
- Partial suspension of database operation for up to six months, extendable once.
- Suspension of the data processing activity for up to six months, extendable once.
- Partial or total prohibition of data processing activities.
ANPD Resolution CD/ANPD No. 4/2023 sets the dosimetry methodology for calculating fines, weighing severity, good faith, repeat offenses, cooperation, and the adoption of a compliance program. The ANPD has been active since 2023, with preventive measures against large platforms over data use for AI training and enforcement actions on data broker practices.
Beyond ANPD fines, Article 42 makes controllers and processors liable for damages caused to data subjects, and Brazilian consumer protection bodies and public prosecutors can bring collective actions independently.
Building an LGPD-Compliant Privacy Policy
Article 9 lists what you must tell data subjects in clear, adequate, and conspicuous form. Your privacy policy is the primary vehicle for that disclosure and must cover:
- The specific purpose of the processing.
- The form and duration of processing, respecting commercial and industrial secrecy.
- The identity and contact details of the controller.
- Information about the shared use of data by the controller and the purpose.
- The responsibilities of the agents that will carry out the processing.
- The data subject's rights, with explicit mention of the rights in Article 18.
Two additions matter for international sites. Article 33 governs international data transfers, permitting them to countries with an adequate level of protection, under contractual clauses or binding corporate rules, or with specific and highlighted consent among other bases. If you use US-based hosting, analytics, or email tools, name that transfer and its safeguard in your policy.
Article 41 requires the identification of the encarregado, the person in charge of personal data processing, with contact details published publicly, preferably on the controller's website. A privacy policy that names no contact for privacy questions fails this on its face.
Language is the practical detail most companies get wrong. If you market to Brazil in Portuguese, transparency under Article 6(VI) is hard to argue when your policy exists only in English. A privacy policy generator that supports multi-language output and covers LGPD, GDPR, and CCPA disclosures together saves maintaining three separate documents. For a broader view of how these frameworks overlap, the GDPR vs CCPA comparison covers the structural differences that also shape LGPD drafting.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowCookies, Trackers, and LGPD Brazil
The LGPD contains no cookie-specific article equivalent to Article 5(3) of the EU ePrivacy Directive. Cookies fall under the general regime because cookie identifiers, IP addresses, and device IDs are personal data when they allow a person to be identified, per the Article 5(I) definition.
In October 2022, the ANPD published its Guia Orientativo on cookies and personal data protection, setting out the regulator's expectations:
- Necessary cookies for the site to function may rely on legitimate interests or contract performance, with no consent required.
- Analytics, advertising, and profiling cookies generally require consent, obtained before the cookie is set.
- Banners must present clear, granular options, with rejecting as easy as accepting.
- Nudging designs that push acceptance through visual prominence or dark patterns undermine the freedom of consent.
- Sites must maintain a cookie inventory describing each cookie, its purpose, duration, and whether it is first or third party.
This maps closely to the EU model, so a consent banner already configured for cookie consent under GDPR usually satisfies ANPD expectations once you add Portuguese text and a Brazil geo-rule. The harder part is the inventory. Most sites cannot list their own cookies accurately, because tag managers, embedded videos, and chat widgets inject third-party cookies nobody documented. A compliance scanner that crawls the site and enumerates what actually fires is the only reliable starting point, and it is exactly what TermsBox automates alongside its consent banner.
Security, Breach Notification, and Records
Article 46 requires controllers and processors to adopt security, technical, and administrative measures able to protect personal data from unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or dissemination. The law does not prescribe specific controls, so proportionality to the risk governs.
Breach Notification
Article 48 requires the controller to notify the ANPD and the data subject of a security incident that may create relevant risk or damage to data subjects. The notification must describe the nature of the affected data, information on the data subjects involved, the technical and security measures used, the risks involved, the reasons for any delay, and the measures taken to reverse or mitigate the damage.
Unlike GDPR Article 33, the LGPD statute itself sets no fixed 72-hour clock. ANPD Resolution CD/ANPD No. 15/2024 filled that gap, establishing a three-business-day communication deadline from awareness of the incident and a standard reporting form. Treat three business days as the operative deadline.
Records and Impact Assessments
Article 37 requires controllers and processors to keep records of the personal data processing operations they carry out, especially when based on legitimate interests. This is Brazil's version of the GDPR record of processing activities.
Article 38 empowers the ANPD to require a data protection impact assessment (relatorio de impacto a protecao de dados pessoais), including for processing based on legitimate interests. Article 10, paragraph 3, gives the ANPD the same power specifically where legitimate interests are the basis. Prepare assessments for high-risk processing rather than waiting for the request.
LGPD Brazil vs GDPR: Key Differences
The LGPD was drafted with the GDPR as its template, so a mature GDPR program covers most of the ground. The gaps are specific:
| Topic | LGPD (Brazil) | GDPR (EU) |
|---|---|---|
| Legal bases | 10 (Article 7) | Six (Article 6) |
| Maximum fine | 2 percent of Brazilian revenue, capped at 50 million reais per violation | 20 million EUR or 4 percent of global turnover, whichever is higher |
| Breach deadline | Three business days (ANPD Resolution 15/2024) | 72 hours (Article 33) |
| Access request deadline | Immediate simplified response, 15 days for full declaration | One month, extendable by two months |
| DPO equivalent | Encarregado, required for all controllers with small-agent exemption | DPO required only in cases under Article 37 |
| Automated decisions | Right to request review (Article 20) | Right not to be subject to solely automated decisions (Article 22) |
| Regulator | ANPD | National supervisory authorities plus the EDPB |
The most commonly missed items for GDPR-ready companies are the Portuguese-language disclosures, the named encarregado with a published contact channel, the 15-day access response, and the shorter breach notification window.
LGPD Compliance Steps for a Website
Work through these in order. Each step produces a documented artifact you can show the ANPD under the accountability principle.
- Map your data. Inventory every form, integration, cookie, pixel, and third-party tool that touches personal data of people in Brazil. Record what data, why, where it goes, and how long you keep it.
- Assign a legal basis per activity. Use Article 7 and Article 11 for sensitive data. Document the reasoning, especially for legitimate interests, where a balancing test is expected.
- Appoint an encarregado. Publish the name or role and a working contact channel on your website, per Article 41.
- Rewrite your privacy notice. Cover all Article 9 elements, list international transfers and their Article 33 basis, and publish it in Portuguese if you market in Portuguese.
- Deploy granular consent for cookies. Block non-essential tags until consent, make rejection as easy as acceptance, and log consent records with timestamps.
- Build the rights workflow. Create an intake channel, an identity verification step, and internal service levels that meet the 15-day Article 19 deadline.
- Write an incident response plan. Define detection, assessment, and the three-business-day ANPD notification path with the Resolution 15/2024 form fields.
- Update vendor contracts. Processors need written instructions and security commitments, since Article 42 makes controllers jointly liable for processor failures.
- Keep processing records. Maintain the Article 37 register and refresh it whenever a tool or purpose changes.
- Re-scan on a schedule. New marketing tags appear constantly, and an inventory that is six months old is a fiction. Monthly scanning is a reasonable baseline for most sites.
Steps 1, 5, and 10 are the ones that decay fastest, because they depend on what your site is doing right now rather than what you wrote down last quarter. Automated scanning with change alerts is the practical fix, and TermsBox monitors sites monthly on Starter ($12/mo) and weekly on Pro ($25/mo), updating hosted policy documents when the scanner detects a new tracker.
Frequently Asked Questions
Does LGPD Brazil apply to companies outside Brazil?
Yes. Article 3 of the LGPD applies extraterritorially to any processing carried out in Brazil, processing aimed at offering goods or services to individuals located in Brazil, or processing of data collected in Brazil. A US or EU company with Brazilian customers falls under the law even with no office or servers in the country.
What are the penalties for violating the LGPD?
Article 52 of the LGPD allows fines of up to 2 percent of a company's revenue in Brazil for the prior fiscal year, capped at 50 million reais per violation. The ANPD can also issue daily fines, order publicization of the violation, block or delete the data involved, and partially or fully suspend database operations.
Is consent required under LGPD Brazil?
Not always. Consent is only one of 10 legal bases in Article 7, alongside legal obligation, contract performance, legitimate interests, and credit protection. Consent is required for sensitive personal data under Article 11 unless another narrow exception applies, and it must be free, informed, unambiguous, and given for a specific purpose.
Do I need a Data Protection Officer for LGPD compliance?
Article 41 requires every controller to appoint a person in charge of personal data processing, known in Brazil as the encarregado. ANPD Resolution CD/ANPD No. 2/2022 exempts small processing agents from the mandatory appointment, though they still must maintain a communication channel with data subjects.
How is LGPD different from GDPR?
The LGPD is closely modeled on the GDPR but has 10 legal bases instead of six, no fixed 72-hour breach notification deadline, and a lower fine ceiling of 2 percent of Brazilian revenue capped at 50 million reais versus GDPR's 4 percent of global turnover. The LGPD also grants an explicit right to data portability and to review automated decisions.
What should a Brazilian privacy policy include?
Article 9 requires you to disclose the specific purpose of processing, the form and duration of processing, the controller's identity and contact details, shared use of data with third parties, the responsibilities of processing agents, and the data subject's rights. Provide this in clear Portuguese and keep it accessible before collection begins.