LGPD: Brazil's Comprehensive Data Protection Law
The Lei Geral de Proteção de Dados (LGPD — Lei nº 13.709/2018) is Brazil's comprehensive data protection law, signed on August 14, 2018 and entering into force in stages: processing provisions in September 2020 and sanctions provisions in August 2021. The LGPD draws heavily on the GDPR in structure but has several important differences — most notably a mandatory DPO without volume or sensitivity thresholds, a 2-business-day incident notification deadline to the ANPD, and a distinct set of 10 lawful processing bases.
Brazil is the world's eighth-largest economy with 215 million people and a rapidly growing digital economy. The ANPD (Autoridade Nacional de Proteção de Dados — National Data Protection Authority) has been progressively increasing enforcement activity since 2023, with formal sanctions proceedings and published enforcement guidelines. The LGPD's penalties — up to 2% of Brazil revenue (capped at BRL 50M per violation) — apply to both Brazilian companies and foreign companies processing Brazilian personal data.
Scope and Extraterritorial Application
The LGPD applies to any natural person or legal entity (public or private) that processes personal data in Brazil, where:
- The processing is carried out in Brazil,
- The processing is intended to offer or provide goods or services to individuals located in Brazil, or
- The personal data was collected in Brazil.
This extraterritorial scope means foreign SaaS companies with Brazilian users, e-commerce platforms serving Brazilian consumers, and any organisation collecting personal data in Brazil are subject to LGPD. There is no de minimis exemption based on company size or volume of data subjects (unlike some other privacy laws).
Key Definitions Under LGPD
- Personal data (dado pessoal): Any information relating to an identified or identifiable natural person (titulares).
- Sensitive personal data (dado pessoal sensível): Eight categories (Art. 5 II): racial or ethnic origin, religious conviction, political opinion, trade union or religious/philosophical affiliation, health or sex life data, genetic or biometric data, and child data.
- Controller (controlador): Natural person or legal entity who determines the purposes and means of processing.
- Processor (operador): Natural person or legal entity who processes personal data on behalf of the controller.
- DPO/Encarregado: Person designated by the controller to receive communications from data subjects and the ANPD.
- Anonymised data: Data that cannot be individually re-identified — outside LGPD scope. Pseudonymous data remains within scope.
The 10 LGPD Lawful Bases
Unlike GDPR's 6 bases, LGPD Art. 7 provides 10 lawful bases for processing personal data:
- Consent (consentimento): Freely given, informed, unambiguous, for a specific purpose. Must be in a highlighted separate clause. Withdrawal at any time without detriment.
- Compliance with legal or regulatory obligation: Processing required by law or regulation (e.g. tax records, labour law obligations).
- Execution of public policies: Public sector only, or shared with private sector by law.
- Research: Including historical, scientific, technological, or statistical research, provided data is anonymised where possible and safeguards in place.
- Contract performance or pre-contractual steps: Processing necessary to perform a contract with the data subject or at their request.
- Exercise of rights in judicial, administrative, or arbitration proceedings: E.g. evidence collection, legal defence.
- Protection of life or physical safety: Of the data subject or third party.
- Health protection: By healthcare professionals, health services, or public health authorities.
- Legitimate interests (interesses legítimos): Of the controller or third parties — subject to three-part test (legitimate purpose, necessary, not outweighed by data subject rights). NOT available for sensitive personal data.
- Credit protection: As permitted under financial legislation.
The LGPD adds a distinct set of lawful bases for sensitive personal data (Art. 11), generally requiring explicit consent or specific public interest justifications. Importantly, legitimate interest cannot be used as a lawful basis for sensitive data.
Data Subject Rights (Arts. 18–22)
The LGPD grants data subjects 9 rights, with a 15-calendar-day response deadline:
- Right to confirm existence and access (Arts. 18 I–II): Confirmation that data is being processed and access to the data in simplified or full format; no excessive fee.
- Right to correction (Art. 18 III): Correction of incomplete, inaccurate, or outdated personal data; third-party notification where data has been shared.
- Right to anonymisation, blocking, or deletion (Art. 18 IV): Of unnecessary, excessive, or non-compliant data; anonymisation must be irreversible.
- Right to data portability (Art. 18 V): Portability to another service provider in interoperable format; ANPD to issue portability regulations.
- Right to information about sharing (Art. 18 VII): List of public and private entities with whom the controller has shared data.
- Right to revoke consent (Art. 18 IX): At any time, without detriment.
- Right not to provide consent (Art. 18 VIII): With information about consequences of not consenting; no discrimination for exercising this right.
- Right to object (Art. 18 §2): Right to object to processing that does not comply with LGPD.
- Right to review automated decisions (Art. 20): Right to request review of decisions made solely on automated processing affecting the data subject's interests.
DPO (Encarregado) — Mandatory Without Thresholds
Unlike the GDPR, which requires a DPO only for certain types of organisations (public bodies, large-scale special category processing, or systematic monitoring), the LGPD Art. 41 requires all controllers and processors to designate an Encarregado (DPO). There are no size, sector, or volume thresholds — even a small startup processing Brazilian personal data must have a designated DPO.
The Encarregado's identity and contact information must be publicly disclosed — typically on the organisation's website. Their responsibilities include: receiving data subject complaints; receiving ANPD communications and taking appropriate action; guiding staff on LGPD obligations; fulfilling ANPD requests; and promoting a culture of data protection.
ANPD Resolution CD/ANPD No. 2/2022 introduced ANPD notification requirements for the Encarregado in certain cases — particularly for financial sector entities, public entities, and operators of large-scale processing. The ANPD has signalled it will prioritise organisations that fail to designate and publicly disclose their Encarregado.
Security Incident Notification: The 2-Business-Day Deadline
The LGPD's incident notification requirement is significantly stricter than GDPR's 72-hour window. ANPD Resolution CD/ANPD No. 4/2023 (effective January 2024) requires:
- ANPD notification within 2 business days of the controller becoming aware of a security incident that may cause risk or relevant harm to data subjects.
- Notification must include: nature of the personal data involved; categories and quantity of data subjects affected; technical and security measures adopted before the incident; risks from the incident; reasons for any delay in communication; and measures adopted or to be adopted for remediation.
- Individual notification where the incident may cause relevant harm to data subjects — the ANPD may require broader communication if the controller does not proactively notify individuals.
The 2-business-day clock starts when the controller becomes "aware" of the incident — not from the date of the breach itself. Controllers must build rapid detection and escalation capabilities to meet this deadline. Incident response plans should include a pre-approved ANPD notification template and designated signatory with authority to submit the notification.
International Transfers
LGPD Art. 33 permits international transfers on 8 bases, mirroring GDPR's approach:
- Adequacy: Transfer to countries or international bodies with an ANPD adequacy determination. The ANPD is developing its list — EU/EEA adequacy from the European Commission does not automatically apply under LGPD.
- Standard contractual clauses: The ANPD has published model clauses for controller-to-processor and controller-to-controller transfers. Until formal SCCs are in force, controllers use contractual provisions providing LGPD-equivalent protection.
- Binding corporate rules: Binding internal rules for intra-group transfers; ANPD may recognise BCRs approved by other authorities.
- Certification schemes: ANPD-approved certification schemes (not yet operational).
- Specific consent: Explicit consent disclosing destination country and associated risks.
- Legal obligation or judicial cooperation: Transfer required by law or international legal cooperation framework.
- Protection of life: Vital interests of the data subject.
- Public registry data: Where data is publicly available in the receiving country.
Brazil's financial sector has an additional layer: BACEN (Central Bank) Resolution 4.658/2019 sets specific requirements for financial institutions processing data in cloud environments, including requirements for data stored abroad.
ANPD Enforcement and Penalties
The ANPD's administrative sanction regime (Art. 52) includes:
- Warning with compliance deadline
- Simple fine (multa simples): up to 2% of revenues from activities in Brazil in the prior fiscal year, limited to BRL 50 million per violation
- Daily fine (multa diária): up to BRL 50 million total
- Publicisation of the infringement
- Data blocking: Blocking of the personal data to which the violation relates
- Data deletion: Deletion of the personal data subject to the violation
- Partial suspension of processing for up to 6 months
- Prohibition on processing
ANPD considers mitigating factors including good-faith compliance programme (Art. 52 §1 VII), data subject rights implementation, and cooperation with ANPD investigation. Organisations with documented LGPD compliance programmes, designated Encarregados, and proper incident notification processes receive significant penalty reductions.
Brazil LGPD Compliance Checklist Tool
The Brazil LGPD Compliance Checklist covers 42 key obligations across six categories:
- Lawful Bases & Consent (Arts. 7–11): Legal basis documentation for all processing activities, consent architecture (freely given/informed/unambiguous/specific), legitimate interest three-part test, purpose limitation, sensitive data explicit consent, children's data parental consent, consent withdrawal without detriment
- Data Subject Rights (Arts. 18–22): 15-day response to access/correction/deletion/portability/sharing information/consent revocation requests; accessible rights intake channel; ANPD complaint escalation pathway; automated decision review right
- Controller Obligations (Arts. 37–43): Privacy/transparency notice with all Art. 9 elements in Portuguese, DPO/Encarregado designation and public disclosure, Records of Processing Activities (RoPA), data minimisation and necessity, retention schedule with automated deletion, data processor contracts (operador agreements), Privacy Impact Assessment (RIPD) for high-risk processing
- Security & Incident Notification (Arts. 46–51): Technical and administrative security measures, incident detection and response capability, ANPD notification within 2 business days (Resolution CD/ANPD No. 4/2023), individual notification for relevant harm, incident register (5-year retention), anonymisation standards, post-incident review
- International Transfers (Arts. 33–36): Legal basis for each transfer, ANPD adequacy list, standard contractual clauses, BCRs, specific consent, transfer inventory, sub-processor transfer chain control
- Governance & ANPD Enforcement (Arts. 50–55): LGPD compliance programme (Art. 50 good-faith factor), Portuguese privacy policies, ANPD interaction protocol, staff training, penalty risk management (BRL 50M/violation), privacy by design and by default
Who it's for: Brazilian companies of any size; multinationals with Brazilian operations; SaaS companies serving Brazilian businesses or consumers; e-commerce platforms targeting Brazil; financial services and healthtech operating in Brazil; privacy/compliance teams building LGPD programmes from scratch or adapting existing GDPR programmes.