AuditXYZ

Compliance Framework

Lei Geral de Proteção de Dados Pessoais (General Data Protection Law) (LGPD)

Brazil's LGPD is a comprehensive data protection law closely modeled on the GDPR, establishing rights for data subjects, obligations for controllers and processors, and enforcement by the ANPD. This guide covers legal bases, data subject rights, and practical compliance.

$8,000–$120,0003–10 months2018 (enforced September 18, 2020)
Issuing BodyNational Congress of Brazil / Autoridade Nacional de Proteção de Dados (ANPD)
First Published2018-08-14
Latest Version2018 (enforced September 18, 2020)
Typical Cost$8,000–$120,000
Typical Timeline3–10 months
Audit RequiredNo
Audit FrequencyNo mandatory periodic external audit. The ANPD may conduct audits and investigations. Data Protection Impact Reports may be required for high-risk processing.
Geographybrazil

LGPD: The Complete Guide

Brazil's Lei Geral de Proteção de Dados (LGPD) is Latin America's most comprehensive data protection law and one of the most significant privacy regulations enacted outside Europe. Passed in August 2018 and enforceable since September 2020, with administrative sanctions effective August 2021, the LGPD applies to any processing of personal data carried out in Brazil, data collected in Brazil, or data used to offer goods and services to individuals in Brazil. Brazil's 215 million residents and status as Latin America's largest economy make LGPD compliance a business imperative for any organization with regional operations.

What the LGPD Is and Who Enforces It

The LGPD was enacted by Brazil's National Congress (Lei 13.709/2018) and amended by the Lei da Liberdade Econômica. The Autoridade Nacional de Proteção de Dados (ANPD) was created as the regulatory body responsible for enforcing the law, issuing guidance, and promoting data protection culture in Brazil. The ANPD was initially structured as a provisional government body but was transformed into a permanent independent authority in 2022, strengthening its institutional capacity for enforcement.

The ANPD has been building its enforcement program progressively. In 2023 and 2024, it issued its first binding decisions, guidance on legitimate interests, consent requirements, and guidance on cookies and tracking. By 2025, the ANPD had initiated formal enforcement proceedings against multiple organizations and demonstrated willingness to investigate cross-border companies with Brazilian operations.

Territorial and Material Scope

The LGPD applies broadly to any processing of personal data:

  • Carried out in Brazil, regardless of where the processor is based.
  • By a legal entity or natural person located in Brazil.
  • Where the object of processing is personal data of individuals located in Brazil.
  • Where the processing aims to offer goods or services to individuals in Brazil.
  • Where the personal data was collected in Brazilian territory.

This reach captures global SaaS companies with Brazilian customers, e-commerce platforms offering goods to Brazilian consumers, and organizations with Brazilian subsidiaries or employees. The LGPD applies to both automated and non-automated processing, and covers both private and public sector entities (with some distinctions in the public sector regime).

Notably, the LGPD does not apply to processing carried out by natural persons exclusively for private and non-economic purposes, for journalistic, artistic, or academic purposes, or for public security and national defense purposes under separate legislation.

The LGPD establishes ten legal bases for processing personal data under Article 7 — four more than the GDPR's six. Organizations must identify and document the applicable basis for each processing activity:

  1. Consent — Free, informed, and unambiguous agreement for a specific purpose.
  2. Compliance with legal or regulatory obligation — Processing required by law.
  3. Execution of public policies — For public administration bodies.
  4. Research — For study bodies or research organizations, with anonymization where possible.
  5. Performance of contract — Where the data subject is a party.
  6. Exercise of rights in judicial, administrative, or arbitration proceedings.
  7. Protection of life or physical safety of the data subject or third parties.
  8. Protection of health — for health professionals, services, or authorities.
  9. Legitimate interests — Of the controller or third parties, except where the data subject's rights prevail.
  10. Credit protection — Processing of information for creditworthiness assessment.

The credit protection basis is unique to the LGPD and reflects the importance of credit bureau operations in Brazil's financial sector. Legitimate interests under Article 10 requires a balancing test and written record of the assessment.

Data Subject Rights

Data subjects (titulares) are granted extensive rights under Articles 17 through 22:

  • Confirmation of processing — Right to know whether data is processed.
  • Access — Right to receive a copy of personal data held.
  • Correction — Right to have incomplete, inaccurate, or outdated data corrected.
  • Anonymization, blocking, or deletion — For unnecessary, excessive, or unlawfully processed data.
  • Data portability — Transfer of data to another service provider.
  • Deletion — Of data processed with consent, when consent is withdrawn.
  • Information on sharing — Details of public and private entities with which data has been shared.
  • Information on consequences of not consenting — Where consent is the legal basis.
  • Revocation of consent — At any time.

Controllers must respond to requests within 15 days — a significantly shorter window than the GDPR's 30 days, requiring more efficient operational processes.

Sensitive Personal Data

The LGPD defines sensitive personal data as: racial or ethnic origin, religious belief, political opinion, union or religious organization membership, health or sex life data, genetic or biometric data, and data of children and adolescents. Processing sensitive data requires explicit, free, and informed consent for specific purposes, or must fall under specific statutory exceptions such as compliance with legal obligations, protection of life, or public health.

Data Protection Officer

Article 41 requires controllers to appoint a Data Protection Officer (in Portuguese, Encarregado). The DPO must have their contact details published, serve as a channel between the controller and data subjects, receive complaints and communications from data subjects, and receive communications from the ANPD. The DPO may be a natural person or a legal entity. Unlike the GDPR, the LGPD does not restrict which organizations must appoint a DPO — the obligation applies broadly, with the ANPD having power to establish different rules for micro-enterprises and small businesses.

Breach Notification

Controllers must notify the ANPD and affected data subjects of any security incident that could result in relevant risk or damage to data subjects. The ANPD established a 72-hour notification period for notifiable incidents through its breach notification regulation. Notifications must describe the nature of the incident, data involved, mitigation measures, and potentially affected individuals.

International Data Transfers

Articles 33 through 36 restrict transfers of personal data to countries that do not provide an adequate level of protection. Permitted transfer mechanisms include:

  • Adequacy decision by the ANPD recognizing the destination country's protections.
  • Standard contractual clauses issued by the ANPD.
  • Binding corporate rules approved by the ANPD.
  • Specific contractual clauses for individual transfers verified by the ANPD.
  • Compliance certification programs recognized by the ANPD.
  • Consent of the data subject.
  • Transfer for legal compliance, contract performance, or protection of life.

The ANPD has been developing its adequacy framework gradually. Organizations using GDPR-compliant SCCs as a basis for transfers to Brazil partners should verify whether the ANPD has endorsed equivalent clauses.

Enforcement and Penalties

The ANPD may impose: warnings; fines of up to 2% of revenue in Brazil in the previous fiscal year (capped at 50 million reais — approximately $10 million — per violation); daily fines; public disclosure of the violation; blocking of personal data; and data deletion. For micro-enterprises and small businesses, the ANPD applies a simplified sanctioning regime.

The ANPD's 2024-2025 enforcement actions targeted health sector operators for consent failures and financial institutions for excessive data retention. Cross-border companies with Brazilian customer-facing operations have also been placed under scrutiny for inadequate breach notification timelines.

The LGPD shares approximately 80% structural overlap with the GDPR, making it the closest global equivalent to the European regulation. Key differences:

  • Ten legal bases vs. six — The LGPD adds credit protection and expands the research and health bases.
  • 15-day response window for data subject requests vs. GDPR's 30 days.
  • Breach notification is risk-based like GDPR but implemented through a separate ANPD regulation.
  • Enforcement structure — The ANPD is newer and still building its institutional capacity compared to established EU supervisory authorities.

Compared to the CCPA (50% overlap), the LGPD is far more similar to GDPR: it covers all sectors without revenue thresholds, requires a legal basis for processing, and grants broader individual rights rather than focused opt-out rights.

Organizations with existing GDPR compliance programs have a significant head start on LGPD. The primary incremental work involves adapting to the 15-day response window, documenting the additional legal bases, and engaging with ANPD-specific requirements.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
AssessmentData mapping, legal basis review, gap analysis vs. GDPR3-6 weeks
DesignPrivacy notices, consent flows, DPO appointment, DSR workflows4-8 weeks
ImplementationVendor agreements, breach notification pipeline, training6-10 weeks
OngoingANPD guidance monitoring, request fulfillment, DPIA programContinuous

Key compliance steps:

  1. Legal basis mapping — Identify and document the legal basis for each processing activity, including the additional LGPD-specific bases.
  2. Data subject rights — Implement intake and response mechanisms meeting the 15-day deadline for all ten rights.
  3. DPO appointment — Designate a Data Protection Officer and publish contact information prominently.
  4. Vendor management — Execute data processing agreements (Contratos de Processamento de Dados) with all processors.
  5. Breach notification — Establish a 72-hour breach identification, assessment, and notification procedure.
  6. Cross-border transfers — Assess international transfer mechanisms and verify ANPD equivalence of existing safeguards.
  7. Sensitive data review — Identify all sensitive data processing and verify that explicit consent or statutory exceptions are in place.

How Privacy Automation Helps

The LGPD's operational demands — 15-day DSR response windows, multi-basis legal mapping, Brazilian-Portuguese privacy notices — make automation valuable from day one of compliance. TruePrivacy supports LGPD alongside GDPR, CCPA, and DPDPA within a single platform. Its AI data discovery across 128-plus sources accelerates the data inventory needed to power accurate disclosures and breach scope assessments. DSR automation helps manage the compressed 15-day response requirement at scale.

Priced at $5,000 per year with 24-hour onboarding, TruePrivacy earns an 88/100 AuditXYZ score for mid-market programs. Organizations managing very complex multi-jurisdiction Latin America portfolios should compare capabilities at best privacy management tools or review the TruePrivacy vs OneTrust comparison.

Frequently Asked Questions

Does the LGPD apply to my company if we are based outside Brazil but sell to Brazilian consumers? Yes. The LGPD's extraterritorial reach captures any organization offering goods or services to individuals in Brazil or processing data collected in Brazil. A European or US company with a Brazilian-language website and Brazilian customer accounts is within scope.

We already comply with the GDPR. What additional steps do we need for LGPD? The primary gaps to address are: adapting DSR response workflows to 15-day windows (vs. 30 days under GDPR), mapping the additional legal bases (particularly credit protection), verifying that ANPD-compatible transfer mechanisms are in place for data flows involving Brazil, publishing your DPO contact information, and ensuring your incident response plan reflects ANPD breach notification requirements.

When does consent need to be renewed under the LGPD? When the purpose of processing changes, consent must be refreshed. Data subjects must also be informed and given an opportunity to revoke consent where data is to be used for a new purpose. The LGPD does not specify a blanket time limit on existing consent, but ANPD guidance emphasizes that consent must remain current and specific to the stated purpose.

What is a Data Protection Impact Report and when is it required? The Relatório de Impacto à Proteção de Dados Pessoais (RIPD) is the LGPD equivalent of a DPIA. The ANPD may require a controller to prepare a RIPD for processing activities that carry significant risks. The report must describe the processing, legal basis, risk mitigation measures, and security safeguards. Although mandatory RIPDs are triggered by ANPD direction rather than self-assessment as under the GDPR, best practice is to conduct them proactively for high-risk activities.

How do we handle employee personal data under the LGPD? Employee data falls within LGPD scope. Processing employment-related data can rely on multiple legal bases including contract performance, compliance with legal obligations, and in some cases legitimate interests. However, consent is not generally appropriate for employment contexts where the power imbalance makes it questionable whether consent is freely given. Employers should document applicable bases and ensure employment contracts and HR processes are aligned.

Request a LGPD consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

GDPRHigh80%
CCPAMedium50%

Related frameworks

Get matched with a LGPD auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools