Loading…
Brazil's framework combines the LGPD with regulations issued by the national data protection authority, internet and consumer protection legislation, and sector-specific rules. Depending on its activities, an organisation may need to consider several of these alongside one another.
The requirements applicable to an organisation depend on its activities, sector, processing operations, and size.
The LGPD, Law No. 13,709/2018, is Brazil's general data protection law. It sets principles, legal bases, data subject rights, and obligations for controllers and operators (processors) that process personal data.
Depending on applicability, organisations may need to address:
Organisations should assess the LGPD's territorial scope, its statutory exceptions, and their role as controller or operator before determining which obligations apply.
The ANPD, Brazil's national data protection authority, issues binding resolutions that put the LGPD into practice, along with guidance and enforcement decisions.
Its resolutions cover, among other things, the calculation and application of sanctions, simplified rules for small-scale processing agents, security incident communication, the role of the Encarregado, and international data transfers.
ANPD's regulatory agenda continues to develop. Organisations should confirm the current resolutions that apply to them.
The Marco Civil da Internet, Law No. 12,965/2014, establishes principles, rights, and duties for internet use in Brazil, including provisions on privacy, connection and application log retention, and the liability of internet providers.
Organisations operating online services in Brazil should review its requirements alongside the LGPD.
The Consumer Defence Code, Law No. 8,078/1990, protects consumers in their dealings with suppliers and includes rules on consumer databases and records.
Consumer protection bodies can act on data-related consumer harms, so the Code remains relevant alongside the LGPD for consumer-facing businesses.
The LGPD requires that children's and adolescents' personal data be processed in their best interest, and Brazil has enacted further legislation addressing the protection of children and adolescents in digital environments.
Organisations whose services may be used by minors should assess these requirements and monitor how they are being implemented.
Businesses operating in regulated industries may face additional obligations beyond general data protection law.
Sector considerations:
The LGPD and related requirements may apply to:
Controllers and operators that carry out processing operations in Brazilian territory.
Businesses outside Brazil that offer goods or services to individuals in Brazil, or process personal data collected in Brazil.
Companies processing customer, employee, user, or account information, whether as a controller or as an operator for their customers.
Consumer-facing businesses, which should also consider the Consumer Defence Code and the Marco Civil da Internet.
Organisations handling employee records, recruitment data, and other employment-related personal data.
Smaller organisations, which may benefit from simplified rules under ANPD regulation but remain subject to the LGPD.
The precise obligations depend on the organisation's role, processing activities, size, risk profile, and territorial scope.
A controller makes the decisions about processing personal data; an operator processes it on the controller's behalf. Both must keep records of their processing operations and can be held liable for damage caused by unlawful processing.
The LGPD provides ten legal bases for processing, including consent, performance of a contract, legal obligation, and legitimate interest, with a narrower set for sensitive personal data. Organisations should document the basis relied on and give clear information to data subjects.
Data subjects have rights that include confirmation of processing, access, correction, anonymisation, blocking or deletion, portability, and information about sharing. Organisations should maintain processes to receive and respond to these requests within the applicable timeframes.
Controllers must communicate security incidents that may create relevant risk or damage to data subjects, both to the ANPD and to the individuals affected. ANPD regulation sets a deadline of three business days from the controller becoming aware that the incident affected personal data.
Personal data may be transferred outside Brazil only under a mechanism the LGPD recognises, such as an adequacy decision, standard contractual clauses approved by the ANPD, binding corporate rules, or specific consent. ANPD regulation sets out the standard clauses and how they must be used.
Controllers must appoint an Encarregado, the person who acts as the channel of communication between the controller, data subjects, and the ANPD. The Encarregado's identity and contact details should be made publicly available.
Small-scale processing agents may be exempt from appointing an Encarregado under ANPD rules, but must still provide a communication channel for data subjects.
The LGPD gives data subjects a number of rights over their personal data. Depending on the circumstances, these may include:
Data subjects may ask whether their personal data is processed and obtain access to it.
Data subjects may request the correction of incomplete, inaccurate, or out-of-date data.
Data subjects may request the anonymisation, blocking, or deletion of unnecessary or excessive data, or of data processed in breach of the law.
Data subjects may request the transfer of their data to another service or product provider, subject to ANPD regulation.
Data subjects may ask who their data has been shared with, be told about the consequences of refusing consent, and withdraw consent.
Data subjects may request a review of decisions made solely on the basis of automated processing that affect their interests.
Organisations should establish a clear channel for requests and assess the timeframes and exceptions that apply to each right.
The LGPD and its supporting regulations have come into effect in stages.
Law No. 13,709/2018 was enacted, establishing Brazil's general framework for the protection of personal data.
The LGPD's main provisions took effect, applying its principles, legal bases, and data subject rights to organisations within its scope.
The LGPD's administrative sanctions became enforceable, allowing the ANPD to apply penalties for infringements.
The ANPD issued its regulations on security incident communication and on international data transfers, including standard contractual clauses.
Important: ANPD regulations can include their own deadlines and transition periods. Confirm the current requirements using official sources before changing your compliance programme.
The ANPD is Brazil's national data protection authority. It supervises compliance with the LGPD, issues regulations and guidance, investigates infringements, and applies administrative sanctions.
Other bodies can also act on data-related matters, including consumer protection authorities such as Senacon and the Procons, the Public Prosecutor's Office, and the courts. Sector regulators, such as the Banco Central do Brasil, set additional requirements for the industries they oversee.
Organisations should consider all the bodies that may have jurisdiction over an issue rather than assuming that the ANPD is the only one.
The LGPD's administrative sanctions include warnings, a simple fine of up to 2% of the company's revenue in Brazil in the previous financial year, limited to R$50 million per infringement, daily fines, and publication of the infringement.
The ANPD can also order the blocking or deletion of the personal data involved and, in more serious cases, the suspension or prohibition of processing activities. Its regulation on the calculation of sanctions sets out how penalties are determined, and organisations may additionally face civil claims.
RegulatoryBridge helps organisations assess Brazil's regulatory requirements and coordinate their compliance activities with wider international programmes.
Review your processing activities, legal bases, notices, policies, governance arrangements, and operational controls to identify potential gaps.
Determine which privacy governance roles apply to your organisation, including Encarregado requirements and any exemptions that may be relevant.
Review request-handling processes, response timelines, privacy notices, and related documentation against the requirements applicable to you.
Evaluate incident procedures, escalation responsibilities, evidence preservation, and readiness to communicate with the ANPD and data subjects.
Assess data flows out of Brazil, transfer mechanisms, standard contractual clauses, and vendor relationships in light of ANPD requirements.
Help organise requirements across privacy, consumer protection, financial services, and other regulatory frameworks relevant to your business.
Monitor relevant developments and review compliance plans when legislation, ANPD resolutions, or official guidance change.
The scope of support is tailored to the organisation's activities, risk profile, and applicable legal requirements.
Assess your organisation's activities, role in processing personal data, industry, and connections to Brazil.
Identify applicable provisions, relevant authorities, effective dates, and sector-specific requirements.
Review existing policies, notices, consent mechanisms, contracts, security controls, and operational processes.
Prioritise remediation activities and establish owners, milestones, documentation requirements, and implementation plans.
Review regulatory developments, reassess relevant obligations, and update compliance processes when required.
We support your Encarregado function, ANPD interactions, and incident response - so your global product team doesn't have to.