Field Guide

Brazil LGPD Compliance: A Practitioner's Guide

The short version

The LGPD is Brazil's general data protection law, Law No. 13,709/2018. It reaches an organization that processes the personal data of people in Brazil even when the organization is established elsewhere. Processing runs under one of ten legal bases, and consent is one of them. Data subjects hold rights exercisable directly against the controller. The controller (controlador) and processor (operador) carry defined roles, an encarregado answers for the program, and the ANPD enforces the law, with the power to fine up to two percent of revenue in Brazil, capped at fifty million reais per infraction. The LGPD borrows the GDPR's structure, and the two remain separate laws.

This guide describes the LGPD as it operates today: the organizations it covers, the legal bases processing runs under, the rights a controller honors, the roles an organization staffs, the authority that enforces it, the rules on moving data out of the country, and where the law lines up with the GDPR and where it diverges. A GDPR program does not carry over to Brazil unchanged.

What the LGPD is, and where it reaches

The LGPD, the Lei Geral de Proteção de Dados, is Brazil's comprehensive data protection statute. It governs how personal data is collected, stored, used, shared, and deleted, whether a private company does the processing or, under some specific rules, the public sector. Personal data under the law is any information relating to an identified or identifiable natural person.

Scope is the first thing to get right, and it is wide. The law applies when the processing happens inside Brazil, when the purpose of the processing is to offer goods or services to people in Brazil, or when the data was collected in Brazil. Where the company sits does not decide the question. An organization headquartered outside Brazil that targets people located in Brazil falls inside the law's scope.

The principles the whole law turns on

Before the mechanics, the LGPD sets out principles that every processing activity has to satisfy. The ANPD reasons through them, and they are worth knowing because a program can satisfy a checklist and still fail a principle.

PrincipleWhat it requires in practice
PurposeProcessing serves a specific, explicit, and legitimate purpose, made known to the data subject.
Adequacy and necessityThe processing fits the stated purpose, and the data collected is limited to what the purpose actually needs.
Free access and qualityData subjects can consult their data easily, and the data is kept accurate, clear, and current.
TransparencyClear, accessible information about the processing and the agents who carry it out.
Security and preventionTechnical and administrative measures that protect the data and prevent harm.
Non-discrimination and accountabilityNo processing for unlawful or abusive discriminatory ends, and the agent can demonstrate the measures it took to comply.

The legal bases for processing

Processing personal data under the LGPD requires a legal basis, and the law lists ten of them for ordinary personal data. Consent is one of the ten. Organizations often rely on consent where a sturdier basis, such as contract or legal obligation, fits the activity better and holds up after the data subject changes their mind.

Legal basisWhen it tends to apply
ConsentThe data subject gives a free, informed, and unambiguous agreement for a specific purpose. It can be withdrawn at any time.
Legal or regulatory obligationProcessing the controller must do to comply with a legal or regulatory duty, such as tax or recordkeeping rules.
Performance of a contractProcessing necessary to carry out a contract, or preliminary steps at the data subject's request.
Regular exercise of rightsProcessing for the exercise of rights in judicial, administrative, or arbitration proceedings.
Protection of lifeProcessing to protect the life or physical safety of the data subject or a third party.
Protection of healthProcessing for health protection, in a procedure carried out by health professionals or health entities.
Legitimate interestProcessing for the legitimate interests of the controller or a third party, balanced against the data subject's rights and reasonable expectations.
Credit protectionProcessing for credit protection, including as set out in the relevant Brazilian legislation.
Public policy executionProcessing by the public administration to carry out public policies set in law or regulation.
Study by a research bodyProcessing for study by a research body, with anonymization where possible.

Sensitive personal data, covered below, has its own narrower set of bases. The basis selected determines what the controller may do with the data, what the data subject can demand back, and how the activity holds up under ANPD review.

Personal data and sensitive personal data

The law draws a line between two categories, and the rules run stricter on one side of it.

Personal data is any information relating to an identified or identifiable natural person. Sensitive personal data is a defined subset: data on racial or ethnic origin, religious conviction, political opinion, union or religious or philosophical organization membership, data concerning health or sex life, and genetic or biometric data tied to a natural person. Sensitive data may be processed only under a tighter list of bases, with consent that is specific and highlighted, or, without consent, where the processing is indispensable for purposes the law names directly, such as a legal obligation, health protection by health professionals, or fraud prevention. A program that treats biometric or health data as ordinary contact details does not meet that standard.

The rights of the data subject

The LGPD gives the titular, the data subject, a set of rights they can exercise against the controller, free of charge and on request. A working program has a defined channel to receive these requests, a way to verify the requester, and the operational ability to act across its systems.

RightWhat the data subject can ask for
Confirmation and accessConfirmation that processing exists, and access to the data being processed.
CorrectionCorrection of incomplete, inaccurate, or outdated data.
Anonymization, blocking, or deletionAnonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in noncompliance with the law.
PortabilityPortability of data to another service or product provider, on request and subject to the ANPD's rules.
Deletion of consented dataDeletion of personal data processed with consent, subject to the law's retention exceptions.
Information on sharingInformation about the public and private entities the controller has shared the data with.
Information on not consentingInformation about the possibility of denying consent and the consequences of denial.
Withdrawal of consentWithdrawal of consent at any time, by an easy and free procedure.
Review of automated decisionsThe right to request review of decisions made solely on automated processing that affect the data subject's interests.

The roles: controlador and operador

The LGPD assigns responsibility through two defined roles, and every data flow maps to one of them. The controlador, the controller, is the agent who decides on the processing of personal data: the why and the how. The operador, the processor, is the agent who processes personal data on the controller's behalf, under the controller's instructions.

The controller carries the primary obligations and answers for the purposes of the processing. The processor has to follow the controller's instructions and is bound by its own duties under the law, including security. When a processor steps outside the instructions and starts deciding purposes on its own, the law can treat it as a controller for that activity. A contract or equivalent instrument connects the two and sets out the scope of the processing, and both can be liable for harm caused to data subjects. Because the role determines the obligation, each flow is mapped to a role before the controls are built.

The encarregado, Brazil's DPO

The LGPD requires the controller to appoint an encarregado, the person who serves as the channel of communication between the controller, the data subjects, and the ANPD. The encarregado is the Brazilian counterpart to the GDPR data protection officer, and the accountability model runs through this role.

The law names the duties directly. The encarregado receives complaints and communications from data subjects, provides clarifications and takes action, receives communications from the ANPD, advises employees on data protection practices, and handles the other duties the controller sets or the ANPD specifies. The ANPD has issued regulation that scales the requirement for smaller processing agents, so how the role is staffed depends on the size and risk of the operation. The encarregado's identity and contact details are published clearly and accessibly, usually on the controller's website.

The ANPD and enforcement

Enforcement belongs to the Autoridade Nacional de Proteção de Dados, the ANPD, Brazil's national data protection authority. The ANPD is a Brazilian federal authority, not an EU body and not a court. It supervises and enforces the LGPD, issues regulations and guidance that fill in the law's detail, handles complaints, and applies administrative sanctions.

The sanctions run on a scale the law lists. They include a warning with a deadline to take corrective action, a simple fine, a daily fine, publicizing the infraction, and the blocking or deletion of the personal data involved. The fine reaches up to two percent of the revenue of the company, group, or conglomerate in Brazil for the prior financial year, capped at fifty million reais per infraction. The ANPD weighs factors such as the seriousness of the violation, the good faith of the agent, the advantage gained, and the measures the agent took to mitigate harm. A documented good-faith program therefore forms part of the record on which the ANPD sets the sanction.

International data transfer

The LGPD restricts the transfer of personal data out of Brazil, so an organization that moves data to servers or affiliates abroad needs a lawful basis for the transfer itself. The law sets out the permitted routes. They include transfer to a country or international organization the ANPD recognizes as providing an adequate level of protection, and transfer where the controller offers and proves adequate guarantees through instruments the ANPD recognizes, such as standard contractual clauses, specific contractual clauses, global corporate rules, or seals and certificates. The law also permits transfers in specific situations it names, including the data subject's specific consent to the transfer, international legal cooperation, protection of life, and the performance of a contract. The ANPD defines and approves these mechanisms. As of 2024 the ANPD has given those guarantees concrete form: Resolution CD/ANPD No. 19/2024 approved Brazil's own standard contractual clauses and made them mandatory for transfers that rely on the contractual route, with the grace period to incorporate them into existing contracts ending in August 2025. For any cross-border flow, the controller identifies which recognized route applies, uses the approved clauses where the contractual route applies, and documents the basis.

How the LGPD compares to the GDPR, at a high level

The LGPD was modeled on the GDPR, so the family resemblance is real and useful. They share the controller and processor structure, a data protection officer role, a list of data-subject rights, the requirement of a legal basis, and an accountability principle. A team that has done GDPR work will recognize the shape of the LGPD quickly.

The differences sit beneath the shared vocabulary. The LGPD and the GDPR are two separate regimes that share terminology.

DimensionLGPDGDPR
AuthorityThe ANPD, a Brazilian federal authority.National supervisory authorities across the EU member states, coordinated under the EDPB.
Legal basesTen bases for ordinary personal data, including credit protection and protection of health.Six lawful bases under Article 6.
Core termsControlador, operador, encarregado, titular.Controller, processor, data protection officer, data subject.
Maximum fineUp to two percent of revenue in Brazil, capped at fifty million reais per infraction.Up to four percent of global annual turnover or twenty million euros, whichever is higher.
Transfer modelAdequacy and ANPD-recognized guarantee instruments, defined by Brazilian law and the ANPD.Adequacy decisions and Article 46 safeguards, defined by EU law and the EDPB.

A GDPR program covers part of the LGPD's ground and stops short of covering it fully. The legal bases differ, the authority differs, the sanction calculation differs, and Brazilian rules define the recognized transfer instruments. The Brazil-specific work remains.

A readiness checklist

The items an organization confirms before treating its LGPD posture as sound.

The LGPD turns on the same disciplines as other comprehensive privacy regimes: an inventory of the data held, a documented purpose for holding it, working mechanisms for the control the law grants data subjects, and a record of the reasoning behind each decision. That record is what the organization presents when the ANPD reviews the program.

Common questions

What is the LGPD?
The LGPD is Brazil's Lei Geral de Proteção de Dados, Law No. 13,709/2018, the general data protection law that governs the processing of personal data in Brazil. It sets out legal bases for processing, rights for data subjects, obligations for controllers and processors, and an enforcement authority, the ANPD. It applies to processing carried out in Brazil and to processing that targets people located in Brazil, regardless of where the organization is based.
Who enforces the LGPD?
The LGPD is enforced by the Autoridade Nacional de Proteção de Dados (ANPD), Brazil's national data protection authority. The ANPD is a Brazilian federal authority, not an EU body. It supervises and enforces the law, issues regulations and guidance, and can apply administrative sanctions that range from a warning up to a fine of two percent of the entity's revenue in Brazil, capped at fifty million reais per infraction.
What are the legal bases for processing under the LGPD?
The LGPD lists ten legal bases for processing personal data, including consent, compliance with a legal or regulatory obligation, performance of a contract, the regular exercise of rights, protection of life or physical safety, protection of health, legitimate interest, credit protection, public administration carrying out public policy, and research by study bodies. Sensitive personal data has its own, narrower set of bases. Consent is one option among several, not the default.
Does the LGPD require a DPO?
The LGPD requires the controller to appoint an encarregado, the person who acts as the channel of communication between the controller, data subjects, and the ANPD. The encarregado is the Brazilian counterpart to the GDPR data protection officer. The ANPD has issued guidance that scales the requirement for smaller processing agents, but the role sits at the center of the accountability model.
How is the LGPD different from the GDPR?
The two laws share structure and vocabulary, but they are separate regimes. The LGPD is enforced by the ANPD, a Brazilian authority, not an EU one. It uses its own set of ten legal bases, where the GDPR has six. Its terms are Portuguese: controlador for controller, operador for processor, encarregado for DPO, titular for data subject. Its sanction ceiling and procedural rules are set by Brazilian law. Compliance with one does not equal compliance with the other.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.