Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01

Latin America

Brazil, the Lei Geral de Proteção de Dados

The LGPD is the most consequential privacy law in Latin America, both because of the size of the market and because it has become the template other regional legislatures borrow from. It is structurally close to the GDPR, which makes an existing European programme a good starting point, but it differs in ways that matter: ten lawful bases rather than six, a DPO requirement that is broader in principle and narrower in practice, and a regulator, the ANPD, that has built out its sanctioning framework over several distinct regulations.

Guidance only, not legal advice. Verify against the current Brazilian text and ANPD regulation before you rely on it.

Applicability

Territorial and material scope

The LGPD applies to any processing operation carried out in Brazil, to processing aimed at offering goods or services to, or processing the data of, individuals located in Brazil, and to data collected in Brazil. The medium is irrelevant, and the public sector is covered by its own chapter rather than a separate statute.

Controller (controlador)

Decides on the processing. Holds the notice, basis, rights and security duties, and must be identifiable to the data subject.

Operator (operador)

Processes on the controller’s behalf. Jointly liable where it fails to follow lawful instructions or breaches the statute, which makes instruction records important.

Encarregado, the DPO

Both controllers and operators must appoint one and publish the contact details. The ANPD has exempted small processing agents from the mandatory appointment, while still requiring a communication channel.

Exclusions

Purely personal and non-economic processing, journalistic, artistic and academic purposes, and public security and defence, which is reserved for separate legislation.

Sensitive data

Racial or ethnic origin, religious conviction, political opinion, trade union or religious organisation membership, health, sex life, genetic and biometric data. A separate and shorter list of bases applies.

Children and adolescents

Processing must be in their best interest. Children’s data generally requires specific and highlighted consent from a parent or guardian.

Processing conditions

Ten lawful bases

The additional bases relative to the GDPR are genuinely useful and are under-used by teams porting a European programme. Credit protection and the protection of health in a procedure carried out by health professionals both solve problems that would otherwise fall awkwardly onto consent.

Lawful bases for processing personal data under the LGPD
BasisWhen it worksPractitioner caution
ConsentFreely given, informed and unambiguous, for a specific purpose.Must be separable from other terms and provable. Generic authorisations are void, and consent may be revoked at any time by a free and simple procedure.
Legal or regulatory obligationThe controller must process to comply with a Brazilian legal duty.Cite the obligation. A foreign legal obligation does not fit here.
Public administrationProcessing by the public administration for public policy purposes.Public sector; carries its own transparency duties.
ResearchStudies by a research body, with anonymisation where possible.The body must qualify as a research entity under the statute.
ContractNecessary to perform a contract, or for preliminary steps at the data subject's request.Narrow. Performance only, not ancillary profiling.
Judicial or administrative proceedingsThe regular exercise of rights in proceedings, including arbitration.Keep it proportionate to the matter and retain the matter reference.
Protection of lifeProtecting the life or physical safety of the data subject or a third party.Emergency facing.
Health protectionIn a procedure carried out by health professionals, health services or a health authority.Restricted to those actors. Not a general basis for wellness or insurance analytics.
Legitimate interestsLegitimate interests of the controller or a third party, except where fundamental rights prevail.Requires a documented balancing test and, on ANPD request, a legitimate interest report. Not available for sensitive data.
Credit protectionCredit scoring and protection, under the applicable legislation.Sector specific and tied to the credit bureau framework.

Individual rights

Data subject rights

Confirmation and access

Confirmation that processing exists and access to the data, in a simplified format immediately or a full declaration within fifteen days.

Correction and anonymisation

Correction of incomplete or out-of-date data, and anonymisation, blocking or deletion of data that is unnecessary, excessive or processed unlawfully.

Portability

Portability to another provider, subject to ANPD regulation and commercial and industrial secrecy.

Information on sharing

Information about the public and private entities with which the controller has shared the data, which is broader than the equivalent GDPR duty in practice.

Review of automated decisions

The right to request review of decisions made solely on automated processing that affect the data subject’s interests, and information about the criteria used.

Revoking consent

Consent may be revoked at any time by an express, free and simplified procedure, with the consequences explained beforehand.

Cross-border

International transfers

The ANPD has published standard contractual clauses and the rules governing their use, which means the practical position now resembles the European one. Note the clauses are Brazilian instruments, not a translation of the EU set, and contracts signed before the regulation carried an adaptation deadline.

Adequacy

Transfers to a country or international organisation recognised by the ANPD as providing an adequate level of protection.

Standard contractual clauses

The ANPD clauses, adopted without modification to their substance, are the main route for ordinary commercial transfers.

Specific contractual clauses

Bespoke clauses or global corporate rules, each requiring ANPD verification.

Consent and derogations

Specific and highlighted consent to the transfer, or narrower derogations such as protection of life, judicial proceedings or international legal cooperation.

Enforcement

ANPD supervision, breaches and sanctions

Sanctions

Warning, fines of up to two percent of the group’s revenue in Brazil for the preceding year capped at fifty million reais per infraction, daily fines, publicisation of the infraction, and blocking or deletion of the data.

Suspension

For serious cases the ANPD can partially suspend database operation or the processing activity itself, which is an operational rather than financial risk.

Breach communication

Security incidents that may create relevant risk or damage must be communicated to the ANPD and to affected individuals within the period the ANPD has set, using its prescribed form.

Impact reports

The ANPD may require a data protection impact report at any time, including for processing based on legitimate interests.

Mitigating factors

The sanction regulation gives weight to a demonstrable governance programme, prompt remediation and cooperation, which rewards documentation.

Private actions

Collective actions by public prosecutors and consumer bodies are a real source of exposure alongside regulatory action.

Where to go next

Related reading

Brazil is usually the anchor for a wider regional programme. Our Latin America overview covers Mexico, Chile, Colombia, Argentina and Peru, and the jurisdiction index lists every regime we track. To map an LGPD programme onto an existing GDPR baseline, talk to us.