Brazil
ComprehensiveLei Geral de Proteção de Dados (LGPD)
Authority: Autoridade Nacional de Proteção de Dados (ANPD) | Enforcement: Active | Enacted: September 2020
Overview
Brazil's LGPD is a comprehensive data protection law closely modelled on the GDPR. It applies to any processing of personal data in Brazil, regardless of where the processor is located. The ANPD became operational in 2020 and has been issuing regulations and guidance on various aspects including international transfers, DPO requirements, and data breach notification.
14-Topic Coverage
Data Protection Authority
Fully AddressedANPD is the national authority responsible for enforcement, guidance, and international cooperation. Transitioned to independent autarquia status.
Consent Requirements
Fully AddressedTen legal bases for processing (broader than GDPR). Consent must be written or demonstrated. Specific consent for sensitive data. Legitimate interest is available.
Data Subject Rights
Fully AddressedNine rights: confirmation of processing, access, correction, anonymisation/blocking/deletion, portability, information about sharing, consent management, revocation, and opposition.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection, SCCs, binding corporate rules, or with data subject consent. ANPD has issued transfer regulation.
Breach Notification
Fully AddressedNotification to ANPD and data subjects within reasonable time of security incidents that may create risk or relevant damage. ANPD regulation specifies procedures.
DPO Requirements
Fully AddressedEvery controller must appoint a DPO (Encarregado). ANPD resolution allows small businesses to be exempt in certain circumstances.
Children's Data
Fully AddressedSpecific consent of at least one parent/guardian required for children and adolescents. Best interests of the child must be considered.
Penalties & Enforcement
Fully AddressedUp to 2% of revenue in Brazil (max BRL 50 million per infraction). ANPD can also impose warnings, partial/total suspension of database, and daily fines.
Sector-Specific Rules
Partially AddressedBrazilian Central Bank data regulations, health data regulations (ANVISA), consumer protection code supplements LGPD. Sectoral regulation still developing.
Cookie/Tracking
Partially AddressedNo specific cookie law. General LGPD consent requirements apply to cookies collecting personal data. ANPD guidance expected.
AI & Automated Decisions
Fully AddressedLGPD Article 20 provides right to request review of automated decisions. AI regulation bill (PL 2338/2023) progressing through Congress.
Data Localisation
Not AddressedNo general data localisation requirement. Some sector-specific requirements for government and health data.
Significant Data Fiduciary
Not AddressedNo direct equivalent. LGPD obligations apply to all controllers. Small businesses have reduced obligations per ANPD resolution.
Government Data
Partially AddressedLGPD applies to government processing with specific provisions. Processing for public safety, national defence, and state security is excluded.
Key Statistics
- Maximum Penalty
- BRL 50 million per infraction or 2% of revenue
- Sections in Law
- 65
- Authority
- ANPD
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Brazil's regulations.
Book a Consultation