Brazil

Comprehensive

Lei Geral de Proteção de Dados (LGPD)

Authority: Autoridade Nacional de Proteção de Dados (ANPD) | Enforcement: Active | Enacted: September 2020

Overview

Brazil's LGPD is a comprehensive data protection law closely modelled on the GDPR. It applies to any processing of personal data in Brazil, regardless of where the processor is located. The ANPD became operational in 2020 and has been issuing regulations and guidance on various aspects including international transfers, DPO requirements, and data breach notification.

14-Topic Coverage

Data Protection Authority

Fully Addressed

ANPD is the national authority responsible for enforcement, guidance, and international cooperation. Transitioned to independent autarquia status.

LGPD Articles 55-A to 55-L

Data Subject Rights

Fully Addressed

Nine rights: confirmation of processing, access, correction, anonymisation/blocking/deletion, portability, information about sharing, consent management, revocation, and opposition.

LGPD Article 18

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection, SCCs, binding corporate rules, or with data subject consent. ANPD has issued transfer regulation.

LGPD Article 33

Breach Notification

Fully Addressed

Notification to ANPD and data subjects within reasonable time of security incidents that may create risk or relevant damage. ANPD regulation specifies procedures.

LGPD Article 48

DPO Requirements

Fully Addressed

Every controller must appoint a DPO (Encarregado). ANPD resolution allows small businesses to be exempt in certain circumstances.

LGPD Article 41

Children's Data

Fully Addressed

Specific consent of at least one parent/guardian required for children and adolescents. Best interests of the child must be considered.

LGPD Article 14

Penalties & Enforcement

Fully Addressed

Up to 2% of revenue in Brazil (max BRL 50 million per infraction). ANPD can also impose warnings, partial/total suspension of database, and daily fines.

LGPD Article 52

Sector-Specific Rules

Partially Addressed

Brazilian Central Bank data regulations, health data regulations (ANVISA), consumer protection code supplements LGPD. Sectoral regulation still developing.

LGPD Article 4, sector regulations

AI & Automated Decisions

Fully Addressed

LGPD Article 20 provides right to request review of automated decisions. AI regulation bill (PL 2338/2023) progressing through Congress.

LGPD Article 20, PL 2338/2023

Data Localisation

Not Addressed

No general data localisation requirement. Some sector-specific requirements for government and health data.

LGPD Article 33

Significant Data Fiduciary

Not Addressed

No direct equivalent. LGPD obligations apply to all controllers. Small businesses have reduced obligations per ANPD resolution.

ANPD Resolution CD/ANPD No. 2

Government Data

Partially Addressed

LGPD applies to government processing with specific provisions. Processing for public safety, national defence, and state security is excluded.

LGPD Article 4

Key Statistics

Maximum Penalty
BRL 50 million per infraction or 2% of revenue
Sections in Law
65
Authority
ANPD

Coverage Summary

Fully Addressed9/14
Partially Addressed3/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Brazil's regulations.

Book a Consultation