Compliance

What Is the Brazil LGPD: Data Protection Law Explained

Understand Brazil's LGPD data protection law, its 10 legal bases, ANPD enforcement, and what international businesses must do to comply and avoid fines.

Editorial Team ·
7 min read intermediate

Introduction

Brazil is home to 215 million people, the world’s 9th-largest economy, and one of the highest rates of smartphone penetration in Latin America. Every major global technology company — from Amazon and Google to regional champions like MercadoLibre — processes the personal data of millions of Brazilians daily. Yet until 2018, Brazil had no comprehensive data protection framework. Companies operated under a patchwork of sector-specific rules with minimal enforcement.

That changed dramatically when Brazil enacted the Brazil LGPD — the Lei Geral de Proteção de Dados Pessoais, or General Personal Data Protection Law — on August 14, 2018. Effective from September 2020, the LGPD established Brazil as one of the world’s most significant privacy jurisdictions, covering 1.5 billion personal data records and affecting every company doing business in or with the Brazilian market.

If you collect email addresses, process payment data, run targeted advertising, or manage employee records involving Brazilian individuals, the LGPD likely applies to your organization — regardless of whether you are based in São Paulo or San Francisco. Understanding its requirements is essential for market access and regulatory credibility.

What Is the Brazil LGPD?

The LGPD (Lei n.º 13.709/2018) is Brazil’s first comprehensive national data protection law, modelled substantially on the European Union’s GDPR. It governs the collection, storage, sharing, use, and deletion of personal data of individuals located in Brazil (data subjects, called titulares in Portuguese).

The law applies to any processing operation carried out by a natural or legal person — public or private, Brazilian or foreign — provided at least one of the following conditions is met:

  • The processing occurs in Brazilian territory.
  • The processing involves offering or providing goods or services to individuals in Brazil.
  • The personal data was collected in Brazil.

Personal data (dados pessoais) under the LGPD means any information that relates to an identified or identifiable natural person. Sensitive personal data (dados pessoais sensíveis) — a higher-protection category — includes racial or ethnic origin, religious beliefs, political opinions, health or sexual life data, genetic and biometric data, and data about children.

The ANPD (Autoridade Nacional de Proteção de Dados) was established as Brazil’s supervisory authority. Structured under the Presidency’s Office rather than as an independent agency (a design criticized for limiting its independence), the ANPD has gradually established itself as an active regulator, issuing opinions, conducting investigations, and imposing its first enforcement actions since 2021.

How the LGPD Works

The LGPD establishes 10 legal bases (hipóteses de tratamento) that justify data processing — more than the GDPR’s six. An organization must identify at least one applicable legal basis for each processing activity.

#Legal BasisDescription
1ConsentFreely given, informed, unambiguous written consent by the data subject.
2Legal obligationProcessing is necessary to comply with a legal or regulatory obligation.
3Public policyProcessing by the public administration for policy execution or public service delivery.
4ResearchProcessing by a research body, with guaranteed anonymization where possible.
5Contract performanceProcessing necessary for a contract to which the data subject is party.
6Legal processProcessing for the exercise of rights in judicial, administrative, or arbitration proceedings.
7Life protectionProcessing necessary to protect life or physical safety of the data subject or a third party.
8Health tutelageProcessing by health professionals or health authorities for health protection.
9Legitimate interestsProcessing based on the controller’s or third party’s legitimate interests — unless data subject’s rights prevail.
10Credit protectionProcessing for consumer credit protection, including credit scoring.

Note that legitimate interests (basis 9) in the LGPD is more restricted than in the GDPR: the ANPD has issued guidance limiting it and the law itself originally confined it to certain use cases. Organizations relying on legitimate interests should review current ANPD guidance before depending on it as their primary basis.

The Woodrow Wilson Center's explainer introduces the LGPD's structure, its relationship to the GDPR, and the role of Brazil's ANPD in an accessible overview.

LGPD vs GDPR: Key Differences

Both laws are built on similar principles, but several practical differences matter for organizations operating across both jurisdictions.

FeatureLGPD (Brazil)GDPR (EU)
Legal bases10 legal bases.6 legal bases.
Supervisory authoritySingle national ANPD.27 national DPAs (one per member state).
Maximum fine2% of annual Brazil revenue, capped at R$50 million per infraction.4% of global annual turnover or €20 million, whichever is higher.
Data Protection OfficerEncarregado required for all controllers (no exemptions by size).DPO required only for certain controllers.
Children’s dataUnder 18 (vs GDPR’s under 16, with member state variation).Age of consent varies by member state (13–16).
Cross-border transfersAdequacy, standard clauses, or ANPD approval.Adequacy, SCCs, BCRs, or specific derogations.

The most operationally significant difference is the Encarregado (DPO equivalent) requirement: the LGPD requires all data controllers to appoint an encarregado regardless of the size or nature of their processing. There is no SME or threshold exemption as exists in certain GDPR interpretations.

Real-World Use Cases

E-Commerce Platform Serving Brazilian Consumers: A European fashion retailer launches a Brazilian-language website targeting Brazilian consumers, accepting BRL payments and delivering to Brazilian addresses. Even operating entirely from European servers with no physical presence in Brazil, the retailer triggers the LGPD. It must publish a Portuguese-language privacy policy disclosing the legal basis for each processing activity, appoint an encarregado with a Brazilian contact channel, and implement data subject rights processes (access, correction, deletion) in Portuguese.

Fintech Processing Brazilian Payment Data: A US-based fintech integrating with Brazilian open finance (Open Banking) APIs processes consumers’ financial history to generate credit scores. This involves sensitive financial data triggering heightened obligations. The legal basis will typically be credit protection (basis 10) or contract performance (basis 5). The ANPD has also issued specific guidance on open finance data, requiring explicit consent for secondary uses.

HR System with Brazilian Employees: A multinational company uses a centralized HR SaaS platform (hosted in the US) for its Brazilian employees. Employee personal data — salary, health insurance enrollment, performance reviews — processed in the HR system is subject to the LGPD because it was collected in Brazil from Brazilian individuals. The company must ensure the US-hosted HR vendor provides adequate contractual guarantees, and any cross-border transfer to the US must be covered by standard contractual clauses or another ANPD-approved mechanism.

Common Mistakes to Avoid

The most common compliance failure for international organizations is treating the LGPD as a pure clone of the GDPR. While the structural similarities enable significant overlap in compliance programs, three key differences trip up GDPR-compliant organizations:

First, the mandatory encarregado for all controllers — regardless of size — is frequently overlooked by small international businesses that assume the GDPR’s DPO threshold exemptions apply. They do not. Every controller must appoint an encarregado and publish their contact details.

Second, organizations misapply the legitimate interests basis. Unlike the GDPR, where legitimate interests is a broad, well-tested legal basis used for marketing, analytics, and fraud prevention, the LGPD’s use of legitimate interests has been subject to ANPD restrictions and the regulator’s interpretation has been more narrow. Organizations that rely exclusively on legitimate interests as their Brazilian legal basis for marketing activities should re-examine their legal basis documentation.

Third, failing to implement Portuguese-language data subject rights processes is a common oversight. Brazilian data subjects have the right to exercise their rights (access, correction, deletion, etc.) — and the LGPD requires controllers to respond. A non-Portuguese-speaking privacy team in New York or Dublin without a process for receiving and fulfilling Brazilian data subject rights requests creates a compliance gap.

Getting Started

Bringing your organization into LGPD compliance requires a structured review of your Brazilian data processing activities. Work through this checklist:

  1. Map your Brazilian data flows and document the legal basis for each processing activity, as required by the record-keeping duty in LGPD Art. 37.

  2. Appoint an encarregado (data protection officer equivalent) and publish their contact channel in Portuguese, per LGPD Art. 41.

  3. Map each processing activity to one of the 10 legal bases in LGPD Art. 7 (personal data) or Art. 11 (sensitive personal data), with special care for marketing, profiling, and health/biometric data.

  4. Publish a Portuguese-language privacy notice disclosing the legal basis for each category of processing, the encarregado’s identity, and your cross-border transfer mechanism, as required by LGPD Art. 9.

  5. Implement Portuguese-language workflows for data subject rights (access, correction, anonymization, portability, deletion) with response processes that meet the deadlines in LGPD Art. 18 and Art. 19.

  6. Establish a security incident response and ANPD notification workflow covering the reporting obligations in LGPD Art. 48.

  7. Validate every international data transfer against one of the mechanisms in LGPD Art. 33 (adequacy, standard contractual clauses, binding corporate rules, or ANPD-approved specific guarantees).

For organizations already managing GDPR compliance, the LGPD offers meaningful efficiency through framework alignment — but the operational differences demand dedicated attention rather than assuming full transferability.

FAQ

Common questions — answered in plain English.

What is the Brazil LGPD?
The LGPD (Lei Geral de Proteção de Dados Pessoais) is Brazil's comprehensive data protection law. Enacted in 2018 and effective from September 2020, it establishes rights for data subjects and obligations for organizations that process personal data in Brazil, closely modelled on the EU's GDPR.
Who must comply with the LGPD?
Any organization — Brazilian or foreign — that processes personal data of individuals located in Brazil must comply with the LGPD, provided the processing occurs in Brazilian territory, involves offering goods or services to individuals in Brazil, or the personal data was collected in Brazil.
What are the LGPD fines and penalties?
The ANPD can impose fines of up to 2% of an organization's annual revenue in Brazil (excluding taxes) per violation, capped at R$50 million (approximately US$10 million) per infraction. Penalties range from warnings and fines to prohibitions on data processing activities.
What is the ANPD?
The ANPD (Autoridade Nacional de Proteção de Dados) is Brazil's national data protection authority, responsible for overseeing and enforcing the LGPD. It was formally established in 2020 and issues guidelines, opinions, and enforcement decisions similar to the EU's data protection authorities.
How does the LGPD compare to the GDPR?
The LGPD is closely inspired by the GDPR and shares many concepts — legal bases for processing, data subject rights, data protection officers, and security requirements. Key differences include 10 legal bases (vs GDPR's 6), different regulatory structure (single national authority vs 27 DPAs), and somewhat less prescriptive technical requirements.
Does the LGPD require data localization?
No, the LGPD does not impose data localization requirements. Personal data may be transferred internationally as long as the transfer meets one of the permitted mechanisms: the destination country has adequate protection, the transferring organization uses approved standard contractual clauses, or another ANPD-approved mechanism applies.

References

  1. [1]
    Lei Geral de Proteção de Dados Pessoais (Lei 13.709/2018)Governo do Brasil (Government of Brazil), 2018
  2. [2]
    ANPD — Autoridade Nacional de Proteção de DadosAutoridade Nacional de Proteção de Dados
  3. [3]
  4. [4]
  5. [5]
    IAPP LGPD Summary and AnalysisInternational Association of Privacy Professionals (IAPP)