Brazil
Brazil Data Privacy Laws: LGPD Compliance Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

Brazil's Lei Geral de Protecao de Dados (Law No. 13.709/2018), in force since September 2020, is the country's comprehensive data privacy law. It covers any organization processing personal data in Brazil, provides 10 legal bases for processing under Article 7, and is enforced by the ANPD with fines up to BRL 50 million per violation.
Brazil's Lei Geral de Protecao de Dados (LGPD), enacted as Law No. 13.709/2018, is the country's general data protection law and one of the most comprehensive privacy frameworks in Latin America. The law has been in force since September 18, 2020, applies extraterritorially to any organization processing data of people in Brazil, and is enforced by the Agencia Nacional de Protecao de Dados (ANPD). For a side-by-side comparison of Brazil's framework with the European Union's GDPR, see our GDPR vs LGPD comparison. For Brazilian recording consent rules, see Brazil recording laws.
What Is the LGPD?
Brazil's Lei Geral de Protecao de Dados, commonly known as the LGPD, is the country's general data protection law. Enacted as Law No. 13.709 on August 14, 2018, and effective since September 18, 2020, the LGPD unified approximately 40 different Brazilian laws that previously regulated various aspects of personal data processing.
The law applies to any natural person or legal entity, public or private, that processes personal data in Brazil. It has explicit extraterritorial reach, meaning it applies to any foreign business that offers goods or services to individuals in Brazil, collects personal data from Brazilian residents, or operates through a Brazilian subsidiary.
The LGPD draws heavily from the European Union's General Data Protection Regulation (GDPR), but includes several provisions unique to Brazil's legal and commercial landscape. It establishes a comprehensive framework covering data collection, storage, processing, sharing, and deletion, with strong protections for individual privacy rights.
Data Protection as a Constitutional Right (EC 115/2022)
On February 10, 2022, the Brazilian Congress enacted Constitutional Amendment No. 115 (EC 115/2022), which elevated the protection of personal data to an explicit fundamental right under Brazil's 1988 Federal Constitution. The amendment added item LXXIX to Article 5, which now reads: "it is guaranteed, in the terms of the law, the right to personal data protection, including in digital means."
This constitutional change has two major practical effects. First, personal data protection now carries the same constitutional status as other fundamental rights in Article 5, such as privacy, freedom of expression, and the right to due process. Any legislation or government action that violates data protection rights is subject to constitutional challenge. Second, EC 115/2022 granted the federal government exclusive jurisdiction to legislate on personal data protection and processing. This preempts state and municipal governments from enacting conflicting privacy rules, ensuring uniform application of the LGPD across all Brazilian states and territories.
The amendment originated from Proposal for Constitutional Amendment No. 17/2019 and was motivated in part by the LGPD's entry into force, which had already established a statutory framework. EC 115/2022 gave that framework constitutional footing, reinforcing the LGPD's principles in the text of the constitution itself. The European Commission cited the constitutional amendment as one of the factors supporting Brazil's adequacy decision in January 2026.
The ANPD: Brazil's Data Protection Authority
The Agencia Nacional de Protecao de Dados (ANPD) is Brazil's national data protection authority, created by the LGPD to oversee, enforce, and regulate data protection across the country. It was known as the Autoridade Nacional de Protecao de Dados until 2026.
The authority began as a body inside the Presidency of the Republic. Law No. 14.460/2022 converted it into an autarquia de natureza especial. Medida Provisoria No. 1.317/2025, converted into Law No. 15.352 of February 25, 2026, rewrote Article 55-A of the LGPD to create the Agencia Nacional de Protecao de Dados as an autarquia de natureza especial linked to the Ministry of Justice and Public Security, governed by the Regulatory Agencies Law (Law No. 13.848/2019), with functional, technical, decision-making, administrative, and financial autonomy.
The same law added the ANPD to the list of regulatory agencies in Article 2 of Law No. 13.848/2019, added an internal audit unit to its structure, and created a dedicated data protection regulation and supervision career track for its staff.

The ANPD's responsibilities include issuing regulations and guidelines on data protection, investigating complaints and potential violations, imposing administrative sanctions for non-compliance, promoting public awareness of data protection rights, and cooperating with data protection authorities in other countries.
In November 2025, the ANPD launched its Enforcement Dashboard on gov.br/anpd, an interactive tool that provides aggregated data on oversight actions, preparatory procedures, and administrative proceedings. This dashboard represents a significant step toward enforcement transparency.
ANPD Regulatory Agenda for 2025-2026
The ANPD has published an updated regulatory agenda that prioritizes several key areas. These include data subject rights enforcement, biometric data processing rules, artificial intelligence governance and security standards, Data Protection Impact Assessment (DPIA) guidelines, data sharing by government entities, and security measures for high-risk processing.
For the 2026-2027 biennium, the ANPD has identified four priority themes for heightened scrutiny: data subject rights (with special attention to sensitive data used for advertising), protection of children and adolescents online (including compliance with the Digital ECA, age verification, and blocking of inappropriate content), processing of personal data by public authorities, and artificial intelligence and emerging technologies. These priorities reflect the ANPD's stated intention to move from educational enforcement toward active sanctioning across all sectors.
The 10 Legal Bases for Data Processing
One of the LGPD's defining features is that it establishes 10 legal bases for the lawful processing of personal data, outlined in Article 7. There is no hierarchy among these bases. Organizations must identify the most appropriate legal basis for each specific processing activity based on the purpose and the relationship with the individual.
1. Consent
The data subject provides free, informed, and unequivocal consent for a specific purpose. Consent must be given in writing or through another means that demonstrates the data subject's intent. It can be revoked at any time, and the controller must inform the data subject of the consequences of revoking consent.
2. Legal or Regulatory Obligation
Processing is necessary to comply with a legal or regulatory obligation of the controller. This covers situations where Brazilian law requires certain data to be collected or retained, such as tax records, employment data, or anti-money laundering requirements.
3. Public Policy Execution
Processing is necessary for the execution of public policies provided for in laws, regulations, or supported by contracts, agreements, or similar instruments. This basis is available exclusively to the public administration.
4. Research
Research bodies may process personal data for studies of a historical, scientific, technological, or statistical character. Wherever possible, data must be anonymized. This basis requires compliance with ethical standards and cannot be used for commercial purposes without additional legal grounds.
5. Contract Execution
Processing is necessary to execute a contract or preliminary procedures related to a contract of which the data subject is a party. This covers processing needed to fulfill contractual obligations at the data subject's request.
6. Exercise of Legal Rights
Processing is necessary for the regular exercise of rights in judicial, administrative, or arbitration proceedings. This allows organizations to process personal data when needed to establish, exercise, or defend legal claims.
7. Protection of Life or Physical Safety
Processing is necessary to protect the life or physical safety of the data subject or a third party. This emergency basis applies in situations where obtaining consent is not feasible and there is an immediate threat to someone's life or safety.
8. Health Protection
Processing is necessary for health protection purposes, carried out by health professionals, health services, or health authorities. This basis covers medical treatment, public health measures, and health-related research conducted by qualified entities.
9. Legitimate Interests
Processing is necessary for the legitimate interests of the controller or a third party, except where overridden by the data subject's fundamental rights and freedoms. Controllers relying on this basis must conduct a balancing test and maintain documentation of their assessment.
10. Credit Protection
Processing is necessary for the protection of credit, including credit scoring. This is a legal basis unique to the LGPD and not found in the GDPR. It reflects Brazil's extensive credit reporting system and allows data processing for creditworthiness assessments and fraud prevention.
Data Subject Rights Under the LGPD
Article 18 of the LGPD grants data subjects nine rights regarding their personal data, set out in incisos I through IX. These rights can be exercised at any time and free of charge through a request to the data controller.
Article 19 sets the response clock, and it is the most operationally load-bearing number in this chapter. Confirmation that processing exists, or access to the data, must be provided immediately in simplified form, or within 15 days by way of a clear and complete declaration stating the origin of the data, whether a record exists, the criteria used, and the purpose of the processing, subject to trade and industrial secrecy. Where the controller cannot adopt the requested measure immediately, Article 18, paragraph 4 requires it to reply either stating that it is not the processing agent, indicating the agent where possible, or giving the factual or legal reasons that prevent immediate action. Small processing agents get double these deadlines, and up to 15 days for the simplified declaration.

Confirmation of Processing. Data subjects have the right to confirm whether their personal data is being processed by a controller.
Access to Data. Individuals can request access to their personal data held by the controller, including information about what data is being processed and how.
Correction of Inaccurate Data. Data subjects can request the correction of incomplete, inaccurate, or outdated personal data.
Anonymization, Blocking, or Deletion. Individuals can request anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in non-compliance with the LGPD.
Data Portability. Data subjects have the right to request portability of their personal data to another service or product provider, in accordance with ANPD regulations.
Deletion of Processed Data. Individuals can request the deletion of personal data processed with their consent, except where the controller has a legal basis to retain it.
Information About Sharing. Data subjects have the right to know which public and private entities the controller has shared their data with.
Information About Consent Denial. Individuals must be informed about the possibility of denying consent and the consequences of such denial.
Revocation of Consent. Data subjects can revoke their consent at any time through an express request to the controller, through a free and facilitated procedure.
Review of Automated Decisions (Article 20)
Automated decisions are governed by Article 20, not Article 18, and the right is a right of review rather than a right to an explanation. Under Article 20 a data subject may request review of a decision taken solely on the basis of automated processing that affects their interests, including decisions that define a personal, professional, consumer, or credit profile, or aspects of their personality.
Read the wording carefully. The original 2018 text gave a right to review "por pessoa natural", by a natural person. That phrase was removed by Medida Provisoria No. 869/2018, and the removal stands in the current wording given by Law No. 13.853/2019. The LGPD therefore guarantees a review, not a human reviewer.
Article 20, paragraph 1 requires the controller, whenever asked, to supply clear and adequate information about the criteria and procedures used for the automated decision, subject to trade and industrial secrecy. Where a controller withholds that information on secrecy grounds, Article 20, paragraph 2 allows the ANPD to audit the processing for discriminatory effects.
Sensitive Personal Data
The LGPD provides enhanced protection for sensitive personal data. Under Article 5(II), sensitive data includes information related to racial or ethnic origin, religious beliefs, political opinions, trade union membership, religious, philosophical, or political organization membership, health data or data concerning sex life, and genetic or biometric data when linked to a natural person.
The statute says "vida sexual", meaning sex life, not sexual orientation. That is the broader category: data about sexual activity, history, or practices is sensitive whether or not it reveals a person's orientation.
Processing of sensitive data requires specific and prominent consent from the data subject, with clear information about the purposes of the processing. Without consent, sensitive data may only be processed where it is indispensable for one of the seven situations listed in Article 11(II): compliance with a legal or regulatory obligation; shared processing needed by the public administration to execute public policies; studies by a research body, anonymised wherever possible; the regular exercise of rights, expressly including rights under a contract and in judicial, administrative, or arbitral proceedings; protection of life or physical safety; health protection, carried out by health professionals, health services, or a health authority; and fraud prevention and the data subject's security in identification and authentication processes.
That fourth item is easy to miss and it matters. Legitimate interest under Article 7(IX) has no counterpart in Article 11, so it is never available for sensitive data. Contract performance under Article 7(V) is likewise not itself an Article 11 basis. But Article 11(II)(d) does permit non-consensual processing of sensitive data for the regular exercise of rights, and the text says "inclusive em contrato", expressly including rights arising under a contract. The LGPD also prohibits the sharing of health-related sensitive data between controllers for economic advantage. Article 11, paragraph 4 carves out only situations relating to the provision of health services, pharmaceutical assistance, and health care, including auxiliary diagnosis and therapy services, and then only to permit data portability requested by the data subject or the financial and administrative transactions arising from the use and provision of those services.
Data Protection Officer (Encarregado) Requirements
Article 41 of the LGPD requires every controller to appoint a Data Protection Officer (referred to as "encarregado" in Portuguese). The DPO serves as the primary point of contact between the controller, data subjects, and the ANPD.
The DPO's responsibilities include accepting complaints and communications from data subjects and providing clarifications, receiving communications from the ANPD and taking appropriate measures, guiding the controller's employees and contractors on data protection practices, and executing any other duties assigned by the controller or established by regulation.
The governing regulation is Resolution CD/ANPD No. 18 of July 16, 2024, which sets complementary rules on appointing the encarregado and running the function. Appointment must be by formal act, meaning a written, dated, and signed document that clearly designates a natural or legal person and states how the role will be exercised, producible to the ANPD on request (art. 3). A substitute must be formally designated to cover absences, impediments, and vacancies (art. 4). The processing agent must publish the encarregado's identity and contact details publicly, clearly, in a prominent and easily accessible place on its website, and keep them current (arts. 8 and 9).
The same regulation confirms that the role does not require registration with any body, nor any certification or specific professional training (art. 14), that the encarregado must be able to communicate with data subjects and the ANPD clearly and in Portuguese (art. 13), and that one encarregado may serve more than one processing agent so long as each agent's duties can be fully met and no conflict of interest exists (art. 19). Performing the role does not shift responsibility for compliance from the processing agent to the encarregado (art. 17).
Small processing agents, as defined by Resolution CD/ANPD No. 2/2022, are exempt from the mandatory DPO appointment requirement. This exemption applies to microenterprises, small businesses, startups, and natural persons or legal entities whose data processing activities pose limited risk. However, the ANPD still recommends voluntary appointment as a best practice.
In November 2024, the ANPD initiated proceedings against 20 companies for failing to appoint or publicly disclose a DPO. By April 2025, all companies had achieved compliance, demonstrating both the ANPD's willingness to target non-compliant organizations and the effectiveness of targeted enforcement campaigns.
Breach Notification Requirements
The LGPD requires controllers to report security incidents involving personal data to the ANPD and affected data subjects. Resolution CD/ANPD No. 15/2024, adopted on April 24, 2024, established detailed requirements for this notification process.
Timeline. Controllers must notify the ANPD and affected data subjects within three business days of becoming aware that a security incident involved personal data likely to result in risk or relevant harm. If complete details are not immediately available, a preliminary notification can be submitted within this window, with supplementary information due within 20 business days.
Small processing agents get double time, so six business days, under Article 14(II) of Resolution CD/ANPD No. 2/2022 as amended by Resolution CD/ANPD No. 15/2024.
Content of Notification. The notification must include a description of the nature of the affected personal data, information about the data subjects involved, the technical and security measures used to protect the data (subject to trade secret protections), the risks related to the incident, the measures taken to reverse or mitigate the effects of the incident, and the reasons for any delay in notification if the three-day deadline was not met.
Notification to Data Subjects. When individual notification is required, it must be made in simple, easy-to-understand language. Controllers should contact data subjects directly through email, SMS, letter, or electronic message, preferably using the communication channel normally used with the data subject. If the controller cannot identify all affected individuals, it must publicly disclose the incident through its website, applications, social media, and customer service channels for at least three months.
DPO Role in Notification. The breach notification must be submitted by the controller's DPO or legal representative with the corresponding nomination documentation or power of attorney, using the breach reporting form provided by the ANPD.
Penalties and ANPD Enforcement
The LGPD establishes a graduated system of administrative sanctions for non-compliance, outlined in Articles 52 through 54. The ANPD classifies infractions as minor, medium, or serious under Resolution CD/ANPD No. 4/2023, which sets the methodology for calculating fine amounts (dosimetria) and determines the severity of sanctions applied.
Types of Sanctions
Warning. The ANPD may issue a warning with a deadline for the controller to adopt corrective measures.
Simple Fine. Fines of up to 2% of the legal entity's, group's, or conglomerate's revenue in Brazil in the preceding fiscal year, net of taxes, capped at BRL 50 million per infraction. Article 52(II) makes that BRL 50 million figure a hard ceiling, not an alternative to the percentage.
Daily Fine. The ANPD may impose daily fines subject to the same BRL 50 million cap, designed to compel compliance within a specified timeframe.
Public Notice. After a violation is duly investigated and confirmed, the ANPD may publicly disclose the infraction, which can cause significant reputational damage.
Blocking of Data. The ANPD can order the blocking of personal data related to the violation until the processing is regularized.
Deletion of Data. The authority can order the complete deletion of personal data related to the infraction.
Suspension of Processing. The ANPD may suspend data processing activities for up to six months, with the possibility of renewal, until the controller resolves the non-compliance.
Prohibition of Processing. In severe cases, the ANPD can impose a partial or total ban on data processing activities.
Public Bodies Cannot Be Fined. Article 52, paragraph 3 limits which of these sanctions may be applied to public entities and bodies. Warning, publicisation of the infraction, blocking, deletion, suspension, and prohibition are available. Simple fines and daily fines are not. That is without prejudice to the separate regimes in Law No. 8.112/1990, Law No. 8.429/1992, and Law No. 12.527/2011.
Notable Enforcement Actions
Through 2025 the ANPD's monetary sanctions were very small. Its published list of concluded sanctioning administrative processes names eight matters, and seven of the eight are public bodies, which Article 52, paragraph 3 exempts from fines altogether. The only monetary fine among them was Telekall's BRL 14,400 in 2023.
That changed on August 25, 2026, when the ANPD fined ByteDance BRL 153.7 million. Public bodies remain outside the fine regime, but private controllers now face a demonstrated nine-figure ceiling rather than the five-figure one the earlier record suggested.
Telekall Infoservice (2023). The ANPD's first-ever enforcement action targeted this small telecom company after a complaint that it was offering a list of voters' WhatsApp contacts for election campaign use. The authority found three violations, and they did not all draw the same sanction. Processing personal data with no legal basis (Article 7) and failing to answer the inspection team's requests (Article 5 of Resolution CD/ANPD No. 1/2021) each drew a simple fine, capped for each infraction at 2% of the microenterprise's gross revenue under Article 52(II) and totalling BRL 14,400. Failing to appoint an encarregado (Article 41) drew a warning, not a fine. Though modest in amount, the case signaled that compliance obligations apply to businesses of all sizes.
IAMSPE (2024). The ANPD's second enforcement action targeted the Instituto de Assistencia Medica ao Servidor Publico Estadual de Sao Paulo (IAMSPE), a public health body. The sanctions arose from a security incident in which personal data of state civil servants and their dependents was accessed by an unauthorized external user. The ANPD issued two warnings: the first for failing to notify the ANPD and affected data subjects within the required timeframe (a violation of Article 48 of the LGPD); the second for inadequate security controls protecting a high volume of personal data including data of vulnerable subjects such as minors and the elderly (a violation of Article 49). Public sector entities carry the same substantive LGPD duties as private controllers, but they do not face the same sanctions. Under Article 52, paragraph 3 they cannot be fined at all, which is why IAMSPE received two warnings and no monetary penalty.
Meta Platforms (July 2024). The ANPD issued a preventive measure ordering Meta to stop using personal data from Facebook, Instagram, and Messenger to train its AI systems. The ANPD found four distinct LGPD violations: inadequate disclosures, insufficient protections for children's data, failure to provide opt-out mechanisms, and disregard for the legitimate expectations of Brazilian social media users. Meta faced daily fines of BRL 50,000 for non-compliance. After Meta implemented required adjustments, the measure was suspended in August 2024.
TikTok/ByteDance (August 2026). On August 25, 2026 the ANPD fined ByteDance, the company behind TikTok, BRL 153.7 million for processing the personal data of children and adolescents without a valid legal basis. It is the largest LGPD sanction imposed to date, by a wide margin.
The decision covers five violations of Articles 6(VIII), 6(X), and 7, spanning both the logged-out feed and the registered-account feed. The ANPD also ordered deletion of the data collected irregularly. ByteDance had ten business days from the August 24, 2026 notification to appeal to the ANPD's Conselho Diretor, a window that closed in early September 2026.
In a decision published the same day, the Conselho Diretor approved a compliance plan for the platform. It requires the most restrictive privacy settings by default on accounts of users under 16, changeable only with a guardian's authorisation, stronger parental supervision tools, and stricter content filters. In the logged-out experience TikTok must suspend all advertising in Brazil, bar posting, commenting, direct messages, following, and live streams, cap the session at 12 hours, limit content to material suitable for all ages, and reduce data collection to the minimum. The plan is subject to the age verification schedule set under the ECA Digital.
Ongoing Investigations. As of 2026, the ANPD has active supervisory actions against social media networks (regarding children's data), messaging platforms (transparency and consent issues), pharmaceutical loyalty programs, and 23 football clubs using facial recognition technology for stadium access.
Proposed Penalty Increases
Bill PL 4530/2023, filed in the Senate by Senator Angelo Coronel in September 2023, proposes significant increases to LGPD penalties. If approved, the maximum fine percentage would increase from 2% to 20% of revenue, and the absolute cap would double from BRL 50 million to BRL 100 million per violation.
The bill has gone nowhere. It has never left its first committee, the Senate's Committee on Transparency, Governance, Oversight, Control and Consumer Protection, and its recorded status has been "awaiting designation of a rapporteur" since November 13, 2025, when the previous rapporteur returned it. It has not been voted in committee, let alone by either house. Treat the 20% figure as a proposal, not a trend.
International Data Transfers and Standard Contractual Clauses
The LGPD provides specific rules for the international transfer of personal data, detailed in Articles 33 through 36. Transfers are only permitted under legally defined mechanisms.

Transfer Mechanisms
Adequacy Decisions. The ANPD can recognize that a foreign country or international organization provides an adequate level of personal data protection. This is the simplest mechanism, as it allows transfers without additional safeguards.
Standard Contractual Clauses (SCCs). Resolution CD/ANPD No. 19/2024, published on August 23, 2024, introduced ANPD-approved Standard Contractual Clauses as the primary transfer mechanism for organizations without an adequacy decision. The SCCs cover both controller-to-controller and controller-to-processor transfers. The grace period for implementing these SCCs expired on August 23, 2025. Since that date, international data transfers are only valid if SCCs or another ANPD-approved mechanism are in place.
Binding Corporate Rules (BCRs). For intragroup international data transfers, organizations may use binding corporate rules, which require prior assessment and approval from the ANPD. As of September 2026, the ANPD's own international transfer page states that no global corporate rules have been approved by the Conselho Diretor, making them a technically available but practically unavailable mechanism.
Specific Contractual Clauses. When SCCs are insufficient, organizations may use specific contractual clauses as a subsidiary mechanism. These must mirror the SCCs as closely as possible and require prior ANPD approval.
Seals, Certificates, and Codes of Conduct. Article 33(II)(d) also allows a controller to demonstrate the required guarantees through regularly issued seals, certificates, and codes of conduct.
Other Permitted Circumstances. International transfers are also permitted for international legal cooperation, protection of life or physical safety, data subject consent, compliance with legal or regulatory obligations, contractual necessity, and the regular exercise of legal rights.
In practice the menu is far shorter than the statute suggests. The ANPD's international transfer page states that the Conselho Diretor has to date approved no equivalent standard contractual clauses, no specific contractual clauses, and no global corporate rules, and that the European Union is the only adequacy recognition it has granted, through Resolution CD/ANPD No. 32/2026. That leaves the ANPD's own standard contractual clauses under Resolution CD/ANPD No. 19/2024 and the EU adequacy decision as the operative mechanisms.
The EU-Brazil Mutual Adequacy Decision
On January 26, 2026, Brazil and the European Union adopted mutual adequacy decisions, marking a watershed moment for international data transfers between the two jurisdictions. This was formalized through Resolution CD/ANPD No. 32/2026 on the Brazilian side and the corresponding European Commission implementing decision on the EU side.
This mutual recognition means personal data can circulate between Brazil and the EU directly, securely, and without additional transfer mechanisms under LGPD Article 33(I). The decision covers transfers to all EU member states plus Iceland, Liechtenstein, and Norway (EEA/EFTA countries), as well as EU institutions, bodies, and agencies.
The adequacy framework excludes transfers conducted exclusively for public security, national defense, state security, or criminal investigation and prosecution purposes. The agreement is subject to review every four years. This is Brazil's first-ever adequacy decision and the most comprehensive one adopted by the European Union under the GDPR, covering both public and private sectors simultaneously.
Brazil's AI Bill (PL 2338/2023)
Brazil's proposed Artificial Intelligence Act, Bill No. 2338/2023, represents a significant regulatory development for organizations using AI systems to process personal data. The Brazilian Federal Senate approved the bill on December 10, 2024. As of September 2026 it is still before the Chamber of Deputies, in the special committee established on April 29, 2025, with Deputy Aguinaldo Ribeiro designated as rapporteur on May 20, 2025.
The bill establishes a risk-based framework with three tiers. Excessive-risk AI systems are banned outright. High-risk systems, which include those used for biometric identification, employment decisions, credit scoring, and social services, require formal impact assessments before deployment. Significant-risk systems face transparency and disclosure obligations.
The ANPD is designated as the primary AI regulator under the bill's current text. This would give the ANPD jurisdiction over AI systems that process personal data, creating direct overlap with LGPD enforcement. The bill also creates specific obligations for generative AI foundation models, including transparency requirements for training data.
The Chamber's review has surfaced competing concerns about biometric surveillance carve-outs for public security, the scope of liability for foundation model developers, and the relationship between the AI bill and existing LGPD provisions. As of September 2026 the committee has not voted an opinion, the recent activity on the file consists of related bills being attached to it, and no floor vote has been scheduled. Until the bill is enacted and in force, the ANPD regulates AI-related data processing under existing LGPD provisions, as demonstrated by the 2024 Meta AI training enforcement action.
LGPD vs. GDPR: Key Differences
While the LGPD is modeled on the GDPR, several important differences distinguish the two frameworks. The table below summarizes the most significant structural variations.
| Topic | LGPD (Brazil) | GDPR (EU) |
|---|---|---|
| Legal bases for processing | 10 (includes credit protection) | 6 |
| Maximum fine | 2% of Brazilian revenue, with BRL 50M as a hard per-infraction ceiling (art. 52, II) | The higher of EUR 20M or 4% of worldwide annual turnover (art. 83(5)); EUR 10M or 2% for art. 83(4) infringements |
| Breach notification to authority | 3 business days (6 for small processing agents) | 72 hours |
| Breach notification to individuals | 3 business days, same window (6 for small processing agents) | Without undue delay when high risk |
| DPO requirement | All controllers (with narrow SME exemption) | Conditional (large-scale, public authority, special category) |
| Direct processor obligations | Yes. Operators are directly bound (arts. 37, 39, 46), jointly liable (art. 42, para. 1, I) and directly sanctionable (art. 52) | Yes (directly bound) |
| Children's data consent age | Parental consent required under 12 | 16 (member states may lower to 13) |
| Non-discrimination principle | Explicit standalone principle | Not a standalone principle |
| Constitutional foundation | Yes (EC 115/2022, Art. 5 LXXIX) | Yes (EU Charter Art. 8) |
One difference the table cannot capture in a single cell: the LGPD has no equivalent of GDPR Article 28's mandatory list of controller-to-processor contract terms. Brazil binds the operator directly by statute rather than by prescribing what the contract must say.
For a full analysis of both frameworks, see our GDPR vs LGPD comparison.
Data Protection Impact Assessments
The LGPD does not impose a general duty to carry out a Data Protection Impact Assessment. This is a common misreading, and it matters, because the obligation is triggered by the regulator rather than by the controller's own risk score.
Article 38 says the national authority "podera determinar", meaning it may determine, that a controller produce a relatorio de impacto a protecao de dados pessoais (RIPD), including for sensitive data, in the terms of a regulation and subject to trade and industrial secrecy. Article 10, paragraph 3 similarly says the ANPD may request a RIPD from a controller relying on legitimate interest. Both are discretionary powers of the authority, not self-executing duties on every controller.
Article 38, sole paragraph sets the minimum contents of the report: the types of data collected, the methodology used for collection and for securing the information, and the controller's analysis of the measures, safeguards, and risk mitigation mechanisms adopted.
There is a separate high-risk test that is often mistaken for a DPIA trigger. Article 4 of Resolution CD/ANPD No. 2/2022 treats processing as high risk when it meets at least one general criterion (large-scale processing, or processing that may significantly affect data subjects' interests and fundamental rights) and at least one specific criterion (emerging or innovative technologies, surveillance or control of publicly accessible zones, decisions taken solely on automated processing, or use of sensitive data or the data of children, adolescents, or the elderly). That test exists for one purpose: deciding whether a small processing agent forfeits its reduced-obligation regime under Article 3 of the same resolution. It is not a DPIA trigger for controllers generally.
A dedicated RIPD regulation remains on the ANPD's regulatory agenda and has not been issued. Until it is, the practical posture is that the ANPD can order a RIPD, so a controller running high-risk processing should be able to produce one on demand.
Children's and Adolescents' Data
The LGPD provides specific protections for the processing of children's and adolescents' personal data under Article 14. Processing must always be carried out in the best interest of the child or adolescent.
For children under 12, the processing of personal data requires specific and prominent consent from at least one parent or legal guardian. Controllers must make reasonable efforts to verify that consent was actually given by the parent or guardian, using available technology.
The LGPD does not define crianca or adolescente itself. It borrows the definitions in Article 2 of the ECA (Law No. 8.069/1990): a child is a person under 12, and an adolescent is a person between 12 and 18. So adolescents are 12 up to 18, not 13 to 17, and a twelve-year-old falls in the adolescent band.
For adolescents, the LGPD does not require parental consent, but Article 14 still requires that processing serve the adolescent's best interest. The ANPD has signaled heightened scrutiny of data processing involving minors as a priority for the 2026-2027 biennium.
Brazil's Digital Statute for Children and Adolescents (ECA Digital, Law No. 15.211/2025) creates additional rules for protecting minors when using online applications, electronic games, social networks, and software. Its commencement date is now fixed by statute: Article 41-A, inserted by Law No. 15.352/2026, provides that the law entered into force on March 17, 2026. Platform operators must implement age verification mechanisms, privacy-by-default settings, and content moderation for minors.
The ECA Digital carries its own sanctions regime, separate from the LGPD's and steeper in rate. Article 35 provides for a warning with up to 30 days to adopt corrective measures; a simple fine of up to 10% of the economic group's revenue in Brazil in its last financial year, or, where there is no revenue, BRL 10 to BRL 1,000 per registered user, capped in total at BRL 50 million per infraction; temporary suspension of activities; and prohibition of activities. Enforcement sits with the autonomous authority named in Article 34, a role the ANPD is exercising, and the ANPD's August 2026 ByteDance compliance plan was expressly tied to the ECA Digital age verification schedule.
Compliance Requirements for Organizations
Organizations processing personal data in Brazil or of Brazilian residents should take the following steps to ensure LGPD compliance.
Appoint a Data Protection Officer. Unless exempt as a small processing agent, every controller must appoint a DPO and publicly disclose the DPO's contact information. The DPO must be able to communicate in Portuguese with the ANPD.
Map Data Processing Activities. Conduct a comprehensive inventory of all personal data processing activities, identifying the types of data collected, purposes of processing, legal bases relied upon, data sharing arrangements, and retention periods.
Establish Legal Bases. Identify and document the appropriate legal basis for each processing activity. Legitimate interest is never available for sensitive data. Contract performance is not itself an Article 11 basis either, but Article 11(II)(d) does allow sensitive data to be processed for the regular exercise of rights, expressly including rights under a contract.
Implement Data Subject Rights Mechanisms. Create clear, accessible, and free processes for data subjects to exercise their rights, including access, correction, deletion, portability, and consent revocation.
Develop a Breach Response Plan. Prepare an incident response plan that enables notification to the ANPD and affected data subjects within three business days, or six if you qualify as a small processing agent. Designate team members responsible for breach assessment and notification.
Be Ready to Produce a RIPD. There is no general DPIA mandate. Under Article 38 the ANPD may order a controller to produce a relatorio de impacto, and under Article 10, paragraph 3 it may request one for legitimate-interest processing. Document the assessment methodology, identified risks, and mitigation measures for high-risk activities so a report can be produced on request.
Review International Transfer Mechanisms. If transferring data internationally, ensure compliance with LGPD Articles 33-36. Transfers to EU countries benefit from the January 2026 mutual adequacy decision and require no additional mechanisms. Transfers to other jurisdictions require ANPD-approved SCCs (under Resolution CD/ANPD No. 19/2024, with the grace period having expired on August 23, 2025), a future BCR approval, or another lawful mechanism. Organizations that have not yet implemented SCCs for non-EU transfers are currently non-compliant.
Train Employees. Provide regular data protection training to employees and contractors who handle personal data. The DPO should oversee training programs.
Maintain Records. Keep detailed records of processing activities, consent obtained, DPIAs conducted, breach notifications submitted, and data subject requests fulfilled.
Monitor AI and Children's Data Developments. Organizations using AI systems to process personal data should track the progress of PL 2338/2023 in the Chamber of Deputies. Operators of online platforms accessible to minors must comply with ECA Digital (Law No. 15.211/2025), in force since March 17, 2026, whose own sanctions reach 10% of Brazilian group revenue capped at BRL 50 million per infraction.
Frequently Asked Questions
Does the LGPD apply to foreign companies that process data of people in Brazil?
Yes. The LGPD has explicit extraterritorial reach. It applies to any organization, regardless of where it is located, that processes personal data of individuals in Brazil, offers goods or services to people in Brazil, or collects data from individuals physically located in Brazil. Foreign companies must comply with the same requirements as Brazilian organizations, including appointing a DPO and establishing mechanisms for data subject rights.
What did Brazil's Constitutional Amendment EC 115/2022 change for data protection?
EC 115/2022, enacted on February 10, 2022, added personal data protection as an explicit fundamental right under Article 5, item LXXIX of Brazil's Federal Constitution. The amendment guarantees the right to data protection 'including in digital means.' It also gave the federal government exclusive jurisdiction to legislate on data protection, preventing states and municipalities from enacting conflicting rules. This constitutional footing strengthens the LGPD's authority and was cited as a key factor in the EU's decision to grant Brazil an adequacy decision in January 2026.
How does the LGPD credit protection legal basis work, and why is it unique?
The credit protection basis under Article 7(X) of the LGPD allows organizations to process personal data for credit scoring, creditworthiness assessments, and fraud prevention without obtaining consent. This legal basis reflects Brazil's extensive credit reporting system and the importance of credit access in the Brazilian economy. It is unique to the LGPD and has no direct equivalent in the GDPR, where credit-related processing typically relies on legitimate interest or legal obligation.
What changed with the EU-Brazil mutual adequacy decision in January 2026?
The mutual adequacy decision adopted on January 26, 2026 allows personal data to flow freely between Brazil and the EU (including EEA/EFTA countries) without additional transfer safeguards. Before this decision, organizations needed standard contractual clauses, binding corporate rules, or other approved mechanisms for every transfer. Now, transfers can occur directly under LGPD Article 33(I) and GDPR Article 45. The decision is reviewed every four years and excludes transfers for national security or criminal prosecution purposes.
What are Brazil's SCC requirements for international data transfers outside the EU?
Resolution CD/ANPD No. 19/2024, published August 23, 2024, introduced ANPD-approved Standard Contractual Clauses for international data transfers. The SCCs cover both controller-to-controller and controller-to-processor transfers. The 12-month grace period for implementing SCCs expired on August 23, 2025. Organizations transferring personal data to countries without an adequacy decision (i.e., most countries other than EU/EEA member states) must now have SCCs in place or face non-compliance. Binding Corporate Rules remain technically available but require ANPD pre-approval, and the ANPD states that none had been approved as of September 2026.
What are the penalties for violating the LGPD, and could they increase?
Current penalties include fines up to 2% of revenue in Brazil (capped at BRL 50 million per infraction), daily fines, public disclosure of the infraction, data blocking or deletion, suspension of processing for up to six months, and total prohibition of data processing activities. Public bodies cannot be fined at all under Article 52, paragraph 3; only warning, publicisation, blocking, deletion, suspension and prohibition apply to them. Bill PL 4530/2023 proposes raising the maximum fine to 20% of revenue with a cap of BRL 100 million per violation, but it has sat in a Senate committee since 2023 and has been awaiting designation of a rapporteur since November 2025, so it has never been voted. The ANPD's largest sanction to date is the BRL 153.7 million fine imposed on ByteDance, TikTok's parent company, on August 25, 2026. Before that, its only monetary fine was BRL 14,400 against Telekall in 2023.
How does Brazil's breach notification rule differ from the GDPR's 72-hour requirement?
Under Resolution CD/ANPD No. 15/2024, controllers must notify the ANPD and affected data subjects within three business days of becoming aware that a security incident may result in risk or harm. Small processing agents get double that window, so six business days. The GDPR requires notification to the supervisory authority within 72 hours. A key difference is that the LGPD also requires direct notification to affected data subjects within the same three-day window, while the GDPR requires data subject notification only when there is a high risk to their rights and freedoms, with no specific deadline beyond 'without undue delay.'
What is the status of Brazil's AI bill PL 2338/2023?
The Brazilian Federal Senate approved Bill No. 2338/2023 on December 10, 2024. As of September 2026 it is still before the Chamber of Deputies special committee established on April 29, 2025, which has not voted an opinion, and no floor vote has been scheduled. The bill establishes a risk-based AI framework and designates the ANPD as the primary AI regulator. It has not yet been enacted into law. Until enacted, the ANPD regulates AI-related data processing under existing LGPD provisions.
Are small businesses exempt from the LGPD?
Small processing agents, as defined by Resolution CD/ANPD No. 2/2022, have reduced compliance obligations under the LGPD. This category covers microenterprises, small businesses, startups, and natural persons or legal entities whose data processing activities pose limited risk. The reliefs are specific. No mandatory encarregado, provided a communication channel for data subjects is offered instead (art. 11). Double the normal deadlines for answering data-subject requests and for notifying the ANPD and data subjects of a security incident, so six business days rather than three (art. 14, in the wording given by Resolution CD/ANPD No. 15/2024). Up to 15 days for the simplified declaration under Article 19(I) of the LGPD (art. 15). A simplified record of processing activities (art. 9) and a simplified information security policy (art. 13). Everything else still applies, including legal basis identification, data subject rights, and breach notification itself. A small agent that carries out high-risk processing loses the whole regime under art. 3. The ANPD's first enforcement action (Telekall, 2023) was against a small telecom company.
Updates
Corrected Brazil enforcement and statute detail: added the ANPD fine of BRL 153.7 million imposed on ByteDance (TikTok) on August 25, 2026 and removed an unsupported claim that the ANPD had fined a cumulative BRL 98 million, noted that public bodies cannot be fined under Article 52, paragraph 3, renamed the regulator the Agencia Nacional de Protecao de Dados following Law No. 15.352/2026, rewrote the impact-assessment section because the LGPD has no general DPIA mandate, added the Article 11(II)(d) basis allowing sensitive data to be processed for the exercise of contractual rights, moved automated decisions from Article 18 to Article 20 as a right of review, fixed the GDPR fine and processor rows in the comparison table, corrected the adolescent age band to 12 up to 18, and replaced three broken links to ANPD regulations. Corrected the regulator's name to the Agencia Nacional de Protecao de Dados in the opening summary, put the ByteDance appeal window in the past now that it has closed, noted that the BRL 153.7 million fine covers five separate infractions under the BRL 50 million per-infraction cap, and restated the health-data sharing exception in Article 11, paragraph 4 as data portability requested by the data subject or the financial and administrative transactions arising from health services.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Independently fact-checked against the cited primary sources
Full audit-and-evolve refresh: added constitutional amendment section (EC 115/2022), AI Bill section (PL 2338/2023), updated international transfer section with Resolution CD/ANPD No. 19/2024 and SCC August 2025 deadline, expanded enforcement section with IAMSPE and TikTok cases, added LGPD vs GDPR comparison table, added internal links. Title and meta unchanged (strong existing signals). Word count expanded from ~3,850 to ~5,800.
Reviewed and approved by an editor
Sources and References
- Lei Geral de Protecao de Dados (Law No. 13.709/2018)(planalto.gov.br).gov
- ANPD Official Website(gov.br).gov
- Constitutional Amendment EC 115/2022: Data Protection as Fundamental Right(diascarneiro.com.br)
- European Commission: EU-Brazil Data Adequacy Agreement(ec.europa.eu).gov
- ANPD Normative Acts Index: Resolution CD/ANPD No. 15/2024 (Security Incident Communication) and Resolution CD/ANPD No. 4/2023 (Sanctions Dosimetry), with current status(gov.br).gov
- Resolution CD/ANPD No. 2/2022: Application of the LGPD to Small Processing Agents (official text)(gov.br).gov
- Resolution CD/ANPD No. 19/2024: International Data Transfer Regulation and Standard Contractual Clauses (official text)(gov.br).gov
- Law No. 15.211/2025: Digital Statute for Children and Adolescents (ECA Digital)(planalto.gov.br).gov
- Mayer Brown: End of Grace Period for Brazil SCCs (August 2025)(mayerbrown.com)
- Baker McKenzie: Brazil and EU Mutual Data Protection Adequacy Decision(bakermckenzie.com)
- Mayer Brown: A New Era for Personal Data Transfers (EU-Brazil)(mayerbrown.com)
- IAPP: ANPD Becomes Independent Regulatory Agency(iapp.org)
- Kasznar Leonardos: ANPD Second Penalty (IAMSPE)(kasznarleonardos.com)
- ICLG: Data Protection Laws and Regulations Brazil 2025-2026(iclg.com)
- Trench Rossi Watanabe: ANPD Priority Issues 2026-2027(trenchrossi.com)
- Library of Congress: Brazil Senate Advances AI Bill (2025)(loc.gov).gov
- Mattos Filho: Data Protection as Fundamental Right in Brazil(mattosfilho.com.br)
- Law No. 15.352 of February 25, 2026 (conversion of MP 1.317/2025): renames and reconstitutes the ANPD as the Agencia Nacional de Protecao de Dados and fixes the ECA Digital commencement at March 17, 2026(planalto.gov.br).gov
- ANPD: TikTok (ByteDance) fined BRL 153.7 million for failures in protecting children and adolescents data, August 25, 2026(gov.br).gov
- ANPD: how we supervise, including the list of concluded sanctioning administrative processes(gov.br).gov
- ANPD: International Data Transfers, including the approval status of each transfer mechanism(gov.br).gov
- Statute of the Child and Adolescent (Law No. 8.069/1990), Article 2: definitions of child and adolescent(planalto.gov.br).gov