EnglishPortuguês
Brazil flag

Brazil

Brazil Data Privacy Laws: LGPD Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

Brazil Data Privacy Laws: LGPD Compliance Guide (2026)

Frequently Asked Questions

Does the LGPD apply to foreign companies that process data of people in Brazil?

Yes. The LGPD has explicit extraterritorial reach. It applies to any organization, regardless of where it is located, that processes personal data of individuals in Brazil, offers goods or services to people in Brazil, or collects data from individuals physically located in Brazil. Foreign companies must comply with the same requirements as Brazilian organizations, including appointing a DPO and establishing mechanisms for data subject rights.

What did Brazil's Constitutional Amendment EC 115/2022 change for data protection?

EC 115/2022, enacted on February 10, 2022, added personal data protection as an explicit fundamental right under Article 5, item LXXIX of Brazil's Federal Constitution. The amendment guarantees the right to data protection 'including in digital means.' It also gave the federal government exclusive jurisdiction to legislate on data protection, preventing states and municipalities from enacting conflicting rules. This constitutional footing strengthens the LGPD's authority and was cited as a key factor in the EU's decision to grant Brazil an adequacy decision in January 2026.

How does the LGPD credit protection legal basis work, and why is it unique?

The credit protection basis under Article 7(X) of the LGPD allows organizations to process personal data for credit scoring, creditworthiness assessments, and fraud prevention without obtaining consent. This legal basis reflects Brazil's extensive credit reporting system and the importance of credit access in the Brazilian economy. It is unique to the LGPD and has no direct equivalent in the GDPR, where credit-related processing typically relies on legitimate interest or legal obligation.

What changed with the EU-Brazil mutual adequacy decision in January 2026?

The mutual adequacy decision adopted on January 26, 2026 allows personal data to flow freely between Brazil and the EU (including EEA/EFTA countries) without additional transfer safeguards. Before this decision, organizations needed standard contractual clauses, binding corporate rules, or other approved mechanisms for every transfer. Now, transfers can occur directly under LGPD Article 33(I) and GDPR Article 45. The decision is reviewed every four years and excludes transfers for national security or criminal prosecution purposes.

What are Brazil's SCC requirements for international data transfers outside the EU?

Resolution CD/ANPD No. 19/2024, published August 23, 2024, introduced ANPD-approved Standard Contractual Clauses for international data transfers. The SCCs cover both controller-to-controller and controller-to-processor transfers. The 12-month grace period for implementing SCCs expired on August 23, 2025. Organizations transferring personal data to countries without an adequacy decision (i.e., most countries other than EU/EEA member states) must now have SCCs in place or face non-compliance. Binding Corporate Rules remain technically available but require ANPD pre-approval, and the ANPD states that none had been approved as of September 2026.

What are the penalties for violating the LGPD, and could they increase?

Current penalties include fines up to 2% of revenue in Brazil (capped at BRL 50 million per infraction), daily fines, public disclosure of the infraction, data blocking or deletion, suspension of processing for up to six months, and total prohibition of data processing activities. Public bodies cannot be fined at all under Article 52, paragraph 3; only warning, publicisation, blocking, deletion, suspension and prohibition apply to them. Bill PL 4530/2023 proposes raising the maximum fine to 20% of revenue with a cap of BRL 100 million per violation, but it has sat in a Senate committee since 2023 and has been awaiting designation of a rapporteur since November 2025, so it has never been voted. The ANPD's largest sanction to date is the BRL 153.7 million fine imposed on ByteDance, TikTok's parent company, on August 25, 2026. Before that, its only monetary fine was BRL 14,400 against Telekall in 2023.

How does Brazil's breach notification rule differ from the GDPR's 72-hour requirement?

Under Resolution CD/ANPD No. 15/2024, controllers must notify the ANPD and affected data subjects within three business days of becoming aware that a security incident may result in risk or harm. Small processing agents get double that window, so six business days. The GDPR requires notification to the supervisory authority within 72 hours. A key difference is that the LGPD also requires direct notification to affected data subjects within the same three-day window, while the GDPR requires data subject notification only when there is a high risk to their rights and freedoms, with no specific deadline beyond 'without undue delay.'

What is the status of Brazil's AI bill PL 2338/2023?

The Brazilian Federal Senate approved Bill No. 2338/2023 on December 10, 2024. As of September 2026 it is still before the Chamber of Deputies special committee established on April 29, 2025, which has not voted an opinion, and no floor vote has been scheduled. The bill establishes a risk-based AI framework and designates the ANPD as the primary AI regulator. It has not yet been enacted into law. Until enacted, the ANPD regulates AI-related data processing under existing LGPD provisions.

Are small businesses exempt from the LGPD?

Small processing agents, as defined by Resolution CD/ANPD No. 2/2022, have reduced compliance obligations under the LGPD. This category covers microenterprises, small businesses, startups, and natural persons or legal entities whose data processing activities pose limited risk. The reliefs are specific. No mandatory encarregado, provided a communication channel for data subjects is offered instead (art. 11). Double the normal deadlines for answering data-subject requests and for notifying the ANPD and data subjects of a security incident, so six business days rather than three (art. 14, in the wording given by Resolution CD/ANPD No. 15/2024). Up to 15 days for the simplified declaration under Article 19(I) of the LGPD (art. 15). A simplified record of processing activities (art. 9) and a simplified information security policy (art. 13). Everything else still applies, including legal basis identification, data subject rights, and breach notification itself. A small agent that carries out high-risk processing loses the whole regime under art. 3. The ANPD's first enforcement action (Telekall, 2023) was against a small telecom company.

Updates

Corrected Brazil enforcement and statute detail: added the ANPD fine of BRL 153.7 million imposed on ByteDance (TikTok) on August 25, 2026 and removed an unsupported claim that the ANPD had fined a cumulative BRL 98 million, noted that public bodies cannot be fined under Article 52, paragraph 3, renamed the regulator the Agencia Nacional de Protecao de Dados following Law No. 15.352/2026, rewrote the impact-assessment section because the LGPD has no general DPIA mandate, added the Article 11(II)(d) basis allowing sensitive data to be processed for the exercise of contractual rights, moved automated decisions from Article 18 to Article 20 as a right of review, fixed the GDPR fine and processor rows in the comparison table, corrected the adolescent age band to 12 up to 18, and replaced three broken links to ANPD regulations. Corrected the regulator's name to the Agencia Nacional de Protecao de Dados in the opening summary, put the ByteDance appeal window in the past now that it has closed, noted that the BRL 153.7 million fine covers five separate infractions under the BRL 50 million per-infraction cap, and restated the health-data sharing exception in Article 11, paragraph 4 as data portability requested by the data subject or the financial and administrative transactions arising from health services.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Independently fact-checked against the cited primary sources

Full audit-and-evolve refresh: added constitutional amendment section (EC 115/2022), AI Bill section (PL 2338/2023), updated international transfer section with Resolution CD/ANPD No. 19/2024 and SCC August 2025 deadline, expanded enforcement section with IAMSPE and TikTok cases, added LGPD vs GDPR comparison table, added internal links. Title and meta unchanged (strong existing signals). Word count expanded from ~3,850 to ~5,800.

Reviewed and approved by an editor

Sources and References

  1. Lei Geral de Protecao de Dados (Law No. 13.709/2018)(planalto.gov.br).gov
  2. ANPD Official Website(gov.br).gov
  3. Constitutional Amendment EC 115/2022: Data Protection as Fundamental Right(diascarneiro.com.br)
  4. European Commission: EU-Brazil Data Adequacy Agreement(ec.europa.eu).gov
  5. ANPD Normative Acts Index: Resolution CD/ANPD No. 15/2024 (Security Incident Communication) and Resolution CD/ANPD No. 4/2023 (Sanctions Dosimetry), with current status(gov.br).gov
  6. Resolution CD/ANPD No. 2/2022: Application of the LGPD to Small Processing Agents (official text)(gov.br).gov
  7. Resolution CD/ANPD No. 19/2024: International Data Transfer Regulation and Standard Contractual Clauses (official text)(gov.br).gov
  8. Law No. 15.211/2025: Digital Statute for Children and Adolescents (ECA Digital)(planalto.gov.br).gov
  9. Mayer Brown: End of Grace Period for Brazil SCCs (August 2025)(mayerbrown.com)
  10. Baker McKenzie: Brazil and EU Mutual Data Protection Adequacy Decision(bakermckenzie.com)
  11. Mayer Brown: A New Era for Personal Data Transfers (EU-Brazil)(mayerbrown.com)
  12. IAPP: ANPD Becomes Independent Regulatory Agency(iapp.org)
  13. Kasznar Leonardos: ANPD Second Penalty (IAMSPE)(kasznarleonardos.com)
  14. ICLG: Data Protection Laws and Regulations Brazil 2025-2026(iclg.com)
  15. Trench Rossi Watanabe: ANPD Priority Issues 2026-2027(trenchrossi.com)
  16. Library of Congress: Brazil Senate Advances AI Bill (2025)(loc.gov).gov
  17. Mattos Filho: Data Protection as Fundamental Right in Brazil(mattosfilho.com.br)
  18. Law No. 15.352 of February 25, 2026 (conversion of MP 1.317/2025): renames and reconstitutes the ANPD as the Agencia Nacional de Protecao de Dados and fixes the ECA Digital commencement at March 17, 2026(planalto.gov.br).gov
  19. ANPD: TikTok (ByteDance) fined BRL 153.7 million for failures in protecting children and adolescents data, August 25, 2026(gov.br).gov
  20. ANPD: how we supervise, including the list of concluded sanctioning administrative processes(gov.br).gov
  21. ANPD: International Data Transfers, including the approval status of each transfer mechanism(gov.br).gov
  22. Statute of the Child and Adolescent (Law No. 8.069/1990), Article 2: definitions of child and adolescent(planalto.gov.br).gov
Share: