LGPD
Lei Geral de Proteção de Dados (Brazil)
Brazil's GDPR-inspired law, with ten legal bases and a national authority.
The law in brief
The LGPD is Brazil's general data protection law. Modeled in many ways on the GDPR, it sets legal bases for processing, gives individuals rights over their data, and requires organizations to account for how they protect it. It is enforced by the national data protection authority, the ANPD, which has issued detailed resolutions on incidents, international transfers and smaller organizations.
Who it applies to
- Processing carried out in Brazil, of any personal data.
- Processing aimed at offering goods or services to individuals in Brazil, or of data about individuals located in Brazil.
- Data collected in Brazil.
- It does not apply to purely personal, journalistic, artistic or academic uses, or to certain public security and defense purposes.
What it requires
A legal basis for every use
Process personal data only on one of the ten legal bases in Article 7, such as consent, legal obligation, contract, legitimate interest or credit protection; sensitive data has its own narrower list in Article 11.
A data protection officer
Controllers appoint an encarregado to handle complaints and communications with data subjects and the ANPD, and publish their identity and contact information.
Security and incident notice
Adopt security measures to protect personal data, and notify the ANPD and the data subjects of security incidents that may create relevant risk or damage to them.
International transfers
Transfer personal data abroad only to countries with adequate protection, under safeguards such as ANPD-approved standard contractual clauses, or on another basis in Article 33.
People's rights
Data subjects can request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about who their data is shared with, information about refusing consent, and revocation of consent (Art. 18). They can also ask for review of decisions made solely by automated processing (Art. 20).
Enforcement and penalties
Warnings, fines of up to 2% of the organization's revenue in Brazil for the previous year, capped at R$50 million per infraction, daily fines, public disclosure of the infraction, blocking or deletion of the data concerned, and partial or total suspension of processing (Art. 52).
What to do first
- Map processing and give each purpose one of the legal bases in Article 7, or Article 11 for sensitive data.
- Appoint a data protection officer (encarregado) unless an ANPD exemption for small agents applies, and publish their contact details.
- Set up a rights-request process.
- Prepare incident response to notify the ANPD and data subjects within the deadline in ANPD's incident regulation.
- Review international transfers against ANPD's rules, including its standard contractual clauses.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The recommendations aim to use privacy law enforcement to reduce manipulative political content and protect democratic processes. The Electronic Frontier Foundation, Access Now and Data Privacy Brasil issued recommendations urging stronger personal data protection in Brazil's elections. They call for prohibiting processing of sensitive political data, requiring explicit consent, and disabling political micro‑targeting tools.
Source: EFF updates. LGPD in the regulations library.
Sources
- Lei Geral de Proteção de Dados Pessoais (Lei nº 13.709/2018) Planalto · Official text or regulator