Regulations › Rest of world

LGPD

Lei Geral de Proteção de Dados (Brazil)

In force privacy
WhenIn effect since 18 September 2020
Who enforces itAutoridade Nacional de Proteção de Dados (ANPD)
Who it applies toOrganizations processing personal data in Brazil or of people in Brazil.

Brazil's GDPR-inspired law, with ten legal bases and a national authority.

The law in brief

The LGPD is Brazil's general data protection law. Modeled in many ways on the GDPR, it sets legal bases for processing, gives individuals rights over their data, and requires organizations to account for how they protect it. It is enforced by the national data protection authority, the ANPD, which has issued detailed resolutions on incidents, international transfers and smaller organizations.

Who it applies to

  • Processing carried out in Brazil, of any personal data.
  • Processing aimed at offering goods or services to individuals in Brazil, or of data about individuals located in Brazil.
  • Data collected in Brazil.
  • It does not apply to purely personal, journalistic, artistic or academic uses, or to certain public security and defense purposes.

What it requires

A legal basis for every use

Process personal data only on one of the ten legal bases in Article 7, such as consent, legal obligation, contract, legitimate interest or credit protection; sensitive data has its own narrower list in Article 11.

A data protection officer

Controllers appoint an encarregado to handle complaints and communications with data subjects and the ANPD, and publish their identity and contact information.

Security and incident notice

Adopt security measures to protect personal data, and notify the ANPD and the data subjects of security incidents that may create relevant risk or damage to them.

International transfers

Transfer personal data abroad only to countries with adequate protection, under safeguards such as ANPD-approved standard contractual clauses, or on another basis in Article 33.

People's rights

Data subjects can request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about who their data is shared with, information about refusing consent, and revocation of consent (Art. 18). They can also ask for review of decisions made solely by automated processing (Art. 20).

Enforcement and penalties

Warnings, fines of up to 2% of the organization's revenue in Brazil for the previous year, capped at R$50 million per infraction, daily fines, public disclosure of the infraction, blocking or deletion of the data concerned, and partial or total suspension of processing (Art. 52).

What to do first

  1. Map processing and give each purpose one of the legal bases in Article 7, or Article 11 for sensitive data.
  2. Appoint a data protection officer (encarregado) unless an ANPD exemption for small agents applies, and publish their contact details.
  3. Set up a rights-request process.
  4. Prepare incident response to notify the ANPD and data subjects within the deadline in ANPD's incident regulation.
  5. Review international transfers against ANPD's rules, including its standard contractual clauses.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Sources