Brazil (LGPD)

Brazil's LGPD Reads Like the GDPR Until You Count the Legal Bases

Key Takeaways

  • Article 7 of the LGPD sets out ten legal bases for processing, including credit protection and the regular exercise of rights in judicial proceedings, which have no direct GDPR counterpart
  • Article 20 grants a right to request review of solely automated decisions, but the words "by a natural person" were removed from the enacted text by Law 13.853 of 2019
  • Administrative fines under Article 52 are capped at 2% of the group's revenue in Brazil, and separately at R$50,000,000 per infraction
  • The European Commission adopted an adequacy decision for Brazil on 26 January 2026; ANPD Resolution No. 32 of the same date recognised the EU in return
  • Of the sanctioning proceedings ANPD publishes as concluded for 2023 and 2024, eight of nine were against public-sector bodies

A Note on Language Before Anything Else

The Lei Geral de Proteção de Dados is Portuguese law and there is no official English text of it. The statute cited throughout this guide is the consolidated version published by the Presidency's Casa Civil on the Planalto site, and the article summaries below are this publication's rendering of that Portuguese text rather than authoritative wording.

Two English-language documents do carry official weight and are used here where they overlap: the European Commission's implementing decision on Brazilian adequacy, which describes the LGPD at length as part of its assessment, and ANPD Resolution No. 32, which the Brazilian authority itself published in an English version. Where this guide quotes, it quotes those.

Mutual Adequacy Arrived in January 2026

The most consequential recent development is not in the statute at all. On 26 January 2026 the European Commission adopted Implementing Decision C(2026) 373 final under Article 45(3) of the GDPR. Its Article 1 is short and its scope limit is worth reading closely:

For the purpose of Article 45 of Regulation (EU) 2016/679, Brazil ensures an adequate level of protection for personal data transferred from the European Union to controllers and processors in Brazil subject to the General Data Protection Law (LGPD).

Commission Implementing Decision C(2026) 373 final, Article 1

Adequacy attaches to importers subject to the LGPD, not to Brazilian territory as such. Article 3 of the decision commits the Commission to continuous monitoring, requires member states and the Commission to inform each other where the ANPD or another competent Brazilian authority fails to ensure compliance, and provides for evaluation after four years and at least every four years thereafter. Paragraphs 5 and 6 reserve the power to suspend, repeal or amend the decision — including where a lack of cooperation from the Brazilian government prevents the Commission from assessing whether the Article 1 finding still holds.

The Brazilian half was adopted the same day and separately. ANPD Resolution No. 32, in the authority's own English version, recognises the European Union as an international organisation providing an adequate level of protection. Its sole paragraph extends that recognition to all EU member states, to the three EFTA states in the EEA — Iceland, Liechtenstein and Norway — and to the institutions, bodies and agencies of the European Union under Regulation (EU) 2018/1725. Article 2 carves out transfers carried out exclusively for public safety, national defence, State security, or the investigation and prosecution of criminal offences. Article 4 sets a four-year reassessment, mirroring the European side.

These are two unilateral instruments adopted in coordination, not a treaty. Either side can revisit its own decision on its own timetable.

Ten Legal Bases, Not Six

The most cited similarity between the LGPD and the GDPR is the legal basis structure, and it is also where the two most clearly part company. Article 7 of the LGPD lists ten hypotheses on which processing may be carried out, against the GDPR's six. Several are recognisable — consent, compliance with a legal or regulatory obligation, performance of a contract, protection of life or physical safety, legitimate interests. Others have no direct European counterpart, including processing for the regular exercise of rights in judicial, administrative or arbitral proceedings, for the protection of health in a procedure carried out by health professionals or health entities, and for credit protection.

Article 11 governs sensitive personal data separately and more restrictively, with its own enumerated hypotheses rather than an Article 9-style prohibition-plus-exceptions construction. Consent for sensitive data must be specific and highlighted, for specific purposes.

The practical effect of a longer list is that consent carries less of the load in Brazil than a reader arriving from a consent-centric regime might expect — and that a controller reasoning from GDPR bases alone will find Brazilian processing grounds it did not know existed, and Brazilian formalities attached to grounds it thought it understood.

Territorial Reach Is Written Three Ways

Article 3 applies the law to any processing operation by a natural or legal person, public or private, "regardless of the medium, of the country of its headquarters or of the country where the data are located", provided one of three conditions is met.

  • Item I. The processing operation is carried out in the national territory
  • Item II. The processing activity has as its object the offer or supply of goods or services, or the processing of data of individuals located in the national territory
  • Item III. The personal data being processed were collected in the national territory

Item III has no GDPR analogue and is the widest of the three, because it attaches to the data rather than to the activity or the individual. Paragraph 1 defines collection in the national territory as covering personal data whose subject is in Brazil at the moment of collection — so data collected from a person physically in Brazil remains within Article 3 after they leave, and after it does.

The ANPD's transfer regulation adds a boundary from the other direction. Article 6 of the Regulation annexed to Resolution 19/2024 provides that international collection of data does not constitute an international data transfer, and Article 8 states that the LGPD applies to personal data originating abroad whenever that data is processed in the national territory.

The Automated-Decision Right That Lost Its Human

Article 20 is the clearest illustration of why the LGPD cannot be read as a translated GDPR, and the evidence is visible in the statute's own amendment apparatus.

As enacted in 2018, Article 20 gave the data subject the right to request review "por pessoa natural" — by a natural person — of decisions taken solely on the basis of automated processing that affect their interests, including decisions intended to define their personal, professional, consumer or credit profile or aspects of their personality. Provisional Measure 869 of 2018 removed those three words, and Law 13.853 of 2019 enacted the amended wording. The consolidated text now carries all three versions in sequence, with the operative one attributed to Law 13.853.

The right to request review survived. The requirement that a human conduct the review did not. That is a narrower guarantee than GDPR Article 22, and it is narrower by deliberate legislative choice rather than by drafting accident.

Two paragraphs qualify what follows. Paragraph 1 requires the controller, whenever asked, to provide clear and adequate information about the criteria and procedures used for the automated decision — subject to commercial and industrial secrecy. Paragraph 2 supplies the answer to the obvious objection: where the controller withholds that information on trade-secret grounds, the national authority may carry out an audit to check for discriminatory aspects in the automated processing. Secrecy blocks the individual, not the regulator.

The Transfer Regulation Did What the Statute Left Undone

Article 33 permits international transfers on nine grounds, among them transfer to countries or international organisations providing an adequate level of protection; controller-provided guarantees in the form of specific contractual clauses, standard contractual clauses, global corporate rules, or regularly issued seals, certificates and codes of conduct; authorisation by the national authority; and the data subject's specific and highlighted consent, given with prior information about the international character of the operation and clearly distinguished from other purposes.

For years most of that machinery was unusable, because Article 35 reserves to the national authority the definition of standard contractual clause content and the verification of the other instruments, and the authority had not acted. Resolution CD/ANPD No. 19 of 23 August 2024 closed that gap, approving both the International Data Transfer Regulation and the content of the standard contractual clauses, under Articles 33, 34, 35 and 36 of the LGPD.

Its Article 2 sole paragraph set the transition: processing agents using contractual clauses for international transfers were to incorporate the ANPD-approved standard contractual clauses into their contractual instruments within up to twelve months of publication. The Regulation also sets out the adequacy-recognition procedure the ANPD later used for the European Union, and requires that transfers serve legitimate, specific, explicit purposes communicated to the data subject, resting both on an Article 7 or Article 11 legal basis and on one of the transfer mechanisms.

Incident Notification: A Deadline the Statute Refused to Set

Article 48 requires the controller to communicate to the national authority and to the data subject the occurrence of a security incident that may bring about relevant risk or damage to data subjects. Paragraph 1 then declines to say when. The communication is to be made "in a reasonable period, as defined by the national authority" — the statute delegating its own deadline to the regulator.

Paragraph 1 does prescribe the minimum contents: a description of the nature of the affected personal data; information about the data subjects involved; the technical and security measures used to protect the data, subject to commercial and industrial secrecy; the risks related to the incident; the reasons for delay where the communication was not immediate; and the measures taken or to be taken to reverse or mitigate the effects. Paragraph 2 lets the authority, having assessed the seriousness of the incident, require the controller to publicise the fact widely in the media or take mitigating measures. Paragraph 3 makes encryption relevant to that seriousness assessment, directing that evidence of technical measures rendering the affected data unintelligible to unauthorised third parties be weighed.

The regulator supplied the missing number in 2024. Resolution CD/ANPD No. 15 of 24 April 2024 sets it at three working days, in two places: Article 6 for communication to the ANPD, and Article 9 for communication to the data subject, the latter counted from the controller's knowledge that the incident affected personal data. Article 6 preserves any different deadline set by specific legislation, and Article 9 paragraph 3 allows information to be supplemented, with reasons, within twenty working days of the communication.

Article 10 of the same regulation carries the obligation most easily overlooked: the controller must keep a record of the security incident — expressly including incidents not communicated to the ANPD or to data subjects — for a minimum of five years from the date of the record, unless other obligations require longer. As with PIPEDA's section 10.3, the recording duty has no risk threshold; only the reporting duty does.

Article 41 requires every controller to appoint an encarregado for personal data processing, whose identity and contact information must be publicly disclosed clearly and objectively, preferably on the controller's website. The role's listed activities are narrower than a GDPR data protection officer's: accepting complaints and communications from data subjects, providing clarifications and taking action; receiving communications from the national authority and taking action; instructing employees and contractors on data protection practices; and carrying out whatever else the controller determines or complementary rules establish. Paragraph 3 lets the national authority set complementary rules on the role, including circumstances in which appointment is waived according to the nature and size of the entity or the volume of processing.

Sanctions on Paper

Article 52 lists the administrative sanctions the national authority may apply, and their range is wider than a fine schedule:

ItemSanction
IWarning, with a deadline for adopting corrective measures
IISimple fine of up to 2% of the private legal entity's, group's or conglomerate's revenue in Brazil in its last financial year, excluding taxes, capped in total at R$50,000,000 per infraction
IIIDaily fine, subject to the same total limit
IVPublicising the infraction once duly investigated and confirmed
VBlocking the personal data concerned until regularisation
VIDeletion of the personal data concerned
XPartial suspension of the database's operation for up to six months, renewable once, until the controller regularises the processing
XISuspension of the processing activity concerned for up to six months, renewable once
XIIPartial or total prohibition of activities related to data processing

Items X, XI and XII were added by Law 13.853 of 2019; items VII to IX were vetoed. The two ceilings in item II operate together — a percentage of Brazilian revenue, and an absolute cap in reais — so the turnover figure that matters is domestic rather than worldwide, which is a materially different exposure calculation from the GDPR's global turnover base or Quebec's. Paragraph 1 requires sanctions to be applied after an administrative procedure allowing a full defence, gradually, and singly or cumulatively, against listed criteria beginning with the seriousness and nature of the infraction and the personal rights affected.

Enforcement in Practice Has Been Mostly Against the State

The ANPD publishes a register of concluded sanctioning proceedings, and its composition is the most useful thing in it. For 2023 and 2024 the register lists nine proceedings. Eight are against public bodies: the Ministry of Health twice, a Pernambuco state social development secretariat, the Federal District education secretariat, the INSS social security institute, the Santa Catarina state health secretariat, the Rio de Janeiro Botanical Garden research institute, and the São Paulo state public servants' assistance institute. One — Telekall Inforservice, proceeding 00261.000489/2022-62 — is against a private company. As published, the register lists no concluded proceedings after 2024.

That is not the whole enforcement picture, and the Commission's adequacy decision fills in what a register of concluded proceedings cannot show. It records that the ANPD issued several warnings to the Ministry of Health for failing to provide a data protection impact assessment and to notify a data breach, among other things. It records that the ANPD ordered a large social media platform to suspend the processing of personal data for training generative artificial intelligence systems across all its products, and imposed a daily fine of R$50,000 alongside that preventive measure until the processing was brought into compliance. And it records that the ANPD has announced investigations against several large multinational technology platforms, social media companies and a bank, while continuing investigations against public-sector entities.

On volume, the decision states that the ANPD receives around 400 complaints and 100 requests from individuals every month, following the July 2024 introduction of a modernised submission platform.

Two things follow, and neither is a prediction. First, a register dominated by public-sector respondents describes an authority that spent its early years supervising the state. Second, the preventive measure and the announced investigations are, on the Commission's account, aimed at private multinationals — but announced investigations are not concluded proceedings, and this guide does not treat them as outcomes.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

How many legal bases does the LGPD have?
Article 7 sets out ten hypotheses under which personal data may be processed, against six lawful bases in the GDPR. Several overlap, including consent, contract, legal obligation, protection of life and legitimate interests. Others have no direct GDPR counterpart, such as processing for the regular exercise of rights in judicial, administrative or arbitral proceedings and processing for credit protection. Sensitive personal data is governed separately by Article 11.
Does the LGPD require a human to review an automated decision?
Not in the enacted text. Article 20 as originally passed in 2018 gave a right to request review "by a natural person", but Provisional Measure 869 of 2018 removed that phrase and Law 13.853 of 2019 enacted the amended version. The right to request review remains; the requirement that a person conduct it does not. Paragraph 2 allows the national authority to audit for discriminatory aspects where a controller invokes trade secrecy.
How large can an LGPD fine be?
Article 52(II) caps a simple fine at 2% of the private legal entity's, group's or conglomerate's revenue in Brazil in its last financial year, excluding taxes, and separately at R$50,000,000 per infraction. Both limits apply. The percentage is calculated on Brazilian revenue rather than worldwide turnover. A daily fine under Article 52(III) is subject to the same total limit.
Can data move between the EU and Brazil without additional safeguards?
As of 26 January 2026, in both directions. Commission Implementing Decision C(2026) 373 final finds that Brazil ensures an adequate level of protection for data transferred to controllers and processors in Brazil that are subject to the LGPD. ANPD Resolution No. 32, adopted the same day, recognises the European Union, its member states, the three EEA EFTA states and EU institutions and bodies. Both sides provide for reassessment after four years.
Does the LGPD apply to a company with no presence in Brazil?
Article 3 applies the law regardless of the country of the controller's headquarters or of where the data is located, where the processing occurs in national territory, where the activity targets the offer of goods or services to or the processing of data of individuals located in Brazil, or where the data was collected in national territory. Paragraph 1 treats data as collected in national territory where the subject was in Brazil at the moment of collection.
What has the ANPD actually sanctioned?
Its published register of concluded sanctioning proceedings lists nine for 2023 and 2024, eight against public bodies and one against a private company, Telekall Inforservice. The European Commission's adequacy decision additionally records warnings to the Ministry of Health, a preventive measure ordering a large social media platform to suspend processing for generative AI training with a R$50,000 daily fine, and announced investigations into multinational platforms and a bank.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.