Brazil (LGPD)

The LGPD's Small-Business Regime: Who Qualifies, Who Is Excluded and Which Clocks Run at Double Speed

Key Takeaways

  • The Regulation covers microenterprises, small enterprises and startups as defined by Brazil's small-business and startup statutes, plus private non-profits, natural persons and unincorporated private entities acting as controller or processor
  • The relief is lost for high-risk processing, for revenue above R$4,800,000 a year (R$16,000,000 for startups), and for membership of an economic group whose combined revenue exceeds those caps
  • Processing is high risk when it meets at least one general criterion (large scale, or significant effect on rights) and one specific criterion (emerging technology, surveillance of public spaces, solely automated decisions, or sensitive, children's, adolescents' or elderly people's data)
  • Resolution CD/ANPD No. 15 of 2024 rewrote the incident-deadline rule: qualifying agents now have six working days instead of three to notify the ANPD and data subjects, and the former safety and national-security exception no longer appears
  • Article 6 states that none of the relief exempts qualifying agents from the LGPD's legal bases, principles or data subject rights, and Article 16 lets the ANPD require any waived obligation

A Regulation the Statute Asked For

Law 13.853 of 2019 added item XVIII to Article 55-J of the LGPD, directing the ANPD to issue simplified and differentiated rules, guidance and procedures, including on deadlines, so that micro and small enterprises and self-declared startups or innovation companies can adapt to the law. The ANPD's Board of Directors responded with Resolution CD/ANPD No. 2 of 27 January 2022, published in the Diário Oficial da União on 28 January 2022 and effective on publication.

The Regulation has been amended once. Article 2 of Resolution CD/ANPD No. 15 of 24 April 2024, the security incident regulation, replaced item II of Article 14. The consolidated text on the ANPD's website shows the superseded wording struck through and the new wording marked as given by Resolution 15. The ANPD's table of regulations lists Resolution 2 as in force with that amendment and no other. This post reads the consolidated text and treats the struck language as repealed; all translations from the Portuguese are this publication's own.

Who Counts as a Small Processing Agent

Article 2, I defines small processing agents (agentes de tratamento de pequeno porte) by listing who they are, not by counting data subjects:

  • Microenterprises and small enterprises, defined by cross-reference to Articles 3 and 18-A, paragraph 1 of Complementary Law 123 of 2006 and including the individual microentrepreneur (MEI)
  • Startups meeting the criteria in Chapter II of Complementary Law 182 of 2021
  • Private-law legal entities, expressly including non-profits
  • Natural persons and unincorporated private entities that process personal data with the typical obligations of a controller or processor

The revenue lines sit in those other statutes. Under Article 3 of Complementary Law 123, a microenterprise earns gross revenue of up to R$360,000 in each calendar year and a small enterprise more than that and up to R$4,800,000, the ceiling set by Complementary Law 155 of 2016. Under Article 4, paragraph 1 of Complementary Law 182, a startup is eligible with gross revenue of up to R$16,000,000 in the previous calendar year (or R$1,333,334 multiplied by the months of activity, if fewer than twelve), up to ten years of registration in the national company register, and either an innovative business model declared in its constitutive act or enrolment in the Inova Simples regime.

Article 1's sole paragraph keeps the Regulation away from processing the LGPD itself does not reach, such as processing by a natural person for purely private, non-economic purposes.

The Three Exclusions

Qualifying under Article 2 is necessary but not sufficient. Article 3 withholds the differentiated treatment from any small processing agent that:

  1. Carries out high-risk processing for data subjects (subject to Article 8, discussed below)
  2. Earns gross revenue above the Article 3, II limit of Complementary Law 123, or for startups the Article 4, paragraph 1, I limit of Complementary Law 182
  3. Belongs to a de facto or de jure economic group whose global revenue exceeds those limits

Article 5 puts the burden on the agent: when the ANPD asks, the agent has up to fifteen days to prove that it fits Articles 2 and 3.

The high-risk test

Article 4 makes processing high risk when it meets, cumulatively, at least one general criterion and at least one specific criterion:

General criteria (at least one)Specific criteria (at least one)
Large-scale processing: a significant number of data subjects, also weighing data volume and the duration, frequency and geographic reach of the processingUse of emerging or innovative technologies
Processing that may significantly affect data subjects' interests and fundamental rights, for example by preventing the exercise of a right or use of a service, or causing material or moral damage such as discrimination, harm to physical integrity, image or reputation, financial fraud or identity theftSurveillance or control of areas accessible to the public, which Article 2, IV illustrates with squares, shopping centres, public roads, bus, metro and train stations, airports, ports and public libraries
Decisions based solely on automated processing, including profiling of personal, professional, health, consumer or credit aspects or personality
Use of sensitive personal data, or personal data of children, adolescents or elderly people

The ANPD's December 2024 guidance on the encarregado applies the test to two hypotheticals. A home-care company with revenue of R$2,500,000 that processes health data about patients over 60 meets both a general and a specific criterion, so its small-enterprise status does not bring the differentiated regime with it. A credit-analysis startup using artificial intelligence for more than two million customers meets the large-scale and emerging-technology criteria and is excluded on the same reasoning.

Article 8 is the one relief that survives high-risk processing. Any small processing agent, including one carrying out high-risk processing, may organise through business representative bodies, legal entities or natural persons to negotiate, mediate and conciliate data subjects' complaints.

What the Relief Consists Of

A record of processing in simplified form

Article 37 of the LGPD requires controllers and processors to keep a record of their processing operations. Article 9 of the Regulation allows small processing agents to keep it in simplified form and commits the ANPD to supply a model. The model is published as a two-page form, Modelo de Registro das Operações de Tratamento de Dados Pessoais para Agentes de Tratamento de Pequeno Porte, with a filling-in page. Its columns are contact information for the organisation; the process, purpose and legal basis under Articles 7 or 11; the personal data involved; the categories of data subject (general, children and adolescents, elderly people); sharing outside the organisation; security measures; retention period; and observations. The form carries no publication date, and the ANPD's small-agent security guidance page links it in Excel and PDF versions.

No mandatory encarregado, with a condition

Article 11 states that small processing agents are not obliged to appoint the encarregado required by Article 41 of the LGPD. Paragraph 1 attaches the condition: an agent that does not appoint one must provide a communication channel with data subjects, to meet Article 41, paragraph 2, I, which covers accepting complaints and communications, giving clarifications and taking action. Paragraph 2 treats a voluntary appointment as a good-practice and governance policy for sanctioning purposes. Resolution CD/ANPD No. 18 of 2024, the encarregado regulation, repeats the channel requirement in its Article 3, paragraph 3. The appointment rules that apply when the waiver is not available are covered in a separate post on that regulation.

Simplified security

Article 12 still requires essential administrative and technical security measures based on minimum information-security requirements, calibrated to the privacy risk and to the agent's circumstances. Its sole paragraph states that following the ANPD's security recommendations and good practices, including its guides, counts as observance of Article 52, paragraph 1, VIII of the LGPD, one of the factors weighed when sanctions are set. Article 13 permits a simplified information security policy that takes account of implementation cost and the agent's structure, scale and volume, and paragraph 2 commits the ANPD to consider such a policy under Articles 6, X and 52, paragraph 1, VIII and IX. The ANPD's own security guide for small agents is version 1.0 of October 2021, three months older than the Regulation.

Doubled Deadlines, and the One That Changed in 2024

Article 14 grants small processing agents double time in four places. Each doubling depends on a base deadline set somewhere else, so the table below pairs them:

Article 14 itemBase deadline and where it is setSmall-agent deadline
I: responding to data subject requests under LGPD Article 18, paragraphs 3 and 5Article 18, paragraph 5 leaves the deadlines to regulation; the ANPD's table of regulations, read on 21 September 2026, lists no regulation setting themDouble, once a base deadline exists
II: incident notice to the ANPD and to data subjectsThree working days under Articles 6 and 9 of Resolution CD/ANPD No. 15 of 2024, with twenty working days to supplement the ANPD noticeSix working days; forty working days to supplement
III: the clear and complete declaration under LGPD Article 19, IIFifteen days from the request, set by the statuteThirty days
IV: information, documents, reports and records the ANPD requestsWhatever the relevant instrument sets for other agentsDouble

Item II is where the 2024 amendment bites. As originally written, it doubled the incident deadline except where there was potential harm to data subjects' physical or moral integrity or to national security, in which case the ordinary deadline applied. Resolution 15 replaced that item with a plain cross-reference to the incident regulation, and the incident regulation itself doubles the deadlines in Article 6, paragraph 8 (the notice to the ANPD and the twenty-day supplement) and Article 9, paragraph 6 (the notice to data subjects). Neither provision repeats the old exception. Article 6, paragraph 2, IX of the incident regulation also asks the notifying controller to state, where applicable, that it is a small processing agent.

Article 15 adds a timing relief that runs the other way from a doubling. The LGPD's Article 19, I requires confirmation of processing or access in simplified format immediately; the Regulation lets small processing agents provide that simplified declaration within up to fifteen days of the request.

One further doubling sits outside Resolution 2. Article 17 of the annex to Resolution CD/ANPD No. 4 of 2023, the sanctions-calculation regulation, sets twenty working days to pay a fine from official notice of the decision, and its paragraph 2 gives small processing agents, as defined by Resolution 2, double that period.

What the Regulation Does Not Relax

Article 6 is the limiting clause. Waiving or softening the obligations in the Regulation does not exempt small processing agents from the rest of the LGPD, expressly including its legal bases and principles, from other legal, regulatory and contractual data protection provisions, or from data subjects' rights. Article 7 keeps the duty to provide information about processing and to meet requests under Articles 9 and 18, by electronic, printed or any other means that secures the rights and easy access.

Article 10 promised a simplified incident-notification procedure for small agents under specific regulation. The incident regulation that followed in 2024 delivered doubled deadlines and a self-identification field, as described above, rather than a separate procedure.

Article 16 closes the Regulation with a reservation of power: the ANPD may require a small processing agent to comply with any waived or relaxed obligation, taking into account relevant circumstances such as the nature or volume of the operations and the risks to data subjects. The differentiated regime is therefore a default the regulator can withdraw from a particular agent, not a fixed status.

Frequently Asked Questions

What revenue limit applies to the LGPD small processing agent regime?
Article 3, II of Resolution CD/ANPD No. 2 excludes agents whose gross revenue exceeds the limit in Article 3, II of Complementary Law 123 of 2006, which is R$4,800,000 per calendar year, or for startups the limit in Article 4, paragraph 1, I of Complementary Law 182 of 2021, which is R$16,000,000 in the previous calendar year. Article 3, III applies the same caps to the global revenue of an economic group the agent belongs to.
Does processing children's data take a small business out of the LGPD relief?
Not by itself. Article 4 requires at least one general criterion (large-scale processing, or processing that may significantly affect data subjects' interests and fundamental rights) and at least one specific criterion. Processing data of children, adolescents or elderly people is one of the specific criteria, so it produces high-risk status only when combined with a general criterion.
How long does a small processing agent have to report a security incident in Brazil?
Six working days. Articles 6 and 9 of Resolution CD/ANPD No. 15 of 2024 set three working days, counted from the controller's knowledge that the incident affected personal data, for notice to the ANPD and to data subjects, and Articles 6, paragraph 8 and 9, paragraph 6 double those periods for small processing agents. The twenty working days to supplement the ANPD notice also doubles, to forty.
Does a small processing agent still need a record of processing?
Yes, in simplified form. Article 9 of Resolution CD/ANPD No. 2 allows small processing agents to meet the LGPD Article 37 record-keeping obligation in a simplified way, and the ANPD publishes a two-page model form covering purpose and legal basis, data, data subject categories, sharing, security measures and retention.
Can the ANPD take the small-business relief away from a qualifying company?
Article 16 allows the ANPD to require a small processing agent to comply with any obligation the Regulation waives or relaxes, considering circumstances such as the nature or volume of the processing and the risks to data subjects. Article 5 separately requires an agent to prove, within fifteen days of an ANPD request, that it meets the qualifying conditions.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. Resolução CD/ANPD nº 2, de 27 de janeiro de 2022: Regulamento de aplicação da LGPD para agentes de tratamento de pequeno porte (ANPD consolidated text, as amended by Resolução CD/ANPD nº 15/2024) (January 28, 2022) regulation
  2. Resolução CD/ANPD nº 15, de 24 de abril de 2024: Regulamento de Comunicação de Incidente de Segurança (Diário Oficial da União, 26 April 2024) (April 26, 2024) regulation
  3. Lei nº 13.709, de 14 de agosto de 2018 (LGPD), consolidated text, Articles 18, 19, 37, 41 and 55-J (September 21, 2026) statute
  4. Lei Complementar nº 123, de 14 de dezembro de 2006 (Estatuto Nacional da Microempresa e da Empresa de Pequeno Porte), consolidated text (September 21, 2026) statute
  5. Lei Complementar nº 182, de 1º de junho de 2021 (Marco Legal das Startups), consolidated text (September 21, 2026) statute
  6. Resolução CD/ANPD nº 4, de 24 de fevereiro de 2023: Regulamento de Dosimetria e Aplicação de Sanções Administrativas (February 27, 2023) regulation
  7. ANPD, Modelo de Registro das Operações de Tratamento de Dados Pessoais para Agentes de Tratamento de Pequeno Porte (ATPP) agency guidance
  8. ANPD, Guia orientativo sobre segurança da informação para agentes de tratamento de pequeno porte (page linking the guide and the record template) (June 21, 2024) agency guidance
  9. ANPD, Guia Orientativo sobre Segurança da Informação para Agentes de Tratamento de Pequeno Porte, version 1.0 (October 2021) agency guidance
  10. ANPD, Guia Orientativo: Atuação do encarregado pelo tratamento de dados pessoais, version 1.0 (December 2024) agency guidance

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.