Brazil's LGPD borrows heavily from the GDPR, but its national authority has developed its own enforcement priorities. This hub covers ANPD sanctions and transfer rules for companies operating in Brazil.

Brazil (LGPD)

Brazil's Encarregado Regulation: The Appointment Paperwork, the Website Notice and the Conflict Rules

September 21, 2026

The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.

Read more →
Brazil (LGPD)

The LGPD's Small-Business Regime: Who Qualifies, Who Is Excluded and Which Clocks Run at Double Speed

September 21, 2026

Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.

Read more →
Brazil (LGPD)

Brazil's LGPD Reads Like the GDPR Until You Count the Legal Bases

August 24, 2026

The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.

Read more →