Brazil LGPD Compliance Hub
Brazil's Lei Geral de Proteção de Dados Pessoais (), Law 13.709/2018, can apply to an organisation outside Brazil. Article 3 looks at each processing operation: whether it occurs in Brazil, targets the offering of goods or services to people in Brazil or the processing of their data, or uses personal data collected while the person was in Brazil.
New to ? Start with applicability and roles. Then choose the legal basis and data category before designing notices, rights, vendor, transfer, or incident controls.
Start with the data flow, then check Article 4 exclusions. If the applies, record the and , the Article 7 or 11 legal basis, transparency and rights controls, security measures, and any incident or international-transfer route. Binding regulations from the Agência Nacional de Proteção de Dados () add procedures to the law's general duties; ANPD guides explain practice but do not create new statutory duties.
Key milestones for LATAM Brazil LGPD compliance
Separate the law's phased commencement from later rules. Most provisions have applied since 18 September 2020 and administrative sanctions since 1 August 2021. Resolution 15 took effect on 26 April 2024 and set the incident procedure and three-business-day notification clock. Resolution 19 took effect on 23 August 2024 and set transfer procedures and ANPD standard contractual clauses; its 12-month contractual transition has ended. Resolution 32, dated 26 January 2026 and currently in force, recognises the European Union as adequate for covered transfers.
Choose the next LGPD decision
Start with the processing activity, territorial link, and role. Once those are documented, move to legal basis and rights, then implement evidence, incident, transfer, and enforcement workflows.
Start here: scope and roles
Decide whether the LGPD applies, identify controller, operator, and encarregado responsibilities, and account for the proportionate rules available to eligible small processing agents.
Legal bases, transparency, and rights
Match each purpose and data category to an LGPD basis, explain the processing, and build a complete response path for Articles 18-20 requests.
Implementation and evidence
Turn the decisions into an owned programme, processing records, privacy-risk analysis, controls, and reusable evidence.
Security incidents and international transfers
Use the current ANPD regulations to apply the three-business-day incident rule and select a valid transfer mechanism. For EU destinations, confirm that Resolution 32/2026 covers the transfer rather than assuming every European destination or onward transfer is covered.
Dates and enforcement
Distinguish commencement dates, ongoing operational clocks, ANPD procedure, and the factors that affect sanctions.
Compare laws or answer a focused question
Use comparisons to identify reusable programme elements without assuming equivalence, or open the FAQ for a direct answer to a specific LGPD question.
Turn the LGPD decisions into owned work
Use the hub to assign the scope decision, legal basis, rights controls, incident route, transfer mechanism, evidence owner, and review date for each data flow.
- Scope the work by entity, product, processing purpose, system, and .
- Use cited research for unresolved scope, timing, mechanism, or interpretation questions.
- Assign each control, evidence request, approver, due date, exception, and reassessment trigger.
- Keep the resulting decision record with the processing inventory and implementation evidence.
