Artifact GuideBrazilApplicability Test

Brazil LGPD Applicability Test

The LGPD applies if any Article 3 territorial link is met for the processing operation, unless an Article 4 exclusion covers that operation.

Test the operation, not only the entity. A foreign headquarters or foreign server does not by itself put processing outside the LGPD.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this test for each processing operation under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), Law 13.709/2018. The LGPD applies when the operation occurs in Brazil, the activity offers or supplies goods or services to people in Brazil or processes their data, or the personal data was collected while the person was in Brazil. If one link is present, test the Article 4 exclusions before deciding the LGPD is inapplicable.

Section 1

What should the Brazil LGPD Applicability Test decide?

Apply separately to collection, access, storage, analysis, disclosure, deletion, and other operations in the data flow. One covered operation is enough for the LGPD to govern that operation, regardless of the organisation's headquarters or the medium used.

For the collection link, data is collected in Brazil when the data subject is in Brazil at the time of collection. For the targeting link, record the facts showing that the activity concerns offering goods or services to individuals in Brazil or processing their data; a globally accessible website alone does not answer that fact-specific question.

End with one of three outcomes for each operation: outside on the recorded facts, within Article 3 but covered by a specific , or subject to the LGPD. A mixed data flow can produce different outcomes for different operations.

  • Describe the operation, purpose, people, data, collection point, user location, systems, access locations, recipients, and countries.
  • Mark every link that applies; do not stop after finding that the company or server is abroad.
  • If no link is present, record the facts supporting that conclusion and a trigger for reassessment.
  • If a link is present, continue to Article 4 rather than treating scope as the end of the compliance analysis.
Section 2

Who should own the Brazil LGPD applicability test, and what evidence should prove the decision?

The controller should approve the scope conclusion. Product, data, procurement, security, and local business teams supply the facts; privacy or legal should review exclusions and unresolved territorial questions.

Keep the data-flow map, the analysis for each operation, any , controller and operator allocation, source version, assumptions, reviewer, approval date, and change trigger.

  • Name one accountable owner and one reviewer for the Applicability Test workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which edge cases should teams check before relying on a Brazil LGPD applicability test decision?

Article 4 excludes processing by a natural person for exclusively private, non-economic purposes; exclusively journalistic or artistic processing; specified public-security, national-defence, state-security, and criminal-investigation processing; and a narrow foreign-origin data case. Academic processing remains subject to Articles 7 and 11.

Do not treat pseudonymised or potentially re-identifiable data as automatically anonymous. Anonymised data falls outside the personal-data rules only when reversal is not reasonably possible using the controller's own means or reasonable available efforts. Record the facts supporting an exclusion and reopen the decision if the data is shared, enriched, reused, or made available to a Brazilian processing agent.

  • Do not extend the private-household exclusion to a company, employer, platform, or revenue-generating activity.
  • Do not treat an academic purpose as a complete exemption; identify the Article 7 or 11 basis that still applies.
  • For foreign-origin data, confirm the conditions for transit or return to the country of origin and whether any Brazilian processing agent receives or uses the data.
  • Pseudonymised data remains personal data when re-identification is reasonably possible; only data meeting the LGPD anonymity test falls outside the law as anonymous data.
Section 4

What should the applicability decision contain?

Use a per-operation intake. A company-level yes or no cannot capture different products, collection points, purposes, recipients, or Article 4 exclusions.

The output should name the covered operation and link, or the precise and its facts. It should also identify the controller and operators, unresolved assumptions, downstream LGPD work, approver, decision date, source version, and reassessment trigger.

  • Reassess when a new market, localised offer, collection channel, remote-access location, recipient, vendor, or purpose changes the facts.
  • If the LGPD applies, move next to role allocation, Article 7 or 11 legal basis, transparency, rights, security, retention, and any transfer or incident rule.
  • If an exclusion is relied on, restrict the operation to the facts that support it and record what would cause the exclusion to stop applying.
  • Do not use this page as a conclusion about another Brazilian law, sector rule, contract, or consumer-protection duty.
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Binding Articles 3 and 4 for territorial scope and exclusions, Article 5 for personal and anonymous data definitions, and Article 12 for the anonymity test.
planalto.gov.br
Referenced sections
  • Operational implementation support for the Brazil LGPD applicability test.
"Esta Lei aplica-se a qualquer operação de tratamento"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.