Artifact GuideBrazilChecklist

Brazil LGPD Checklist

Use this checklist before launch and after material changes to confirm that each applicable LGPD duty has an owner, an operating control, and dated evidence.

A policy or signed vendor contract is not enough if the related notice, rights path, security measure, or transfer mechanism does not work for the real data flow.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Work from the processing inventory. For each purpose, identify scope, and operator roles, data category, Article 7 or 11 basis, transparency, rights, retention, security, recipients, international transfers, and incident handling. Mark an item complete only when the control operates and the evidence identifies the affected data flow.

Section 1

What must the LGPD checklist cover before processing starts?

First confirm that Article 3 applies and whether Article 4 excludes the operation. Then document the , each operator, the specific purpose, the personal-data categories, the Article 7 basis for ordinary data or Article 11 basis for sensitive data, and any best-interest analysis required for children or adolescents.

Before collection or reuse, make the Article 9 information available in clear language, limit the data to what is necessary, define retention and deletion rules, and connect the operation to the channel that handles Articles 18-20 rights.

  • Scope and roles pass when the record identifies the Article 3 link or exact Article 4 exclusion, the factual and operators for each operation, the encarregado or documented small-agent dispensation, and a working public contact channel.
  • Purpose and basis pass when each purpose has its own Article 7 or 11 decision, necessity evidence, matching notice, consent record where used, and legitimate-interest test where relevant. A single basis attached to an entire product is not enough when its purposes differ.
  • People and lifecycle pass when the rights channel has been tested, identity checks are proportionate, searches cover operators and archives, sharing corrections can be propagated, and retention ends in deletion or a documented Article 16 conservation ground.
  • Risk and data flow pass when design-stage security controls have operating evidence, vendors have usable instructions and escalation duties, every transfer has both a processing basis and Article 33 mechanism, incidents reach the , and any required or risk-based RIPD is approved and tracked.
Section 2

What evidence should close each checklist item?

Each row should name the requirement and affected processing activity, not merely cite a policy. Record the accountable control owner, reviewer, implementation state, exception, due date, evidence location, and event that will trigger reassessment.

Evidence should show operation: a current data-flow map, processing record, notice as displayed, consent event where applicable, completed basis assessment, rights log, retention rule, vendor instruction, access review, security test, executed transfer mechanism, incident exercise, or filed communication.

  • Legal source and provision; entity, product, system, purpose, people, data categories, , operators, and recipients.
  • Required action, owner, reviewer, status, due date, exception, legal or factual assumption, and reassessment trigger.
  • Evidence that can be opened and dated, with the version or environment checked.
  • For a gap, a remediation action and interim risk decision rather than an unsupported 'not applicable' result.
  • For a not-applicable result, record the exclusion or missing trigger and the facts tested. Reopen it when those facts change.
Section 3

Which clocks, exceptions, and change triggers need a separate check?

For confirmation or access requests, distinguish an immediate simplified response from the complete Article 19 declaration due within 15 days. Eligible small processing agents have specific doubled or simplified periods under Resolution 2/2022; the regulation does not excuse them from the rest of the LGPD.

For a confirmed security incident that may cause relevant risk or damage, the generally has three business days to notify the ANPD and affected people, subject to a shorter sector-specific rule. Keep records of security incidents involving personal data for at least five years.

For international transfers, document both an Article 7 or 11 processing basis and a valid Article 33 transfer mechanism. ANPD standard clauses must be used in full when that mechanism is selected; adequacy must come from an ANPD decision.

  • Reopen the checklist after a new purpose, data category, market, user group, vendor, subprocessor, remote-access location, security incident, complaint, or material ANPD rule.
  • Test exemptions such as small-agent relief against their eligibility and high-risk limits instead of applying them from company size alone.
  • For children and adolescents, document how their best interest prevails in the concrete case; do not treat parental consent as the only possible basis or as a substitute for that rule.
  • Record unresolved interpretation questions and the interim control rather than marking the item complete.
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Articles 6, 37, 38, 46, and 50 support necessity, accountability records, impact-report content, security measures, and governance evidence.
gov.br
Referenced sections
  • Binding rule allowing eligible small processing agents to use simplified records and certain proportionate measures while preserving the remaining LGPD duties and data-subject rights.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.