Artifact GuideBrazilCompliance

Brazil LGPD Compliance

An LGPD program starts with the real processing inventory, then assigns each applicable duty to the team that can change the data flow.

Completion requires operating evidence: notices as shown, request logs, configured retention, executed contracts, tested security controls, transfer records, and incident decisions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this page to build and review a program under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), Law 13.709/2018, and binding regulations from the Agência Nacional de Proteção de Dados (ANPD). Confirm scope and roles first; document an Article 7 or 11 basis for each purpose; then implement transparency, rights, retention, vendor, security, incident, and transfer controls. The controller remains accountable even when operators perform part of the work.

Section 1

How should teams structure a Brazil LGPD Compliance plan?

Start with a that identifies purposes, people, data categories, collection points, systems, controller and operators, recipients, countries, retention, security, and the Article 7 or 11 legal basis. Article 37 requires controllers and operators to maintain processing records, especially for legitimate-interest processing.

Group remediation by dependency: scope and roles; principles, purpose, and basis; notices and rights; retention and vendors; security and incidents; transfers; then governance testing. A later control cannot repair an invalid purpose or missing legal basis.

  • Map Article 3 scope and any Article 4 exclusion for each processing operation.
  • Assign controller, operator, and encarregado responsibilities from actual decisions and instructions, not contract labels alone.
  • Record the purpose-specific Article 7 or 11 basis, necessity, transparency, retention, recipients, rights path, and safeguards.
  • Apply current ANPD regulations to incident notification, international transfers, the encarregado, and any small-agent relief.
Section 2

Who should own the Brazil LGPD compliance, and what evidence should prove the decision?

Assign each control to the team that can change the processing. Product owns purpose and collection design; data and engineering own system implementation and retention; procurement and business owners manage operators; security manages preventive and incident controls; privacy or legal reviews the legal route; the controller approves residual risk.

Use dated evidence such as a scope memo, role map, , live notice, consent record, legitimate-interest test, rights log, operator instructions, deletion result, access review, security test, transfer record, or incident exercise. A Relatório de Impacto à Proteção de Dados Pessoais () should describe the processing, risks, safeguards, and mitigation when the ANPD requires one; organisations may also use it as a governance tool for high-risk processing.

  • Name one accountable owner and one reviewer for the Compliance workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which limits and exceptions change the program?

Small-agent status does not erase the LGPD. Resolution 2/2022 offers specified simplified records, an encarregado dispensation, and differentiated periods only to eligible agents; high-risk processing and revenue or group thresholds can prevent access to that treatment.

Children and adolescents require a concrete best-interest assessment. Sensitive data requires an Article 11 basis; Article 7 legitimate interest is unavailable. International transfers require both a processing basis and a transfer mechanism. Reassess after changes to purpose, data, role, system, vendor, market, people, transfer, complaint, or incident.

  • Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams test and maintain the program?

Test the program against a sample of live processing activities. Confirm that the notice matches the system, rights requests reach every relevant system and recipient, retention jobs run, operator instructions are followed, access controls are reviewed, incident clocks can start, and transfer mechanisms match the actual importer and onward transfers.

Keep an owned remediation register with the source provision, affected activity, gap, action, interim measure, evidence, reviewer, due date, exception, and reassessment trigger. Escalate repeated or high-impact failures for controller decision and, where appropriate, a or other risk review.

Use the statutory and regulatory clocks as test cases. For example, a complete confirmation or access declaration must be supportable within Article 19's 15-day period, a reportable incident must reach the ANPD and affected people within the applicable Resolution 15 period, and a standard-clause transfer must support the 15-day clause-access request in Resolution 19.

  • Sample high-risk and routine processing rather than testing only the best-documented system.
  • Trace one notice statement to the live collection screen, system field, recipient, retention setting, and rights response.
  • Trace one operator instruction and one transfer mechanism through the contract, technical access, sub-operator chain, and deletion or return evidence.
  • Repeat testing after a new purpose, data category, vulnerable population, vendor, country, incident, complaint, or binding ANPD rule.
Primary sources

References and citations

gov.br
Referenced sections
  • Official register showing the current status of ANPD regulations that supplement the LGPD.
planalto.gov.br
Referenced sections
  • Primary LGPD source for the compliance program scope, including treatment of personal data, controller obligations, rights handling, and governance evidence.
"Esta Lei dispõe sobre o tratamento de dados pessoais, inclusive nos meios digitais"
planalto.gov.br
Referenced sections
  • Articles 37-41 allocate processing-record, RIPD, operator-instruction, and encarregado duties; Articles 46 and 50 support security and governance evidence.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.