Artifact GuideBrazilController Operator and DPO Roles

Brazil LGPD Controller Operator and DPO Roles

The controller decides the purpose and essential elements of processing. The operator processes on the controller's behalf and under lawful instructions.

The encarregado is the communication and advisory function. It does not become the controller or own the controller's compliance decisions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this guide to classify the , , , and under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), Law 13.709/2018, from actual decisions, instructions, processing facts, and communication duties.

Section 1

What should teams decide about Controller Operator and DPO Roles under the Brazil LGPD?

Classify each purpose and relationship from actual conduct. A decides why personal data is processed and the essential elements of that processing. An acts on the controller's behalf and must follow the controller's lawful instructions. A supplier can be an operator for one activity and a controller for another if it determines a separate purpose.

The is not a third processing agent. The LGPD's Article 5 definition, amended by Law 15,352 on 25 February 2026, describes the encarregado as a person designated by the and to serve as the communication channel among the controller, data subjects, and the ANPD. Article 41 continues to state the controller's appointment duty, while Resolution 18/2024 makes operator appointment optional and treats it as a governance practice.

  • List who decides each purpose, data category, affected population, collection source, retention period, disclosure, essential system feature, and means of exercising rights.
  • List every written instruction the receives and every decision it may make within those instructions.
  • Identify sub-operators, their instructions, approval path, security duties, incident escalation, return or deletion, and audit evidence.
  • Do not use the contract label as the conclusion; explain where the contract and actual conduct agree or differ.
Section 2

What does each role own?

The owns the legal basis and purpose, transparency, data-subject responses, RIPD decision, transfer mechanism verification, instructions, and reportable-incident notifications. Operators must process within lawful instructions, maintain their own Article 37 records, assist with information in their control, apply security, and escalate incidents without unjustified delay.

Resolution 18 requires a formal written, dated, signed designation and a formally designated substitute for absences, impediments, or vacancies. The agent must publish and keep current the encarregado's identity and contact information, provide resources and technical autonomy, enable direct access to senior decision-makers, and maintain effective routes for data subjects and ANPD communications.

  • evidence: purpose and decision map, legal bases, notices, processing record, instructions, approvals, rights decisions, transfer records, RIPDs, and incident decisions.
  • evidence: contract, instruction log, processing record, chain, control evidence, deletion or return, assistance, and incident escalation.
  • evidence: designation and substitute, published contact, ANPD and data-subject communications, training, advice, conflicts, resources, and access to leadership.
  • Keep the role matrix at the purpose and processing-operation level rather than assigning one label to the entire corporate relationship.
Section 3

Which edge cases should teams check before relying on a Controller Operator and DPO Roles decision?

A service provider that uses customer data for its own independent purpose may be a for that use even if the main service contract calls it an . An operator that processes contrary to lawful controller instructions can be treated like a controller for liability arising from that processing under Article 42(1). This is a fact-specific liability rule, not an automatic reclassification of every operator activity.

An may be a natural person or legal entity and may be internal or external. The function needs technical autonomy and must avoid conflicts that impair objective judgment. The encarregado advises and assists, but Resolution 18 states that these activities do not transfer responsibility for the processing agent's legal compliance to the encarregado.

Employees and internal departments that act for the same legal entity are not separate operators merely because they handle data. By contrast, an external call centre following the customer's purposes and instructions is a typical . A cloud provider hired by that operator can be a ; the ANPD guide recommends formal authorisation for that subcontracting.

  • Small processing agents that qualify under Resolution 2/2022 need not appoint an but must maintain a data-subject communication channel if they do not.
  • Public bodies covered by Resolution 18 must appoint an when they process personal data and should follow the regulation's public-sector designation rules.
  • Joint decision-making can create more than one ; document each party's decisions and duties rather than forcing the relationship into a controller- model.
  • Reassess roles after a new purpose, analytics use, product feature, , retention decision, transfer, or instruction change.
Section 4

How should teams operationalize Controller Operator and DPO Roles with proportionate controls?

Produce a role matrix for each purpose showing the decision-maker, instructed processor, , system owner, rights owner, security owner, transfer owner, incident escalation route, channel, evidence owner, and reassessment trigger.

Translate the matrix into contracts and procedures. State permitted processing, documented instructions, confidentiality, security, conditions, assistance, incident escalation, rights support, transfer restrictions, audit evidence, retention, return or deletion, and change control.

  • Compare the written role against product configuration, sales promises, analytics, support access, and actual data flows.
  • Keep the 's instructions specific enough to test and update them when processing changes. The may choose non-essential technical measures within those instructions, but it does not acquire the controller's purpose-setting role by doing so.
  • Publish a working contact and test absence coverage; appointment paperwork alone does not provide a usable channel.
  • Record unresolved shared decisions or independent uses and obtain case-specific legal review before assigning duties.
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Binding 2026 amendment to the LGPD Article 5(VIII) definition of encarregado and the ANPD's institutional name.
planalto.gov.br
Referenced sections
  • Binding definitions, instruction duties, records, security, rights, transfer, and incident responsibilities used by the role matrix.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.