Artifact GuideBrazilData Subject Rights

Brazil LGPD Data Subject Rights

A data subject can ask the controller to confirm processing, provide access, correct data, restrict unlawful or excessive processing, and exercise the other rights in Articles 18 and 20.

Only confirmation and access have Article 19's immediate simplified or 15-day complete-response choices. Other rights must follow their own conditions and applicable regulation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Identify the right under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), Law 13.709/2018, before starting the clock. Article 18 covers confirmation, access, correction, anonymisation, blocking or deletion of unnecessary, excessive, or unlawful data, portability, deletion of consent-based data, sharing information, information about refusing consent, revocation, and objection to unlawful non-consent processing. Article 20 separately covers review of decisions made solely through automated processing that affect the person's interests; the Agência Nacional de Proteção de Dados (ANPD) issues binding procedures and public guidance on exercising these rights.

Section 1

What should teams decide about Data Subject Rights under the Brazil LGPD?

For confirmation or access, allows an immediate simplified response or a clear and complete declaration within 15 days. The complete declaration identifies the data's origin, lack of a record where applicable, criteria used, and processing purpose, subject to commercial and industrial secrets.

The controller must not promise every requested deletion. Article 18(IV) applies to unnecessary, excessive, or unlawful data; Article 18(VI) applies to consent-based data, subject to . Those grounds are compliance with a legal or regulatory obligation, research by a research body with anonymisation where possible, transfer to a third party that meets the LGPD, or the controller's exclusive use with access by third parties prohibited and data anonymised. Portability is subject to ANPD regulation and commercial and industrial secrets and excludes data already anonymised.

The data subject exercises these rights by express request and without charge. Use the 15-day period only for 's complete confirmation or access declaration; do not invent the same deadline for correction, deletion, objection, portability, consent, or automated-decision requests.

  • Classify the request under Article 18, Article 20, or another applicable law; do not apply the 15-day rule to every request automatically.
  • Verify identity proportionately without collecting more data than necessary, and preserve an authorised representative's authority where relevant.
  • Search every system, operator, archive, and recipient needed for the response or action, while protecting other people and commercial or industrial secrets.
  • If immediate action is impossible, state the factual or legal reason or, where the recipient is not the processing agent, identify the agent when possible.
Section 2

Who should own Data Subject Rights, and what evidence should prove the decision?

The controller owns the response. The encarregado or published privacy channel coordinates intake; system owners locate and act on data; operators assist under the controller's instructions; privacy or legal reviews limitations, secrets, competing rights, and .

When data has been shared, the responsible agent must immediately inform the other processing agents of a correction, deletion, anonymisation, or blocking so they repeat the action, unless communication is proven impossible or requires disproportionate effort.

  • Name one accountable owner and one reviewer for the Data Subject Rights workflow.
  • Keep the request record, reply text, supporting tickets, and approval notes together.
  • Keep the request, identity check, right and data scope, search record, decision, response, delivery date, system actions, recipient notifications, exception, reviewer, and closure evidence.
  • Do not disclose another person's data or authentication secrets in an access response. Record any redaction and the reason.
Section 3

Which conditions can change the response?

Revoking consent stops future reliance on that consent; it does not make earlier lawful processing retroactively unlawful. If another legal basis is proposed for continued processing, verify that it genuinely fits the purpose and explain the resulting processing transparently.

A person may object to processing based on a consent exemption when the processing violates the LGPD. applies only to decisions made solely through automated processing that affect the person's interests; the controller must also provide clear and adequate information about the criteria and procedures when requested, subject to protected secrets.

  • For public bodies, use the specific procedures and periods referenced in Article 23, including the Habeas Data, administrative-process, and access-to-information laws.
  • Eligible small processing agents have specified differentiated periods under Resolution 2/2022; confirm eligibility and the exact request type before using them.
  • A data subject generally must first present the request to the controller before petitioning the ANPD and should retain proof of that attempt.
  • Consumer-protection bodies may also receive rights complaints when processing occurs in a consumer relationship.
Section 4

What should the rights workflow do?

Log the request, acknowledge the channel, verify identity proportionately, classify the right, locate the controller and systems, assign actions, apply the correct period, review the response, deliver it securely, and preserve closure evidence.

For correction, deletion, anonymisation, or blocking, verify execution in active systems and downstream recipients. For a refusal or limitation, give the factual or legal reason in plain language and preserve the decision record.

  • Publish an easy-to-find channel and make support staff able to recognise and route rights requests regardless of wording.
  • Keep confirmation or access response templates separate from correction, deletion, objection, portability, consent, and automated-decision workflows.
  • Test the workflow across backups, analytics, support tools, vendors, and shared-data recipients rather than only the primary account database.
  • Use request trends to fix notices, retention, product controls, and data quality.
Primary sources

References and citations

gov.br
Referenced sections
  • Official procedure requiring proof that the person first tried to exercise the right with the controller before petitioning the ANPD.
gov.br
Referenced sections
  • Official explanation of the rights and request context, including the distinction between access, deletion, objection, and automated decisions.
planalto.gov.br
Referenced sections
  • Binding Articles 16 and 18-20 for conservation grounds, rights, response formats and periods, downstream updates, objections, and automated decisions.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.