Artifact GuideBrazilDeadlines and Compliance Calendar

Brazil LGPD Deadlines and Compliance Calendar

Use this calendar to separate completed LGPD commencement milestones from deadlines that start when a person makes a request, an incident occurs, or the ANPD issues a decision.

Record the legal trigger, start date, business-day rule, owner, evidence, and any sector-specific deadline for each obligation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The live dates most teams need are these: provide simplified confirmation or access immediately, or a complete access statement within 15 days of the request; report a qualifying to the ANPD and affected data subjects within three business days; and supplement a justified preliminary incident report within 20 business days of the preliminary filing. The LGPD does not impose one universal deadline for every privacy task, so a useful calendar must distinguish these fixed clocks from retention decisions, contract reviews, internal targets, and deadlines stated in an ANPD notice.

Section 1

Which LGPD dates are historical milestones rather than current deadlines?

The LGPD was enacted on 14 August 2018. The ANPD governance provisions identified in Article 65 took effect on 28 December 2018. Most remaining provisions have applied since 18 September 2020, and Articles 52 to 54 on administrative sanctions took effect on 1 August 2021. These dates explain when the legal regime began; they are not recurring due dates.

Resolution CD/ANPD No. 19 took effect on 23 August 2024. Its 12-month transition for organizations using contractual clauses for international transfers ended on 23 August 2025. A team that missed that transition has an existing compliance issue, not a future calendar entry: it should identify each affected transfer and confirm that its contract uses the ANPD clauses or another valid Article 33 mechanism.

  • 14 August 2018: enactment of Law No. 13,709, the LGPD.
  • 28 December 2018: commencement of the ANPD and council provisions listed in Article 65(I).
  • 18 September 2020: commencement of most operational LGPD provisions.
  • 1 August 2021: commencement of Articles 52, 53, and 54 on administrative sanctions.
  • 23 August 2025: end of Resolution 19/2024's transition for incorporating ANPD standard contractual clauses into contracts that rely on contractual clauses for international transfers.
Section 2

Which event-driven deadlines belong in the live compliance calendar?

For confirmation that processing exists or access to personal data, Article 19 gives the controller two routes: a simplified response immediately, or a clear and complete statement within 15 days from the data subject's request. The complete statement must address the origin of the data, whether records exist, the criteria used, and the purpose of processing, subject to commercial and industrial secrecy. The ANPD may set different deadlines for specific sectors, so the request log should record any applicable sector rule.

For a capable of causing relevant risk or harm, the controller must notify the ANPD and affected data subjects within three business days, counted under Resolution 15/2024 and subject to any deadline in specific legislation. If the controller cannot provide complete information, it may file a justified preliminary notice and complete the ANPD submission within 20 business days from that notice. The preliminary notice does not complete the Article 48 duty. The controller must keep incident records for at least five years, including incidents it concluded were not reportable.

If an operator discovers the incident first, it should notify the controller without unjustified delay and provide the facts needed for the controller's assessment. The controller's log should preserve the occurrence date, operator notice time, controller knowledge time, reportability decision, and each communication time instead of using one incident date for every clock.

  • Data-subject access: log receipt time, response route, identity-verification steps, scope, and delivery evidence; do not treat the 15-day complete-response route as a general deadline for every Article 18 right.
  • Security incidents: log when the controller learned that personal data were affected, the relevant-risk assessment, the three-business-day calculation, notices sent, any delay reason, and completion of missing information.
  • ANPD fines: calendar the deadline stated in the decision. Resolution 4/2023 sets payment at up to 20 business days after official notice, doubled for small processing agents as defined by Resolution 2/2022.
  • ANPD orders and proceedings: use the date in the notice or decision. There is no single substitute deadline that can be prefilled for every request, defense, corrective measure, or appeal.
Section 3

Which LGPD obligations do not have one fixed statutory deadline?

The LGPD does not supply one numeric response period for every Article 18 right, one retention period for all personal data, or one review cycle for privacy notices, processing records, impact reports, contracts, and governance controls. Do not label an internal service level as a statutory deadline. Set an internal target from the applicable legal trigger, risk, contract, sector rule, and any ANPD instruction, then label its legal status.

Retention requires a purpose-by-purpose decision. Articles 15 and 16 address when processing ends and when data may be retained, including compliance with legal or regulatory obligations, research under safeguards, transfer to a third party that meets the LGPD, and the controller's exclusive use with third-party access prohibited and data anonymized. Other laws and regulated-sector rules may set specific retention periods.

The same event can start several clocks. A breach may trigger the ANPD rule, a sector regulator's rule, contractual notice, consumer communications, and litigation-preservation duties. Keep each authority, trigger, calculation, recipient, and completion record separate.

  • Mark each entry as a binding deadline, regulator deadline, contract deadline, internal target, or completed historical milestone.
  • Record the trigger and start event; a date without its trigger cannot show when the clock began.
  • State whether the rule uses calendar days or business days and which holiday calendar the team applied.
  • Link completion evidence, including the response, notice, filing receipt, corrected contract, payment record, or documented retention decision.
  • Recalculate the entry when the facts, sector rule, ANPD notice, or controlling regulation changes.
Section 4

How should teams maintain the LGPD compliance calendar?

Privacy or legal should maintain the rule and interpretation; the operational owner should maintain the start event, action, and evidence. Incident response, data-subject rights, procurement, security, finance, and business teams each need access to the entries they trigger.

For every live item, keep the source, legal status, covered processing, trigger timestamp, calculation, owner, reviewer, required action, completion evidence, delay reason, and escalation route. A calendar entry is complete only when the organization can show both what it did and why the recorded deadline applied.

  • Use reminders before the legal deadline; keep the legal due date unchanged so the record does not confuse an internal target with the rule.
  • Route incident and rights requests from intake systems into the calendar automatically where possible, while preserving the original receipt timestamp.
  • Review unresolved and overdue entries with the responsible owner, and document any legal or factual uncertainty instead of guessing the date.
  • Review the rule set after a new ANPD regulation, a sector-law change, a new processing activity, or a change in the controller-operator relationship.
Primary sources

References and citations

gov.br
Referenced sections
  • The ANPD assigns the notification duty to the controller and tells operators to inform the controller without unjustified delay and provide the information needed for notification.
gov.br
Referenced sections
  • Article 2 made the resolution effective on publication and gave processing agents using contractual clauses up to 12 months to incorporate the ANPD standard clauses.
in.gov.br
Referenced sections
  • Articles 17 and 18 set the fine-payment period, the doubled period for small processing agents, and the conditional 25% reduction for waiving appeal.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.