Artifact GuideBrazilDSAR Workflow

Brazil LGPD DSAR Workflow

Send each request to the controller that decides the relevant processing, identify the right being exercised, and apply the timing and exceptions for that right.

Confirmation and access have express response forms and deadlines. Other rights still require a documented response, but the LGPD does not impose one universal 15-day deadline on every request.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this workflow for requests made under Brazil's Lei Geral de Protecao de Dados Pessoais (LGPD). The controller owns the response. Verify the requester without collecting unnecessary identity data, identify the specific right and processing activity, search the relevant systems and operators, apply any lawful limitation or retention rule, and keep evidence of the decision and delivery.

Section 1

How should an LGPD data-subject request be triaged?

First confirm that the request concerns personal data processed by the receiving controller. Record the request date, channel, requester, represented person if applicable, requested right, relevant product or process, and the systems or operators likely to hold the data. Use a proportionate identity check and do not disclose personal data until the requester or authorized representative is sufficiently verified.

Article 18 covers confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability subject to ANPD regulation; deletion of data processed on consent, subject to Article 16 retention exceptions; information about public and private entities with which data was shared; information about the option and consequences of refusing consent; and revocation of consent. Objection to processing carried out on a legal basis other than consent is available when the LGPD has been breached. Article 20 separately addresses review of decisions based solely on automated processing that affect the data subject.

  • Acknowledge receipt and preserve the original wording; do not silently convert an access request into a narrower support ticket.
  • Identify the controller for each purpose. If the organization is not the responsible processing agent, Article 18(4) requires a response stating that fact and, when possible, identifying the agent.
  • Send scoped searches to the systems and operators that hold the relevant data, including archives and active records, while preventing alteration or deletion during the search.
  • Record the legal and factual reason for every fulfilled, partially fulfilled, or refused item.
  • Branch by right: correct inaccurate data; anonymize, block, or delete data that is unnecessary, excessive, or unlawfully processed; test consent-based deletion against Article 16 conservation; assess an objection against the alleged LGPD breach; and route a qualifying solely automated decision to Article 20 review.
Section 2

Which deadline and response form apply?

For confirmation and access, Article 19 allows an immediate simplified response or a clear and complete declaration within 15 days. The complete declaration must indicate the data's origin, absence of a record where applicable, processing criteria, and purpose, while protecting commercial and industrial secrets. It must be supplied electronically in a secure form or as a printed copy, according to the data subject's choice.

Do not apply the 15-day period to every Article 18 right without a specific rule. Track a reasonable internal due date for correction, deletion, objection, portability, consent, and sharing-information requests, and state any dependency or lawful limitation. Small processing agents have differentiated rules under Resolution 2/2022, including double time for the clear and complete Article 19 declaration and up to 15 days for the simplified declaration.

  • Response header: controller identity, request reference, date received, verified channel, right requested, response date, and contact route.
  • Decision: fulfilled, partially fulfilled, refused, redirected, or awaiting a documented dependency, with a separate reason for each requested item.
  • Access package: personal data about the requester, source, processing criteria, purposes, and relevant sharing information; exclude another person's data and protect commercial and industrial secrets.
  • Action evidence: corrected field, deletion or blocking record, retention basis and period, consent status, operator instruction, delivery proof, reviewer, and approval date.
Section 3

How should the controller close or escalate the request?

Before delivery, confirm that the response answers each item, uses clear language, reaches the verified requester through a secure channel, and does not expose another person's data. When correction, anonymization, blocking, or deletion is carried out, Article 18(6) requires the controller to inform agents with which it shared the data so they can repeat the action, unless that communication is proven impossible or involves disproportionate effort.

Keep the request, verification result, searches, legal analysis, copies of the response and disclosed data, operator communications, delivery proof, and any exception. A data subject petition to the ANPD generally requires evidence that the person first tried to exercise the right with the controller, so give the requester a usable protocol or reference number.

  • Escalate identity conflicts, requests involving another person's rights, legal holds, protected secrets, unclear controller status, or a conflict between deletion and an Article 16 retention ground.
  • Do not treat consent withdrawal as retroactively invalidating processing completed before withdrawal; separately assess whether the data must now be deleted.
  • Check whether consumer, employment, health, financial, or public-sector rules provide another route or stricter requirement.
  • Review recurring delays and search failures by system and operator, then update ownership, contracts, and retention maps.
Primary sources

References and citations

gov.br
Referenced sections
  • ANPD's public explanation of confirmation, access, correction, deletion, portability, objection, consent, and automated-decision rights.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.