Artifact GuideBrazilFAQ

Brazil LGPD FAQ

Use this FAQ to answer common LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.

Each answer distinguishes the LGPD text, binding ANPD regulations, and non-binding guidance, then identifies the action and evidence to keep.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
FAQ modules
10

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

Brazil's Lei Geral de Proteção de Dados Pessoais (), Law 13.709/2018, applies to personal-data processing connected with Brazil, subject to Article 4 exclusions. Start with the processing operation, identify the controller and operator, classify ordinary and sensitive data, choose an Article 7 or 11 legal basis for each purpose, and then apply the binding rules and guidance from the Agência Nacional de Proteção de Dados (ANPD) for rights, children, security incidents, international transfers, impact reports, eligible , and enforcement.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items30
Focused FAQ modules
10
Showing 10 of 10
FAQ module

What should teams do about Children's Data under the Brazil LGPD?

Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.

3 items
FAQ module

What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?

Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Cookies under the Brazil LGPD?

Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about International Transfer Mechanisms under the Brazil LGPD?

Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Legal Bases under the Brazil LGPD?

Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about RIPD and DPIA under the Brazil LGPD?

Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Sanctions Methodology under the Brazil LGPD?

Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.

3 items
FAQ module

What should teams do about Small Processing Agents under the Brazil LGPD?

Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.

3 items
Question 1

How should teams use the Brazil LGPD FAQ hub for privacy compliance decisions?

Use the FAQ after identifying the processing operation, purpose, people, data, systems, recipients, and countries. The is the binding statute. ANPD resolutions add binding procedures; ANPD guides explain the authority's approach but do not create a new legal basis, right, exemption, or penalty.

Answer in order: decide scope and any exclusion; identify controller, operator, and encarregado responsibilities; classify ordinary or sensitive data; document the Article 7 or 11 basis; then apply the relevant transparency, rights, retention, security, incident, transfer, or governance rule.

  • Record the exact processing operation and the fact that triggers the answer.
  • Name the controller decision-maker, instructed operator, system owner, evidence owner, reviewer, and reassessment trigger.
  • Keep the cited provision or regulation with the decision record rather than using a source link as a substitute for the answer.
  • Reopen the answer after a new purpose, data category, child or vulnerable population, vendor, country, automated decision, complaint, incident, or ANPD rule.
Question 2

Who should maintain the Brazil LGPD FAQ evidence and source-review process?

The controller remains accountable for the processing purpose, legal basis, transparency, rights response, transfer route, reportable-incident decision, and risk acceptance. An operator processes on the controller's behalf under lawful instructions and must maintain its own Article 37 record. A supplier can be an operator for the contracted service and a controller for a separate use it determines.

The encarregado is the published communication and advisory function between the processing agent, data subjects, and the ANPD. Resolution 18/2024 requires a formal designation and substitute, resources, technical autonomy, and a usable contact route. Its advisory work does not transfer the controller's or operator's compliance responsibility.

  • Keep a per-purpose role map; a contract label alone does not decide the role.
  • Record the controller's instructions, operator assistance, sub-operator approval, security duties, incident escalation, rights support, and return or deletion terms.
  • Publish the encarregado's identity and contact details, maintain absence coverage, and preserve complaints, ANPD communications, advice, training, conflicts, and escalation records.
  • Reassess roles when a supplier chooses a new purpose, retention period, recipient, analytics use, or onward transfer.
Question 3

Which edge cases should teams check before relying on Brazil LGPD FAQ guidance?

Ordinary personal data uses Article 7; sensitive data uses Article 11. includes racial or ethnic origin, religious belief, political opinion, union or religious, philosophical, or political affiliation, health or sex-life data, and genetic or biometric data linked to a person. Article 7 legitimate interest is not an Article 11 basis.

Children's and adolescents' data must be processed in their best interests. Article 14 also sets specific transparency and consent rules for children. Eligible receive only the measures stated in Resolution 2/2022; high-risk processing and revenue or group thresholds can remove that treatment.

  • Do not treat public, pseudonymised, hashed, or encrypted data as automatically anonymous.
  • Do not promise deletion where Article 16 permits conservation, or apply Article 19's 15-day complete access period to every Article 18 request.
  • Do not treat consent as the default basis. It must be demonstrable, purpose-specific, and revocable, and refusal consequences must be explained.
  • Check public-sector, consumer, employment, health, finance, telecoms, and other sector rules separately.
Question 4

How should teams turn Brazil LGPD FAQ guidance into owned controls?

Use current ANPD procedure for regulated decisions. Resolution 15/2024 sets the reportability test, three-business-day incident period, staged ANPD filing, affected-person notice, and five-year record. Resolution 19/2024 requires both an Article 7 or 11 processing basis and an Article 33 transfer mechanism; its standard clauses must be adopted in full when selected.

The ANPD applies administrative sanctions through due process and its enforcement and dosimetry regulations. The statutory maximum simple fine is 2% of Brazilian revenue for the prior financial year, excluding taxes and capped at R$50 million per infringement. It is a ceiling, not an automatic amount.

  • For incidents, keep the knowledge timestamp, risk analysis, filing, affected-person notice, supplement, remediation, and five-year record.
  • For transfers, keep the exporter, importer, roles, countries, purpose, data, processing basis, mechanism, contract or adequacy decision, onward transfers, security, transparency, and review date.
  • For a , keep the processing description, methodology, safeguards, risk analysis, mitigation, controller approval, and source data; prepare it when the ANPD requires one and use it proactively for high-risk processing where appropriate.
  • For enforcement readiness, preserve dated decisions, notices, request logs, processing records, contracts, tests, remediation, cooperation, and proof of corrective action.
Primary sources

References and citations

gov.br
Referenced sections
  • Official explanation of confirmation, access, correction, restriction, deletion, consent, sharing, objection, automated-decision, and free-exercise rights.
gov.br
Referenced sections
  • Current binding incident-reporting test, period, filing, notice, supplement, and five-year record procedure under Resolution 15/2024.
in.gov.br
Referenced sections
  • Official ANPD interpretive statement allowing children's and adolescents' data to be processed under an Article 7 or 11 basis when their best interest is observed and prevails in the concrete case.
"O tratamento de dados pessoais de crianças e adolescentes poderá ser realizado com base nas hipóteses legais previstas no art. 7º ou no art. 11"
planalto.gov.br
Referenced sections
  • Primary LGPD source for RIPD/DPIA records, controller accountability, lawful basis, data-subject rights, security duties, and ANPD authority requests.
"relatório de impacto à proteção de dados pessoais: documentação do controlador"
gov.br
Referenced sections
  • Binding eligibility, high-risk, revenue, and economic-group limits for the special treatment available to small processing agents.
"será considerado de alto risco o tratamento de dados pessoais que atender cumulativamente a pelo menos um critério geral e um critério específico"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.