Artifact GuideBrazilCookies

Brazil LGPD Cookies

The LGPD does not impose one legal basis on every cookie. Classify each cookie or tracker by purpose, data, party, duration, and necessity before choosing an Article 7 basis.

Explain each use clearly, keep consent-based trackers off by default, offer an equally visible rejection route, and make later withdrawal work in practice.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The LGPD does not impose one consent rule on all . For each cookie or similar tracker, identify the provider, purpose, data, recipients, duration, and whether the requested service can work without it. Then choose an Article 7 basis for ordinary personal data or an Article 11 basis if sensitive data is involved, provide Article 9 information, and implement the choice the visitor was shown.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Cookies under the Brazil LGPD?

ANPD's 2022 cookie guide is non-binding guidance on how the binding LGPD principles, legal bases, transparency duties, consent conditions, and rights apply online. Its scope includes and similar tracking technologies on websites, applications, phones, and tablets when personal data is collected.

Start with a technical scan and owner interview. Separate from , and classify each item by first or third party, session or persistent duration, and purpose: authentication or requested functionality, preferences, audience measurement, advertising, profiling, or another stated use.

Choose the legal basis only after classification. Legitimate interest may fit a necessary authentication or shopping-cart cookie, or limited audience measurement using aggregate data without third-party sharing, cross-service combination, or user profiles. The test remains fact-specific. ANPD says legitimate interest will generally be difficult to support for third-party advertising, cross-site tracking, preference prediction, or behavioral profiles; consent is usually more appropriate in those examples.

Where consent is the basis, the visitor needs a real and informed choice. Do not infer consent from continued browsing, silence, or preselected settings. Keep consent-based off until an affirmative choice, make rejecting all as easy to find as accepting them, permit purpose-level choices, and provide a free, simple withdrawal route comparable to the consent route.

  • Owner: inventory each cookie or tracker by name, provider, first- or third-party status, purpose, data, duration, recipients, service necessity, legal basis, and transfer destination.
  • Privacy and product: document the Article 7 or 11 basis, any legitimate-interest test, the notice and banner design, retention rule, data-subject channel, and approval.
  • Engineering: test a clean session for no consent, accept all, reject all, purpose-level selection, later withdrawal, expiry, and tag-manager changes; record the and outbound requests observed in each state.
  • Reassess after a new vendor, tag, purpose, recipient, retention period, cross-site combination, profile use, or sensitive-data inference. A change to the premises of consent requires a new valid basis and, where consent remains the basis, a new choice.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

The current LGPD text supplies the principles, transparency duties, data-subject rights, and lawful-basis framework that ANPD applies to cookie and tracking technologies.

Question 2

What evidence should teams keep for Cookies under the Brazil LGPD?

Keep a current cookie inventory linked to the deployed configuration. Preserve the purpose and party, data collected, duration, legal basis, banner and notice versions, consent or preference logs, tag-manager tests, vendor recipients and international transfers, retention settings, and change approvals.

  • Keep the inventory, legal-basis assessment, legitimate-interest test where used, banner and policy versions, consent action and timestamp, tag-manager configuration, vendor settings, retention, and withdrawal tests.
  • Explain the specific purposes, cookie categories, duration, controller and contact route, third-party sharing, rights, and choices in clear and accessible Portuguese. Browser controls can supplement, but do not replace, a direct site mechanism.
  • Use a first layer with essential information and easy accept, reject, and manage choices; use the second layer for category purposes and granular settings. Avoid visual emphasis that makes rejection harder to see or understand.
  • Retest after marketing, analytics, consent-platform, application, or vendor changes. The interface, stored preference, network calls, and actually set must match.
Citations
Question 3

Which mistakes create risk when handling Cookies under the Brazil LGPD?

Do not call a tracker necessary because marketing or analytics depends on it. Necessity concerns the requested function or service, not the controller's preferred business model. Indefinite or excessive cookie retention is also incompatible with the LGPD's purpose and necessity principles.

  • Do not pre-enable consent-based or infer consent from continued browsing, omission, or a preselected toggle.
  • Do not offer one accept-only button, hide the reject control, or make rejection or later withdrawal materially harder than acceptance.
  • Do not bundle unrelated purposes into one consent or describe them only as 'improving the experience.'
  • Do not assume a cookie policy proves that the tag-manager implementation follows the stated choices; verify the deployed behavior.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

Official source supporting the risk and boundary notes in this FAQ because LGPD Article 6 requires purpose, adequacy, necessity, and transparency limits for personal-data processing.

Primary sources

References and citations

gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because ANPD connects cookie compliance to transparency and user control in digital environments.
"promover a cultura da proteção de dados pessoais no ambiente digital"
gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because the ANPD guide warns that cookie use is only legitimate when it respects LGPD principles, rights, and the data-protection regime.
"somente será legítimo se respeitados os princípios, os direitos dos titulares"
planalto.gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because LGPD Article 6 requires purpose, adequacy, necessity, and transparency limits for personal-data processing.
"finalidades legítimas, específicas, explícitas e informadas ao titular"
in.gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because LGPD cookie failures can become enforcement issues under ANPD's sanctions and dosimetry regulation.
"dosimetria e aplicação de sanções administrativas"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.