FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
30of30items
Across 10 modules • Updated May 9, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
What should teams do about Children's Data under the Brazil LGPD?

What should teams do about Children's Data under the Brazil LGPD?

Article 14 requires every processing activity involving a child or adolescent to serve that person's best interest. A child is a person under 12; an adolescent is a person from 12 through 17 under Brazil's Child and Adolescent Statute. For a child's data, paragraph 1 requires specific and highlighted consent from at least one parent or legal guardian when consent is the basis. ANPD Statement No. 1/2023 interprets Articles 7 and 11 as available alternatives when their conditions are met and the best interest is assessed and prevails.

Choose the legal basis purpose by purpose. If consent supports a child's data, obtain and document parental consent, the disclosed purpose, and reasonable verification efforts. If another Article 7 or 11 basis applies, record every condition and why that basis and the processing serve the child or adolescent's best interest. Consent, contract necessity, legal obligation, life protection, health protection, and legitimate interest are different tests.

Document the user's age range, age-assurance method, purpose, legal basis, necessity, likely benefits and harms, safeguards, and how the design respects development and the ability to understand the processing. A generic statement that the service benefits children is not a best-interest assessment.

  • Separate children from adolescents when Article 14 applies different wording, while applying the best-interest standard to both groups.
  • If relying on parental consent, use reasonable efforts and available technology to verify that it came from a parent or legal guardian.
  • Collect data without consent only when necessary to contact the parent or guardian or protect the child, use it once, do not retain it, and do not disclose it to a third party without the statutory permission.
  • Treat a child's emergency contact detail collected once to reach a guardian as an example of the narrow contact branch. Reusing that detail for marketing, account creation, or profiling would require a separate legal analysis and does not fit the one-use, no-storage condition.
Citations
What should teams do about Children's Data under the Brazil LGPD?

What evidence should teams keep for Children's Data under the Brazil LGPD?

Keep the age-assurance rationale, best-interest assessment, purpose and minimum-data analysis, legal-basis decision, parental-consent record and verification effort where applicable, child-accessible notice, rights route, recipients, retention, safeguards, and approval.

The controller should own the Article 14 decision. Product and design should show how the experience limits collection and presents information; security should show access and protection measures; legal or privacy should record the basis and exceptions; and customer support should preserve rights-request and guardian-contact evidence.

  • Publish the types of data collected, how they are used, and how parents or guardians can exercise Article 18 rights.
  • Provide information in simple, clear, accessible language suited to the child's physical, sensory, intellectual, and mental characteristics.
  • Test whether refusal of unnecessary data blocks a game, application, or online activity; Article 14 prohibits conditioning participation on data beyond what is strictly necessary.
  • Reassess after a new purpose, age group, profiling or automated-decision feature, advertising use, third-party recipient, sensitive-data category, incident, complaint pattern, or material change to the age or guardian verification method.
Citations
What should teams do about Children's Data under the Brazil LGPD?

Which mistakes create risk when handling Children's Data under the Brazil LGPD?

Do not collapse children and adolescents into one consent rule: the best-interest standard covers both, while Article 14(1)'s parent-or-guardian consent wording concerns children. Do not condition a game or online activity on personal data beyond what is strictly necessary.

Do not describe the narrow Article 14(3) collection branch as a general emergency exemption. It permits collection without the paragraph 1 consent only when necessary to contact the parent or guardian, with one-time use and no storage, or when necessary to protect the child; third-party disclosure still requires the consent specified by that paragraph.

  • Do not state that parental consent is the only possible legal basis after ANPD Statement No. 1/2023.
  • Do not treat a parent's acceptance as curing an activity that fails the best-interest test.
  • Do not copy an adult privacy notice into a child-facing journey without adapting its language and presentation.
Citations
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?

What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?

The binding definitions are in LGPD Article 5, with operational duties in Articles 37 to 42. ANPD guidance explains how the Agency applies those definitions but does not replace the statute. Start with one processing purpose, identify who decides that purpose and the essential elements of the operation, then identify who acts on whose documented instructions.

A controller can be a natural person or a legal entity. More than one party may be a controller when each makes relevant decisions; the ANPD guide treats joint control as a fact-specific situation in which multiple controllers have common, convergent, or complementary decisions and influence the purposes and essential elements. Shared infrastructure or commercial cooperation alone does not settle the result.

An operator must act on behalf of a controller. A payroll provider may be an operator for calculating salaries under the employer's instructions, for example, but may be a controller for a separate purpose it determines itself. Employees, directors, and teams acting under the organization's direct authority are part of that organization rather than separate operators for routine internal work.

The encarregado is a channel and adviser, not the owner of the business purpose or legal-basis decision. LGPD Article 41 assigns the controller the appointment and publication duties, while the current Article 5 definition and ANPD rules frame the role as the channel for the processing agent. Record which entity made the formal appointment and which processing activities and entities the appointment covers.

  • Controller: approve the purpose, legal basis, essential processing design, transparency, retention, recipients, rights response, operator instructions, and any reportable-incident decision.
  • Operator: document the controller, instructions, permitted purpose, data and people covered, security measures, suboperator conditions, assistance duties, audit evidence, and return, deletion, or lawful retention at the end.
  • Encarregado: maintain a clear public contact channel, accept complaints and ANPD communications, route action to the accountable owner, guide employees and contractors, and retain the appointment and activity records.
  • Reassess the map when a party starts reusing data for its own purpose, chooses new essential processing elements, appoints a suboperator, changes the affected controller, or materially changes the service.
Citations
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?

What evidence should teams keep for Controller Operator and DPO Roles under the Brazil LGPD?

Keep one role record per purpose. It should connect the factual decision map to contracts, instructions, the suboperator chain, rights and incident cooperation, and the published encarregado channel. Review real system access, approvals, and data reuse against the written allocation; a signature alone does not prove the role.

  • Keep the role analysis by purpose, controller approvals, contracts and instructions, suboperator authorizations, security requirements, request routing, incident escalation, retention decisions, and audit evidence.
  • Keep the formal encarregado appointment and substitute arrangement. Publish the required identity and contact information clearly and keep it current; a legal entity may perform the role when the responsible natural person is identified as the ANPD rules require.
  • Give the encarregado direct access to the people who decide processing matters, adequate human, technical, and administrative resources, and timely information about material activities.
  • Record conflicting duties and the measures used to avoid them. A conflict exists when another role can lead the encarregado to decide the purposes and means of processing or otherwise compromise objective performance.
Citations
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?

Which mistakes create risk when handling Controller Operator and DPO Roles under the Brazil LGPD?

A contract label is not conclusive. A service provider may be an operator for instructed work and a controller for a separate purpose it determines. Under Article 42, an operator can be jointly liable for damage when it breaches data-protection law or fails to follow lawful controller instructions, in which case it is treated like the controller for that damage, subject to Article 43 defenses.

  • Do not classify a vendor as an operator merely because a contract uses that label; test each purpose and any independent reuse.
  • Do not treat employees acting under the organization's authority as separate operators for routine internal processing.
  • Do not assume every multi-party arrangement creates joint control. Record each party's actual decision power, common or convergent decisions, and responsibility to data subjects.
  • Do not assign the encarregado responsibility for business decisions that belong to the controller or combine the role with duties that create a conflict of interest.
Citations
What should teams do about Cookies under the Brazil LGPD?

What should teams do about Cookies under the Brazil LGPD?

ANPD's 2022 cookie guide is non-binding guidance on how the binding LGPD principles, legal bases, transparency duties, consent conditions, and rights apply online. Its scope includes cookies and similar tracking technologies on websites, applications, phones, and tablets when personal data is collected.

Start with a technical scan and owner interview. Separate necessary cookies from non-necessary cookies, and classify each item by first or third party, session or persistent duration, and purpose: authentication or requested functionality, preferences, audience measurement, advertising, profiling, or another stated use.

Choose the legal basis only after classification. Legitimate interest may fit a necessary authentication or shopping-cart cookie, or limited audience measurement using aggregate data without third-party sharing, cross-service combination, or user profiles. The test remains fact-specific. ANPD says legitimate interest will generally be difficult to support for third-party advertising, cross-site tracking, preference prediction, or behavioral profiles; consent is usually more appropriate in those examples.

Where consent is the basis, the visitor needs a real and informed choice. Do not infer consent from continued browsing, silence, or preselected settings. Keep consent-based cookies off until an affirmative choice, make rejecting all non-necessary cookies as easy to find as accepting them, permit purpose-level choices, and provide a free, simple withdrawal route comparable to the consent route.

  • Owner: inventory each cookie or tracker by name, provider, first- or third-party status, purpose, data, duration, recipients, service necessity, legal basis, and transfer destination.
  • Privacy and product: document the Article 7 or 11 basis, any legitimate-interest test, the notice and banner design, retention rule, data-subject channel, and approval.
  • Engineering: test a clean session for no consent, accept all, reject all, purpose-level selection, later withdrawal, expiry, and tag-manager changes; record the cookies and outbound requests observed in each state.
  • Reassess after a new vendor, tag, purpose, recipient, retention period, cross-site combination, profile use, or sensitive-data inference. A change to the premises of consent requires a new valid basis and, where consent remains the basis, a new choice.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

The current LGPD text supplies the principles, transparency duties, data-subject rights, and lawful-basis framework that ANPD applies to cookie and tracking technologies.

What should teams do about Cookies under the Brazil LGPD?

What evidence should teams keep for Cookies under the Brazil LGPD?

Keep a current cookie inventory linked to the deployed configuration. Preserve the purpose and party, data collected, duration, legal basis, banner and notice versions, consent or preference logs, tag-manager tests, vendor recipients and international transfers, retention settings, and change approvals.

  • Keep the inventory, legal-basis assessment, legitimate-interest test where used, banner and policy versions, consent action and timestamp, tag-manager configuration, vendor settings, retention, and withdrawal tests.
  • Explain the specific purposes, cookie categories, duration, controller and contact route, third-party sharing, rights, and choices in clear and accessible Portuguese. Browser controls can supplement, but do not replace, a direct site mechanism.
  • Use a first layer with essential information and easy accept, reject, and manage choices; use the second layer for category purposes and granular settings. Avoid visual emphasis that makes rejection harder to see or understand.
  • Retest after marketing, analytics, consent-platform, application, or vendor changes. The interface, stored preference, network calls, and cookies actually set must match.
Citations
What should teams do about Cookies under the Brazil LGPD?

Which mistakes create risk when handling Cookies under the Brazil LGPD?

Do not call a tracker necessary because marketing or analytics depends on it. Necessity concerns the requested function or service, not the controller's preferred business model. Indefinite or excessive cookie retention is also incompatible with the LGPD's purpose and necessity principles.

  • Do not pre-enable consent-based cookies or infer consent from continued browsing, omission, or a preselected toggle.
  • Do not offer one accept-only button, hide the reject control, or make rejection or later withdrawal materially harder than acceptance.
  • Do not bundle unrelated purposes into one consent or describe them only as 'improving the experience.'
  • Do not assume a cookie policy proves that the tag-manager implementation follows the stated choices; verify the deployed behavior.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

Official source supporting the risk and boundary notes in this FAQ because LGPD Article 6 requires purpose, adequacy, necessity, and transparency limits for personal-data processing.

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

LGPD Article 48 creates the binding notification duty, and ANPD Resolution 15/2024 defines the current threshold, content, procedure, and deadlines. A vulnerability without a confirmed event, an incident that does not involve personal data subject to the LGPD, or an incident that cannot cause relevant risk or harm does not meet all three reporting criteria. Keep the assessment even when the outcome is non-reportable.

Assess the nature and sensitivity of the data, the processing context, the number and vulnerability of affected people, possible material or moral effects, and safeguards already effective at the time of the event. For example, the theft of strongly encrypted data may present a different risk from theft of the same readable data, but encryption is evidence to assess rather than an automatic exemption.

The three-business-day period starts when the controller learns that the incident affected personal data, not when the investigation closes or the threshold assessment is complete. The duty to notify still applies only if the incident may cause relevant risk or harm. Record the occurrence, detection, operator notice, controller knowledge, facts available for the threshold decision, and any shorter or different sector-specific deadline.

The controller owns the reportability decision and both required communications. The operator should alert the controller without unjustified delay and provide logs, affected systems and data, containment actions, and other facts required by contract or instruction. The encarregado or a legal representative may submit the ANPD filing, but that does not transfer the controller's accountability.

  • Identify the controller for each affected dataset; one organization may be controller for one purpose and operator for another, and an operator's customer notice does not replace the controller's notices.
  • Check banking, health, telecommunications, consumer, contractual, and other incident regimes in parallel. A specific legal deadline can displace the Resolution 15/2024 period, while contractual or insurance notices do not.
  • If required information is unavailable, file a preliminary communication on time, justify what is missing, and submit the complementary information within twenty business days of that filing unless ANPD sets another period.
  • Tell affected people directly, in simple language, about the nature and category of data, risks and possible effects, measures taken or recommended, incident date if known, and a controller or encarregado contact. If direct and individualized notice is infeasible or affected people cannot be identified, Resolution 15/2024 requires a prominent notice through available communication channels for at least three months.
Citations
ANPD - Comunicação de Incidente de Segurança

ANPD's incident communication page supports the FAQ's reporting workflow by identifying controller responsibility, SEI filing, reportable incident criteria, and the three-business-day communication period.

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

What evidence should teams keep for Incident Reporting To ANPD under the Brazil LGPD?

Keep a decision record for every confirmed incident, including those assessed as non-reportable. It should connect the chronology and technical evidence to each reporting criterion and show who made the controller decision. Resolution 15/2024 requires the controller to keep the incident record for at least five years from the record date, unless another rule requires longer retention; public bodies and entities must also observe the archival periods in the legislation that governs them.

  • Chronology: occurrence if known, detection, containment, operator escalation, controller knowledge that personal data was affected, threshold decision, filing, affected-person notice, supplements, and closure.
  • Scope and threshold: controller and operator roles, systems and locations, categories and approximate volume of data and people, vulnerable groups, likely effects, and safeguards such as effective encryption.
  • Response: preserved logs, investigation findings, containment and recovery steps, measures offered to affected people, ANPD form and receipt, notice text and delivery evidence, delay explanation, and corrections.
  • Governance: decision owner, legal and security review, sector-regulator notices, processor cooperation, lessons learned, control changes, and the next reassessment date.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

Official source supporting the FAQ answer because LGPD Article 48 requires controllers to communicate security incidents that may create relevant risk or harm to data subjects.

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

Which mistakes create risk when handling Incident Reporting To ANPD under the Brazil LGPD?

Do not rely on the LGPD's general 'reasonable time' wording without applying Resolution 15/2024. A preliminary communication is not complete compliance: investigate, mitigate, notify affected people, and supply the justified missing information within the complementary period. ANPD may require corrections, broader disclosure, additional mitigation, or other measures after reviewing the case.

  • Do not start the clock only when a forensic report is final or the threshold assessment is complete; start from the controller's knowledge that the incident affected personal data.
  • Do not wait for proof of actual harm, complaints, fraud, or publication; the test is whether relevant risk or harm may result.
  • Do not let contractual, insurance, law-enforcement, or other regulator workflows delay the LGPD communication, and do not assume one filing satisfies every regime.
  • If filing late, explain the cause, record the chronology, and state the measures taken to reduce harm. A delay explanation does not erase the missed deadline.
Citations
What should teams do about International Transfer Mechanisms under the Brazil LGPD?

What transfer mechanisms are allowed under the Brazil LGPD?

Start with scope. Document the exporter, foreign importer, controller and operator roles, countries and remote-access locations, data and people, purpose, frequency, systems, and onward recipients. Direct collection from a person in Brazil by a processing agent abroad may bring the foreign processing within LGPD Article 3, but Resolution 19/2024 classifies it as international collection rather than an international transfer.

Next, choose both layers of authority. An Article 7 or 11 basis permits the processing purpose; it does not permit the cross-border movement by itself. Match the actual flow to one Article 33 case and retain the facts that make that mechanism available.

For contractual safeguards, the standard contractual clauses in Annex II of Resolution 19/2024 may be incorporated without changing their prescribed text. Specific clauses and binding corporate rules require prior ANPD approval. Contractual safeguards remain subject to LGPD principles, data-subject rights, security duties, accountability, and ANPD oversight.

An adequacy decision in ANPD Resolution 32/2026 recognizes transfers within its defined European Union and European Economic Area scope, including EU institutions and the EEA EFTA states Iceland, Liechtenstein, and Norway. The decision excludes processing exclusively for public security, national defense, state security, or criminal investigation and repression. It took effect on publication on 27 January 2026 and must be reassessed within four years, while ANPD continues to monitor the level of protection. Verify the current decision and the importer's coverage before using this route.

Article 33 also permits specified non-contractual cases, including international legal cooperation, protection of life or physical integrity, ANPD authorization, commitments in international cooperation agreements, execution of public policy or legal public-service attribution, specific and prominent consent for the transfer, and the Article 7(II), (V), and (VI) situations expressly incorporated by Article 33(IX). Apply the exact conditions rather than treating these as broad exceptions.

  • Adequacy decision: verify that the effective ANPD decision covers the destination, importer, data flow, purpose, and sector, and record any exclusion.
  • ANPD clauses: execute the Annex II text between the exporter and importer, allocate the stated responsibilities, control onward transfers, and make required Portuguese information available to data subjects.
  • Approved safeguards: obtain ANPD approval before relying on specific contractual clauses or group-wide binding corporate rules; an application or internal policy is not an approved mechanism.
  • Other Article 33 cases: document the exact statutory paragraph, its facts and limits, and any consent, authorization, cooperation instrument, public-policy mandate, emergency, contract request, or legal-proceeding evidence.
  • Reassess before adding a destination, remote-access country, importer, subprocessor, onward transfer, purpose, data category, or incompatible commercial term.
Citations
ANPD - Transferência Internacional de Dados

ANPD's current transfer page identifies the mechanisms in force, the European adequacy recognition, and the status of approvals for equivalent clauses, specific clauses, and binding corporate rules.

What should teams do about International Transfer Mechanisms under the Brazil LGPD?

What evidence should teams keep for International Transfer Mechanisms under the Brazil LGPD?

Keep one transfer record that connects the system flow to the legal basis and Article 33 mechanism. The record should let a reviewer identify the exporter and importer, reproduce the scope decision, inspect the executed or approved safeguard, trace onward transfers, and confirm that rights and security controls work across borders.

  • Flow record: systems, exporter, importer, roles, destinations and access locations, people and data, purpose, frequency, retention, subprocessors, and onward transfers.
  • Authority record: Article 7 or 11 basis, Article 33 mechanism, adequacy-scope analysis, consent or statutory evidence, signed clauses, or final ANPD approval as applicable.
  • Operational record: transfer impact and security assessment, incident cooperation, rights-request route, deletion or return controls, audit information, and responsibility for changes.
  • Transparency record: the public transfer notice and, when the Resolution requires it, the Portuguese clauses or information supplied to a data subject who requests them within fifteen days.
  • Review record: owner, approval, effective date, transition remediation, vendor and group changes, legal developments, and scheduled reassessment.
Citations
What should teams do about International Transfer Mechanisms under the Brazil LGPD?

Which mistakes create risk when handling International Transfer Mechanisms under the Brazil LGPD?

ANPD standard contractual clauses are not the European Commission's clauses and cannot be replaced by a generic data-processing agreement. The transition for contracts already using clauses ended on 23 August 2025, so verify that the current Brazilian text is incorporated in full, signed by the correct parties, reflected in operations, and supported by the required transparency.

  • Do not use a controller-operator agreement, foreign-law clause, certification, or vendor assurance as a substitute for an Article 33 transfer mechanism.
  • Do not assume that cloud hosting in Brazil prevents transfers; foreign support access, replication, telemetry, and onward subprocessors can create covered flows.
  • Do not edit the mandatory ANPD clause text. Put additional commercial terms elsewhere and resolve any contradiction in favor of the required safeguard.
  • Do not rely on a submitted application for specific clauses or binding corporate rules before ANPD approval, and check ANPD's current repository rather than assuming an approval exists.
  • Do not treat the European adequacy decision as covering every European territory, organization, or law-enforcement purpose; apply Resolution 32/2026's stated scope and exclusions.
Citations
Page 1 of 2
Previous12Next