FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
30of30items
Across 10 modules • Updated May 9, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
What should teams do about Children's Data under the Brazil LGPD?

What should teams do about Children's Data under the Brazil LGPD?

Teams should treat Children's Data under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

The safest first step is to identify the controller/operator role, purpose, lawful basis, data category, data-subject right, transfer, or incident trigger before assigning the LGPD action.

  • Write the Children's Data decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
What should teams do about Children's Data under the Brazil LGPD?

What evidence should teams keep for Children's Data under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
What should teams do about Children's Data under the Brazil LGPD?

Which mistakes create risk when handling Children's Data under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about Controller Operator And DPO Roles under the Brazil LGPD?

What should teams do about Controller Operator And DPO Roles under the Brazil LGPD?

Under the Brazil LGPD, the controller makes the decisions about the processing of personal data, the operator processes personal data on the controller's behalf, and the encarregado serves as the communication channel between the controller, the data subjects, and the ANPD.

Teams should treat Controller Operator And DPO Roles under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

The safest first step is to identify the controller/operator role, purpose, lawful basis, data category, data-subject right, transfer, or incident trigger before assigning the LGPD action.

  • Write the Controller Operator And DPO Roles decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
What should teams do about Controller Operator And DPO Roles under the Brazil LGPD?

What evidence should teams keep for Controller Operator And DPO Roles under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
What should teams do about Controller Operator And DPO Roles under the Brazil LGPD?

Which mistakes create risk when handling Controller Operator And DPO Roles under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about Cookies under the Brazil LGPD?

What should teams do about Cookies under the Brazil LGPD?

Teams should treat Cookies under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

The safest first step is to identify the controller/operator role, purpose, lawful basis, data category, data-subject right, transfer, or incident trigger before assigning the LGPD action.

  • Write the Cookies decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

The current LGPD text supplies the principles, transparency duties, data-subject rights, and lawful-basis framework that ANPD applies to cookie and tracking technologies.

What should teams do about Cookies under the Brazil LGPD?

What evidence should teams keep for Cookies under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
What should teams do about Cookies under the Brazil LGPD?

Which mistakes create risk when handling Cookies under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

Teams should treat Incident Reporting To ANPD under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

Under article 48 of the LGPD, the controller must notify the ANPD and the data subject about a security incident that may cause relevant risk or harm to the data subjects. The LGPD also says the communication must be made in a reasonable time, and ANPD rules define the detailed procedure.

The safest first step is to identify the controller/operator role, purpose, lawful basis, data category, data-subject right, transfer, or incident trigger before assigning the LGPD action.

  • Write the Incident Reporting To ANPD decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
ANPD - Comunicação de Incidente de Segurança

ANPD's incident communication page supports the FAQ's reporting workflow by identifying controller responsibility, SEI filing, reportable incident criteria, and the three-business-day communication period.

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

What evidence should teams keep for Incident Reporting To ANPD under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

Evidence support for the FAQ answer because LGPD Article 48 requires controllers to communicate security incidents that may create relevant risk or harm to data subjects.

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

Which mistakes create risk when handling Incident Reporting To ANPD under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about International Transfer Mechanisms under the Brazil LGPD?

What transfer mechanisms are allowed under the Brazil LGPD?

Teams should treat international transfers under the Brazil LGPD as a source-linked operating decision: confirm whether the transfer can rely on adequacy, contractual safeguards, binding corporate rules, consent, legal necessity, public policy, ANPD authorization, international cooperation, or other cases listed in Article 33, then assign the team that can change the process and keep evidence showing the action and review trigger.

The first step is to identify the transfer base in Article 33 and match it to the data flow before execution.

  • Adequacy: transfer to countries or international organizations that provide an adequate level of personal data protection recognized by ANPD.
  • Contractual safeguards: specific contractual clauses, standard contractual clauses, or binding corporate rules when the controller proves compliance with LGPD principles, data subject rights, and the data protection regime.
  • Other Article 33 cases: cooperation between public bodies, protection of life or physical integrity, ANPD authorization, international cooperation agreements, public policy or legal attribution, specific consent, or the hypotheses in Article 7 or Article 11.
  • Keep the legal basis, the mechanism used, and the source quote together in the evidence record.
Citations
What should teams do about International Transfer Mechanisms under the Brazil LGPD?

What evidence should teams keep for International Transfer Mechanisms under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
What should teams do about International Transfer Mechanisms under the Brazil LGPD?

Which mistakes create risk when handling International Transfer Mechanisms under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about Legal Bases under the Brazil LGPD?

What should teams do about Legal Bases under the Brazil LGPD?

Teams should treat Legal Bases under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

The safest first step is to identify the controller/operator role, purpose, lawful basis, data category, data-subject right, transfer, or incident trigger before assigning the LGPD action.

  • Write the Legal Bases decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
What should teams do about Legal Bases under the Brazil LGPD?

What evidence should teams keep for Legal Bases under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
What should teams do about Legal Bases under the Brazil LGPD?

Which mistakes create risk when handling Legal Bases under the Brazil LGPD?

The common failure pattern is using a GDPR-style answer without checking LGPD roles, lawful bases, ANPD guidance, transfer rules, incident thresholds, and Brazilian enforcement context.

  • Using an old threshold, deadline, source page, or contract template without checking current source text.
  • Treating a source-linked exception as a general exemption for every product or data flow.
  • Publishing notices, controls, or answers that do not match the actual product behavior.
Citations
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

Teams should treat Legitimate Interest Balancing under the Brazil LGPD as a source-linked operating decision: confirm whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure, assign the team that can change the process, and keep evidence showing the action and review trigger.

In plain language, the rule lets a controller rely on legitimate interest only when the purpose is real and specific, the processing stays within what is strictly necessary, and the controller can explain the balance and show why the activity is allowed.

  • Write the Legitimate Interest Balancing decision in one sentence before drafting controls.
  • Attach the external source URL and a short source quote to the evidence record.
  • Route unclear cases to legal, privacy, security, or compliance review before launch.
Citations
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

What evidence should teams keep for Legitimate Interest Balancing under the Brazil LGPD?

Useful evidence is not just a privacy notice. Keep the source, role map, lawful-basis note, rights log, transfer analysis, incident assessment, DPO review, and approval trail together.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, and role mapping.
  • Implementation ticket, approval record, exception notes, and review date.
Citations
Page 1 of 2
Previous12Next