FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
30of30items
Across 10 modules • Updated May 9, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
What should teams do about Legal Bases under the Brazil LGPD?

What should teams do about Legal Bases under the Brazil LGPD?

Classify the data before selecting from a list. Ordinary personal data may rely on one of Article 7's ten bases: consent; compliance with a legal or regulatory obligation; public-administration processing for laws, regulations, contracts, agreements, or public policies; research by a research body with anonymization where possible; performance of a contract or preliminary procedure requested by the data subject; regular exercise of rights in judicial, administrative, or arbitral proceedings; protection of life or physical integrity; health protection by health professionals, health services, or health authorities; legitimate interest; or credit protection.

Article 11 permits sensitive-data processing with specific and prominent consent for specific purposes, or without consent when the processing is indispensable for one of its stated cases: legal or regulatory compliance; shared processing by public administration for public policies; research with anonymization where possible; regular exercise of rights, including in contracts and proceedings; protection of life or physical integrity; health protection by the authorized health actors; or fraud prevention and data-subject security in electronic identification and authentication, subject to the statutory protections and the data subject's rights prevailing where applicable.

Match the facts to every condition. A contract basis covers performance or a preliminary step requested by the person, not unrelated advertising. Legal obligation requires an identifiable binding duty, not a preference or customer contract. Vital protection is for life or physical integrity, not routine convenience. Credit protection follows applicable law and remains subject to LGPD principles.

Consent is one basis, not a default or a cure. The controller must be able to prove a free, informed, unambiguous, purpose-specific choice; written consent must be prominent; generic authorizations are void; and withdrawal must be free and facilitated. Sensitive-data consent has the additional Article 11 requirement that it be specific, prominent, and for specific purposes.

A lawful basis does not make all subsequent use lawful. Apply purpose adequacy, necessity, transparency, security, data-subject rights, retention limits, and accountability. Data made manifestly public by the person does not remove the LGPD principles or rights, and a cross-border transfer still needs a separate Article 33 mechanism.

  • Owner: describe one sufficiently specific purpose, the affected people, the data and whether it is sensitive, the collection source, recipients, retention, and decision-maker.
  • Decision: record the exact Article 7 or 11 paragraph, each condition and supporting fact, why the data is necessary, and why a narrower alternative would not meet the purpose.
  • Implementation: align the notice, collection fields, access, sharing, retention, rights workflow, consent control where used, and international-transfer mechanism with the recorded decision.
  • Review: reassess before a new purpose, sensitive inference, new recipient, product or contract change, public-data reuse, automated decision, transfer, or material change to a consent choice.
Citations
What should teams do about Legal Bases under the Brazil LGPD?

What evidence should teams keep for Legal Bases under the Brazil LGPD?

Keep a purpose-level decision record, not one legal basis for an entire system or vendor. It should let a reviewer connect the real operation to the selected statutory paragraph, verify necessity and conditions, and confirm that notices, controls, retention, sharing, and rights handling match the decision.

  • Core record: purpose, data and people, ordinary or sensitive classification, collection source, Article 7 or 11 paragraph, necessity, recipients, retention, disclosures, rights route, owner, approval, and review trigger.
  • Consent evidence: the notice and version shown, affirmative action, purpose and data covered, time and channel, absence of preselection or improper conditioning, withdrawals, and operational suppression.
  • Non-consent evidence: the binding obligation, requested contract step, proceeding, health or life facts, public-policy mandate, research-body status, credit rule, or other facts that satisfy the chosen paragraph.
  • Legitimate interest evidence: the concrete interest, compatibility, necessity, less intrusive alternatives, data-subject impacts and expectations, safeguards, transparency, approval, and reassessment.
  • Keep earlier decisions and change history so a new purpose or materially changed consent does not erase the evidence for prior processing.
Citations
What should teams do about Legal Bases under the Brazil LGPD?

Which mistakes create risk when handling Legal Bases under the Brazil LGPD?

Do not choose a basis from convenience after collection. The facts and data category control the available basis: legitimate interest is not in Article 11, public data remains subject to purpose, good-faith, and public-interest limits, and consent cannot be stretched to a materially different purpose without new information and a valid choice where consent remains the basis.

  • Do not apply Article 7 legitimate interest to sensitive personal data or disguise a sensitive inference as an ordinary-data purpose.
  • Do not cite legal obligation without identifying the law or regulation, or contract necessity when the processing is optional or unrelated to a person-requested step.
  • Do not bundle unrelated purposes into one consent request, condition a service on unnecessary consent, or continue after withdrawal without documenting another basis that independently applies.
  • Do not treat data from public records, social media, or another controller as exempt from transparency, rights, security, necessity, and purpose limitations.
  • Do not confuse a processing basis with an Article 33 international-transfer mechanism, or use one basis to cover several materially different purposes.
Citations
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

Begin with an eligibility gate. Do not use this basis for sensitive personal data under Article 11. Identify whether the interest belongs to the controller or a third party, confirm that it is lawful, concrete, and linked to a specific purpose, and check whether another basis is more appropriate. A general aim such as improving business, security, or user experience is not specific enough without the actual operation and benefit.

ANPD's non-binding guide then uses three phases. Purpose asks whether the interest is legitimate and the purpose specific. Necessity asks whether the processing can achieve the purpose, whether every data item is strictly necessary, and whether a less intrusive effective alternative exists. Balancing and safeguards compare benefits with the nature of the data, source, relationship, context, legitimate expectations, affected people, likely effects, and the ability to prevent or reduce harm.

Examples remain fact-specific. Limited first-party audience measurement using aggregate results, no cross-service combination, no profiles, short retention, and clear opt-out may be easier to justify than third-party behavioral advertising. Fraud detection may support a concrete interest, but broad indefinite monitoring of every customer or worker still requires proof of necessity and proportionate controls.

Children and adolescents require special caution because Article 14 requires their best interests. Vulnerability, employment or platform power imbalances, systematic observation, profiling, unexpected secondary use, third-party data, denial of a service, or significant effects can shift the balance. Public authorities should not use legitimate interest merely to avoid the public-sector bases and duties that fit their statutory activity.

  • Purpose gate: identify the interest holder, concrete benefit, specific purpose, legality, data category, affected people, and why Article 7(IX) is appropriate.
  • Necessity gate: show the processing contributes to the purpose, remove unnecessary data and recipients, compare less intrusive means, and set the shortest justified retention.
  • Balance: document collection source, relationship, notice, customary context, vulnerable groups, legitimate expectations, benefits, probabilities, severity, and effects on rights and freedoms.
  • Controls and outcome: assign safeguards, explain the processing clearly, operate rights and objection routes, record the approver and conclusion, and stop or choose another basis if the balance fails.
  • Reassess after a new purpose, data source, profiling logic, recipient, population, technology, retention period, complaint pattern, incident, or evidence that a safeguard does not work.
Citations
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

What evidence should teams keep for Legitimate Interest Balancing under the Brazil LGPD?

Keep the completed assessment with evidence for each answer, not a checked box or conclusion alone. The record should connect the planned data flow to the purpose, alternatives, impacts, controls, implementation owners, approval, and review history; Article 10 also allows ANPD to require an impact report.

  • Inputs: controller and third-party interests, purpose, data and sources, people, systems, recipients, frequency, retention, and linked processing records.
  • Analysis: why the interest is lawful and specific, contribution to the purpose, necessity by data item, alternatives considered, expected benefits, legitimate expectations, and adverse effects.
  • Implementation: notices, minimization, access restrictions, pseudonymization, retention jobs, human review, opt-out or objection handling where relevant, monitoring, and accountable owners.
  • Decision: pass or fail, conditions, unresolved risk, reviewer, approver, decision date, launch gate, next review, and changes that invalidate the assessment.
  • Operation: complaints, objections, rights requests, incidents, metric drift, exceptions, control tests, and evidence that promised safeguards remain effective.
Citations
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?

Which mistakes create risk when handling Legitimate Interest Balancing under the Brazil LGPD?

Legitimate interest is not an Article 11 basis for sensitive data and is not established by a privacy notice, contract clause, common industry practice, or business convenience. Treat children, vulnerable groups, unexpected reuse, systematic monitoring, profiling, and significant effects as heightened cases and record why the balance still passes, if it does.

  • Do not begin balancing before confirming that the data is ordinary personal data and the interest is lawful, concrete, and specific.
  • Do not describe a desired outcome as proof of necessity; test data fields, recipients, frequency, retention, and effective alternatives separately.
  • Do not assume silence means acceptance or that a notice creates legitimate expectations for an otherwise surprising use.
  • Do not count promised controls that are absent from the product, contract, or operating procedure.
  • Do not proceed when rights and freedoms prevail, and do not reuse a passing test for a materially different purpose or population.
Citations
What should teams do about RIPD and DPIA under the Brazil LGPD?

What should teams do about RIPD and DPIA under the Brazil LGPD?

The controlling law is the LGPD. Article 38 lets ANPD require a controller to prepare an impact report, including for sensitive data, and specifies minimum content; Article 10(3) permits an ANPD request for legitimate-interest processing; and Article 32 addresses public-sector operations. The federal government's RIPD template is practical guidance for federal public bodies, not a regulation that changes those statutory triggers.

Use an intake screen before a new or materially changed activity. Identify the controller, operator and joint decision-makers, purpose, legal basis, people, data and sources, scale, technology, monitoring or profiling, decisions and effects, vulnerable groups, recipients, transfers, retention, security, and applicable ANPD or sector requirement.

Treat high-risk processing as a strong reason for a fuller assessment. Resolution 2/2022's specific small-agent test requires at least one general criterion, such as large scale or significant effects on fundamental interests and rights, plus at least one specific criterion, such as emerging technology, surveillance or control of publicly accessible areas, sensitive data, or data on children, adolescents, or older people. It is not a universal RIPD trigger for every controller.

The controller owns the document and final decision. The encarregado, legal and privacy teams, security, engineering, product, procurement, operators, and business owners can supply evidence. Complete the assessment early enough to change the design; then approve, reject, condition, or escalate the processing and assign every mitigation.

Describe inherent risks to people rather than limiting the assessment to corporate or cybersecurity risk. Evaluate likely harms, existing and planned controls, and residual risk. The LGPD does not prescribe one scoring matrix, so state the method, assumptions, likelihood and severity scales, evidence, risk owner, acceptance authority, and review trigger.

  • Trigger: record the ANPD request, legal or sector rule, high-risk screen, legitimate-interest link, public-sector requirement, or internal risk decision that led to the report.
  • Minimum statutory content: types of data collected, collection methodology, security methodology, and the controller's analysis of safeguards and risk-mitigation mechanisms.
  • Operational content: purposes and legal bases, necessity and proportionality, data flow and retention, people and vulnerabilities, transfers and recipients, risk scenarios, controls, residual risk, decisions, owners, deadlines, and evidence.
  • Outcome: do not launch until required conditions are assigned and accepted; stop, narrow, redesign, or seek further review when risk remains outside the controller's criteria.
  • Reassess after changes to purpose, data, source, people, technology, automated logic, scale, recipient, transfer, retention, threat, incident, complaint pattern, law, or ANPD direction.
Citations
What should teams do about RIPD and DPIA under the Brazil LGPD?

What evidence should teams keep for RIPD and DPIA under the Brazil LGPD?

Keep the approved report, its inputs, and proof that required controls were implemented. Preserve version history and the link to the processing record so a reviewer can reproduce the trigger, scope, risk judgments, decisions, owners, and later reassessments. Protect commercial and industrial secrets appropriately if ANPD requests submission.

  • Scope evidence: system and data-flow diagrams, roles, data inventory, people, purposes, legal bases, sources, recipients, transfers, retention, technology, scale, and interfaces.
  • Risk evidence: method and scales, scenarios affecting data subjects, assumptions, likelihood, severity, existing controls, test results, planned mitigation, residual risk, and dependencies.
  • Decision evidence: trigger, contributors, consultation, conditions, control owners and dates, acceptance or rejection, accountable approver, and launch decision.
  • Follow-through: tickets, contracts, architecture changes, notices, rights procedures, security tests, monitoring, incidents, complaints, exceptions, and closure evidence.
  • Submission record: ANPD request and deadline, report version supplied, protected-secret handling, correspondence, corrections, and any resulting measures.
Citations
What should teams do about RIPD and DPIA under the Brazil LGPD?

Which mistakes create risk when handling RIPD and DPIA under the Brazil LGPD?

Do not state that every processing activity has a universal statutory pre-launch RIPD duty. The LGPD gives ANPD express powers to require reports and states minimum content, while organizations often use pre-launch screening as accountable risk practice. Identify any ANPD request, public-sector, legitimate-interest, sector, contractual, or internal trigger and label guidance and internal policy accurately.

  • Do not copy a GDPR DPIA threshold, template, or conclusion into the LGPD without mapping the Brazilian scope, legal bases, actors, rights, and statutory content.
  • Do not treat the small-agent high-risk criteria as the only possible RIPD screen or as an automatic report duty for every organization.
  • Do not assess only risks to the company; describe effects on the civil liberties and fundamental rights of the people whose data is processed.
  • Do not send every report to ANPD or publish it automatically; retain it and disclose it when the LGPD, ANPD, or another applicable rule requires, with appropriate handling of protected secrets.
  • Do not close the report at approval. Verify mitigation, track residual risk, and reopen it when assumptions, controls, law, or the processing change.
Citations
What should teams do about Sanctions Methodology under the Brazil LGPD?

How should teams prepare for ANPD sanctions decisions under the Brazil LGPD?

The binding framework is LGPD Articles 52 and 53, ANPD's inspection and administrative-proceeding rules, and Resolution 4/2023. Sanctions follow an administrative proceeding with due process; an investigation, finding, or maximum statutory number is not itself a final sanction.

ANPD first performs an infringement classification. A medium infringement significantly affects fundamental interests and rights by impeding or limiting rights or access to services or by causing material or moral damage. A serious infringement meets that threshold plus at least one listed factor, including large scale, intent, risk to life or physical integrity, sensitive data or data on children, adolescents, or older people, absence of a legal basis, unlawful or discriminatory effects, systematic unlawful practice, or inspection obstruction. Other infringements are light.

Article 52 sanctions include a warning with a corrective deadline; simple or daily fine; public disclosure after confirmation and investigation; blocking or deletion of affected personal data; partial suspension of the database or processing activity; and partial or total prohibition of personal-data processing. Resolution 4 links the selection to gravity, nature and circumstances, data-subject rights, proportionality, recurrence, cooperation, governance, remediation, harm, advantage, good faith, and economic condition.

For a simple fine, calculate the base amount using the classification and the Resolution's applicable revenue method, then apply its aggravating and mitigating factors and the minimum and maximum limits. The LGPD ceiling for a private legal person is two percent of prior-year revenue in Brazil, excluding taxes, limited to R$50 million per infringement; it is a ceiling, not the starting point.

Build the record as soon as an ANPD inquiry or inspection begins. Preserve the alleged conduct and legal duties, chronology, processing and affected people, scale and harm, advantage sought or obtained, intent and good faith, recurrence, cooperation, governance, remediation, economic condition, and verified Brazilian revenue inputs.

  • Case scope: identify each alleged infringement, legal provision, conduct, responsible processing agent, duration, affected operation, procedural deadline, and disputed fact.
  • Classification: map the evidence to the light, medium, or serious criteria without assuming that data sensitivity or scale alone decides every case.
  • Sanction selection: compare warning, monetary and restrictive measures against the established facts, prior measures, effects on people, proportionality, and need to correct the processing.
  • Fine calculation: retain source financial statements, taxes excluded, Brazilian entity or group perimeter, prior-year period, classification parameters, adjustments, and cap check.
  • Response: assign counsel and evidence owners, preserve due-process objections, cooperate accurately, stop continuing violations, remediate harm, and prove each completed corrective action.
Citations
What should teams do about Sanctions Methodology under the Brazil LGPD?

What evidence should teams keep for Sanctions Methodology under the Brazil LGPD?

Keep a traceable case file that separates facts established in the proceeding from estimates, legal positions, and disputed points. Connect every classification criterion, adjustment, corrective action, and financial input to dated evidence and the version submitted to ANPD.

  • Proceeding: notices, service dates, access records, submissions, exhibits, hearing or inspection material, decisions, appeals, payment or compliance dates, and responsible counsel.
  • Conduct: data flows, roles, purposes and bases, records, notices, contracts, controls, logs, people and data, duration, scale, intent, benefits, incidents, complaints, and effects.
  • Adjustment factors: prior final cases, cooperation chronology, good-faith evidence, governance program, policies and training, risk reviews, audit results, voluntary cessation, remediation, and measures preventing recurrence.
  • Financial record: legal entity and economic-group perimeter, Brazilian gross revenue for the relevant prior year, excluded taxes, source statements, calculation workbook, assumptions, and independent verification.
  • Corrective record: each obligation, owner, deadline, implementation proof, effectiveness test, communication to affected people, and ANPD acceptance or follow-up.
Citations
What should teams do about Sanctions Methodology under the Brazil LGPD?

Which mistakes create risk when handling Sanctions Methodology under the Brazil LGPD?

The headline simple fine is not automatic. ANPD must apply the administrative framework to the proven facts, and non-monetary sanctions may be more consequential to operations. Civil damages, consumer remedies, criminal questions, contractual consequences, and sector-regulator action remain legally distinct and may proceed separately.

  • Do not present the maximum simple fine as the automatic, likely, or exclusive outcome of an infringement.
  • Do not skip classification or treat a serious factor as proof without first satisfying the medium-infringement threshold.
  • Do not calculate from unverified global revenue when the applicable rule uses the defined Brazilian revenue base, excluding taxes, subject to the statutory cap and Resolution methodology.
  • Do not claim cooperation, cessation, governance, or remediation without dated proof that meets the applicable adjustment conditions.
  • Do not confuse a preventive or inspection action with a final sanction, or ANPD administrative sanctions with civil and sector-specific liability.
Citations
What should teams do about Small Processing Agents under the Brazil LGPD?

What should teams do about Small Processing Agents under the Brazil LGPD?

Resolution 2/2022 covers qualifying microenterprises and small businesses under Complementary Law 123/2006, startups that meet Complementary Law 182/2021, and the other private legal persons, natural persons, or unincorporated private entities within its definition when they process personal data as controller or operator. Record the exact statutory category rather than relying on headcount or an informal small-company label.

The differentiated regime is unavailable when the agent performs high-risk processing, has gross revenue above the applicable small-business or startup ceiling, or belongs to an economic group whose global revenue exceeds the applicable ceiling. Determine the legal entity, relevant revenue period and evidence, group perimeter, and any special category condition. Do not divide one operation among related entities to manufacture eligibility.

Apply the risk test to every material activity. It is high risk only when at least one general criterion, large scale or significant effects on fundamental interests and rights, combines with at least one specific criterion: emerging or innovative technology; surveillance or control of publicly accessible areas; decisions based solely on automated processing, including profiling; or sensitive data or data on children, adolescents, or older people.

Where the agent qualifies, identify the exact flexibility used. Resolution 2 permits a simplified processing record and simplified security policy; it does not require appointment of an encarregado if another public communication channel is provided; and it doubles specified response, ANPD-request, and incident-communication periods. The incident period under Resolution 15/2024 is therefore generally six business days for a qualifying small agent unless a specific legal period or exception applies.

ANPD may require the ordinary duty after considering the nature and volume of the processing and risks to people. A high-risk agent generally loses the differentiated treatment but may still use the collective representation arrangement in Article 8 for negotiation, mediation, and conciliation of complaints.

  • Eligibility: retain formation documents, legal category, revenue period and statements, tax or startup evidence, economic-group structure and global revenue, controller or operator role, and approval.
  • Risk: screen each activity against both general criteria and all four specific criteria, with data volumes, people, geography, frequency, technology, monitoring, automated effects, and vulnerable-person evidence.
  • Adaptation: record the exact Resolution article used, owner, operational control, ordinary rule it changes, deadline calculation, exception, and review date.
  • Implementation: keep a current simplified processing record, proportionate technical and administrative security, a public data-subject channel, rights and incident procedures, contracts, training, and corrective-action evidence.
  • Reassessment: repeat after revenue growth, acquisition or group change, new technology, scale, profiling, sensitive data, vulnerable people, public-area monitoring, incident, ANPD request, or regulatory amendment.
Citations
What should teams do about Small Processing Agents under the Brazil LGPD?

What evidence should teams keep for Small Processing Agents under the Brazil LGPD?

Keep a dated eligibility file for the entity and a separate risk screen for each material processing activity. Link every claimed adaptation to the evidence, control, responsible person, deadline rule, and reassessment event; an entity-level conclusion alone cannot show that a later high-risk activity remains eligible.

  • Maintain a simplified processing record that identifies purposes, data and people, collection sources, sharing and transfers, retention, security, controller and operator roles, legal bases, and responsible owners.
  • If no encarregado is appointed under the flexibility, publish and operate another channel for data-subject communications and requests, with intake, identity verification, routing, response, and completion records.
  • Document proportionate technical and administrative security measures, including access control, backups, updates, endpoint and network protection, staff awareness, supplier terms, incident handling, and periodic review appropriate to the risks.
  • For an extended deadline, preserve the triggering request or incident, start date, ordinary deadline, Resolution 2 provision, doubled deadline, sector-specific exception check, response, filing receipt, and any delay explanation.
  • Keep ANPD directions requiring an ordinary duty, remediation owners and deadlines, evidence of completion, and the date eligibility was last reapproved.
Citations
What should teams do about Small Processing Agents under the Brazil LGPD?

Which mistakes create risk when handling Small Processing Agents under the Brazil LGPD?

Do not assume every small business qualifies or that one eligibility review covers every activity. Resolution 2/2022 grants only specified adaptations, its incident provision now operates with Resolution 15/2024, and ANPD may order a small agent to meet a duty that the regulation otherwise simplified or waived.

  • Do not apply the regime from headcount, nonprofit status, natural-person status, or an informal small-company label without the defined category and exclusion evidence.
  • Do not test high risk by counting criteria across unrelated activities or by checking only sensitive data; one general and one specific criterion must coexist in the assessed processing.
  • Do not treat the absence of an encarregado as permission to omit a public data-subject channel or the controller's accountability.
  • Do not use extended deadlines in administrative sanction proceedings or where a governing specific rule or ANPD direction requires the ordinary period.
  • Do not treat a simplified processing record or security policy as optional, static, or evidence that the underlying LGPD duties disappeared.
Citations
Page 2 of 2