Artifact GuideBrazilRIPD and DPIA

Brazil LGPD RIPD and DPIA

An RIPD is the controller's LGPD impact report. It describes the processing, the risks to data subjects, and the measures used to reduce those risks.

The ANPD may require an RIPD, including for processing based on legitimate interest. A Brazilian RIPD is not automatically the same document as a GDPR DPIA.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

An is the LGPD controller's impact report: it describes personal-data processing that may create risks to civil liberties and fundamental rights and the measures, safeguards, and mechanisms used to mitigate them. ANPD may require the report, including for legitimate-interest processing. Screen risk before launch, but distinguish this Brazilian statutory record from a GDPR DPIA and from any separate sector-specific assessment.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about RIPD and DPIA under the Brazil LGPD?

The controlling law is the LGPD. Article 38 lets ANPD require a controller to prepare an impact report, including for sensitive data, and specifies minimum content; Article 10(3) permits an ANPD request for legitimate-interest processing; and Article 32 addresses public-sector operations. The federal government's template is practical guidance for federal public bodies, not a regulation that changes those statutory triggers.

Use an intake screen before a new or materially changed activity. Identify the controller, operator and joint decision-makers, purpose, legal basis, people, data and sources, scale, technology, monitoring or profiling, decisions and effects, vulnerable groups, recipients, transfers, retention, security, and applicable ANPD or sector requirement.

Treat as a strong reason for a fuller assessment. Resolution 2/2022's specific small-agent test requires at least one general criterion, such as large scale or significant effects on fundamental interests and rights, plus at least one specific criterion, such as emerging technology, surveillance or control of publicly accessible areas, sensitive data, or data on children, adolescents, or older people. It is not a universal trigger for every controller.

The controller owns the document and final decision. The encarregado, legal and privacy teams, security, engineering, product, procurement, operators, and business owners can supply evidence. Complete the assessment early enough to change the design; then approve, reject, condition, or escalate the processing and assign every mitigation.

Describe inherent risks to people rather than limiting the assessment to corporate or cybersecurity risk. Evaluate likely harms, existing and planned controls, and . The LGPD does not prescribe one scoring matrix, so state the method, assumptions, likelihood and severity scales, evidence, risk owner, acceptance authority, and review trigger.

  • Trigger: record the ANPD request, legal or sector rule, high-risk screen, legitimate-interest link, public-sector requirement, or internal risk decision that led to the report.
  • Minimum statutory content: types of data collected, collection methodology, security methodology, and the controller's analysis of safeguards and risk-mitigation mechanisms.
  • Operational content: purposes and legal bases, necessity and proportionality, data flow and retention, people and vulnerabilities, transfers and recipients, risk scenarios, controls, , decisions, owners, deadlines, and evidence.
  • Outcome: do not launch until required conditions are assigned and accepted; stop, narrow, redesign, or seek further review when risk remains outside the controller's criteria.
  • Reassess after changes to purpose, data, source, people, technology, automated logic, scale, recipient, transfer, retention, threat, incident, complaint pattern, law, or ANPD direction.
Citations
Question 2

What evidence should teams keep for RIPD and DPIA under the Brazil LGPD?

Keep the approved report, its inputs, and proof that required controls were implemented. Preserve version history and the link to the processing record so a reviewer can reproduce the trigger, scope, risk judgments, decisions, owners, and later reassessments. Protect commercial and industrial secrets appropriately if ANPD requests submission.

  • Scope evidence: system and data-flow diagrams, roles, data inventory, people, purposes, legal bases, sources, recipients, transfers, retention, technology, scale, and interfaces.
  • Risk evidence: method and scales, scenarios affecting data subjects, assumptions, likelihood, severity, existing controls, test results, planned mitigation, , and dependencies.
  • Decision evidence: trigger, contributors, consultation, conditions, control owners and dates, acceptance or rejection, accountable approver, and launch decision.
  • Follow-through: tickets, contracts, architecture changes, notices, rights procedures, security tests, monitoring, incidents, complaints, exceptions, and closure evidence.
  • Submission record: ANPD request and deadline, report version supplied, protected-secret handling, correspondence, corrections, and any resulting measures.
Citations
Question 3

Which mistakes create risk when handling RIPD and DPIA under the Brazil LGPD?

Do not state that every processing activity has a universal statutory pre-launch duty. The LGPD gives ANPD express powers to require reports and states minimum content, while organizations often use pre-launch screening as accountable risk practice. Identify any ANPD request, public-sector, legitimate-interest, sector, contractual, or internal trigger and label guidance and internal policy accurately.

  • Do not copy a GDPR DPIA threshold, template, or conclusion into the LGPD without mapping the Brazilian scope, legal bases, actors, rights, and statutory content.
  • Do not treat the small-agent high-risk criteria as the only possible screen or as an automatic report duty for every organization.
  • Do not assess only risks to the company; describe effects on the civil liberties and fundamental rights of the people whose data is processed.
  • Do not send every report to ANPD or publish it automatically; retain it and disclose it when the LGPD, ANPD, or another applicable rule requires, with appropriate handling of protected secrets.
  • Do not close the report at approval. Verify mitigation, track , and reopen it when assumptions, controls, law, or the processing change.
Citations
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Primary LGPD source for RIPD/DPIA records, controller accountability, lawful basis, data-subject rights, security duties, and ANPD authority requests.
"relatório de impacto à proteção de dados pessoais: documentação do controlador"
gov.br
Referenced sections
  • ANPD small-agent regulation source for high-risk treatment evaluation, simplified records, security measures, and evidence expectations.
"auxiliar os agentes de tratamento de pequeno porte na avaliação do tratamento de alto risco"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.