What should teams do about RIPD and DPIA under the Brazil LGPD?
The controlling law is the LGPD. Article 38 lets ANPD require a controller to prepare an impact report, including for sensitive data, and specifies minimum content; Article 10(3) permits an ANPD request for legitimate-interest processing; and Article 32 addresses public-sector operations. The federal government's template is practical guidance for federal public bodies, not a regulation that changes those statutory triggers.
Use an intake screen before a new or materially changed activity. Identify the controller, operator and joint decision-makers, purpose, legal basis, people, data and sources, scale, technology, monitoring or profiling, decisions and effects, vulnerable groups, recipients, transfers, retention, security, and applicable ANPD or sector requirement.
Treat as a strong reason for a fuller assessment. Resolution 2/2022's specific small-agent test requires at least one general criterion, such as large scale or significant effects on fundamental interests and rights, plus at least one specific criterion, such as emerging technology, surveillance or control of publicly accessible areas, sensitive data, or data on children, adolescents, or older people. It is not a universal trigger for every controller.
The controller owns the document and final decision. The encarregado, legal and privacy teams, security, engineering, product, procurement, operators, and business owners can supply evidence. Complete the assessment early enough to change the design; then approve, reject, condition, or escalate the processing and assign every mitigation.
Describe inherent risks to people rather than limiting the assessment to corporate or cybersecurity risk. Evaluate likely harms, existing and planned controls, and . The LGPD does not prescribe one scoring matrix, so state the method, assumptions, likelihood and severity scales, evidence, risk owner, acceptance authority, and review trigger.
- Trigger: record the ANPD request, legal or sector rule, high-risk screen, legitimate-interest link, public-sector requirement, or internal risk decision that led to the report.
- Minimum statutory content: types of data collected, collection methodology, security methodology, and the controller's analysis of safeguards and risk-mitigation mechanisms.
- Operational content: purposes and legal bases, necessity and proportionality, data flow and retention, people and vulnerabilities, transfers and recipients, risk scenarios, controls, , decisions, owners, deadlines, and evidence.
- Outcome: do not launch until required conditions are assigned and accepted; stop, narrow, redesign, or seek further review when risk remains outside the controller's criteria.
- Reassess after changes to purpose, data, source, people, technology, automated logic, scale, recipient, transfer, retention, threat, incident, complaint pattern, law, or ANPD direction.
Primary LGPD source for RIPD/DPIA records, controller accountability, lawful basis, data-subject rights, security duties, and ANPD authority requests.
ANPD sanctions regulation source for enforcement exposure, corrective action, and compliance evidence planning.