Artifact GuideBrazilSmall Processing Agents

Brazil LGPD Small Processing Agents

Resolution 2/2022 gives qualifying small processing agents limited procedural simplifications; it does not exempt them from the LGPD.

Confirm entity status and high-risk processing before using simplified records, DPO alternatives, or extended deadlines.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A may use only the specific adaptations in ANPD Resolution 2/2022. Confirm the entity category, applicable revenue and economic-group limits, and each activity's two-part high-risk test before relying on simplified records, the encarregado waiver, simplified security policy, or extended deadlines. Qualification changes procedure; it does not remove LGPD legal bases, principles, rights, security, incident response, or accountability.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Small Processing Agents under the Brazil LGPD?

Resolution 2/2022 covers qualifying microenterprises and small businesses under Complementary Law 123/2006, startups that meet Complementary Law 182/2021, and the other private legal persons, natural persons, or unincorporated private entities within its definition when they process personal data as controller or operator. Record the exact statutory category rather than relying on headcount or an informal small-company label.

The differentiated regime is unavailable when the agent performs , has gross revenue above the applicable small-business or startup ceiling, or belongs to an economic group whose global revenue exceeds the applicable ceiling. Determine the legal entity, relevant revenue period and evidence, group perimeter, and any special category condition. Do not divide one operation among related entities to manufacture eligibility.

Apply the risk test to every material activity. It is high risk only when at least one general criterion, large scale or significant effects on fundamental interests and rights, combines with at least one specific criterion: emerging or innovative technology; surveillance or control of publicly accessible areas; decisions based solely on automated processing, including profiling; or sensitive data or data on children, adolescents, or older people.

Where the agent qualifies, identify the exact flexibility used. Resolution 2 permits a and simplified security policy; it does not require appointment of an encarregado if another public communication channel is provided; and it doubles specified response, ANPD-request, and incident-communication periods. The incident period under Resolution 15/2024 is therefore generally six business days for a qualifying small agent unless a specific legal period or exception applies.

ANPD may require the ordinary duty after considering the nature and volume of the processing and risks to people. A high-risk agent generally loses the differentiated treatment but may still use the collective representation arrangement in Article 8 for negotiation, mediation, and conciliation of complaints.

  • Eligibility: retain formation documents, legal category, revenue period and statements, tax or startup evidence, economic-group structure and global revenue, controller or operator role, and approval.
  • Risk: screen each activity against both general criteria and all four specific criteria, with data volumes, people, geography, frequency, technology, monitoring, automated effects, and vulnerable-person evidence.
  • Adaptation: record the exact Resolution article used, owner, operational control, ordinary rule it changes, deadline calculation, exception, and review date.
  • Implementation: keep a current , proportionate technical and administrative security, a public data-subject channel, rights and incident procedures, contracts, training, and corrective-action evidence.
  • Reassessment: repeat after revenue growth, acquisition or group change, new technology, scale, profiling, sensitive data, vulnerable people, public-area monitoring, incident, ANPD request, or regulatory amendment.
Citations
Question 2

What evidence should teams keep for Small Processing Agents under the Brazil LGPD?

Keep a dated eligibility file for the entity and a separate risk screen for each material processing activity. Link every claimed adaptation to the evidence, control, responsible person, deadline rule, and reassessment event; an entity-level conclusion alone cannot show that a later high-risk activity remains eligible.

  • Maintain a that identifies purposes, data and people, collection sources, sharing and transfers, retention, security, controller and operator roles, legal bases, and responsible owners.
  • If no encarregado is appointed under the flexibility, publish and operate another channel for data-subject communications and requests, with intake, identity verification, routing, response, and completion records.
  • Document proportionate technical and administrative security measures, including access control, backups, updates, endpoint and network protection, staff awareness, supplier terms, incident handling, and periodic review appropriate to the risks.
  • For an extended deadline, preserve the triggering request or incident, start date, ordinary deadline, Resolution 2 provision, doubled deadline, sector-specific exception check, response, filing receipt, and any delay explanation.
  • Keep ANPD directions requiring an ordinary duty, remediation owners and deadlines, evidence of completion, and the date eligibility was last reapproved.
Citations
Question 3

Which mistakes create risk when handling Small Processing Agents under the Brazil LGPD?

Do not assume every small business qualifies or that one eligibility review covers every activity. Resolution 2/2022 grants only specified adaptations, its incident provision now operates with Resolution 15/2024, and ANPD may order a small agent to meet a duty that the regulation otherwise simplified or waived.

  • Do not apply the regime from headcount, nonprofit status, natural-person status, or an informal small-company label without the defined category and exclusion evidence.
  • Do not test high risk by counting criteria across unrelated activities or by checking only sensitive data; one general and one specific criterion must coexist in the assessed processing.
  • Do not treat the absence of an encarregado as permission to omit a public data-subject channel or the controller's accountability.
  • Do not use extended deadlines in administrative sanction proceedings or where a governing specific rule or ANPD direction requires the ordinary period.
  • Do not treat a or security policy as optional, static, or evidence that the underlying LGPD duties disappeared.
Citations
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Official LGPD authority provision supporting ANPD rules for differentiated treatment of small processing agents.
"editar normas, orientações e procedimentos simplificados e diferenciados, inclusive quanto aos prazos"
gov.br
Referenced sections
  • ANPD inspection regulation used to connect cited decisions to preventive, monitoring, and enforcement review records.
"atuação baseada, preferencialmente, na construção conjunta e dialogada de soluções"
gov.br
Referenced sections
  • ANPD small-processing-agent regulation used to identify which organizations qualify and which LGPD adaptations apply.
"agentes de tratamento de pequeno porte: microempresas, empresas de pequeno porte, startups"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.