LGPD and CCPA can apply to the same data flow, but they regulate different actors and use different compliance models. Test each law separately before reusing notices, request workflows, contracts, or incident controls.
Use the comparison to decide whether each law applies, which rights and deadlines control, and where one shared privacy process needs a Brazil- or California-specific branch.
is a general Brazilian data-protection law: covered processing needs a legal basis, and the law assigns duties to controllers and operators. regulates qualifying businesses doing business in California and centers on disclosure, access, deletion, correction, sale or sharing opt-outs, limits on certain sensitive-personal-information uses, and non-discrimination. Neither law substitutes for the other. A company serving people in Brazil and California may need both workstreams.
Side-by-side comparison
LGPD vs CCPA: practical compliance comparison
Read each row against the same processing activity. The implication column states what the implementation record should decide or preserve.
Brazil's general data-protection law applies through Article 3 connections to Brazil and regulates processing through principles, legal bases, data-subject rights, controller and operator duties, security, and transfer rules.
Second framework
CCPA
California's law applies to qualifying businesses and focuses on notice, consumer rights, sale and sharing choices, sensitive-personal-information limits, contracting, and purpose-based restrictions.
can apply to public or private legal entities and natural persons processing personal data when an Article 3 connection to Brazil exists, regardless of where the organization is headquartered or the data is stored. Article 4 then removes specified activities from scope.
regulates a for-profit business doing business in California that determines processing purposes and means and meets a threshold: more than $26,625,000 in preceding-year gross revenue, 100,000 consumers or households whose personal information it annually buys, sells, or shares, or at least 50% of annual revenue from selling or sharing. Statutory extensions and exemptions still need separate review.
Record a Brazil nexus and a California business-threshold finding for each entity. A company may be subject to one law, both, or neither for the activity under review.
The controller makes decisions about personal-data processing; the operator processes personal data on the controller's behalf and according to its instructions. The controller generally designates an encarregado, subject to ANPD rules and exemptions.
A business determines processing purposes and means. A service provider or contractor processes personal information under statutory contract restrictions; a recipient that does not meet those conditions may be a third party, and the disclosure may be a sale or sharing event.
Classify each relationship under each law from actual decision rights, instructions, contracts, and permitted uses. Controller does not always equal business, and operator does not always equal service provider.
Each purpose needs an Article 7 legal basis for personal data or an Article 11 condition for sensitive personal data. Consent is one option, not the default for every activity. The Article 6 principles also apply.
does not use an -style list of legal bases for all processing. A business must disclose its purposes and keep collection, use, retention, and sharing reasonably necessary and proportionate to disclosed compatible purposes; particular activities can trigger opt-out, limit, or consent rules.
Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that deadline.
consumers may request access or know, deletion, and correction, subject to verification and statutory exceptions. A business generally has 45 days to respond and may take one additional 45-day extension when reasonably necessary if it gives notice within the first period. Opt-out requests use different handling rules.
A shared portal needs separate request types, verification logic, exceptions, clocks, response content, and escalation paths. Do not apply 15 days to every right or 45 days to every choice.
has no -equivalent sale or cross-context behavioral-advertising opt-out category. A disclosure or advertising use must instead satisfy the applicable legal basis, purpose, transparency, necessity, rights, and controller-operator rules. Sensitive personal data follows Article 11.
A consumer can direct a business to stop selling or sharing personal information. Sharing covers disclosure for even without payment. Separate rules allow limits on specified uses and disclosures of sensitive personal information; statutory exceptions and permitted purposes matter.
Do not relabel a opt-out as consent withdrawal. Map the flow once, then implement the distinct legal basis, notice, signal, link, and downstream-notification duties.
Keep processing records, purpose and legal-basis decisions, privacy information, rights responses, controller-operator instructions, security evidence, incident records, and transfer documentation. The ANPD may require a data-protection impact report in the circumstances stated by the LGPD; it is not automatic for every activity labeled high risk.
Keep notices at collection and privacy policies, request records, opt-out signal handling, sale or sharing records, and contracts with required service-provider, contractor, or third-party terms. Additional 2026 risk-assessment and cybersecurity-audit rules apply only when their triggers and phased deadlines are met.
Reuse an inventory or vendor record only when it contains the fields and approvals required by both laws. Preserve law-specific notices, contract language, and conclusions as linked evidence.
agents must adopt technical and administrative security measures. A controller must notify the ANPD and affected data subjects of an incident that may cause relevant risk or damage; Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation. International transfers also need an Article 33 mechanism.
requires reasonable security in the contexts stated by the statute and gives consumers a limited private action for specified unauthorized access and exfiltration, theft, or disclosure resulting from a failure to maintain reasonable security. CCPA does not impose an -style transfer mechanism merely because data leaves California.
Maintain separate breach and transfer decision trees. The same incident may also trigger other Brazilian, California, US federal, contractual, or sector-specific notification laws that this comparison does not determine.
The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.
The California Privacy Protection Agency and Attorney General have statutory enforcement authority. The consumer private action is narrower: section 1798.150 confines it to specified security breaches and says it is not based on violations of other sections.
Track regulator, legal basis, affected people, remedy, procedure, and evidence separately. Do not describe every violation as privately actionable or every issue as exclusively administrative.
Run the workstream when Article 3 applies: document the processing purpose, Article 7 or 11 basis, controller and operator roles, transparency, rights, security, and any transfer mechanism.
Run the workstream when the entity meets the business definition: document notices, requests, sale or sharing and sensitive-data choices, contract status, purpose restrictions, and applicable 2026 regulatory triggers.
Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.
can apply to public or private legal entities and natural persons processing personal data when an Article 3 connection to Brazil exists, regardless of where the organization is headquartered or the data is stored. Article 4 then removes specified activities from scope.
regulates a for-profit business doing business in California that determines processing purposes and means and meets a threshold: more than $26,625,000 in preceding-year gross revenue, 100,000 consumers or households whose personal information it annually buys, sells, or shares, or at least 50% of annual revenue from selling or sharing. Statutory extensions and exemptions still need separate review.
Record a Brazil nexus and a California business-threshold finding for each entity. A company may be subject to one law, both, or neither for the activity under review.
The controller makes decisions about personal-data processing; the operator processes personal data on the controller's behalf and according to its instructions. The controller generally designates an encarregado, subject to ANPD rules and exemptions.
A business determines processing purposes and means. A service provider or contractor processes personal information under statutory contract restrictions; a recipient that does not meet those conditions may be a third party, and the disclosure may be a sale or sharing event.
Classify each relationship under each law from actual decision rights, instructions, contracts, and permitted uses. Controller does not always equal business, and operator does not always equal service provider.
Each purpose needs an Article 7 legal basis for personal data or an Article 11 condition for sensitive personal data. Consent is one option, not the default for every activity. The Article 6 principles also apply.
does not use an -style list of legal bases for all processing. A business must disclose its purposes and keep collection, use, retention, and sharing reasonably necessary and proportionate to disclosed compatible purposes; particular activities can trigger opt-out, limit, or consent rules.
Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that deadline.
consumers may request access or know, deletion, and correction, subject to verification and statutory exceptions. A business generally has 45 days to respond and may take one additional 45-day extension when reasonably necessary if it gives notice within the first period. Opt-out requests use different handling rules.
A shared portal needs separate request types, verification logic, exceptions, clocks, response content, and escalation paths. Do not apply 15 days to every right or 45 days to every choice.
has no -equivalent sale or cross-context behavioral-advertising opt-out category. A disclosure or advertising use must instead satisfy the applicable legal basis, purpose, transparency, necessity, rights, and controller-operator rules. Sensitive personal data follows Article 11.
A consumer can direct a business to stop selling or sharing personal information. Sharing covers disclosure for even without payment. Separate rules allow limits on specified uses and disclosures of sensitive personal information; statutory exceptions and permitted purposes matter.
Do not relabel a opt-out as consent withdrawal. Map the flow once, then implement the distinct legal basis, notice, signal, link, and downstream-notification duties.
Keep processing records, purpose and legal-basis decisions, privacy information, rights responses, controller-operator instructions, security evidence, incident records, and transfer documentation. The ANPD may require a data-protection impact report in the circumstances stated by the LGPD; it is not automatic for every activity labeled high risk.
Keep notices at collection and privacy policies, request records, opt-out signal handling, sale or sharing records, and contracts with required service-provider, contractor, or third-party terms. Additional 2026 risk-assessment and cybersecurity-audit rules apply only when their triggers and phased deadlines are met.
Reuse an inventory or vendor record only when it contains the fields and approvals required by both laws. Preserve law-specific notices, contract language, and conclusions as linked evidence.
agents must adopt technical and administrative security measures. A controller must notify the ANPD and affected data subjects of an incident that may cause relevant risk or damage; Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation. International transfers also need an Article 33 mechanism.
requires reasonable security in the contexts stated by the statute and gives consumers a limited private action for specified unauthorized access and exfiltration, theft, or disclosure resulting from a failure to maintain reasonable security. CCPA does not impose an -style transfer mechanism merely because data leaves California.
Maintain separate breach and transfer decision trees. The same incident may also trigger other Brazilian, California, US federal, contractual, or sector-specific notification laws that this comparison does not determine.
The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.
The California Privacy Protection Agency and Attorney General have statutory enforcement authority. The consumer private action is narrower: section 1798.150 confines it to specified security breaches and says it is not based on violations of other sections.
Track regulator, legal basis, affected people, remedy, procedure, and evidence separately. Do not describe every violation as privately actionable or every issue as exclusively administrative.
Run the workstream when Article 3 applies: document the processing purpose, Article 7 or 11 basis, controller and operator roles, transparency, rights, security, and any transfer mechanism.
Run the workstream when the entity meets the business definition: document notices, requests, sale or sharing and sensitive-data choices, contract status, purpose restrictions, and applicable 2026 regulatory triggers.
Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.
Decide scope first for each legal entity and processing activity; save the facts and the cited conclusion.
Map roles, purposes, data categories, recipients, advertising uses, rights, transfers, and incidents to the relevant row.
Reuse shared systems only after documenting the law-specific branch for legal basis, notice, request timing, opt-out handling, contracts, transfers, and enforcement.
Escalate fact-specific questions about exemptions, controlled entities, sectoral laws, minors, sensitive data, ad-tech flows, incidents, or remedies to qualified counsel.
applies when personal-data processing takes place in Brazil, targets the offer or supply of goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Article 4 excludes specified activities, including processing by a natural person for exclusively private non-economic purposes and certain journalistic, artistic, public-security, national-defense, state-security, and criminal-investigation activities.
applies to a for-profit legal entity that does business in California, determines the purposes and means of processing California consumers' personal information, and meets a statutory threshold. A consumer is a California resident as defined by the statute and regulations, not every visitor to a California-facing site. Effective January 1, 2025, the adjusted gross-revenue threshold is more than $26,625,000 in the preceding calendar year. The alternatives remain buying, selling, or sharing personal information of 100,000 or more consumers or households annually, or deriving at least 50% of annual revenue from selling or sharing consumers' personal information.
For example, a Brazilian retailer may fall within because it processes data in Brazil without meeting any threshold. A qualifying California business may fall within CCPA for California residents yet have no Article 3 connection to Brazil. A multinational can meet both tests for one customer journey, but a shared database does not merge the legal conclusions.
Map the same entity, people, collection points, purposes, systems, and disclosures under both laws.
For , record the Article 3 connection to Brazil and any Article 4 exclusion. For , record for-profit status, California activity, the applicable threshold, and any data-level exemption.
Treat exemptions carefully. Several provisions exclude specified information processed under sectoral laws, such as GLBA-covered information; they do not necessarily exempt the entire organization or every dataset.
If both laws apply, keep one shared inventory but write separate legal conclusions for the Brazilian and California processing.
Build shared operations, then preserve law-specific branches
Privacy or legal should own the comparison, while product, marketing, data, security, procurement, and customer-support owners supply the facts and operate the controls. One request portal or data inventory can support both laws, but its routing must preserve each law's identity checks, exceptions, deadlines, disclosures, and complaint path.
For each row, retain the source provision, relevant facts, conclusion, accountable owner, implementation evidence, and next review trigger. Reassess after a new market, purpose, data category, advertising use, vendor, transfer destination, or security incident changes the facts.
Record controller and operator roles separately from business, service-provider, contractor, and third-party status.
Link each processing purpose to its Article 7 or 11 basis; do not invent a general consent requirement where California law instead requires notice, opt-out, limitation, or a specific form of consent.
Test whether an advertising disclosure is a sale or sharing event even if no money changes hands; run the separate legal-basis and transparency analysis for the same disclosure.
Keep dated request logs, notices, contracts, opt-out signals, legal-basis records, incident assessments, transfer mechanisms, and decision approvals.
Document the Brazil and California scope findings first, then assign rights, notice, contract, transfer, and incident gaps to their operational owners.