Artifact GuideBrazil and CaliforniaLGPD vs CCPA

LGPD vs CCPA What privacy teams must separate

LGPD and CCPA can apply to the same data flow, but they regulate different actors and use different compliance models. Test each law separately before reusing notices, request workflows, contracts, or incident controls.

Use the comparison to decide whether each law applies, which rights and deadlines control, and where one shared privacy process needs a Brazil- or California-specific branch.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

is a general Brazilian data-protection law: covered processing needs a legal basis, and the law assigns duties to controllers and operators. regulates qualifying businesses doing business in California and centers on disclosure, access, deletion, correction, sale or sharing opt-outs, limits on certain sensitive-personal-information uses, and non-discrimination. Neither law substitutes for the other. A company serving people in Brazil and California may need both workstreams.

Side-by-side comparison

LGPD vs CCPA: practical compliance comparison

Read each row against the same processing activity. The implication column states what the implementation record should decide or preserve.

Review all sources
First framework
LGPD

Brazil's general data-protection law applies through Article 3 connections to Brazil and regulates processing through principles, legal bases, data-subject rights, controller and operator duties, security, and transfer rules.

Second framework
CCPA

California's law applies to qualifying businesses and focuses on notice, consumer rights, sale and sharing choices, sensitive-personal-information limits, contracting, and purpose-based restrictions.

Comparison row 1

Scope and covered activity

LGPD

can apply to public or private legal entities and natural persons processing personal data when an Article 3 connection to Brazil exists, regardless of where the organization is headquartered or the data is stored. Article 4 then removes specified activities from scope.

CCPA

regulates a for-profit business doing business in California that determines processing purposes and means and meets a threshold: more than $26,625,000 in preceding-year gross revenue, 100,000 consumers or households whose personal information it annually buys, sells, or shares, or at least 50% of annual revenue from selling or sharing. Statutory extensions and exemptions still need separate review.

Operational implication

Record a Brazil nexus and a California business-threshold finding for each entity. A company may be subject to one law, both, or neither for the activity under review.

Comparison row 2

Who must act

LGPD

The controller makes decisions about personal-data processing; the operator processes personal data on the controller's behalf and according to its instructions. The controller generally designates an encarregado, subject to ANPD rules and exemptions.

CCPA

A business determines processing purposes and means. A service provider or contractor processes personal information under statutory contract restrictions; a recipient that does not meet those conditions may be a third party, and the disclosure may be a sale or sharing event.

Operational implication

Classify each relationship under each law from actual decision rights, instructions, contracts, and permitted uses. Controller does not always equal business, and operator does not always equal service provider.

Comparison row 3

Basis for collecting and using data

LGPD

Each purpose needs an Article 7 legal basis for personal data or an Article 11 condition for sensitive personal data. Consent is one option, not the default for every activity. The Article 6 principles also apply.

CCPA

does not use an -style list of legal bases for all processing. A business must disclose its purposes and keep collection, use, retention, and sharing reasonably necessary and proportionate to disclosed compatible purposes; particular activities can trigger opt-out, limit, or consent rules.

Operational implication

Keep an basis assessment and a separate purpose-and-choice assessment. A valid result under one test does not answer the other.

Comparison row 4

Individual rights and response periods

LGPD

Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that deadline.

CCPA

consumers may request access or know, deletion, and correction, subject to verification and statutory exceptions. A business generally has 45 days to respond and may take one additional 45-day extension when reasonably necessary if it gives notice within the first period. Opt-out requests use different handling rules.

Operational implication

A shared portal needs separate request types, verification logic, exceptions, clocks, response content, and escalation paths. Do not apply 15 days to every right or 45 days to every choice.

Comparison row 5

Sale, sharing, and sensitive data

LGPD

has no -equivalent sale or cross-context behavioral-advertising opt-out category. A disclosure or advertising use must instead satisfy the applicable legal basis, purpose, transparency, necessity, rights, and controller-operator rules. Sensitive personal data follows Article 11.

CCPA

A consumer can direct a business to stop selling or sharing personal information. Sharing covers disclosure for even without payment. Separate rules allow limits on specified uses and disclosures of sensitive personal information; statutory exceptions and permitted purposes matter.

Operational implication

Do not relabel a opt-out as consent withdrawal. Map the flow once, then implement the distinct legal basis, notice, signal, link, and downstream-notification duties.

Comparison row 6

Notices, contracts, and records

LGPD

Keep processing records, purpose and legal-basis decisions, privacy information, rights responses, controller-operator instructions, security evidence, incident records, and transfer documentation. The ANPD may require a data-protection impact report in the circumstances stated by the LGPD; it is not automatic for every activity labeled high risk.

CCPA

Keep notices at collection and privacy policies, request records, opt-out signal handling, sale or sharing records, and contracts with required service-provider, contractor, or third-party terms. Additional 2026 risk-assessment and cybersecurity-audit rules apply only when their triggers and phased deadlines are met.

Operational implication

Reuse an inventory or vendor record only when it contains the fields and approvals required by both laws. Preserve law-specific notices, contract language, and conclusions as linked evidence.

Comparison row 7

Security, incidents, and international transfers

LGPD

agents must adopt technical and administrative security measures. A controller must notify the ANPD and affected data subjects of an incident that may cause relevant risk or damage; Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation. International transfers also need an Article 33 mechanism.

CCPA

requires reasonable security in the contexts stated by the statute and gives consumers a limited private action for specified unauthorized access and exfiltration, theft, or disclosure resulting from a failure to maintain reasonable security. CCPA does not impose an -style transfer mechanism merely because data leaves California.

Operational implication

Maintain separate breach and transfer decision trees. The same incident may also trigger other Brazilian, California, US federal, contractual, or sector-specific notification laws that this comparison does not determine.

Comparison row 8

Enforcement and liability

LGPD

The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.

CCPA

The California Privacy Protection Agency and Attorney General have statutory enforcement authority. The consumer private action is narrower: section 1798.150 confines it to specified security breaches and says it is not based on violations of other sections.

Operational implication

Track regulator, legal basis, affected people, remedy, procedure, and evidence separately. Do not describe every violation as privately actionable or every issue as exclusively administrative.

Comparison row 9

Practical decision rule

LGPD

Run the workstream when Article 3 applies: document the processing purpose, Article 7 or 11 basis, controller and operator roles, transparency, rights, security, and any transfer mechanism.

CCPA

Run the workstream when the entity meets the business definition: document notices, requests, sale or sharing and sensitive-data choices, contract status, purpose restrictions, and applicable 2026 regulatory triggers.

Operational implication

Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.

Practical decision rule

How to use this comparison

  • Decide scope first for each legal entity and processing activity; save the facts and the cited conclusion.
  • Map roles, purposes, data categories, recipients, advertising uses, rights, transfers, and incidents to the relevant row.
  • Reuse shared systems only after documenting the law-specific branch for legal basis, notice, request timing, opt-out handling, contracts, transfers, and enforcement.
  • Escalate fact-specific questions about exemptions, controlled entities, sectoral laws, minors, sensitive data, ad-tech flows, incidents, or remedies to qualified counsel.
Section 1

Start with two independent scope tests

applies when personal-data processing takes place in Brazil, targets the offer or supply of goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Article 4 excludes specified activities, including processing by a natural person for exclusively private non-economic purposes and certain journalistic, artistic, public-security, national-defense, state-security, and criminal-investigation activities.

applies to a for-profit legal entity that does business in California, determines the purposes and means of processing California consumers' personal information, and meets a statutory threshold. A consumer is a California resident as defined by the statute and regulations, not every visitor to a California-facing site. Effective January 1, 2025, the adjusted gross-revenue threshold is more than $26,625,000 in the preceding calendar year. The alternatives remain buying, selling, or sharing personal information of 100,000 or more consumers or households annually, or deriving at least 50% of annual revenue from selling or sharing consumers' personal information.

For example, a Brazilian retailer may fall within because it processes data in Brazil without meeting any threshold. A qualifying California business may fall within CCPA for California residents yet have no Article 3 connection to Brazil. A multinational can meet both tests for one customer journey, but a shared database does not merge the legal conclusions.

  • Map the same entity, people, collection points, purposes, systems, and disclosures under both laws.
  • For , record the Article 3 connection to Brazil and any Article 4 exclusion. For , record for-profit status, California activity, the applicable threshold, and any data-level exemption.
  • Treat exemptions carefully. Several provisions exclude specified information processed under sectoral laws, such as GLBA-covered information; they do not necessarily exempt the entire organization or every dataset.
  • If both laws apply, keep one shared inventory but write separate legal conclusions for the Brazilian and California processing.
Section 2

Build shared operations, then preserve law-specific branches

Privacy or legal should own the comparison, while product, marketing, data, security, procurement, and customer-support owners supply the facts and operate the controls. One request portal or data inventory can support both laws, but its routing must preserve each law's identity checks, exceptions, deadlines, disclosures, and complaint path.

For each row, retain the source provision, relevant facts, conclusion, accountable owner, implementation evidence, and next review trigger. Reassess after a new market, purpose, data category, advertising use, vendor, transfer destination, or security incident changes the facts.

  • Record controller and operator roles separately from business, service-provider, contractor, and third-party status.
  • Link each processing purpose to its Article 7 or 11 basis; do not invent a general consent requirement where California law instead requires notice, opt-out, limitation, or a specific form of consent.
  • Test whether an advertising disclosure is a sale or sharing event even if no money changes hands; run the separate legal-basis and transparency analysis for the same disclosure.
  • Keep dated request logs, notices, contracts, opt-out signals, legal-basis records, incident assessments, transfer mechanisms, and decision approvals.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • The cited California provisions establish the CCPA-specific tests summarized in the comparison.
"A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers"
cppa.ca.gov
Referenced sections
  • Official source for the regulations effective January 1, 2026 and their trigger-specific obligations and phased dates.
planalto.gov.br
Referenced sections
  • Supports the comparison decision rule.
"Esta Lei aplica-se a qualquer operação de tratamento realizada por pessoa natural ou por pessoa jurídica de direito público ou privado"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.