Artifact GuideBrazil and European UnionLGPD vs GDPR
LGPD vs GDPR What privacy teams must separate
LGPD and GDPR share many privacy concepts, but their territorial tests, legal grounds, roles, deadlines, impact-assessment triggers, incident rules, transfer mechanisms, and sanctions are not interchangeable.
Use one processing inventory, then record a separate Brazil and EU conclusion for every rule that changes the owner, deadline, evidence, or outcome.
and programmes can share inventories, privacy notices, rights tooling, vendor governance, security controls, and assessment methods. They cannot share legal conclusions by default. LGPD applies through its Brazil-focused Article 3 tests; GDPR applies through EU establishment, offering, or monitoring tests. Each law also has its own legal grounds, role definitions, request periods, incident thresholds, transfer mechanisms, and enforcement system.
Side-by-side comparison
LGPD vs GDPR: practical compliance comparison
Read each row against the same processing activity. The implication column states what the implementation record should decide or preserve.
Brazil's law applies through Article 3 connections to Brazil and regulates processing through principles, legal bases, rights, controller and operator duties, security, and transfer rules.
Second framework
GDPR
The EU regulation applies through establishment, offering, or monitoring tests and imposes its own controller, processor, accountability, rights, security, transfer, and supervisory-authority rules.
applies when processing takes place in Brazil, targets the offer or supply of goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Article 4 then excludes specified activities.
applies to processing in the context of an EU establishment. It can also apply to an organization outside the EU when processing relates to offering goods or services to or monitoring people in the Union. Article 2 contains material-scope exclusions.
Write separate territorial and material-scope findings. A Brazil collection or location link is not the same as an EU establishment, offering, or monitoring link.
The controller makes decisions about personal-data processing; the operator processes according to the controller's instructions. Article 41 addresses the encarregado, while ANPD rules can provide exemptions or further conditions.
distinguishes controller, joint controllers, processor, and, where required, an EU representative. Articles 37-39 require a DPO only for the stated public-authority, regular-and-systematic-monitoring, or large-scale special-category or criminal-data triggers, subject to other Union or Member State law.
Classify roles from actual decisions, instructions, establishment, and statutory triggers. Operador is not automatically identical to processor, and encarregado and DPO appointment rules differ.
Each purpose needs an Article 7 basis for personal data or an Article 11 condition for sensitive personal data. The lists are not identical to , and LGPD legitimate interest applies only to non-sensitive personal data under Article 7.
requires an Article 6 basis and, when Article 9 special-category data is processed, an Article 9 exception as well. Criminal-conviction and offense data follows Article 10. Consent is one possible route, not a universal default.
Keep a purpose-by-purpose basis record for each law. Do not map basis labels by name alone; compare the conditions, balancing, documentation, and withdrawal consequences.
Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that period.
Articles 15-22 cover access, rectification, erasure, restriction, portability, objection, and automated-decision rights, subject to their conditions and exceptions. Article 12 generally requires action within one month, extendable by two further months when necessary if the controller gives notice and reasons within the first month.
A shared request portal needs law-specific request types, identity checks, exceptions, extensions, response content, and clocks. Do not apply 15 days to every right or one month to every privacy-law interaction.
controllers and operators must keep processing records, especially for legitimate-interest processing. The ANPD may require a data-protection impact report in the circumstances stated by Articles 10(3), 32, or 38; the statute does not create a blanket automatic report for every activity labeled high risk.
Article 30 requires records of processing subject to its limited exemption. Article 35 requires a before processing likely to result in high risk, including the listed examples, and Article 36 requires prior consultation when unmitigated high risk remains.
A shared inventory can feed both regimes, but keep the law-specific record fields, exemption conclusion, assessment trigger, approval, residual-risk decision, and regulator interaction.
requires technical and administrative security measures. A controller must notify the ANPD and affected data subjects when an incident may cause relevant risk or damage. Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation, and permits staged communication when information is incomplete.
requires risk-appropriate security. A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to create risk. It must notify affected people without undue delay when high risk is likely, subject to Article 34 exceptions.
Use separate documented risk tests and clocks. One law's decision not to notify does not settle the other law, and sectoral or national rules may add duties.
An international transfer needs an Article 33 mechanism and an Article 7 or 11 basis for the underlying processing. Resolution 19/2024 governs adequacy and contractual mechanisms; when using ANPD standard clauses, the approved text must be adopted integrally and without alteration for the mechanism to be valid.
A transfer to a third country or international organization must satisfy Chapter V, such as an adequacy decision, appropriate safeguards under Article 46, binding corporate rules, or a narrowly interpreted Article 49 derogation. EU standard contractual clauses do not remove the need to assess the transfer circumstances.
Identify exporter, importer, destination, onward transfers, processing basis, transfer mechanism, supplementary measures where required, and contract version under each law. One regime's clauses do not automatically satisfy the other.
The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.
Independent EU supervisory authorities have investigative and corrective powers. Depending on the infringement, Article 83 provides upper tiers of EUR 10 million or 2% of worldwide annual turnover, and EUR 20 million or 4%, whichever applicable amount is higher; remedies and Member State law also matter.
Do not compare maximum figures as predicted penalties. Record the competent authority, infringement, affected processing, procedure, aggravating and mitigating facts, possible remedy, and applicable national law.
Run the workstream when Article 3 applies: document the purpose, Article 7 or 11 basis, controller and operator roles, rights, records, security, incident assessment, and any Article 33 transfer mechanism.
Run the workstream when Article 3 applies: document the Article 6 basis and any Article 9 condition, controller and processor roles, rights, accountability records, , incident analysis, and Chapter V transfer route.
Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.
applies when processing takes place in Brazil, targets the offer or supply of goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Article 4 then excludes specified activities.
applies to processing in the context of an EU establishment. It can also apply to an organization outside the EU when processing relates to offering goods or services to or monitoring people in the Union. Article 2 contains material-scope exclusions.
Write separate territorial and material-scope findings. A Brazil collection or location link is not the same as an EU establishment, offering, or monitoring link.
The controller makes decisions about personal-data processing; the operator processes according to the controller's instructions. Article 41 addresses the encarregado, while ANPD rules can provide exemptions or further conditions.
distinguishes controller, joint controllers, processor, and, where required, an EU representative. Articles 37-39 require a DPO only for the stated public-authority, regular-and-systematic-monitoring, or large-scale special-category or criminal-data triggers, subject to other Union or Member State law.
Classify roles from actual decisions, instructions, establishment, and statutory triggers. Operador is not automatically identical to processor, and encarregado and DPO appointment rules differ.
Each purpose needs an Article 7 basis for personal data or an Article 11 condition for sensitive personal data. The lists are not identical to , and LGPD legitimate interest applies only to non-sensitive personal data under Article 7.
requires an Article 6 basis and, when Article 9 special-category data is processed, an Article 9 exception as well. Criminal-conviction and offense data follows Article 10. Consent is one possible route, not a universal default.
Keep a purpose-by-purpose basis record for each law. Do not map basis labels by name alone; compare the conditions, balancing, documentation, and withdrawal consequences.
Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that period.
Articles 15-22 cover access, rectification, erasure, restriction, portability, objection, and automated-decision rights, subject to their conditions and exceptions. Article 12 generally requires action within one month, extendable by two further months when necessary if the controller gives notice and reasons within the first month.
A shared request portal needs law-specific request types, identity checks, exceptions, extensions, response content, and clocks. Do not apply 15 days to every right or one month to every privacy-law interaction.
controllers and operators must keep processing records, especially for legitimate-interest processing. The ANPD may require a data-protection impact report in the circumstances stated by Articles 10(3), 32, or 38; the statute does not create a blanket automatic report for every activity labeled high risk.
Article 30 requires records of processing subject to its limited exemption. Article 35 requires a before processing likely to result in high risk, including the listed examples, and Article 36 requires prior consultation when unmitigated high risk remains.
A shared inventory can feed both regimes, but keep the law-specific record fields, exemption conclusion, assessment trigger, approval, residual-risk decision, and regulator interaction.
requires technical and administrative security measures. A controller must notify the ANPD and affected data subjects when an incident may cause relevant risk or damage. Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation, and permits staged communication when information is incomplete.
requires risk-appropriate security. A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to create risk. It must notify affected people without undue delay when high risk is likely, subject to Article 34 exceptions.
Use separate documented risk tests and clocks. One law's decision not to notify does not settle the other law, and sectoral or national rules may add duties.
An international transfer needs an Article 33 mechanism and an Article 7 or 11 basis for the underlying processing. Resolution 19/2024 governs adequacy and contractual mechanisms; when using ANPD standard clauses, the approved text must be adopted integrally and without alteration for the mechanism to be valid.
A transfer to a third country or international organization must satisfy Chapter V, such as an adequacy decision, appropriate safeguards under Article 46, binding corporate rules, or a narrowly interpreted Article 49 derogation. EU standard contractual clauses do not remove the need to assess the transfer circumstances.
Identify exporter, importer, destination, onward transfers, processing basis, transfer mechanism, supplementary measures where required, and contract version under each law. One regime's clauses do not automatically satisfy the other.
The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.
Independent EU supervisory authorities have investigative and corrective powers. Depending on the infringement, Article 83 provides upper tiers of EUR 10 million or 2% of worldwide annual turnover, and EUR 20 million or 4%, whichever applicable amount is higher; remedies and Member State law also matter.
Do not compare maximum figures as predicted penalties. Record the competent authority, infringement, affected processing, procedure, aggravating and mitigating facts, possible remedy, and applicable national law.
Run the workstream when Article 3 applies: document the purpose, Article 7 or 11 basis, controller and operator roles, rights, records, security, incident assessment, and any Article 33 transfer mechanism.
Run the workstream when Article 3 applies: document the Article 6 basis and any Article 9 condition, controller and processor roles, rights, accountability records, , incident analysis, and Chapter V transfer route.
Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.
Decide scope first for each legal entity and processing activity; save the facts and cited conclusion.
Map purposes, roles, data categories, rights, assessments, incidents, recipients, and transfers to the relevant row.
Reuse shared systems only after documenting the law-specific branch for legal grounds, request timing, DPIAs or impact reports, incidents, transfers, and regulator interactions.
Escalate case-specific questions about establishment, targeting, monitoring, joint control, special-category data, children, transfers, or remedies to qualified counsel.
For , test whether processing occurs in Brazil, aims to offer or supply goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Then check Article 4 exclusions. For , test processing in the context of an EU establishment or, for an organization outside the EU, whether it offers goods or services to or monitors people in the Union. Then check Article 2 exclusions.
If both laws apply, document the purpose, Article 7 or 11 basis, Article 6 basis and any Article 9 condition, roles, rights, security, incident analysis, transfer mechanism, and regulator-facing evidence separately.
The commencement dates also differ. has applied since 25 May 2018; most operational provisions have applied since 18 September 2020, and LGPD administrative-sanction provisions since 1 August 2021. These are historical start dates, not grace periods for current processing.
For example, an EU establishment processing customer data in its local activities may trigger even without targeting people abroad. A service offered to people located in Brazil may trigger without a Brazilian establishment. When both facts exist, neither regulator-facing record substitutes for the other.
Write a territorial and material-scope conclusion for each entity and processing activity.
Classify controller, operator or processor, joint-controller, representative, encarregado, and DPO roles under the law that defines them.
Record each rights request, incident, or transfer under both sets of triggers and deadlines when both laws apply.
Escalate establishment, targeting, monitoring, joint-control, special-category, transfer, and exemption questions that depend on case-specific facts.
Use shared systems without merging the legal tests
Privacy or legal should own the comparison, while product, data, security, procurement, HR, marketing, and customer-support owners supply facts and operate controls. A shared request portal or processing inventory is useful only if it preserves each law's role, exception, deadline, response content, and escalation path.
For every row, retain the source provision, facts, conclusion, owner, evidence, and review trigger. Reassess when the purpose, data category, technology, market, vendor, transfer destination, or incident facts change.
Keep a separate lawful-basis record for each law; similar labels do not guarantee identical conditions.
Route requests through law-specific identity, exception, extension, and response rules.
Use distinct incident assessments: the ANPD relevant-risk-or-damage test and three-business-day period differ from 's risk and high-risk thresholds and 72-hour rule.
Identify the transfer mechanism under each law rather than assuming EU standard contractual clauses satisfy or Brazilian clauses satisfy .
The official regulation governs adequacy and contractual transfer mechanisms and requires integral, unaltered adoption of the ANPD standard clauses when that mechanism is used.