Artifact GuideBrazil and European UnionLGPD vs GDPR

LGPD vs GDPR What privacy teams must separate

LGPD and GDPR share many privacy concepts, but their territorial tests, legal grounds, roles, deadlines, impact-assessment triggers, incident rules, transfer mechanisms, and sanctions are not interchangeable.

Use one processing inventory, then record a separate Brazil and EU conclusion for every rule that changes the owner, deadline, evidence, or outcome.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

and programmes can share inventories, privacy notices, rights tooling, vendor governance, security controls, and assessment methods. They cannot share legal conclusions by default. LGPD applies through its Brazil-focused Article 3 tests; GDPR applies through EU establishment, offering, or monitoring tests. Each law also has its own legal grounds, role definitions, request periods, incident thresholds, transfer mechanisms, and enforcement system.

Side-by-side comparison

LGPD vs GDPR: practical compliance comparison

Read each row against the same processing activity. The implication column states what the implementation record should decide or preserve.

Review all sources
First framework
LGPD

Brazil's law applies through Article 3 connections to Brazil and regulates processing through principles, legal bases, rights, controller and operator duties, security, and transfer rules.

Second framework
GDPR

The EU regulation applies through establishment, offering, or monitoring tests and imposes its own controller, processor, accountability, rights, security, transfer, and supervisory-authority rules.

Comparison row 1

Scope and covered activity

LGPD

applies when processing takes place in Brazil, targets the offer or supply of goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Article 4 then excludes specified activities.

GDPR

applies to processing in the context of an EU establishment. It can also apply to an organization outside the EU when processing relates to offering goods or services to or monitoring people in the Union. Article 2 contains material-scope exclusions.

Operational implication

Write separate territorial and material-scope findings. A Brazil collection or location link is not the same as an EU establishment, offering, or monitoring link.

Comparison row 2

Who must act

LGPD

The controller makes decisions about personal-data processing; the operator processes according to the controller's instructions. Article 41 addresses the encarregado, while ANPD rules can provide exemptions or further conditions.

GDPR

distinguishes controller, joint controllers, processor, and, where required, an EU representative. Articles 37-39 require a DPO only for the stated public-authority, regular-and-systematic-monitoring, or large-scale special-category or criminal-data triggers, subject to other Union or Member State law.

Operational implication

Classify roles from actual decisions, instructions, establishment, and statutory triggers. Operador is not automatically identical to processor, and encarregado and DPO appointment rules differ.

Comparison row 3

Legal grounds and sensitive data

LGPD

Each purpose needs an Article 7 basis for personal data or an Article 11 condition for sensitive personal data. The lists are not identical to , and LGPD legitimate interest applies only to non-sensitive personal data under Article 7.

GDPR

requires an Article 6 basis and, when Article 9 special-category data is processed, an Article 9 exception as well. Criminal-conviction and offense data follows Article 10. Consent is one possible route, not a universal default.

Operational implication

Keep a purpose-by-purpose basis record for each law. Do not map basis labels by name alone; compare the conditions, balancing, documentation, and withdrawal consequences.

Comparison row 4

Individual rights and response periods

LGPD

Article 18 includes confirmation, access, correction, anonymization, blocking or deletion in specified circumstances, portability subject to regulation, sharing information, consent information and withdrawal, and review of certain automated decisions. Article 19 requires simplified confirmation or access immediately, or a complete declaration within 15 days; other rights do not all share that period.

GDPR

Articles 15-22 cover access, rectification, erasure, restriction, portability, objection, and automated-decision rights, subject to their conditions and exceptions. Article 12 generally requires action within one month, extendable by two further months when necessary if the controller gives notice and reasons within the first month.

Operational implication

A shared request portal needs law-specific request types, identity checks, exceptions, extensions, response content, and clocks. Do not apply 15 days to every right or one month to every privacy-law interaction.

Comparison row 5

Evidence and records

LGPD

controllers and operators must keep processing records, especially for legitimate-interest processing. The ANPD may require a data-protection impact report in the circumstances stated by Articles 10(3), 32, or 38; the statute does not create a blanket automatic report for every activity labeled high risk.

GDPR

Article 30 requires records of processing subject to its limited exemption. Article 35 requires a before processing likely to result in high risk, including the listed examples, and Article 36 requires prior consultation when unmitigated high risk remains.

Operational implication

A shared inventory can feed both regimes, but keep the law-specific record fields, exemption conclusion, assessment trigger, approval, residual-risk decision, and regulator interaction.

Comparison row 6

Security incidents

LGPD

requires technical and administrative security measures. A controller must notify the ANPD and affected data subjects when an incident may cause relevant risk or damage. Resolution 15/2024 sets a three-business-day period, subject to a shorter period in specific legislation, and permits staged communication when information is incomplete.

GDPR

requires risk-appropriate security. A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to create risk. It must notify affected people without undue delay when high risk is likely, subject to Article 34 exceptions.

Operational implication

Use separate documented risk tests and clocks. One law's decision not to notify does not settle the other law, and sectoral or national rules may add duties.

Comparison row 7

International transfers

LGPD

An international transfer needs an Article 33 mechanism and an Article 7 or 11 basis for the underlying processing. Resolution 19/2024 governs adequacy and contractual mechanisms; when using ANPD standard clauses, the approved text must be adopted integrally and without alteration for the mechanism to be valid.

GDPR

A transfer to a third country or international organization must satisfy Chapter V, such as an adequacy decision, appropriate safeguards under Article 46, binding corporate rules, or a narrowly interpreted Article 49 derogation. EU standard contractual clauses do not remove the need to assess the transfer circumstances.

Operational implication

Identify exporter, importer, destination, onward transfers, processing basis, transfer mechanism, supplementary measures where required, and contract version under each law. One regime's clauses do not automatically satisfy the other.

Comparison row 8

Enforcement and sanctions

LGPD

The ANPD may apply Article 52 administrative sanctions through the applicable administrative process. also preserves judicial, consumer-law, sector-regulator, contractual, and civil-liability routes; an ANPD outcome does not resolve every other route.

GDPR

Independent EU supervisory authorities have investigative and corrective powers. Depending on the infringement, Article 83 provides upper tiers of EUR 10 million or 2% of worldwide annual turnover, and EUR 20 million or 4%, whichever applicable amount is higher; remedies and Member State law also matter.

Operational implication

Do not compare maximum figures as predicted penalties. Record the competent authority, infringement, affected processing, procedure, aggravating and mitigating facts, possible remedy, and applicable national law.

Comparison row 9

Practical decision rule

LGPD

Run the workstream when Article 3 applies: document the purpose, Article 7 or 11 basis, controller and operator roles, rights, records, security, incident assessment, and any Article 33 transfer mechanism.

GDPR

Run the workstream when Article 3 applies: document the Article 6 basis and any Article 9 condition, controller and processor roles, rights, accountability records, , incident analysis, and Chapter V transfer route.

Operational implication

Proceed under one law, both in parallel, or neither, based on written scope findings. Shared controls can reduce duplicate work but cannot merge the legal tests.

Practical decision rule

How to use this comparison

  • Decide scope first for each legal entity and processing activity; save the facts and cited conclusion.
  • Map purposes, roles, data categories, rights, assessments, incidents, recipients, and transfers to the relevant row.
  • Reuse shared systems only after documenting the law-specific branch for legal grounds, request timing, DPIAs or impact reports, incidents, transfers, and regulator interactions.
  • Escalate case-specific questions about establishment, targeting, monitoring, joint control, special-category data, children, transfers, or remedies to qualified counsel.
Section 1

Compare the same processing under both laws

For , test whether processing occurs in Brazil, aims to offer or supply goods or services to people in Brazil or processes data of people located there, or concerns data collected while the person was in Brazil. Then check Article 4 exclusions. For , test processing in the context of an EU establishment or, for an organization outside the EU, whether it offers goods or services to or monitors people in the Union. Then check Article 2 exclusions.

If both laws apply, document the purpose, Article 7 or 11 basis, Article 6 basis and any Article 9 condition, roles, rights, security, incident analysis, transfer mechanism, and regulator-facing evidence separately.

The commencement dates also differ. has applied since 25 May 2018; most operational provisions have applied since 18 September 2020, and LGPD administrative-sanction provisions since 1 August 2021. These are historical start dates, not grace periods for current processing.

For example, an EU establishment processing customer data in its local activities may trigger even without targeting people abroad. A service offered to people located in Brazil may trigger without a Brazilian establishment. When both facts exist, neither regulator-facing record substitutes for the other.

  • Write a territorial and material-scope conclusion for each entity and processing activity.
  • Classify controller, operator or processor, joint-controller, representative, encarregado, and DPO roles under the law that defines them.
  • Record each rights request, incident, or transfer under both sets of triggers and deadlines when both laws apply.
  • Escalate establishment, targeting, monitoring, joint-control, special-category, transfer, and exemption questions that depend on case-specific facts.
Primary sources

References and citations

gov.br
Referenced sections
  • The official regulation governs adequacy and contractual transfer mechanisms and requires integral, unaltered adoption of the ANPD standard clauses when that mechanism is used.
planalto.gov.br
Referenced sections
  • Supports the comparison decision rule.
"aplica-se a qualquer operação de tratamento realizada por pessoa natural ou por pessoa jurídica"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.