| Scope and covered activity | LGPD: test whether processing occurs in Brazil, aims to offer or supply goods or services to people in Brazil or processes data of people located there, or concerns data collected in Brazil, then check Article 4 exclusions. | GDPR: test establishment processing under Article 3(1), or Article 3(2) offering of goods or services to or monitoring of people in the Union, then check material-scope exclusions. | Write separate territorial and material-scope findings. Presence, targeting, collection, and establishment tests are not interchangeable even when both laws cover the same data flow. |
|---|
| Who must act | LGPD: allocate controlador and operador roles from actual decision rights and instructions; treat the encarregado as the communication and governance role defined by Brazilian law and ANPD rules. | GDPR: allocate controller, joint-controller, processor, representative, and DPO roles under their own definitions and appointment triggers. | Do not translate operador mechanically into every GDPR processor relationship or assume encarregado and DPO appointment rules are identical. |
|---|
| Trigger or threshold | LGPD: identify the relevant purpose and Article 7 or 11 basis, Article 18 right, relevant-risk incident under Resolution 15/2024, Article 33 transfer, or ANPD request or proceeding. | GDPR: identify the corresponding purpose and Article 6 or 9 condition, Chapter III right, Article 33 or 34 breach threshold, Chapter V transfer, or supervisory process. | Compare the exact triggers and thresholds; a request, incident, transfer, or regulator interaction can produce different duties and clocks under each law. |
|---|
| Core obligations | LGPD requires an Article 7 or 11 basis for each purpose and data category, rights handling, appropriate technical and administrative security measures, and incident communication where relevant risk or damage exists. Article 41 addresses the encarregado, but ANPD rules can provide exemptions; the LGPD does not copy the GDPR's DPO criteria. | GDPR requires a documented lawful basis for each processing purpose, appointment of a DPO where required, a Record of Processing Activities, Data Protection Impact Assessments for high-risk processing, 72-hour breach notification to the supervisory authority, and data subject request responses within one month. | Translate obligations into tickets, notices, records, controls, or contract terms. |
|---|
| Evidence and records | LGPD: keep the evidence that supports the scoped claim, including purpose and legal-basis records, notices, role decisions, rights records, contracts, security evidence, incident decisions, transfer records, RIPDs where applicable, and approvals. | GDPR: keep comparator evidence in a distinct record set and link only the artifacts that genuinely satisfy both cited requirements. | Keep source links, factual analysis, owner approval, and implementation evidence together. |
|---|
| Timing and cadence | LGPD: track the applicable commencement history, Article 19 rights-response period, Resolution 15/2024 incident clock, Resolution 19/2024 transfer transition, remediation dates, and internal review triggers separately. | GDPR: track the comparator schedule separately so a later deadline, recurring audit, or incident timer is not hidden by the other workstream. | Use current source dates; do not reuse old project plans after amendments or guidance updates. |
|---|
| Enforcement or assurance route | LGPD: identify ANPD administrative procedure and sanctions separately from judicial, consumer-law, sector-regulator, contractual, or civil-liability routes. | GDPR: identify the competent supervisory authority, cooperation or consistency procedure where relevant, judicial remedy, administrative fine, and any separate certification or contractual assurance claim. | ANPD action does not establish a GDPR result, and a GDPR supervisory or certification outcome does not establish LGPD compliance; keep authority, territorial scope, facts, and evidence separate. |
|---|
| Overlap and reuse | LGPD: reuse controls only where the cited duty, evidence standard, owner, and timing align with the comparator; otherwise keep a bridge note. | GDPR can reuse evidence from the other side only when the same fact pattern, system boundary, control, owner, and cited requirement are genuinely aligned. | Document overlap explicitly instead of merging both tests into one vague compliance label. |
|---|
| Practical decision rule | LGPD: treat this as the controlling workstream when its scope trigger, deadline, regulator, or required artifact is the immediate blocker. | GDPR: run a parallel or follow-on workstream when this side adds separate actors, evidence, timing, penalties, customer assurances, or implementation constraints. | Choose one practical next step: proceed under LGPD, proceed under GDPR, run both in parallel, or document why neither side controls the present fact pattern. |
|---|