Artifact GuideBrazilRequirements

Brazil LGPD Requirements

The LGPD requires more than consent: every covered processing activity needs a valid purpose and legal basis, transparency, rights handling, security, and accountable records.

Sensitive data, children and adolescents, public-sector processing, incidents, and international transfers have additional conditions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this requirements map after confirming Article 3 scope and any Article 4 exclusion. means information related to an identified or identifiable natural person. For each purpose, apply the Article 6 principles and an Article 7 basis for ordinary personal data or Article 11 basis for . Then implement transparency, rights, records, role allocation, security, incident, transfer, retention, and governance duties that match the data flow.

Section 1

How should teams map Brazil LGPD Requirements into owners, controls, and evidence?

Article 3 applies when any one of three links exists: processing occurs in Brazil; the activity targets the offer or supply of goods or services to people in Brazil or the processing of data about people located there; or the was collected in Brazil while the person was there. The controller's headquarters, the server location, and the person's nationality do not replace that test.

Article 4 excludes a natural person's exclusively private and non-economic processing; exclusively journalistic or artistic processing; specified academic processing, although Articles 7 and 11 still apply; specified public-security, national-defence, state-security, and criminal-investigation processing governed by separate law; and qualifying foreign-origin data that is not shared with Brazilian processing agents or transferred onward outside its country of origin and comes from a country with adequate protection.

The common baseline is Articles 5-10: classify the data and actors, follow purpose, adequacy, necessity, access, quality, transparency, security, prevention, non-discrimination, and accountability, and select a purpose-specific legal basis. Consent is one Article 7 basis, not a default or a cure for unnecessary processing.

Additional requirements depend on the facts: Article 11 for ; Article 14 and the child's or adolescent's best interest; Articles 18-20 rights; Articles 23-30 public-sector processing; Articles 33-36 international transfers; Articles 37-41 records, operator instructions, RIPDs, and the ; and Articles 46-50 security, incidents, and governance.

  • Scope and data: Article 3 territorial link, Article 4 exclusion, personal or , children or adolescents, and any anonymous-data rationale.
  • Purpose and fairness: specific purpose, necessity, compatible reuse, legal basis, non-discrimination, notice, recipients, and retention.
  • People and actors: controller, operators, or documented dispensation, rights channel, response process, and automated-decision review.
  • Risk and movement: design-stage security, vendor instructions, incident assessment and records, transfer mechanism, onward transfers, and any RIPD or governance program.
Section 2

Who should own the Brazil LGPD requirements, and what evidence should prove the decision?

The controller decides purposes and essential means and remains accountable. Operators process on the controller's instructions and keep records of their operations. The acts as a communication channel and performs the duties assigned by Article 41 and Resolution 18/2024; eligible small processing agents may be excused from appointing one but must provide a data-subject communication channel.

Role labels in a contract are evidence, not the final test. Determine the controller and operator for each operation from who decides the purpose and essential elements and who acts on instructions. The same organization may be a controller for one operation and an operator for another.

Evidence should match the duty: a processing record, displayed notice, consent event, basis assessment, best-interest assessment, rights log, operator instruction, retention result, security test, transfer record, incident record, formal appointment, or RIPD.

  • Name one accountable owner and one reviewer for the Requirements workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which conditions and exceptions change the baseline?

Erasure is not absolute: Article 16 permits conservation for legal or regulatory obligations, research with anonymisation where possible, a lawful transfer to a third party, or the controller's exclusive use when the data is anonymised and inaccessible to third parties. Portability remains subject to ANPD regulation and commercial and industrial secrets.

Article 7 legitimate interest does not apply to sensitive . For children and adolescents, any Article 7 or 11 basis used under ANPD Statement 1/2023 must still satisfy the concrete best-interest rule in Article 14. Publicly accessible data remains subject to purpose, good faith, public interest, principles, and rights.

  • Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

Which deadlines and change triggers need separate controls?

For rights, confirmation or access must be provided immediately in simplified form or through a clear and complete declaration within 15 days. Other request periods depend on applicable regulation; public-sector procedures also follow the specific laws named in Article 23.

For incidents that may cause relevant risk or damage, Resolution 15/2024 generally requires controller notice to the ANPD and affected people within three business days, subject to a shorter sector-specific period. For transfers, Resolution 19/2024 requires both an Article 7 or 11 processing basis and a valid transfer mechanism.

Review controls after changes to purpose, people, data, interfaces, systems, vendors, suboperators, access countries, retention, complaints, incidents, or ANPD rules.

  • Create a short intake question that identifies the Requirements scenario.
  • Map the answer to a required action, evidence field, owner, reviewer, and review date.
  • Link related artifact pages with descriptive anchors so users can move from scope to deadlines, controls, penalties, and templates.
  • Update the workflow when official source material changes or when non-public evidence shows recurring exceptions.
Primary sources

References and citations

gov.br
Referenced sections
  • Official explanation of access, correction, deletion, portability, consent, sharing information, objection, and automated-decision rights.
gov.br
Referenced sections
  • Official current-status register for ANPD rules supplementing incident, transfer, encarregado, small-agent, inspection, and sanctions duties.
planalto.gov.br
Referenced sections
  • Operational implementation support for the Brazil LGPD requirements.
"O tratamento de dados pessoais somente poderá ser realizado nas seguintes hipóteses"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.