- ANPD small-agent security guidance supports the requirements evidence for administrative, technical, and cloud controls under LGPD security duties.
"medidas administrativas e técnicas de segurança da informação"
This page maps the Brazil LGPD Requirements into scope triggers, accountable owners, controls, evidence records, deadlines, and escalation points.
Use this section to define scope, owner, evidence inputs, and the review outcome before execution.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains the core Brazil LGPD requirements for lawful processing, transparency, data-subject rights, security, children and sensitive data, international transfers, public-sector processing, and ANPD oversight. Use it to identify the trigger, the required action, the responsible role, the evidence to keep, and the review path.
Start by deciding whether the issue affects controller/operator roles, lawful basis, data-subject rights, children data, international transfers, security incidents, DPO/encarregado duties, or ANPD enforcement exposure. The useful answer should name the exact trigger, affected product or process, required action, owner, evidence, and escalation point.
The legal requirements most visitors need to see are the Article 7 lawful bases, Article 11 rules for sensitive data, Article 14 rules for children and adolescents, Article 18 data-subject rights, Article 23 public-sector transparency, Article 26 public-sector sharing limits, Articles 33 to 35 international transfer rules, and Articles 46 to 48 security and incident duties. Keep the LGPD source, role map, lawful-basis analysis, data-subject-right record, transfer basis, incident assessment, and ANPD-facing evidence together.
Ownership should sit with the team that controls the processing purpose, data-subject channel, vendor relationship, transfer mechanism, security incident response, or ANPD communication.
Evidence should show controller/operator mapping, lawful basis, transparency notice, rights response, transfer analysis, incident decision, DPO involvement, and ANPD remediation record where applicable.
Most LGPD mistakes happen at the boundary between controller and operator duties, consent and other lawful bases, academic or public-interest processing, international transfers, and incident notification thresholds.
Apply this section before approving a processing activity, vendor arrangement, transfer, rights workflow, child-data handling, or incident response under LGPD. If evidence is missing, block progression and raise a review task.
Use an LGPD workflow that captures role, purpose, lawful basis, data category, data-subject right, transfer or incident trigger, DPO review, evidence, and review date.
The output should be a lawful-basis memo, role map, privacy notice update, DSAR record, transfer note, incident assessment, or ANPD response pack.
This artifact page provides practical inputs, owner roles, required outputs, and evidence checkpoints for requirements.
Turn Requirements into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with operational practice.
"medidas administrativas e técnicas de segurança da informação"
"O tratamento de dados pessoais somente poderá ser realizado nas seguintes hipóteses"
"4º - - data da portaria DE 4 DE NOVEMBRO DE 2022 2022-11-04T00:00:00 PORTARIA ANPD N° 35 -"
"Seção III Do Recebimento de Requerimentos [FOOTER/URL] Page 7/14 RESOLUÇÃO CD/ANPD Nº 1, DE 28 DE OUTUBRO DE"
"Esta Resolução CD/ANPD nº 4, de 24 de fevereiro de 2023, trata da aplicação de sanções administrativas e"