Artifact GuideBrazilRIPD Workflow

Brazil LGPD RIPD Workflow

The controller should prepare a RIPD for processing that may create high risk and must prepare one when the ANPD requires it.

The LGPD sets minimum content. ANPD guidance recommends completing the report before processing starts and revisiting it after material changes.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A Relatório de Impacto à Proteção de Dados Pessoais () is the controller's documented analysis of processing that may create high risk to LGPD principles, civil liberties, or fundamental rights. Use this workflow to screen the processing, describe it, test necessity and proportionality, assess risks, assign safeguards, approve residual risk, and preserve the report for review or an ANPD request.

Section 1

How should a RIPD Workflow run under the Brazil LGPD?

Start a when the ANPD requires one or when planned or existing processing may create high risk. The LGPD allows the ANPD to require reports in several contexts, including legitimate-interest processing, public-sector processing, and controller operations involving personal data, including sensitive data. The ANPD recommends a RIPD before starts, but the statute does not impose one universal pre-launch RIPD duty for every processing activity.

Until a specific regulation supplies another test, ANPD guidance says controllers may use the Resolution 2/2022 high-risk criteria as a non-exhaustive parameter. Under that test, high risk requires at least one general criterion - large scale or significant effects on interests and fundamental rights - together with at least one specific criterion: emerging or innovative technology, public-area monitoring, solely automated decisions, or sensitive data or data about children, adolescents, or older people.

For example, large-scale biometric access control can combine the general large-scale criterion with the specific sensitive-data criterion. A small pilot using an emerging technology does not meet this particular two-part screen unless it also satisfies a general criterion, but the controller should still assess LGPD principles, security, and any other reason an ANPD request or case-specific risk may justify a .

  • Identify the controller, project, processing purposes, legal bases, systems, operators, data sources, people affected, data categories, recipients, international transfers, retention, and deletion.
  • Document each high-risk criterion as met, not met, or unknown, with the underlying facts rather than a label.
  • If the screen is negative, record the rationale and facts that would require reassessment; if positive or uncertain, continue the before irreversible design or launch decisions.
  • Consult the encarregado where designated and obtain facts from product, security, legal, operators, and affected business owners; accountability remains with the controller.
Section 2

What must the RIPD contain?

Article 38 requires at least the types of personal data collected, the methodology used for collection and information security, and the controller's analysis of measures, safeguards, and risk-mitigation mechanisms. ANPD guidance recommends enough detail to understand the full processing lifecycle, legal bases, necessity and proportionality, risks to people, and the controls selected.

Use one for a project or process whose operations share a purpose and materially similar risks. Separate reports may be clearer when purposes, data, systems, controller decisions, or risk profiles differ. Shared infrastructure does not automatically produce one shared RIPD because each controller may have different purposes and responsibilities.

  • Scope and roles: controller, operators, encarregado, project owner, consulted parties, processing stages, systems, purposes, legal bases, data sources, recipients, transfers, retention, and deletion.
  • Necessity and proportionality: why each data type and operation is needed, less intrusive options considered, transparency, rights handling, accuracy, access controls, and purpose compatibility.
  • Risk register: event, cause, people affected, possible harm, existing controls, likelihood, impact, combined effects, proposed treatment, owner, due date, and evidence.
  • Decision record: residual risk after controls, conditions for launch or continued use, accepted risk and approving controller representative, unresolved issues, change triggers, and review date.
Section 3

How should the controller approve and maintain the RIPD?

The controller should decide whether processing can proceed, must change, or should stop based on the completed analysis. Record which safeguards are approved, who will implement them, when evidence is due, and what residual risk remains. Consultation by the encarregado or other specialists informs this decision but does not transfer controller responsibility.

A private-sector controller does not generally have to publish its full or send it to the ANPD without a request. A public summary may support transparency, but it should not expose commercial secrets, security details, or other protected information. Public bodies must also consider Article 32, access-to-information rules, and applicable secrecy grounds.

Approval should state the outcome: proceed with verified controls, proceed only after named conditions are met, redesign the processing, or stop it. If evidence is incomplete, record the uncertainty and owner rather than treating an unanswered field as a low risk.

  • Reopen the after a new purpose, data category, technology, automated decision, operator, transfer, retention period, affected population, incident, complaint pattern, control failure, or regulatory change.
  • Verify implemented controls against evidence; do not close a mitigation because a policy or ticket exists.
  • Keep prior versions, approvals, divergent views when material, risk acceptances, implementation evidence, and the reason for each revision.
  • If the ANPD requests the report, provide the required scope and preserve protected commercial and industrial information as allowed by Article 38.
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Articles 32 and 38 govern ANPD requests, public-sector publication directions, minimum content, and protection of commercial and industrial secrets.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.