A Relatório de Impacto à Proteção de Dados Pessoais () is the controller's documented analysis of processing that may create high risk to LGPD principles, civil liberties, or fundamental rights. Use this workflow to screen the processing, describe it, test necessity and proportionality, assess risks, assign safeguards, approve residual risk, and preserve the report for review or an ANPD request.
1
Section 1
How should a RIPD Workflow run under the Brazil LGPD?
Start a when the ANPD requires one or when planned or existing processing may create high risk. The LGPD allows the ANPD to require reports in several contexts, including legitimate-interest processing, public-sector processing, and controller operations involving personal data, including sensitive data. The ANPD recommends a RIPD before starts, but the statute does not impose one universal pre-launch RIPD duty for every processing activity.
Until a specific regulation supplies another test, ANPD guidance says controllers may use the Resolution 2/2022 high-risk criteria as a non-exhaustive parameter. Under that test, high risk requires at least one general criterion - large scale or significant effects on interests and fundamental rights - together with at least one specific criterion: emerging or innovative technology, public-area monitoring, solely automated decisions, or sensitive data or data about children, adolescents, or older people.
For example, large-scale biometric access control can combine the general large-scale criterion with the specific sensitive-data criterion. A small pilot using an emerging technology does not meet this particular two-part screen unless it also satisfies a general criterion, but the controller should still assess LGPD principles, security, and any other reason an ANPD request or case-specific risk may justify a .
Identify the controller, project, processing purposes, legal bases, systems, operators, data sources, people affected, data categories, recipients, international transfers, retention, and deletion.
Document each high-risk criterion as met, not met, or unknown, with the underlying facts rather than a label.
If the screen is negative, record the rationale and facts that would require reassessment; if positive or uncertain, continue the before irreversible design or launch decisions.
Consult the encarregado where designated and obtain facts from product, security, legal, operators, and affected business owners; accountability remains with the controller.
Article 38 requires at least the types of personal data collected, the methodology used for collection and information security, and the controller's analysis of measures, safeguards, and risk-mitigation mechanisms. ANPD guidance recommends enough detail to understand the full processing lifecycle, legal bases, necessity and proportionality, risks to people, and the controls selected.
Use one for a project or process whose operations share a purpose and materially similar risks. Separate reports may be clearer when purposes, data, systems, controller decisions, or risk profiles differ. Shared infrastructure does not automatically produce one shared RIPD because each controller may have different purposes and responsibilities.
Scope and roles: controller, operators, encarregado, project owner, consulted parties, processing stages, systems, purposes, legal bases, data sources, recipients, transfers, retention, and deletion.
Necessity and proportionality: why each data type and operation is needed, less intrusive options considered, transparency, rights handling, accuracy, access controls, and purpose compatibility.
Risk register: event, cause, people affected, possible harm, existing controls, likelihood, impact, combined effects, proposed treatment, owner, due date, and evidence.
Decision record: residual risk after controls, conditions for launch or continued use, accepted risk and approving controller representative, unresolved issues, change triggers, and review date.
How should the controller approve and maintain the RIPD?
The controller should decide whether processing can proceed, must change, or should stop based on the completed analysis. Record which safeguards are approved, who will implement them, when evidence is due, and what residual risk remains. Consultation by the encarregado or other specialists informs this decision but does not transfer controller responsibility.
A private-sector controller does not generally have to publish its full or send it to the ANPD without a request. A public summary may support transparency, but it should not expose commercial secrets, security details, or other protected information. Public bodies must also consider Article 32, access-to-information rules, and applicable secrecy grounds.
Approval should state the outcome: proceed with verified controls, proceed only after named conditions are met, redesign the processing, or stop it. If evidence is incomplete, record the uncertainty and owner rather than treating an unanswered field as a low risk.
Reopen the after a new purpose, data category, technology, automated decision, operator, transfer, retention period, affected population, incident, complaint pattern, control failure, or regulatory change.
Verify implemented controls against evidence; do not close a mitigation because a policy or ticket exists.
Keep prior versions, approvals, divergent views when material, risk acceptances, implementation evidence, and the reason for each revision.
If the ANPD requests the report, provide the required scope and preserve protected commercial and industrial information as allowed by Article 38.