Artifact GuideBrazilSmall Processing Agents

Brazil LGPD Small Processing Agents

Resolution 2/2022 covers specified micro and small enterprises, startups, private non-profits, natural persons, and unincorporated private entities acting as controllers or operators.

Qualification alone is not enough: revenue, economic-group, and high-risk exclusions can remove the differentiated treatment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this guide to test whether a controller or operator is a under Resolution 2/2022, identify the available flexibilities, and document the exclusions and continuing LGPD duties.

Section 1

What should teams decide about Small Processing Agents under the Brazil LGPD?

Apply three checks before relying on Resolution 2/2022. First, confirm that the organization fits an eligible category in Article 2. Second, confirm that its gross revenue and, where relevant, the global revenue of its economic group do not exceed the limits incorporated by Article 3. Third, test whether its activity is . An agent that fails any applicable check cannot use the differentiated treatment for small processing agents.

For the incorporated revenue tests, a microenterprise has annual gross revenue up to R$360,000 and a small enterprise has revenue above R$360,000 and up to R$4.8 million under Complementary Law 123/2006. A startup must remain within the Complementary Law 182/2021 ceiling of R$16 million in the previous calendar year, or R$1,333,334 multiplied by the number of months of activity when it operated for less than 12 months. Use the applicable statutory period and include the global revenue of a de facto or de jure economic group.

High risk under Article 4 requires at least one general criterion together with at least one specific criterion. The general criteria are large-scale processing or processing that may significantly affect interests and fundamental rights. The specific criteria are emerging or innovative technology, monitoring publicly accessible areas, decisions based solely on automated processing, or use of sensitive data or data about children, adolescents, or older people.

  • Keep registration and corporate-form evidence for the claimed eligible category.
  • Record the revenue period, applicable statutory limit, group entities, group revenue, and calculation owner.
  • Assess scale, duration, frequency, geographic reach, possible denial of rights or services, and material, moral, discrimination, fraud, identity, image, and reputation harms.
  • If the ANPD requests proof of eligibility, Article 5 gives the agent 15 days to demonstrate that it meets Articles 2 and 3.
Section 2

Which obligations are simplified, and which still apply?

The regime permits a simplified processing record, a simplified security policy, and specified differentiated periods. Qualifying agents are not required to appoint an encarregado, but an agent without one must maintain a communication channel for data subjects. Appointing an encarregado is treated as a governance practice, not as a condition of qualification.

The flexibilities do not waive the LGPD's principles, legal bases, transparency, data-subject rights, security, incident handling, other laws, contracts, or accountability. Security measures must still be essential and necessary for the actual privacy risk and the agent's circumstances.

  • Rights: provide accessible treatment information and a usable request channel; the regulation does not remove Article 18 rights.
  • Records: use the ANPD simplified processing-record model if suitable, but keep enough detail to show purposes, data, roles, sharing, retention, security, and rights handling.
  • Security: adopt necessary administrative and technical measures and keep a policy proportionate to structure, scale, volume, cost, and risk.
  • Timing: verify each differentiated period. The regulation does not create a blanket extension for every LGPD duty.
Section 3

Which timing rules and exceptions need special care?

Article 14 grants double time for specified data-subject requests, the Article 19 complete declaration, incident communication under Resolution 15/2024, and information or records requested by the ANPD. Article 15 allows the simplified Article 19 confirmation or access declaration within up to 15 days rather than immediately. Read the exact provision before calculating a due date.

The ANPD may require a small agent to comply with an otherwise waived or flexible obligation after considering the nature or volume of processing and risks to data subjects. A prior eligibility decision should therefore be reopened when revenue, group structure, scale, technology, automation, monitored spaces, or affected populations change.

  • Do not use the small-agent regime for exclusively personal, non-economic household processing; that activity is outside the regulation and is addressed by the LGPD's scope exclusions.
  • Do not assume that non-profit status, a small headcount, or a supplier contract proves eligibility.
  • Example of high risk: large-scale use of sensitive health data meets a general criterion and a specific criterion. A small trial of innovative technology meets only a specific criterion unless it is also large scale or may significantly affect rights; document both sides instead of treating any single criterion as decisive.
  • High-risk agents may use the collective complaint negotiation option in Article 8, but that exception does not restore the other differentiated treatment.
  • Keep a dated eligibility memo and reassessment trigger beside every flexibility the organization uses.
Section 4

What evidence should support the eligibility decision?

Maintain one controlled eligibility record that identifies the legal category, revenue and group tests, high-risk analysis, each flexibility used, the supporting evidence, owner, approval date, and reassessment conditions. Link it to the processing inventory so reviewers can see whether later processing changed the conclusion.

A controller and an operator may each need their own assessment. Role labels do not decide eligibility, and qualifying as a does not change whether an entity is a controller or operator for a particular activity.

  • Corporate evidence: registration, legal form, startup qualification where used, revenue records, and economic-group analysis.
  • Processing evidence: inventory, scale measures, people and data categories, automation, technologies, locations monitored, possible harms, and controls.
  • Operational evidence: request channel, simplified record, security policy, incident workflow, owners, training, and review log.
  • Decision evidence: each claimed flexibility, exact provision, due-date rule, approver, and trigger for reassessment.
Primary sources

References and citations

planalto.gov.br
Referenced sections
  • Article 3 supplies the R$360,000 microenterprise ceiling and R$4.8 million small-enterprise ceiling incorporated by Resolution 2/2022.
planalto.gov.br
Referenced sections
  • Article 55-J(XVIII) is the statutory authority for simplified and differentiated rules for specified smaller organizations.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.