Artifact GuideBrazilTemplates

Brazil LGPD Templates

Choose the record from the legal event: routine processing, a data-subject request, a security incident, high-risk processing, an international transfer, or a role allocation.

A template is not an official ANPD form unless the authority says so. Adapt each record to the processing facts and keep the source, owner, decision, evidence, and review trigger.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use LGPD templates to make recurring decisions reproducible, not to replace the legal analysis. A or event-specific record should identify the controller or operator, processing and people in scope, applicable provision, decision, responsible owner, evidence, approval, deadline where one exists, and the facts that require review.

Section 1

Which LGPD template should a team use?

Use a for the recurring inventory required by Article 37; a data-subject request record for Articles 18-20; an incident assessment and communication record for Article 48 and Resolution 15/2024; a for high-risk processing or an ANPD request; an international-transfer record for Articles 33-36 and Resolution 19/2024; and a role record for controller, operator, sub-operator, and encarregado decisions.

Keep separate templates when the trigger, responsible actor, deadline, or required evidence differs. One generic compliance form tends to hide whether a request was answered, an incident threshold was tested, a transfer mechanism was valid, or a safeguard was actually implemented.

Use the ANPD's own incident communication form when filing a report, and preserve the filed version and protocol. The model published by government bodies is a working aid rather than a substitute for Article 38's minimum content or the controller's own risk analysis.

  • : purposes, legal bases, data and people, systems, sources, sharing, transfers, retention, security, roles, and owner.
  • Rights record: requester verification, right, scope, searches, response form, due date, decision, action, limitation, reviewer, and delivery proof.
  • Incident record: chronology, personal-data scope, relevant-risk-or-damage test, controller knowledge date, three-business-day clock, notices, any justified preliminary filing, the 20-business-day completion date, mitigation, and five-year retention.
  • , transfer, and role records: decision criteria, contracts or mechanisms, safeguards, residual risk, approval, and change triggers.
Section 2

What fields belong in every controlled template?

Start with stable identification fields: record ID and version, entity, controller and operator roles, product or process, purpose, people and data, source provision, owner, reviewer, decision date, and evidence location. Add the event-specific fields only after the applicable rule is known.

Distinguish a fact from a conclusion and a planned action from completed evidence. For example, a security-policy link does not prove that access was revoked, and an unsigned contract draft does not prove that an international-transfer mechanism is in force.

A rights template should not assign the 15-day Article 19 period to every Article 18 right. It should distinguish immediate simplified confirmation or access, a complete confirmation or access statement within 15 days, and other rights whose timing depends on the applicable ANPD or sector rule and the facts.

  • Scope: jurisdiction, role, purposes, legal bases, processing stages, systems, data, people, sources, recipients, transfers, retention, and deletion.
  • Decision: trigger, criteria, each conclusion, exception or limitation, accountable owner, reviewer, approval, and due date only where supported.
  • Evidence: source document, facts relied on, contract or notice version, system output, test result, delivery proof, filing protocol, and implementation status.
  • Lifecycle: open actions, residual risk, review date, change triggers, superseded version, and retention period.
Section 3

How should templates be approved and maintained?

Assign a content owner for the legal fields and an operational owner for the workflow. Test the template with a real scenario before release, confirm that every required decision can be recorded, and prevent users from selecting a deadline or legal conclusion without the supporting provision.

Review templates after a relevant law or ANPD regulation changes and after evidence shows recurring omissions. A new vendor, purpose, data category, transfer, automated decision, incident pattern, or role change may require a new record, not merely a revised blank form.

  • Version the template and completed record separately; do not overwrite the evidence used for an earlier decision.
  • Remove fields that never affect a decision, but retain legally required or independently useful evidence fields.
  • Update instructions and training when reviewers repeatedly misapply a deadline, role, threshold, or exception.
  • Treat ANPD forms and clause text as controlled source material; do not paraphrase mandatory wording into an internal substitute.
Primary sources

References and citations

gov.br
Referenced sections
  • Current status index for the regulations that change incident, transfer, encarregado, and small-agent template fields.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.