What Is LGPD (Lei Geral de Proteção de Dados)?

Also called: Brazilian General Data Protection Law, Lei Geral de Proteção de Dados Pessoais

Related problems: We have customers, users or employees in Brazil and don't know what applies; A Brazilian customer asked who our data protection officer is; Sending personal data from Brazil to US cloud and SaaS providers; Not sure how fast a data incident in Brazil has to be reported

The Lei Geral de Proteção de Dados (LGPD), Brazil’s General Data Protection Law, sets the rules for processing personal data of people in Brazil. It defines when organizations may use personal data, what rights individuals have, how data must be secured, when it may leave the country and who is accountable. Brazil’s national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), oversees it. This entry is an overview for buyers, not legal advice.

At a glance

  • The LGPD can apply to organizations outside Brazil that process data of people in Brazil, offer them goods or services, or process data collected there.
  • Every processing activity needs a legal basis, such as consent, contract, legal obligation or legitimate interest.
  • Controllers decide how data is used; operators (processors) act on their instructions; controllers generally appoint a data protection officer, the encarregado.
  • Security incidents that may cause relevant risk or harm must be reported to the ANPD and affected individuals within deadlines set by regulation.
  • International transfers need a recognized mechanism, such as ANPD-approved standard contractual clauses.

What problem it solves

Brazil is a large digital market, and before the LGPD its data protection rules were scattered across sector laws and consumer codes. The LGPD gives one framework with clear principles, individual rights and a dedicated regulator, similar in spirit to European law.

For a mid-market buyer, it appears when a company sells to Brazilian customers, employs people there, runs a contact center serving Brazil, or uses cloud and SaaS providers that store Brazilian personal data elsewhere. Each case raises the same questions: what data, on what legal basis, held by which vendors, where, and with what safeguards.

How it works

Legal bases and principles. Processing must rest on one of the legal bases the law lists and follow principles such as purpose limitation, necessity, transparency, security and accountability. Sensitive personal data, such as health or biometric data, has a narrower set of bases.

Rights. Individuals can confirm whether their data is processed, access it, correct it, request anonymization, blocking or deletion of unnecessary data, request portability and obtain information about sharing.

Roles. The controller decides how data is processed. The operator processes it on the controller’s behalf, as most cloud, SaaS and outsourcing providers do. The encarregado is the contact point for individuals and the ANPD.

Incidents. Controllers report incidents that may cause relevant risk or harm to the ANPD and to affected people, within short deadlines set by ANPD regulation. Small agents get longer deadlines.

Transfers and enforcement. Transfers abroad need a recognized mechanism. The ANPD can impose sanctions from warnings and publicizing a violation to fines and suspension of processing.

Roles and obligations

The LGPD has no certification levels. Its closest structure is the set of roles below, plus a lighter regime for small processing agents.

Role Who it applies to What is required Typical evidence
Controller (controlador) Organization that decides why and how data is processed Legal basis, notices, rights handling, security, incident reporting, transfer mechanism Records of processing, privacy notice, impact assessments where needed
Operator (operador) Vendor processing on the controller’s instructions Follow instructions, keep records, apply security Data processing agreement, security reports
Data protection officer (encarregado) Appointed by controllers, generally Point of contact for individuals and the ANPD Published contact details
Small-scale processing agent Qualifying smaller organizations under ANPD rules Simplified obligations, such as a contact channel instead of an encarregado and longer deadlines, unless an exception applies ANPD eligibility assessment

When it matters for buyers

  • When entering Brazil or serving Brazilian customers. Contracts will ask about legal bases, the encarregado and incident handling.
  • When choosing cloud, CCaaS, SaaS or outsourcing providers. Each operator needs a contract and a transfer mechanism if data leaves Brazil.
  • When adopting marketing, analytics or AI tools. These often process more personal data than teams expect.
  • When an incident happens. The reporting clock is short, so vendors’ notification commitments matter.

Our governance, risk and compliance overview covers advisors and tools that map multi-country privacy obligations to controls.

Questions to ask vendors

  • Will you sign a data processing agreement that reflects your role as an operator under the LGPD?
  • Where is Brazilian personal data stored and processed, including backups, support and subprocessors?
  • Which transfer mechanism do you rely on, and have you adopted the ANPD’s standard contractual clauses unchanged?
  • How quickly will you notify us of an incident so we can meet ANPD deadlines?
  • How do you help us answer access, correction and deletion requests?
  • What security reports or certifications can you share, and are they scoped to this service?

How it differs from GDPR

The LGPD and the General Data Protection Regulation (GDPR) share a structure of legal bases, rights, roles and transfer rules, and a GDPR program is a good starting point. They differ in the list of legal bases, incident deadlines, the regulator, the fine caps and the specific transfer clauses, and the ANPD issues its own regulations. Like GDPR and Canada’s PIPEDA, the LGPD does not impose general data residency, but it does control transfers. Its personal data is broader than many US definitions of personally identifiable information (PII). A cross-border data breach may trigger several notification regimes, which a governance, risk and compliance (GRC) program tracks together.

Frequently Asked Questions

Does the LGPD apply to companies outside Brazil?
It can. It reaches processing carried out in Brazil, processing aimed at offering goods or services to people in Brazil, and personal data collected in Brazil, wherever the organization is based. Whether it applies to you depends on the facts, so check with counsel; this is not legal advice.
Is the LGPD the same as GDPR?
No, though it was heavily influenced by GDPR and shares many ideas: lawful bases, data subject rights, controller and processor roles and a data protection officer. Details differ, including the list of legal bases, deadlines, transfer mechanisms and the regulator, so a GDPR program needs a Brazil-specific review.
Do we need a data protection officer for Brazil?
Generally yes. The LGPD expects controllers to appoint a data protection officer, called the encarregado. Regulations relax this for qualifying small-scale processing agents, which can instead offer a communication channel, unless an exception applies. Check the current ANPD rules for your situation.
How can personal data be transferred out of Brazil?
Through mechanisms the LGPD recognizes, such as an adequacy decision by the ANPD, standard contractual clauses approved by the ANPD, binding corporate rules or specific consent. The ANPD's standard clauses are meant to be adopted without changes. Ask vendors which mechanism they rely on.
Who enforces the LGPD?
The national data protection authority, the ANPD, which issues regulations, handles complaints and can impose sanctions ranging from warnings to fines capped as a share of Brazilian revenue per infraction. Courts and consumer protection bodies can also be involved.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.