The Lei Geral de Proteção de Dados (LGPD), Brazil’s General Data Protection Law, sets the rules for processing personal data of people in Brazil. It defines when organizations may use personal data, what rights individuals have, how data must be secured, when it may leave the country and who is accountable. Brazil’s national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), oversees it. This entry is an overview for buyers, not legal advice.
At a glance
- The LGPD can apply to organizations outside Brazil that process data of people in Brazil, offer them goods or services, or process data collected there.
- Every processing activity needs a legal basis, such as consent, contract, legal obligation or legitimate interest.
- Controllers decide how data is used; operators (processors) act on their instructions; controllers generally appoint a data protection officer, the encarregado.
- Security incidents that may cause relevant risk or harm must be reported to the ANPD and affected individuals within deadlines set by regulation.
- International transfers need a recognized mechanism, such as ANPD-approved standard contractual clauses.
What problem it solves
Brazil is a large digital market, and before the LGPD its data protection rules were scattered across sector laws and consumer codes. The LGPD gives one framework with clear principles, individual rights and a dedicated regulator, similar in spirit to European law.
For a mid-market buyer, it appears when a company sells to Brazilian customers, employs people there, runs a contact center serving Brazil, or uses cloud and SaaS providers that store Brazilian personal data elsewhere. Each case raises the same questions: what data, on what legal basis, held by which vendors, where, and with what safeguards.
How it works
Legal bases and principles. Processing must rest on one of the legal bases the law lists and follow principles such as purpose limitation, necessity, transparency, security and accountability. Sensitive personal data, such as health or biometric data, has a narrower set of bases.
Rights. Individuals can confirm whether their data is processed, access it, correct it, request anonymization, blocking or deletion of unnecessary data, request portability and obtain information about sharing.
Roles. The controller decides how data is processed. The operator processes it on the controller’s behalf, as most cloud, SaaS and outsourcing providers do. The encarregado is the contact point for individuals and the ANPD.
Incidents. Controllers report incidents that may cause relevant risk or harm to the ANPD and to affected people, within short deadlines set by ANPD regulation. Small agents get longer deadlines.
Transfers and enforcement. Transfers abroad need a recognized mechanism. The ANPD can impose sanctions from warnings and publicizing a violation to fines and suspension of processing.
Roles and obligations
The LGPD has no certification levels. Its closest structure is the set of roles below, plus a lighter regime for small processing agents.
| Role | Who it applies to | What is required | Typical evidence |
|---|---|---|---|
| Controller (controlador) | Organization that decides why and how data is processed | Legal basis, notices, rights handling, security, incident reporting, transfer mechanism | Records of processing, privacy notice, impact assessments where needed |
| Operator (operador) | Vendor processing on the controller’s instructions | Follow instructions, keep records, apply security | Data processing agreement, security reports |
| Data protection officer (encarregado) | Appointed by controllers, generally | Point of contact for individuals and the ANPD | Published contact details |
| Small-scale processing agent | Qualifying smaller organizations under ANPD rules | Simplified obligations, such as a contact channel instead of an encarregado and longer deadlines, unless an exception applies | ANPD eligibility assessment |
When it matters for buyers
- When entering Brazil or serving Brazilian customers. Contracts will ask about legal bases, the encarregado and incident handling.
- When choosing cloud, CCaaS, SaaS or outsourcing providers. Each operator needs a contract and a transfer mechanism if data leaves Brazil.
- When adopting marketing, analytics or AI tools. These often process more personal data than teams expect.
- When an incident happens. The reporting clock is short, so vendors’ notification commitments matter.
Our governance, risk and compliance overview covers advisors and tools that map multi-country privacy obligations to controls.
Questions to ask vendors
- Will you sign a data processing agreement that reflects your role as an operator under the LGPD?
- Where is Brazilian personal data stored and processed, including backups, support and subprocessors?
- Which transfer mechanism do you rely on, and have you adopted the ANPD’s standard contractual clauses unchanged?
- How quickly will you notify us of an incident so we can meet ANPD deadlines?
- How do you help us answer access, correction and deletion requests?
- What security reports or certifications can you share, and are they scoped to this service?
How it differs from GDPR
The LGPD and the General Data Protection Regulation (GDPR) share a structure of legal bases, rights, roles and transfer rules, and a GDPR program is a good starting point. They differ in the list of legal bases, incident deadlines, the regulator, the fine caps and the specific transfer clauses, and the ANPD issues its own regulations. Like GDPR and Canada’s PIPEDA, the LGPD does not impose general data residency, but it does control transfers. Its personal data is broader than many US definitions of personally identifiable information (PII). A cross-border data breach may trigger several notification regimes, which a governance, risk and compliance (GRC) program tracks together.
