3. What Must the Explanation Cover?
The LGPD does not use this exact terminology, but the same structure follows from article 9 (proactive disclosure at collection) and Articles 18/20 (disclosure of data, logic and outcome on request).
Automated decision-making is routine in credit, insurance, recruitment and public benefit assessments. When those decisions carry legal or significant financial consequences, organisations are not free to rely on algorithms without accountability.
By Vanessa R. T. Borges · Deffenti Lawyers
Under the EU General Data Protection Regulation (GDPR), individuals have the right to know how automated decisions about them were made. Brazil’s Lei Geral de Proteção de Dados (LGPD) does not replicate article 22 of the GDPR in identical terms, but imposes broadly comparable obligations through its transparency and data subject rights framework.
Opaque models create a compliance problem: if an algorithm cannot be adequately explained, the organisation cannot lawfully use it for automated decisions with significant impact under either regime.
The GDPR prohibits fully automated decisions producing legal or similarly significant effects, including access to credit, insurance, employment, or public services, unless: a law authorises it with safeguards; the decision is necessary for a contract; or the individual gave explicit consent.
The LGPD has no direct equivalent to article 22, but creates parallel obligations: article 20 gives a right to review of automated decisions affecting interests; Articles 18-19 grant access, correction and portability; article 6 requires transparency and accountability. The ANPD is empowered to issue further regulation.
Under the GDPR, significant decisions include those materially affecting financial situation, access to services or similar interests: credit scores, insurance pricing, automated recruitment shortlisting.
Under the LGPD, the threshold is broader: any decision made solely on automated processing that affects the data subject’s interests qualifies, arguably wider than the GDPR standard.
The LGPD does not use this exact terminology, but the same structure follows from article 9 (proactive disclosure at collection) and Articles 18/20 (disclosure of data, logic and outcome on request).
Both regimes require information in clear, plain language. The CJEU confirmed in Dun & Bradstreet (C-203/22, February 2025) that a complex algorithm description is neither concise nor comprehensible. The test is whether the individual can understand why the decision was made and how to challenge it.
A useful rule of thumb: the explanation should be comparable to what a person who made the same decision manually would say if asked to justify it.
A layered approach helps: a first layer with the key facts and consequences, and a second, more technical layer available on request. This is endorsed under both the GDPR and, by analogy, the LGPD.
Factor weighting (e.g. SHAP) shows how much each variable contributed; comparative (counterfactual) explanations show what would have had to change for a different outcome. Neither is complete alone; organisations typically need both, plus context on the algorithm’s objectives.
Before deploying any automated decision-making system, organisations must satisfy themselves that adequate explanation is achievable. Complexity is not a defence: it is a risk to be managed at the design stage.
Under the GDPR, significant automated decisions typically require a Data Protection Impact Assessment (DPIA), the natural place to document explainability risk. The LGPD does not yet mandate an equivalent, though the ANPD encourages impact assessments for high-risk processing.
We advise on LGPD and GDPR compliance, including automated decision-making, explainability frameworks and data subject rights. This article is a general overview and does not constitute legal advice.
Contact UsBrazilian lawyers for foreign companies, investors and law firms.