A practical overview of the LGPD for companies entering the Brazilian market: territorial scope, legal bases for processing, data subject rights, the DPO obligation, international data transfers, enforcement, and compliance steps.
Contact Us
Brazil’s Lei Geral de Proteção de Dados (Law 13,709/2018, the “LGPD”) is the country’s comprehensive personal data protection law. It applies to any organisation that processes personal data in Brazil, collects data from individuals located in Brazil, or offers goods or services to the Brazilian market, regardless of where the organisation is headquartered or where the data is stored.
For foreign companies entering Brazil, the LGPD is not a compliance formality that can be deferred until a local entity is established. It applies from the moment you begin collecting data from Brazilian users, customers, or employees. Enforcement by the National Data Protection Authority (ANPD) has intensified significantly since 2023, and the international data transfer rules that took full effect in August 2025 have added a further layer of compliance requirements for cross-border operations.
The LGPD’s reach extends well beyond the borders of Brazil. Foreign companies that interact with Brazilian individuals in almost any commercial context will fall within its scope.
The LGPD applies whenever any of three conditions are met (article 3). First, processing operations are carried out in Brazilian territory, which includes storing data on servers accessible from Brazil or processing data using a device located in Brazil. Second, the processing involves data of individuals who were located in Brazil at the time of collection. Third, the purpose of the processing is to offer or supply goods or services to individuals in Brazil.
These conditions are not cumulative: any one of them is sufficient to bring the processing within the LGPD’s scope. A US software company that has no Brazilian employees and no Brazilian office but sells subscriptions to Brazilian users is subject to the LGPD.
There is no minimum scale or revenue threshold that must be crossed before the LGPD applies. A startup with one Brazilian customer and a multinational with thousands of Brazilian employees are both within scope. The law does, however, provide a lighter compliance regime for small processing agents (defined by the ANPD in Resolution CD/ANPD 2/2022), including exemption from the obligation to appoint a DPO.
The LGPD does not apply to processing carried out exclusively for personal or non-commercial purposes, journalistic or academic research (subject to certain conditions), public security, national defence, or investigation of criminal offences (article 4).
The LGPD was heavily influenced by the EU General Data Protection Regulation (GDPR) and shares its broad extraterritorial reach. Organisations already compliant with the GDPR will find the LGPD’s structure familiar, but there are important differences (notably in the list of legal bases for processing, the DPO obligation, and the international transfer framework) that require a Brazil-specific compliance review rather than a simple extension of an existing GDPR programme.
Understanding the LGPD’s terminology is essential for assessing your obligations. The key definitions are set out in article 5 of the law.
Every processing activity must be supported by one of the ten legal bases listed in article 7 of the LGPD (or, for sensitive data, one of the narrower bases in article 11). Processing without a valid legal basis is unlawful regardless of the purpose.
Processing of sensitive personal data is permitted only on the bases of explicit consent, compliance with a legal obligation, protection of life, health protection by a health body, fraud prevention, protection of the data subject’s interests (when they cannot give consent), or the exercise of rights in judicial or administrative proceedings. Legitimate interests is not available as a basis for processing sensitive data.
Article 18 of the LGPD grants Brazilian data subjects a comprehensive set of rights, which must be honoured by the controller at any time upon request. Foreign companies must have processes in place to respond to these rights.
Controllers must respond to data subject requests in a clear, adequate, and free manner within a reasonable timeframe. The ANPD has indicated that best practice is a response within 15 days, aligned with the timeframe set in article 19. Requests cannot be refused merely because the data subject has not provided a reason. Responses must be provided in Portuguese or in the language in which the service is provided.
Article 41 of the LGPD requires controllers to appoint a Data Protection Officer. This obligation is directly relevant to foreign companies operating in Brazil and was reinforced by ANPD Resolution CD/ANPD 18/2024.
All controllers subject to the LGPD must appoint a DPO (encarregado), with the exception of small processing agents as defined in Resolution CD/ANPD 2/2022. Processors are not required to appoint a DPO under the LGPD, though it is regarded as good practice. In November 2024, the ANPD initiated proceedings against 20 companies for failing to appoint a DPO or disclose DPO contact information; all were required to rectify the failure.
The LGPD does not require the DPO to be Brazilian or located in Brazil, and does not specify professional qualifications. Under Resolution CD/ANPD 18/2024, the DPO must be appointed by formal written agreement, must have autonomy and independence and must report directly to senior management. A substitute must also be appointed for absences.
Many foreign companies appoint a Brazilian-based individual or a local law firm or consultancy as DPO to ensure effective communication with data subjects in Portuguese and with the ANPD. While not legally required, having a Brazil-based DPO significantly reduces the risk of non-compliance arising from language barriers or time zone difficulties in handling data subject requests.
The LGPD restricts transfers of personal data outside Brazil. For foreign companies that collect data in Brazil and process it on servers or systems located abroad, this is a critical compliance area. The rules were substantially updated by Resolution CD/ANPD 19/2024, which took full effect in August 2025.
Personal data may be transferred to a country the ANPD has determined provides an adequate level of protection. As of 2025, no country has been formally declared adequate.
Following Resolution CD/ANPD 19/2024, the primary mechanism is ANPD-approved Standard Contractual Clauses incorporated into contracts between exporter and importer.
Multinational groups may adopt Global Corporate Rules (equivalent to GDPR Binding Corporate Rules) for intragroup transfers, subject to ANPD approval.
Article 33 also permits transfers on the basis of specific informed consent, contract performance, or protection of life or physical safety.
Foreign companies that collect personal data from Brazilian individuals and process it on servers located outside Brazil are conducting an international transfer under the LGPD, even if no data is sent back to Brazil. Such companies must have ANPD-approved SCCs or another valid mechanism in place. This applies to cloud services, SaaS platforms, and any processing infrastructure hosted outside Brazil.
The ANPD’s enforcement posture has moved from guidance-oriented in its early years to active investigation and sanction since 2023. Foreign companies are not immune from its jurisdiction.
The ANPD may impose a graduated range of sanctions under article 52 of the LGPD, calibrated by the severity of the infraction (minor, medium, or serious) under Resolution CD/ANPD 4/2023:
In addition to ANPD administrative sanctions, article 42 of the LGPD allows data subjects who suffer material or moral damages as a result of an LGPD violation to bring civil claims against the controller or processor. Moral damages (equivalent to non-pecuniary loss) are well-established in Brazilian civil law and courts have awarded compensation for data protection violations even without proven financial harm. Collective actions brought by consumer protection bodies, the Ministério Público, or civil society organisations are also possible under Brazil’s consumer defence and collective action framework (Law 8,078/1990 and Law 7,347/1985), enabling class-style litigation on behalf of affected data subjects.
Article 48 of the LGPD requires controllers to notify the ANPD and affected data subjects of any security incident that may result in relevant risk or damage to data subjects. The notification must be made within a reasonable timeframe (the ANPD’s guidance specifies 72 hours for initial notification to the ANPD), with a fuller report to follow. Notification must describe the nature of the data affected, the data subjects involved, the technical and security measures in place, the risks resulting from the incident, and the measures taken or planned.
A structured approach to LGPD compliance for foreign businesses entering Brazil, from initial assessment through to operational compliance.
Vanessa Borges is a partner at Deffenti Lawyers with a focus on data privacy, corporate law and international matters. Before joining the firm, Vanessa worked for the world’s largest search engine company, representing and advising clients on data security, privacy, civil liability on the internet and deceptive practices on social media platforms, giving her direct, practical experience of how data protection issues arise in real-world digital operations.
Vanessa holds an LLM from Penn State Law (Pennsylvania, USA) and a law degree from Mackenzie University in São Paulo. She is co-author, with Fabiano Deffenti, of our article on Brazil’s international data transfer regulations compared with the GDPR, published on LawsofBrazil.
Deffenti Lawyers assists companies with LGPD compliance programmes, data protection impact assessments, privacy policies, DPO services, international data transfer agreements and regulatory matters before the ANPD.
LGPD compliance requirements depend on your processing activities, business model, and sector. Contact us for advice tailored to your organisation.
This guide provides general information on Brazil’s Lei Geral de Proteção de Dados (Law 13,709/2018) and related ANPD regulations as at the date of publication. It does not constitute legal advice and should not be relied upon as such. Data protection rules and ANPD guidance change frequently; always verify current requirements with a qualified Brazilian lawyer before acting. Deffenti Lawyers accepts no liability for any action taken or not taken in reliance on the contents of this guide.
Brazilian lawyers for foreign companies, investors and law firms.