Deffenti Lawyers
PT · EN Contact Us
Legal Guides  /  Data Privacy

Brazil’s General Data Protection Law (LGPD): a guide for foreign businesses

A practical overview of the LGPD for companies entering the Brazilian market: territorial scope, legal bases for processing, data subject rights, the DPO obligation, international data transfers, enforcement, and compliance steps.

Contact Us
Territorial scope Key concepts Legal bases Data subject rights DPO requirement International transfers Enforcement Compliance steps
Decorative abstract artwork

The LGPD applies to you even if you have no office in Brazil.

Brazil’s Lei Geral de Proteção de Dados (Law 13,709/2018, the “LGPD”) is the country’s comprehensive personal data protection law. It applies to any organisation that processes personal data in Brazil, collects data from individuals located in Brazil, or offers goods or services to the Brazilian market, regardless of where the organisation is headquartered or where the data is stored.

For foreign companies entering Brazil, the LGPD is not a compliance formality that can be deferred until a local entity is established. It applies from the moment you begin collecting data from Brazilian users, customers, or employees. Enforcement by the National Data Protection Authority (ANPD) has intensified significantly since 2023, and the international data transfer rules that took full effect in August 2025 have added a further layer of compliance requirements for cross-border operations.

Application

Territorial scope and applicability

The LGPD’s reach extends well beyond the borders of Brazil. Foreign companies that interact with Brazilian individuals in almost any commercial context will fall within its scope.

The LGPD applies whenever any of three conditions are met (article 3). First, processing operations are carried out in Brazilian territory, which includes storing data on servers accessible from Brazil or processing data using a device located in Brazil. Second, the processing involves data of individuals who were located in Brazil at the time of collection. Third, the purpose of the processing is to offer or supply goods or services to individuals in Brazil.

These conditions are not cumulative: any one of them is sufficient to bring the processing within the LGPD’s scope. A US software company that has no Brazilian employees and no Brazilian office but sells subscriptions to Brazilian users is subject to the LGPD.

There is no minimum scale or revenue threshold that must be crossed before the LGPD applies. A startup with one Brazilian customer and a multinational with thousands of Brazilian employees are both within scope. The law does, however, provide a lighter compliance regime for small processing agents (defined by the ANPD in Resolution CD/ANPD 2/2022), including exemption from the obligation to appoint a DPO.

The LGPD does not apply to processing carried out exclusively for personal or non-commercial purposes, journalistic or academic research (subject to certain conditions), public security, national defence, or investigation of criminal offences (article 4).

GDPR comparison

The LGPD was heavily influenced by the EU General Data Protection Regulation (GDPR) and shares its broad extraterritorial reach. Organisations already compliant with the GDPR will find the LGPD’s structure familiar, but there are important differences (notably in the list of legal bases for processing, the DPO obligation, and the international transfer framework) that require a Brazil-specific compliance review rather than a simple extension of an existing GDPR programme.

Definitions

Key concepts and definitions

Understanding the LGPD’s terminology is essential for assessing your obligations. The key definitions are set out in article 5 of the law.

art. 5(I)
Personal data
Any information relating to an identified or identifiable natural person. The definition is broad and includes names, email addresses, IP addresses, device identifiers, location data, and any other data that, alone or in combination, can identify an individual. In January 2024 the ANPD clarified that even data requiring reasonable effort to link to an individual qualifies.
art. 5(II)
Sensitive personal data
A higher-protection category covering data relating to racial or ethnic origin, religious belief, political opinion, trade union membership, health or sex life, genetic or biometric data. Processing of sensitive data is subject to stricter rules and requires specific legal bases (article 11).
art. 5(VI)
Controller (controlador)
The natural or legal person responsible for decisions about the processing of personal data. The controller determines the purposes and means of processing and bears primary responsibility for LGPD compliance, regardless of where it is incorporated.
art. 5(VII)
Processor (operador)
A natural or legal person that processes personal data on behalf of the controller. Cloud providers, payroll processors and marketing platforms handling Brazilian data on instructions are processors, requiring a data processing agreement (contrato de operação).
art. 5(VIII)
Data protection officer (encarregado)
The individual appointed as a communication channel between the controller, data subjects, and the ANPD. Under Resolution CD/ANPD 18/2024, must be appointed by formal written agreement, with a substitute for absences and publicly disclosed contact details.
art. 5(V)
Data subject (titular)
The natural person to whom the personal data relates. The LGPD protects only natural persons. Under article 14 §1º, processing of crianças (children under 12) requires specific, prominent parental consent, a child’s own consent is not sufficient.
Individual Rights

Data subject rights

Article 18 of the LGPD grants Brazilian data subjects a comprehensive set of rights, which must be honoured by the controller at any time upon request. Foreign companies must have processes in place to respond to these rights.

art. 18(I)
Confirmation and access
The right to confirm whether processing of their data exists and to access the data held.
art. 18(II)
Correction
The right to have incomplete, inaccurate, or outdated data corrected.
art. 18(III–IV)
Anonymisation, blocking, or deletion
The right to have unnecessary, excessive, or unlawfully processed data anonymised, blocked, or deleted.
art. 18(V)
Data portability
The right to receive their personal data in a structured, interoperable format for transfer to another service provider, subject to ANPD regulation.
art. 18(VI)
Deletion of consent-based data
The right to have personal data processed on the basis of consent deleted, unless retention is permitted by another legal basis.
art. 18(VII)
Information on sharing
The right to information about third parties with whom the controller has shared the data.
art. 18(VIII)
Information on consent options
The right to information about the option not to provide consent and the consequences of refusal.
art. 18(IX)
Withdrawal of consent
The right to withdraw consent at any time. Withdrawal is as simple as the original grant of consent.
art. 18(X) / art. 20
Review of automated decisions
The right to request human review of decisions taken solely by automated means that affect the data subject’s interests, including profiling.
Response Obligations

Controllers must respond to data subject requests in a clear, adequate, and free manner within a reasonable timeframe. The ANPD has indicated that best practice is a response within 15 days, aligned with the timeframe set in article 19. Requests cannot be refused merely because the data subject has not provided a reason. Responses must be provided in Portuguese or in the language in which the service is provided.

Governance

The DPO (encarregado) requirement

Article 41 of the LGPD requires controllers to appoint a Data Protection Officer. This obligation is directly relevant to foreign companies operating in Brazil and was reinforced by ANPD Resolution CD/ANPD 18/2024.

Who must appoint: controllers (with limited exceptions)

All controllers subject to the LGPD must appoint a DPO (encarregado), with the exception of small processing agents as defined in Resolution CD/ANPD 2/2022. Processors are not required to appoint a DPO under the LGPD, though it is regarded as good practice. In November 2024, the ANPD initiated proceedings against 20 companies for failing to appoint a DPO or disclose DPO contact information; all were required to rectify the failure.

  • Foreign companies that are controllers within the LGPD’s scope must comply
  • Small processing agents (microenterprises, startups, small businesses) are exempt
  • Processors are not obliged but encouraged to appoint

Requirements: who can be the DPO and what they must do

The LGPD does not require the DPO to be Brazilian or located in Brazil, and does not specify professional qualifications. Under Resolution CD/ANPD 18/2024, the DPO must be appointed by formal written agreement, must have autonomy and independence and must report directly to senior management. A substitute must also be appointed for absences.

  • Must be publicly identified (name and contact details disclosed on the controller’s website or privacy notice)
  • Acts as contact point for data subjects and the ANPD
  • Oversees internal compliance with the LGPD
  • Can be an employee or external service provider
  • Must have operational independence from those making data processing decisions
Practical note for foreign companies

Many foreign companies appoint a Brazilian-based individual or a local law firm or consultancy as DPO to ensure effective communication with data subjects in Portuguese and with the ANPD. While not legally required, having a Brazil-based DPO significantly reduces the risk of non-compliance arising from language barriers or time zone difficulties in handling data subject requests.

Cross-Border Data Flows

International data transfers

The LGPD restricts transfers of personal data outside Brazil. For foreign companies that collect data in Brazil and process it on servers or systems located abroad, this is a critical compliance area. The rules were substantially updated by Resolution CD/ANPD 19/2024, which took full effect in August 2025.

Adequacy Decisions
Transfer to an adequate country

Personal data may be transferred to a country the ANPD has determined provides an adequate level of protection. As of 2025, no country has been formally declared adequate.

  • No adequacy decisions issued as of 2025
  • ANPD assessments are underway
  • Controllers must rely on SCCs, GCRs, or another valid mechanism until then
Primary Mechanism
Standard contractual clauses (SCCs)

Following Resolution CD/ANPD 19/2024, the primary mechanism is ANPD-approved Standard Contractual Clauses incorporated into contracts between exporter and importer.

  • Mandatory for controller-to-controller and controller-to-processor transfers
  • Grace period for incorporating SCCs expired 23 August 2025
  • Security incidents must be reported to data subjects and the ANPD
Multinational Groups
Global corporate rules (GCRs)

Multinational groups may adopt Global Corporate Rules (equivalent to GDPR Binding Corporate Rules) for intragroup transfers, subject to ANPD approval.

  • Must be submitted to and approved by the ANPD
  • Must include notification obligations for conflicting foreign laws
  • Appropriate for large multinationals with high intragroup data volumes
Other Mechanisms
Consent and specific clauses

Article 33 also permits transfers on the basis of specific informed consent, contract performance, or protection of life or physical safety.

  • Available alongside, not instead of, the SCC regime
  • The ANPD may approve custom contractual clauses
  • Applicable to a narrower set of transfer scenarios
Impact On Foreign Companies

Foreign companies that collect personal data from Brazilian individuals and process it on servers located outside Brazil are conducting an international transfer under the LGPD, even if no data is sent back to Brazil. Such companies must have ANPD-approved SCCs or another valid mechanism in place. This applies to cloud services, SaaS platforms, and any processing infrastructure hosted outside Brazil.

Sanctions

Enforcement and penalties

The ANPD’s enforcement posture has moved from guidance-oriented in its early years to active investigation and sanction since 2023. Foreign companies are not immune from its jurisdiction.

Maximum Fine
2% of Brazil revenue
Per violation, capped at BRL 50 million per incident
Daily Fine
BRL 50 million
Total daily fine cap for ongoing violations
ANPD Fines (2023–2025)
BRL 98 million+
Total sanctions issued since enforcement began in 2021
Administrative Sanctions

ANPD enforcement powers

The ANPD may impose a graduated range of sanctions under article 52 of the LGPD, calibrated by the severity of the infraction (minor, medium, or serious) under Resolution CD/ANPD 4/2023:

  • Warning with a deadline to implement corrective measures
  • Simple fine of up to 2% of annual Brazilian revenue, capped at BRL 50 million per incident
  • Daily fine up to a total of BRL 50 million
  • Public disclosure of the infraction
  • Blocking or deletion of the personal data involved
  • Suspension of the data processing activity for up to 6 months
  • Prohibition of the data processing activity
  • Partial or total suspension of Brazilian database operations
Civil Liability

Data subject litigation and class actions

In addition to ANPD administrative sanctions, article 42 of the LGPD allows data subjects who suffer material or moral damages as a result of an LGPD violation to bring civil claims against the controller or processor. Moral damages (equivalent to non-pecuniary loss) are well-established in Brazilian civil law and courts have awarded compensation for data protection violations even without proven financial harm. Collective actions brought by consumer protection bodies, the Ministério Público, or civil society organisations are also possible under Brazil’s consumer defence and collective action framework (Law 8,078/1990 and Law 7,347/1985), enabling class-style litigation on behalf of affected data subjects.

ANPD focus sectors and issues

  • Failure to appoint a DPO or disclose DPO contact information
  • Data breach notification failures (72-hour reporting obligation)
  • Unlawful international transfers (particularly post-August 2025)
  • Processing of sensitive data without a valid legal basis
  • Processing of children’s data without parental consent
  • Inadequate security measures leading to data breaches
  • AI and biometric data processing (announced 2025 priority)
Data breaches

Article 48 of the LGPD requires controllers to notify the ANPD and affected data subjects of any security incident that may result in relevant risk or damage to data subjects. The notification must be made within a reasonable timeframe (the ANPD’s guidance specifies 72 hours for initial notification to the ANPD), with a fuller report to follow. Notification must describe the nature of the data affected, the data subjects involved, the technical and security measures in place, the risks resulting from the incident, and the measures taken or planned.

Practical Compliance

Compliance steps for foreign companies

A structured approach to LGPD compliance for foreign businesses entering Brazil, from initial assessment through to operational compliance.

01
Assess whether the LGPD applies to your activities
Map your data flows involving Brazilian individuals: do you collect data from users located in Brazil, process data on Brazilian territory, or offer goods or services to the Brazilian market? Identify whether you are a controller or processor (or both) in each flow.
02
Conduct a personal data inventory
Produce a record of all processing activities involving Brazilian personal data: categories collected, purposes, legal basis, retention periods, and third parties data is shared with. Required to demonstrate accountability under article 50.
03
Identify and document a legal basis for each processing activity
Map every activity to one of the ten bases in article 7 (or the narrower article 11 bases for sensitive data). Consent should not be the default, assess whether a more stable basis is appropriate, and document the reasoning.
04
Update privacy notices and consent mechanisms
Your privacy notice must disclose your identity, the DPO’s contact details, purposes and legal bases, third-party sharing, international transfer mechanisms, and how to exercise rights. Consent must be free, informed, unambiguous, and specific.
05
Appoint a DPO and publish their contact details
Appoint a DPO as required by article 41 and Resolution CD/ANPD 18/2024. Publish their identity and a contact channel. Consider a Brazil-based DPO or engaging a local service provider for practical effectiveness.
06
Put international transfer mechanisms in place
If you transfer Brazilian personal data outside Brazil, implement ANPD-approved SCCs with relevant counterparties. The SCC grace period ended 23 August 2025; transfers without a valid mechanism are unlawful from that date. Multinationals may consider Global Corporate Rules for intragroup transfers.
07
Enter into data processing agreements with processors
Identify vendors and third parties processing Brazilian personal data on your behalf. Enter into data processing agreements (article 39) specifying authorised processing, required security measures, and breach notification obligations.
08
Implement security measures and a breach response plan
Article 46 requires appropriate technical and administrative security measures. Establish an incident response process capable of notifying the ANPD within 72 hours and affected data subjects without undue delay.
09
Build data subject rights response processes
Implement processes to identify, log, and respond to requests across all nine categories of rights under article 18. Responses must be within a reasonable period (best practice: 15 days), free of charge, and clear.
10
Train staff and maintain ongoing compliance
LGPD compliance is not a one-off exercise. Provide regular training, monitor ANPD guidance on AI, biometrics, and sector-specific rules, and review your compliance programme at least annually.
Our Team

Data privacy expertise: acting for multinationals with international data transfers

Vanessa Borges
Vanessa Borges
Partner

Vanessa Borges is a partner at Deffenti Lawyers with a focus on data privacy, corporate law and international matters. Before joining the firm, Vanessa worked for the world’s largest search engine company, representing and advising clients on data security, privacy, civil liability on the internet and deceptive practices on social media platforms, giving her direct, practical experience of how data protection issues arise in real-world digital operations.

Vanessa holds an LLM from Penn State Law (Pennsylvania, USA) and a law degree from Mackenzie University in São Paulo. She is co-author, with Fabiano Deffenti, of our article on Brazil’s international data transfer regulations compared with the GDPR, published on LawsofBrazil.

Deffenti Lawyers assists companies with LGPD compliance programmes, data protection impact assessments, privacy policies, DPO services, international data transfer agreements and regulatory matters before the ANPD.

Contact Us

Need advice on your specific situation?

LGPD compliance requirements depend on your processing activities, business model, and sector. Contact us for advice tailored to your organisation.

Contact Us

This guide provides general information on Brazil’s Lei Geral de Proteção de Dados (Law 13,709/2018) and related ANPD regulations as at the date of publication. It does not constitute legal advice and should not be relied upon as such. Data protection rules and ANPD guidance change frequently; always verify current requirements with a qualified Brazilian lawyer before acting. Deffenti Lawyers accepts no liability for any action taken or not taken in reliance on the contents of this guide.

Deffenti Lawyers

Brazilian lawyers for foreign companies, investors and law firms.

São Paulo
Rua Quintana, 887/32
São Paulo SP 04569-011, Brazil
+55 11 5505 2485
info@deffenti.com
Brisbane
Level 34, 1 Eagle Street
Brisbane QLD 4000, Australia
+61 7 3040 9301
info@deffenti.com
Links
Legal Guides Practice Areas Team Terms of Use