Latin America Brazil

Brazil LGPD: Compliance Guide to Law 13.709/2018

Brazil's LGPD explained: who is covered, the ten lawful bases, data subject rights, ANPD enforcement including the Meta AI order, and fines up to 2% of Brazil revenue.

Regulation

Lei Geral de Protecao de Dados (Law No. 13.709/2018), in force September 2020, sanctions since August 2021

Max Penalty

Up to 2% of the group's Brazil revenue, capped at R$50 million per infraction, plus daily fines, publicization, blocking, and deletion orders

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD)

Official Source

www.gov.br

Executive Summary

  • The LGPD applies to any processing carried out in Brazil, offering goods or services to people in Brazil, or using data collected in Brazil, regardless of where the processor sits, an extraterritorial scope modeled on the GDPR's.
  • It recognizes ten lawful bases (Article 7), four more than the GDPR, including credit protection and research; sensitive data (Article 11) runs on a shorter list.
  • Data subjects hold nine enumerated rights (Article 18), responded to in simplified form immediately or in full within 15 days, a tighter clock than GDPR's one month.
  • The ANPD moved from structuring to enforcing: its first fine came in July 2023, its sanction-calculation regulation (Resolution 4/2023) is in force, and its July 2024 order suspending Meta's use of Brazilian personal data for AI training showed it will act against the largest platforms.
  • Penalties reach 2% of Brazil-sourced group revenue per infraction, capped at R$50 million, alongside publicization of the violation, and blocking or deletion of the data involved.

The LGPD is the GDPR’s most consequential export: a full-scope, extraterritorial data protection law covering Latin America’s largest economy, now paired with a regulator that has finished writing its rulebook and started using it. The 2023-2024 shift was decisive, first fine, sanction dosimetry, transfer rules, DPO regulation, and an order stopping Meta’s AI training, which means “Brazil compliance” is no longer a paper exercise stapled to a GDPR program. The structures are similar; the details (ten bases, 15-day clocks, Brazilian SCCs, published DPO) are not.

LawLGPD, Law No. 13.709/2018
In forceSeptember 18, 2020 (sanctions August 1, 2021)
RegulatorANPD
Max fine2% of Brazil revenue, cap R$50M per infraction
Rights clockImmediate (simplified) / 15 days (full)

Building the Brazil layer of a global program

Start from GDPR, then diff. The LGPD vs GDPR comparison maps the deltas: ten lawful bases instead of six, 15-day access responses, a published encarregado, and Brazilian transfer mechanisms that EU paperwork does not satisfy.

Sequence the work. The compliance roadmap orders it: applicability analysis, data mapping with lawful-basis assignment, notice and consent rework, rights intake on the 15-day clock, DPO designation and publication, transfer instruments, incident response with ANPD notification (3 working days per Resolution 15/2024), and RIPD (impact reports) for high-risk processing.

US and other foreign companies: scope first. The extraterritorial guide covers when offering-to-Brazil is triggered and what a no-establishment compliance posture looks like.

Watch the ANPD’s docket, not just the statute. Resolutions now govern sanctions, transfers, DPOs, small agents, and breach notification; the Meta order shows preventive measures can arrive before any fine.

Brazilian visitors’ consent and tracker behavior are externally visible today: verify your site’s posture with a free scan.

Frequently Asked Questions

Who has to comply with the LGPD?

Any natural or legal person, private or public, that processes personal data: (a) in Brazil; (b) to offer goods or services to individuals located in Brazil; or (c) where the data was collected in Brazil. There are no revenue or volume thresholds. A US SaaS company with Brazilian users, a marketplace shipping to Brazil, and an analytics vendor processing Brazilian visitors' data are all covered. Exemptions cover personal, journalistic, academic, public-safety, and national-defense purposes only.

How do the ten lawful bases differ from GDPR's six?

The LGPD adds credit protection, health protection (in procedures by health professionals and entities), research by study bodies, and the exercise of rights in judicial, administrative, and arbitral proceedings to the familiar consent, contract, legal obligation, vital interests, public interest, and legitimate interest. Legitimate interest carries a documented balancing test the ANPD can demand (Article 10), and consent must be free, informed, unambiguous, and for specific purposes, with revocation as easy as granting. Sensitive data (Article 11) has its own narrower list without legitimate interest.

What are the response deadlines for data subject rights?

Article 18 rights, confirmation of processing, access, correction, anonymization or deletion, portability, information about sharing, information about the consequences of refusing consent, and consent revocation, must be answered immediately in simplified form or within 15 days for a full declaration (access requests). That is half the GDPR's clock. Requests are free of charge, and controllers must pass rectifications and deletions along to processors and third parties with whom data was shared.

What has the ANPD actually enforced?

The first sanction came in July 2023 against Telekall Infoservice (a microenterprise fined for processing without a lawful basis and failing to appoint a DPO), deliberately small to set precedent. Since then: the July 2024 preventive order suspending Meta's use of Brazilian users' posts for AI training (with daily fines for non-compliance, later resolved through remediation commitments), enforcement proceedings over breach notifications, and sanction dosimetry under Resolution 4/2023, which scales fines by revenue, severity, recidivism, and cooperation. State consumer bodies (Procons) and prosecutors add parallel LGPD-based actions.

Does the LGPD require a DPO, and what about international transfers?

Yes: every controller must appoint an encarregado (DPO), whose identity and contact details must be published; ANPD Resolution 18/2024 details the role, and small processing agents get relief under Resolution 2/2022 but must still designate a contact channel. International transfers were fully regulated by Resolution 19/2024: adequacy decisions, ANPD-approved standard contractual clauses (Brazilian SCCs, with a deadline in August 2025 to incorporate them into pre-existing contracts), binding corporate norms, and specific contractual guarantees. EU SCCs do not satisfy the Brazilian requirement by themselves.

Regulatory Crosswalk

GDPRCCPAArgentina PDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.