The LGPD is the GDPR’s most consequential export: a full-scope, extraterritorial data protection law covering Latin America’s largest economy, now paired with a regulator that has finished writing its rulebook and started using it. The 2023-2024 shift was decisive, first fine, sanction dosimetry, transfer rules, DPO regulation, and an order stopping Meta’s AI training, which means “Brazil compliance” is no longer a paper exercise stapled to a GDPR program. The structures are similar; the details (ten bases, 15-day clocks, Brazilian SCCs, published DPO) are not.
| Law | LGPD, Law No. 13.709/2018 |
|---|---|
| In force | September 18, 2020 (sanctions August 1, 2021) |
| Regulator | ANPD |
| Max fine | 2% of Brazil revenue, cap R$50M per infraction |
| Rights clock | Immediate (simplified) / 15 days (full) |
Building the Brazil layer of a global program
Start from GDPR, then diff. The LGPD vs GDPR comparison maps the deltas: ten lawful bases instead of six, 15-day access responses, a published encarregado, and Brazilian transfer mechanisms that EU paperwork does not satisfy.
Sequence the work. The compliance roadmap orders it: applicability analysis, data mapping with lawful-basis assignment, notice and consent rework, rights intake on the 15-day clock, DPO designation and publication, transfer instruments, incident response with ANPD notification (3 working days per Resolution 15/2024), and RIPD (impact reports) for high-risk processing.
US and other foreign companies: scope first. The extraterritorial guide covers when offering-to-Brazil is triggered and what a no-establishment compliance posture looks like.
Watch the ANPD’s docket, not just the statute. Resolutions now govern sanctions, transfers, DPOs, small agents, and breach notification; the Meta order shows preventive measures can arrive before any fine.
Brazilian visitors’ consent and tracker behavior are externally visible today: verify your site’s posture with a free scan.