Latin America Brazil

LGPD Compliance Roadmap: From Data Map to ANPD-Ready

A sequenced LGPD implementation plan: applicability, data mapping, lawful bases, notices, 15-day DSR pipeline, DPO, transfers, breach response, and RIPD assessments.

Regulation

LGPD (Law No. 13.709/2018) and ANPD Resolutions 1/2021 through 19/2024

Max Penalty

Up to 2% of Brazil revenue, capped at R$50 million per infraction, plus publicization, blocking, and deletion orders

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD)

Official Source

www.gov.br

Executive Summary

  • An LGPD program has nine buildable components: applicability analysis, data map with basis assignment, notices, DSR pipeline on the 15-day clock, published DPO, transfer instruments, security and breach response, RIPD impact reports, and processor contracts.
  • The ANPD has now regulated most of the open questions: sanctions dosimetry (Resolution 4/2023), small agents (2/2022), DPO duties (18/2024), international transfers (19/2024), and breach notification (15/2024), so 'the rules aren't final' is no longer a defensible posture.
  • Sequencing matters because some items are externally visible (published DPO, notice, cookie behavior) and regulator-checkable in minutes, while others (data map, RIPD) only surface in an investigation.
  • Small processing agents (micro and small enterprises, startups) get simplified obligations under Resolution 2/2022, including a waiver of the full DPO duty, but must still offer a contact channel and meet the substantive rules.
  • The end state is producibility: when the ANPD asks, the data map, basis register, RIPD, transfer instruments, and breach log come out of a drawer, not a scramble.

LGPD implementation fails most often by ordering, not effort: months on a data map while the site runs consentless trackers and the DPO page returns 404, the two things the ANPD (or a prosecutor, or a Procon) can check before lunch. The roadmap below orders the work by external visibility first, investigation-readiness second, matching how Brazilian enforcement actually arrives.

PhaseDeliverable
1. ScopeApplicability memo; entity and flow list
2. Visible edgePortuguese notice, cookie/consent behavior, published DPO
3. InventoryData map + lawful-basis register
4. Rights15-day DSR pipeline with propagation
5. PaperTransfer instruments, operator contracts
6. Incidents3-working-day ANPD breach runbook
7. AssessmentsRIPD set for high-risk flows

Running the phases

Phase 2 before phase 3 is deliberate. The published encarregado, the Portuguese privacy notice naming real lawful bases, and tracker consent are what outsiders see; they are also what the ANPD’s first fine (Telekall, 2023) punished, no basis, no DPO.

Paper the borders early. If data leaves Brazil, Resolution 19/2024’s Brazilian SCCs had an August 2025 adaptation deadline for existing contracts; new vendor onboarding should demand them by default.

Make breach response Brazilian. Resolution 15/2024’s 3-working-day notification with prescribed content is tighter than most global runbooks assume; pre-draft the ANPD form. Foreign-headquartered companies should pair this with the US-company guide and the LGPD vs GDPR diff to avoid EU-reflex mistakes.

Phase 2’s external evidence, banner behavior, tracker timing, notice links, is exactly what a free scan checks: run one before the ANPD does the equivalent.

Frequently Asked Questions

Where should an LGPD program start?

Applicability and inventory. Confirm which entities and flows touch Brazil (processing in Brazil, offering to Brazil, or data collected in Brazil), then build the data map: systems, data categories, purposes, retention, recipients, and transfers. Assign one lawful basis per purpose as you map, not after, because basis choice drives notice language, consent tooling, and whether legitimate-interest balancing memos are needed. Everything downstream consumes this inventory.

What does the 15-day DSR pipeline need to handle?

The nine Article 18 rights: confirmation, access, correction, anonymization/blocking/deletion of unnecessary or noncompliant data, portability, deletion of consent-based data, information on sharing, information on the consequences of refusing consent, and revocation. Immediate simplified responses plus 15-day complete declarations for access. Intake must be free, accessible, and verify identity proportionately. Deletions and corrections propagate to processors and sharing partners, which the data map's recipient column makes tractable.

Do we need an RIPD (impact report), and when?

The RIPD (Relatorio de Impacto a Protecao de Dados) is the LGPD's DPIA. The ANPD can demand it at any time, and expects it for legitimate-interest processing, high-risk or large-scale processing, and sensitive data. Unlike the GDPR there is no exhaustive trigger list, so the defensible pattern is a screening question in the data map plus full RIPDs for the flows a regulator would ask about first: profiling, biometrics, children's data, large-scale sharing. A GDPR DPIA restructured to LGPD terminology satisfies it.

What do processor (operador) contracts require?

The LGPD makes operators directly liable for damage caused by noncompliant processing and binds them to controllers' instructions. Contracts should fix: processing scope and purposes, security measures, sub-operator authorization, breach notification to the controller in time to meet the 3-working-day ANPD clock, DSR assistance on the 15-day timeline, transfer instruments where the operator is abroad, and deletion or return at termination. Brazilian courts also apply joint liability provisions (Article 42), so indemnities matter more than under GDPR.

How do small businesses reduce the load?

Resolution 2/2022 gives micro-enterprises, small businesses, and startups simplified duties: no mandatory DPO (but a published contact channel is still required), simplified records, doubled deadlines for some obligations, and simplified breach communication. The substantive rules, lawful bases, rights, security, transfers, still apply in full. Companies near the threshold should document their classification; claiming small-agent status without qualifying is itself a violation the dosimetry regulation treats as aggravating.

Regulatory Crosswalk

GDPRISO 27701NIST Privacy Framework

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.