Latin America Brazil

LGPD DPO (Encarregado): Appointment Rules and Duties

Brazil's encarregado requirement under ANPD Resolution 18/2024: who must appoint one, publication duties, permitted outsourcing, and small-business relief.

Regulation

LGPD Article 41 (Law No. 13.709/2018); ANPD Resolution CD/ANPD No. 18/2024

Max Penalty

Failure to appoint a DPO contributed to the ANPD's first-ever fine (Telekall, 2023); sanctions reach 2% of Brazil revenue capped at R$50 million

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD)

Official Source

www.gov.br

Executive Summary

  • Every controller must appoint an encarregado (DPO) under LGPD Article 41, with no size, sector, or volume threshold, broader than the GDPR's conditional duty.
  • The appointee's identity and contact information must be published, clearly and objectively, typically on the controller's website, making non-appointment externally verifiable in seconds.
  • ANPD Resolution 18/2024 formalized the role: the encarregado can be an individual or a legal entity (outsourced DPO services are expressly permitted), internal or external, Brazil-resident or not, appointed by a documented formal act.
  • Duties: receive and respond to data subject requests, receive ANPD communications, train staff, and advise on LGPD compliance; the controller must give the encarregado the means to work and must not create conflicts of interest.
  • Small processing agents (Resolution 2/2022) escape the mandatory appointment but must still publish a contact channel for data subjects, and appointing one anyway counts as a good-practice credit in sanction dosimetry.

The encarregado is the LGPD’s most visible obligation and its cheapest fix: a required, published point of contact that any regulator, journalist, or plaintiff can check by loading your website. Brazil made the duty universal where Europe made it conditional, then, in Resolution 18/2024, made it flexible: outsourced, shared, foreign, individual or firm, so the absence of one is hard to excuse. The first company the ANPD ever fined was cited for exactly this.

ProvisionLGPD Art. 41; ANPD Resolution 18/2024
WhoAll controllers (small agents: contact channel instead)
FormIndividual or legal entity; internal or outsourced
PublicationIdentity + contact, easily accessible
Core dutiesDSR intake, ANPD interface, staff orientation

Standing the role up properly

Appoint by formal act, publish immediately. A documented appointment plus a monitored contact on the privacy notice closes the externally visible gap; wire the same inbox into the 15-day DSR pipeline so publication and performance match.

Choose for autonomy, not seniority. Legal, compliance, or an outsourced specialist beats a conflicted product executive; document the conflict analysis either way.

Give the role teeth. Access to the data map and lawful-basis register, sign-off on RIPDs, a training calendar, and a direct line to leadership, the elements Resolution 18/2024 expects the controller to guarantee.

Foreign controllers included. No Brazilian entity does not mean no encarregado; see the US-company guide and the LGPD vs GDPR comparison for how the duty differs from Article 37 practice.

Whether your DPO contact is actually published and reachable is checkable from outside, along with your consent behavior: run a free scan.

Frequently Asked Questions

Who exactly must appoint an encarregado?

All controllers processing personal data under the LGPD, Brazilian or foreign, of any size, except small processing agents (micro-enterprises, small businesses, and startups as defined in Resolution 2/2022) who may substitute a published contact channel. Processors (operadores) are not required to appoint one, but the ANPD recommends it and Resolution 18/2024 contemplates it. A foreign company with no Brazilian entity but in-scope processing still needs one; nothing requires Brazilian residency or Portuguese nationality, though the role must actually function for Portuguese-speaking data subjects.

Can the DPO be outsourced or shared?

Yes. Resolution 18/2024 expressly allows a legal entity to serve as encarregado, so DPO-as-a-service firms and law firms can hold the role, and one person or entity can serve multiple companies if capacity and conflicts are managed. The appointment must be by formal documented act (board resolution, contract), and the controller remains responsible for giving the encarregado autonomy, resources, and direct access to the highest management level. What cannot be outsourced is accountability: sanctions land on the controller.

What must be published, and where?

The identity (name of the individual or entity) and contact information of the encarregado, in a clear, objective, and easily accessible way, in practice, on the privacy notice or a dedicated page of the controller's website. Email is the minimum viable channel; it must be monitored, because it is the intake for both data subject requests on the 15-day clock and ANPD communications. An unpublished or dead DPO contact is the single easiest LGPD violation for anyone to detect, and it featured in the ANPD's first sanction.

What are the encarregado's legal duties?

Article 41(2) lists four: accept complaints and communications from data subjects, provide clarifications, and take action; receive communications from the ANPD and take action; orient employees and contractors about data protection practices; and perform other duties set by the controller or in complementary rules. Resolution 18/2024 adds that the controller must ensure the encarregado can act with technical autonomy and without conflict of interest, the executive who owns the data-monetization P&L is a poor choice. It is an advisory and interface role; operational compliance stays with the business.

What are the conflict-of-interest rules?

Resolution 18/2024 requires controllers to prevent conflicts: the encarregado should not hold positions where they decide the purposes and means of the processing they would be reviewing (CEO, CTO, head of marketing are the classic problem cases). Where a potential conflict exists it must be managed and documented. For outsourced DPOs, the entity must manage conflicts across its client base. The dosimetry regulation treats governance failures as aggravating factors, so a paper DPO with an obvious conflict can worsen an otherwise routine sanction.

Regulatory Crosswalk

GDPR Articles 37-39LGPD

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.