US companies discovered GDPR the expensive way in 2018; the LGPD is the same lesson with a Brazilian accent and, since 2023-2024, a regulator that finished its rulebook and started using it. The threshold question is rarely close, Portuguese storefront, reais pricing, Brazilian app users, any one suffices, so the useful work is not debating coverage but sizing the Brazil module: a published DPO, a Portuguese notice, Brazilian transfer clauses, and clocks roughly twice as fast as the ones your GDPR program runs on.
| Trigger | Example |
|---|---|
| Processing in Brazil | Brazilian cloud region, local vendor |
| Offering to Brazil | Portuguese site, reais/Pix, Brazil shipping |
| Collected in Brazil | Trackers on Brazilian visitors, app telemetry |
| Statute | LGPD Art. 3 |
The Brazil module, in order
Write the scope memo first. Which products, entities, and data flows hit Article 3, with the offering-analysis documented; this memo is what turns every later decision into engineering rather than debate.
Close the visible gaps. Portuguese notice layer with real lawful bases, a published encarregado, and consent-gated trackers, the externally checkable items the ANPD’s first fine targeted.
Paper the transfers, both directions. Data flowing from Brazil to your US systems needs Brazilian SCCs under Resolution 19/2024; EU SCCs and DPF certification do not substitute.
Configure, don’t rebuild. The LGPD vs GDPR diff lists what your existing program must change; the roadmap sequences it, and the full guide covers the statute end to end.
Whether your site sets ad-tech identifiers on Brazilian visitors before consent is measurable right now: run a free scan.