Latin America Brazil

LGPD for US Companies: When Brazil's Law Reaches You

How Brazil's LGPD applies to US businesses with no Brazilian entity: extraterritorial triggers, the required DPO, transfer paperwork, and enforcement exposure.

Regulation

LGPD Article 3 extraterritorial scope (Law No. 13.709/2018)

Max Penalty

Up to 2% of Brazil-sourced revenue, capped at R$50 million per infraction; blocking or deletion of Brazilian data

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD); Brazilian courts and consumer bodies

Official Source

www.gov.br

Executive Summary

  • LGPD Article 3 reaches any processing (a) carried out in Brazil, (b) related to offering goods or services to individuals located in Brazil, or (c) of personal data collected in Brazil, with no revenue or volume threshold.
  • A US company is covered by shipping to Brazil, running a Portuguese-language storefront, pricing in reais, serving Brazilian users of an app, or buying data collected from Brazilian users, physical presence is irrelevant.
  • Coverage brings the full obligation set: ten lawful bases, 15-day data subject responses, a published DPO (encarregado), Brazilian transfer instruments, and 3-working-day breach notification.
  • Enforcement against foreign companies is practical, not theoretical: the ANPD's 2024 order suspending Meta's AI training on Brazilian data was executed through the Brazilian market, and courts, prosecutors, and consumer bodies (Procons) provide additional tracks.
  • The proportionate posture for a US company is a Brazil module on the existing privacy program: scope memo, Portuguese notice layer, DPO designation, Brazilian SCCs, and the shortened clocks.

US companies discovered GDPR the expensive way in 2018; the LGPD is the same lesson with a Brazilian accent and, since 2023-2024, a regulator that finished its rulebook and started using it. The threshold question is rarely close, Portuguese storefront, reais pricing, Brazilian app users, any one suffices, so the useful work is not debating coverage but sizing the Brazil module: a published DPO, a Portuguese notice, Brazilian transfer clauses, and clocks roughly twice as fast as the ones your GDPR program runs on.

TriggerExample
Processing in BrazilBrazilian cloud region, local vendor
Offering to BrazilPortuguese site, reais/Pix, Brazil shipping
Collected in BrazilTrackers on Brazilian visitors, app telemetry
StatuteLGPD Art. 3

The Brazil module, in order

Write the scope memo first. Which products, entities, and data flows hit Article 3, with the offering-analysis documented; this memo is what turns every later decision into engineering rather than debate.

Close the visible gaps. Portuguese notice layer with real lawful bases, a published encarregado, and consent-gated trackers, the externally checkable items the ANPD’s first fine targeted.

Paper the transfers, both directions. Data flowing from Brazil to your US systems needs Brazilian SCCs under Resolution 19/2024; EU SCCs and DPF certification do not substitute.

Configure, don’t rebuild. The LGPD vs GDPR diff lists what your existing program must change; the roadmap sequences it, and the full guide covers the statute end to end.

Whether your site sets ad-tech identifiers on Brazilian visitors before consent is measurable right now: run a free scan.

Frequently Asked Questions

We have no Brazilian office or entity. Can the LGPD really apply?

Yes. Article 3 is activity-based, not establishment-based, the same design as GDPR Article 3. If your processing relates to offering goods or services to people located in Brazil, or the data was collected in Brazil (a visitor browsing from Sao Paulo counts as collection in Brazil), the law applies to that processing. What presence changes is enforcement mechanics, not coverage: the ANPD can still order blocking of processing, impose fines collectable against Brazilian revenue or partners, and Brazilian users can sue in Brazilian courts.

What signals 'offering to Brazil' versus incidental Brazilian traffic?

The analysis mirrors GDPR targeting doctrine: Portuguese-language content aimed at Brazil, pricing or payment in reais (including Pix or boleto support), shipping to Brazilian addresses, Brazil-specific marketing, app-store availability in Brazil with localized listings, and Brazilian customer support all indicate offering. A US-only store that happens to receive Brazilian visitors is weaker territory for coverage, though the 'collected in Brazil' prong can still capture analytics and tracking data from those visitors, which is why tracker governance matters even for non-targeting sites.

What is the minimum viable LGPD build for a US company?

Seven items: (1) a scope memo documenting which flows are covered; (2) a Portuguese privacy-notice layer stating purposes and LGPD bases; (3) a designated, published encarregado, outsourced DPO services satisfy this; (4) DSR handling on the immediate/15-day clocks; (5) Brazilian SCCs on flows leaving Brazil, including to yourself; (6) breach-response alignment to the ANPD's 3-working-day rule; (7) consent mechanics for trackers and marketing matching the LGPD's specific-consent standard. Most of it configures existing GDPR machinery rather than requiring new systems.

How would Brazilian enforcement actually reach a US company?

Four channels. The ANPD can sanction directly and, more practically, order Brazilian processing blocked or data deleted, orders that app stores, payment processors, and local partners end up implementing, the Meta AI-training suspension (2024) is the template. Brazilian public prosecutors and Procons bring civil actions with damages. Data subjects hold private rights under Articles 42-45 with joint liability. And commercial pressure: Brazilian enterprise customers increasingly demand LGPD paper (SCCs, DPO, RIPD) in procurement, making non-compliance a sales blocker before it is a legal one.

Do we need consent for cookies and analytics from Brazilian visitors?

Non-essential trackers need a lawful basis, and the ANPD's cookie guidance points to consent for advertising and analytics cookies, with legitimate interest defensible only for narrow measurement done with safeguards and a documented balancing test. The practical standard converges on GDPR-style prior consent: no ad-tech identifiers before an affirmative act by Brazilian visitors. Since the banner and tag behavior are externally observable, they are the likeliest first evidence in any complaint, geo-scoped consent for Brazil (or a global consent default) closes it.

Regulatory Crosswalk

GDPR Article 3CCPALGPD

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.