Latin America Brazil

LGPD Lawful Bases: Brazil's 10 Legal Grounds Explained

The LGPD's ten lawful bases for processing personal data, how they differ from GDPR's six, the legitimate-interest balancing test, and sensitive-data rules.

Regulation

LGPD Articles 7, 10, and 11 (Law No. 13.709/2018)

Max Penalty

Processing without a valid lawful basis: up to 2% of Brazil revenue, capped at R$50 million per infraction

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD)

Official Source

www.gov.br

Executive Summary

  • Article 7 lists ten lawful bases: consent, legal/regulatory obligation, public administration, research, contract, judicial/administrative/arbitral proceedings, protection of life, health protection, legitimate interest, and credit protection.
  • Credit protection, health protection, research, and proceedings are the four grounds with no direct GDPR equivalent; they exist because Brazil folded sectoral practices (credit scoring under the Positive Registry law, SUS health data flows) into the general law.
  • Legitimate interest (Article 10) requires a documented balancing test the ANPD can demand, and cannot be used for sensitive data.
  • Sensitive data (Article 11) runs on a shorter list, essentially consent or specific necessity grounds, with 'specific and highlighted' consent as the default.
  • The ANPD's first fine (Telekall, 2023) and its Meta AI-training order (2024) were both, at core, lawful-basis cases: processing that had no valid Article 7 or Article 11 ground.

Ten bases sound more permissive than six; in practice they are more precise. Brazil took the processing that European controllers wedge into “legitimate interest”, credit scoring, health flows, litigation, research, and gave each its own named ground with its own contours. What remains under legitimate interest then gets a sharper test, a documented balancing the ANPD can demand, and no access at all to sensitive data. The compliance craft is assignment: the right basis, per purpose, written down before processing begins.

ProvisionLGPD Articles 7, 10, 11
Bases10 for personal data; consent + necessity grounds for sensitive
Legitimate interestDocumented balancing; ANPD may demand RIPD; not for sensitive data
Unique groundsCredit protection, health protection, research, proceedings
Automated decisionsArticle 20 review right (credit scoring)

Assigning bases without creating debt

Map purposes, then choose. Every purpose in the data inventory gets one primary basis with a one-paragraph justification; legitimate-interest entries get the full balancing memo. This register is what turns an ANPD inquiry into document production instead of archaeology.

Reserve consent for real choices. Marketing, non-essential trackers, optional enrichment. Everything operational (delivery, security, accounting) belongs on contract, legal obligation, or legitimate interest, so a revocation never breaks the service.

Treat Article 11 as a separate regime. Sensitive-data flows (health forms, biometric login, diversity data) get their own inventory, specific-and-highlighted consent flows, and a check against the necessity grounds, with the fraud-prevention biometric basis read narrowly.

Sync with the global program. The mapping from GDPR bases is close but not one-to-one; the LGPD vs GDPR guide covers the diffs, and the US-company guide shows how the bases interact with extraterritorial scope. Transfers layer their own instruments on top (transfer guide).

Consent collection for Brazilian visitors is visible on your site now, banners, trackers, pre-checked boxes: audit it with a free scan.

Frequently Asked Questions

When is consent the right basis, and what does valid consent require?

Consent (Article 7(I)) fits where the person genuinely chooses: marketing, optional features, non-essential cookies. It must be free, informed, unambiguous, and for determined purposes, given in writing or by another demonstrable means, with a highlighted clause if written into a contract. Generic authorizations are void, revocation must be as easy as granting, and the burden of proof sits with the controller. Choosing consent when another basis fits better is a trap: revocation then strands the processing.

How does the legitimate-interest test work under Article 10?

Legitimate interest supports processing for the controller's or third parties' legitimate purposes, considering the data subject's legitimate expectations and fundamental rights. In practice the ANPD expects a documented LIA-style assessment: purpose legitimacy, necessity (only data strictly needed), balancing against the subject's expectations, and safeguards including transparency and opt-out. The ANPD can demand the impact report (RIPD) for legitimate-interest processing specifically. It is unavailable for sensitive data, which is the sharpest divergence from practice under GDPR Article 9's separate-condition model.

What is the credit-protection basis?

Article 7(X) permits processing for credit protection, covering credit analysis, scoring, and fraud prevention in lending, aligned with Brazil's Positive Registry (Cadastro Positivo) regime. It has no GDPR counterpart (EU credit scoring typically runs on legitimate interest or contract). It is not a blank check: purpose limitation, minimization, and the Article 18 rights still apply, and the LGPD's automated-decision provision (Article 20) gives data subjects a right to review of decisions made solely by automated processing, credit scoring being the canonical example.

How is sensitive data handled differently?

Article 11 covers racial or ethnic origin, religious conviction, political opinion, union or organization membership, health, sex-life, genetic, and biometric data. Processing requires specific and highlighted consent, or necessity under enumerated grounds (legal obligation, shared public-policy execution, research with anonymization where possible, rights in proceedings, protection of life, health protection, fraud prevention and safety in identification systems). No legitimate interest, no credit protection. Fraud-prevention biometrics get a basis GDPR lacks, but the ANPD reads it narrowly, identification-system integrity, not general convenience.

Do we need to assign one basis per processing activity, and can we change it later?

Assign one primary basis per purpose in the data map (the RoPA equivalent), documented before processing starts. Stacking multiple bases 'just in case' is discouraged: transparency duties (Article 9) mean the notice must state the real basis, and swapping bases after a consent revocation looks abusive to the ANPD. If purposes change, re-run the analysis and update notices; for consent-based processing, new purposes need new consent. The data map plus basis register is the first document the ANPD requests in an investigation.

Regulatory Crosswalk

GDPR Article 6GDPR Article 9CCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.