The honest way to read the LGPD is as a GDPR fork with Brazilian patches, and the compliance risk lives entirely in the patches. Programs that stamp “GDPR-ready” onto Brazil miss the four grounds that do not exist in Europe, the response clock that is half as long, the DPO that must be published regardless of headcount, and the transfer clauses that must be Brazilian. The ANPD’s enforcement record so far, a symbolic first fine, then a suspension order against Meta, signals a regulator that reads its own rulebook literally.
| Dimension | GDPR | LGPD |
|---|---|---|
| Lawful bases | 6 | 10 (Article 7) |
| Full DSR response | 1 month | 15 days |
| DPO | Conditional | Mandatory, published |
| Transfers | EU SCCs, adequacy, BCRs | Brazilian SCCs (Res. 19/2024), adequacy, BCNs |
| Max fine | 4% worldwide turnover | 2% Brazil revenue, R$50M cap |
| Breach clock | 72 hours | 3 working days (Res. 15/2024) |
Converting a GDPR program into LGPD coverage
Diff, don’t duplicate. Extend the GDPR RoPA with an LGPD-basis column using the ten-bases guide, then close the six deltas above in order of enforcement visibility: published DPO first (checkable from outside), transfers second, clocks third.
Fix the paper that must be Brazilian. Transfer instruments under Resolution 19/2024 and the encarregado designation are the two items where EU documents categorically fail.
Foreign controllers: scope before build. The US-company guide covers when the offering-to-Brazil trigger fires, and the full LGPD guide and roadmap sequence the build.
Your Brazilian visitors’ consent banner and tracker behavior are the externally visible edge of all of this: check them with a free scan.