Latin America Brazil / EU

LGPD vs GDPR: Key Differences That Change Compliance

Where Brazil's LGPD diverges from the GDPR: lawful bases, response deadlines, DPO rules, transfer mechanisms, fines, and what a GDPR program must add for Brazil.

Regulation

LGPD (Law No. 13.709/2018) compared with GDPR (Regulation (EU) 2016/679)

Max Penalty

LGPD: 2% of Brazil revenue, capped at R$50 million per infraction; GDPR: 4% of worldwide turnover or EUR 20 million

Enforcing Authority

ANPD (Brazil); EU/EEA supervisory authorities

Official Source

www.gov.br

Executive Summary

  • The LGPD was drafted with the GDPR open on the desk: same controller/processor split, same rights skeleton, same extraterritorial trigger, which is why a GDPR program covers roughly 80% of Brazil.
  • The remaining 20% is where enforcement lives: ten lawful bases instead of six, a 15-day full-response clock instead of one month, a mandatory published DPO with no size threshold, and Brazilian transfer instruments (Resolution 19/2024) that EU SCCs do not satisfy.
  • Fine mechanics differ structurally: LGPD caps at 2% of Brazil-sourced revenue with an absolute R$50 million ceiling per infraction, versus GDPR's 4% of worldwide turnover, so Brazilian exposure is real but bounded.
  • The LGPD has no direct ePrivacy analogue: cookie and tracker rules derive from the general law plus ANPD's cookie guidance, and consent standards for trackers track the GDPR's in practice.
  • Breach notification differs: the ANPD's regulation sets a 3-working-day baseline (versus GDPR's 72 hours) and its own risk threshold for notifying data subjects.

The honest way to read the LGPD is as a GDPR fork with Brazilian patches, and the compliance risk lives entirely in the patches. Programs that stamp “GDPR-ready” onto Brazil miss the four grounds that do not exist in Europe, the response clock that is half as long, the DPO that must be published regardless of headcount, and the transfer clauses that must be Brazilian. The ANPD’s enforcement record so far, a symbolic first fine, then a suspension order against Meta, signals a regulator that reads its own rulebook literally.

DimensionGDPRLGPD
Lawful bases610 (Article 7)
Full DSR response1 month15 days
DPOConditionalMandatory, published
TransfersEU SCCs, adequacy, BCRsBrazilian SCCs (Res. 19/2024), adequacy, BCNs
Max fine4% worldwide turnover2% Brazil revenue, R$50M cap
Breach clock72 hours3 working days (Res. 15/2024)

Converting a GDPR program into LGPD coverage

Diff, don’t duplicate. Extend the GDPR RoPA with an LGPD-basis column using the ten-bases guide, then close the six deltas above in order of enforcement visibility: published DPO first (checkable from outside), transfers second, clocks third.

Fix the paper that must be Brazilian. Transfer instruments under Resolution 19/2024 and the encarregado designation are the two items where EU documents categorically fail.

Foreign controllers: scope before build. The US-company guide covers when the offering-to-Brazil trigger fires, and the full LGPD guide and roadmap sequence the build.

Your Brazilian visitors’ consent banner and tracker behavior are the externally visible edge of all of this: check them with a free scan.

Frequently Asked Questions

If we are GDPR compliant, what must we add for Brazil?

Six concrete deltas: (1) re-map lawful bases to the ten LGPD grounds, moving credit, litigation, health, and research processing to their named bases; (2) shorten the DSR clock, full access responses in 15 days; (3) appoint and publish an encarregado (DPO) regardless of company size, per Resolution 18/2024; (4) execute Brazilian transfer instruments under Resolution 19/2024, EU SCCs alone do not work; (5) align breach response to the ANPD's 3-working-day notification; (6) translate notices into Portuguese where you address the Brazilian public. Everything else largely inherits.

How do the lawful bases actually differ?

The LGPD's Article 7 adds credit protection, health protection, research, and judicial/administrative/arbitral proceedings to the GDPR's six. Legitimate interest exists in both but Brazil bars it entirely for sensitive data (GDPR handles sensitive data through Article 9 conditions instead). Consent standards are near-identical (free, informed, unambiguous, specific), but the LGPD demands 'specific and highlighted' consent for sensitive data and voids generic authorizations explicitly. Brazil's Article 20 automated-decision right is a review right, weaker than GDPR Article 22's qualified prohibition.

How do fines and enforcement posture compare?

GDPR: up to 4% of worldwide turnover, with cumulative fines against single companies exceeding EUR 2.7 billion (Meta alone), and 27+ national regulators enforcing. LGPD: up to 2% of Brazil revenue capped at R$50 million per infraction, one central regulator (ANPD) that started fining in 2023 and prefers preventive orders, the 2024 Meta AI-training suspension being the model. Brazil adds daily fines, mandatory publicization of the infraction, and data blocking or deletion, sanctions that can hurt more than the capped fine. Courts and consumer bodies (Procons, public prosecutors) provide a second enforcement track Brazil-side.

What are the breach-notification differences?

GDPR Article 33: notify the supervisory authority within 72 hours of awareness where there is risk, and data subjects without undue delay for high risk. LGPD Article 48 originally said 'reasonable time'; the ANPD's breach regulation (Resolution 15/2024) fixed it at 3 working days for incidents involving relevant risk or harm, with a prescribed content list, and communication to affected data subjects in the same window. The Brazilian form and risk analysis differ from EU templates, so incident-response runbooks need a Brazil branch, not just a CC to the DPO.

Can one privacy notice and one DSAR pipeline serve both?

One pipeline, two configurations. The notice needs a Brazil layer: Portuguese language for the Brazilian public, the LGPD basis per purpose (naming credit protection or proceedings where used), the encarregado's published contact, and Brazilian transfer mechanisms. The DSAR pipeline needs a jurisdiction switch on the clock (15 days versus one month) and on scope (LGPD includes an explicit right to information about the consequences of denying consent, and anonymization as a remedy). Companies that run the strictest-common-denominator, 15-day responses everywhere, avoid the switch entirely.

Regulatory Crosswalk

GDPRLGPDArgentina PDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.