Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / SOLUTIONS / LGPD · BRAZIL
LGPD · BRAZIL DATA PROTECTION

Brazil’s privacy law follows the data — and expects you to document every decision.

Brazil’s LGPD governs how organizations collect, use, share, retain, secure, and transfer personal data. Captain Compliance connects Brazilian Portuguese consent experiences, tracker controls, privacy notices, data-subject rights, impact assessments, incident workflows, and accountability evidence in one operating program.

Brazilian Portuguese experiencesLawful-basis workflowsDocumented accountability

LGPD compliance requires more than collecting consent.

Reach
Extraterritorial reach

The LGPD may apply regardless of where an organization is headquartered when processing occurs in Brazil, goods or services are offered to people located in Brazil, or data of individuals located in Brazil is processed. Applicability turns on processing circumstances and location, not citizenship alone.

10 bases
Every activity needs a legal basis

Consent is only one of the LGPD’s legal bases. Organizations must identify and document the appropriate basis for each purpose, such as contractual necessity, legal obligation, legitimate interests, or another permitted basis.

Rights
Rights must become operational

Data subjects can exercise rights involving confirmation, access, correction, portability, deletion, anonymization, blocking, information about sharing, consent withdrawal, and qualifying automated decisions.

ANPD
Administrative and civil exposure

The ANPD can investigate and impose corrective measures or sanctions. Controllers and operators may also face claims for material, moral, individual, or collective damages when statutory conditions are established.

Turn LGPD obligations into repeatable workflows.

Captain Compliance connects Brazilian Portuguese experiences, tracker controls, lawful-basis records, rights workflows, transfer governance, and incident evidence in one coordinated program.

C

Consent and preference management

Brazilian Portuguese banners with accept, reject, and customize controls. Purpose-specific consent, withdrawal, versioned consent receipts, geolocation-based experiences, and blocking rules for configured technologies.

S

Cookie and tracker monitoring

Detect cookies, pixels, SDKs, and scripts, identify third-party technologies, monitor new and changed trackers, and flag technologies firing outside the intended consent state. The LGPD does not state that every cookie always requires consent; the ANPD’s cookie guidance recognizes that consent and legitimate interests are both commonly relevant, while other legal bases may apply in appropriate circumstances.

N

Brazilian Portuguese privacy notices

Explain processing purposes, identify relevant legal bases, describe sharing and international transfers, publish data-subject rights, and provide encarregado contact information, with versions and changes documented.

D

Data-subject request workflows

Support confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, consent withdrawal, and automated-decision requests. A complete access response generally must be supplied within 15 days; not every right carries the same deadline.

B

Lawful-basis documentation

Record the purpose of processing, assign the relevant statutory basis, document legitimate-interest assessments, connect vendors and data categories, track retention and deletion rules, and preserve approvals and changes.

R

Impact assessments — RIPD

Relatório de Impacto à Proteção de Dados Pessoais. Document processing descriptions, risk identification, fundamental-rights analysis, safeguards, mitigation, ownership, and review evidence. The ANPD can require an RIPD in specified circumstances; not every processing activity automatically requires one.

T

International-transfer governance

Address adequacy decisions, standard contractual clauses, specific contractual clauses, binding corporate rules, and other permitted LGPD mechanisms under Resolution CD/ANPD No. 19/2024, with vendor and destination documentation, transfer records, and assessments.

I

Security incidents and accountability

Incident intake, risk and relevant-damage assessment, three-business-day deadline tracking, ANPD and data-subject notification, evidence and remediation records, escalation to the encarregado and management, and ongoing governance documentation.

One deployment for Brazil and your broader global program.

Detect trackers, collection points, vendors, technologies, and unexpected website changes. Decide by connecting every processing purpose to an appropriate legal basis, consent state, retention rule, and accountable owner. Demonstrate by preserving notices, consent receipts, assessments, rights responses, transfer records, incident decisions, and remediation evidence. Geolocation can help deliver a Brazil-specific experience, but geolocation alone does not determine whether the LGPD applies.

Book a LGPD privacy audit
A PRACTICAL ROLLOUT
  • Day 1 — Discover — Scan websites and identify cookies, trackers, forms, vendors, and data flows involving people located in Brazil
  • Week 1 — Classify — Document processing purposes, data categories, sensitive data, legal bases, vendors, and international transfers
  • Week 2 — Control — Configure Portuguese consent experiences, preference controls, blocking rules, and heightened safeguards for sensitive processing
  • Week 3 — Publish — Deploy the privacy notice, cookie disclosures, rights-request channel, and encarregado contact information
  • Week 4 — Operationalize — Implement data-subject requests, RIPDs, transfer records, incident workflows, and governance documentation
  • Ongoing — Monitor — Detect tracker changes, review new vendors, update notices, reassess legal bases, and preserve evidence

From fragmented data handling to documented accountability.

Before
  • Unknown Brazilian website trackers
  • English-only generic banner
  • Consent treated as the only legal basis
  • Rights requests handled through email
  • No international-transfer inventory
  • Encarregado information difficult to locate
  • Incidents handled without deadline controls
  • High-risk processing launched informally
After
  • Continuously maintained tracker inventory
  • Brazilian Portuguese consent experience
  • Purpose-by-purpose lawful-basis records
  • Verified and tracked request workflows
  • Transfer mechanisms and vendors documented
  • Published communication channel
  • Three-business-day notification workflow
  • Documented RIPDs, safeguards, and approvals

Brazil’s LGPD, answered plainly.

What is Brazil’s LGPD?+
The Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018, is Brazil’s general data protection law. It governs how organizations collect, use, share, retain, secure, and transfer personal data, sets out legal bases for processing, creates data-subject rights, and is enforced by the Agência Nacional de Proteção de Dados. It is a distinct statute with its own definitions, bases, and deadlines rather than a Brazilian version of another jurisdiction’s law.
Does the LGPD apply to companies outside Brazil?+
It can. The law defines its own territorial scope, which can reach processing carried out in Brazil, the offering of goods or services to people located in Brazil, and the processing of data of individuals located in Brazil. Being headquartered elsewhere does not by itself place an organization outside the law.
Does the LGPD apply because someone is a Brazilian citizen?+
No. Applicability turns on the processing circumstances and location rather than citizenship alone. A Brazilian citizen located abroad is not automatically within scope, and a person of any nationality located in Brazil may be.
Does the LGPD require consent for every cookie?+
No. Consent is one of several legal bases. The ANPD’s cookie guidance recognizes that consent and legitimate interests are both commonly relevant, and other bases may apply in appropriate circumstances. The correct approach depends on the technology, the purpose, and the data involved.
What are the LGPD’s ten legal bases?+
For ordinary personal data the law sets out consent; compliance with a legal or regulatory obligation; processing by the public administration; studies by a research body; contract performance or preliminary procedures; the exercise of rights in judicial, administrative, or arbitration proceedings; protection of life or physical safety; health protection; legitimate interests; and credit protection. Sensitive personal data is governed by a separate and narrower set of bases.
What rights do Brazilian data subjects have?+
Rights include confirmation that processing exists, access, correction of incomplete or inaccurate data, anonymization, blocking or deletion of unnecessary or non-compliant data, portability, deletion of data processed with consent, information about sharing, information about the consequences of refusing consent, consent withdrawal, and review of qualifying automated decisions. A complete access response generally must be supplied within 15 days, while other rights follow their own timelines.
Does every organization need an encarregado or DPO?+
Controllers must indicate an encarregado, who acts as the communication channel among the organization, data subjects, and the ANPD. The ANPD has issued regulations addressing appointment and publication, and simplified treatment or exemptions can apply to smaller processing agents. Whether and how the requirement applies should be assessed against current ANPD rules.
When must a security incident be reported?+
Not every incident triggers notification. The controller must notify the ANPD and affected data subjects when a security incident may result in relevant risk or damage. Qualifying notifications must be made within three business days. The assessment of relevance and the required content of the notification follow ANPD regulation.
How can personal data be transferred outside Brazil?+
Resolution CD/ANPD No. 19/2024 established Brazil’s international data transfer regulation and its standard contractual clauses. Permitted mechanisms include adequacy decisions, standard contractual clauses, specific contractual clauses, binding corporate rules, and other bases set out in the LGPD. Organizations should document the mechanism relied on, the destination, and the vendors involved.
What penalties and civil claims can arise under the LGPD?+
The ANPD may apply administrative sanctions including warnings, fines of up to 2% of revenue in Brazil for the preceding financial year excluding taxes and capped at R$50 million per infraction, daily fines, publicizing the infraction, and blocking, deleting, suspending, or prohibiting processing. These are maximums applied according to the circumstances rather than automatic amounts. Separately, controllers and operators may face civil claims for material, moral, individual, or collective damages when the statutory conditions are established.

Make LGPD accountability part of how your organization actually handles data.

Connect Brazilian Portuguese consent, tracker monitoring, legal bases, privacy notices, rights requests, impact assessments, international transfers, incidents, and evidence in one coordinated privacy program.

Book a Brazil privacy review Start for free