Brazil’s privacy law follows the data — and expects you to document every decision.
Brazil’s LGPD governs how organizations collect, use, share, retain, secure, and transfer personal data. Captain Compliance connects Brazilian Portuguese consent experiences, tracker controls, privacy notices, data-subject rights, impact assessments, incident workflows, and accountability evidence in one operating program.
LGPD compliance requires more than collecting consent.
The LGPD may apply regardless of where an organization is headquartered when processing occurs in Brazil, goods or services are offered to people located in Brazil, or data of individuals located in Brazil is processed. Applicability turns on processing circumstances and location, not citizenship alone.
Consent is only one of the LGPD’s legal bases. Organizations must identify and document the appropriate basis for each purpose, such as contractual necessity, legal obligation, legitimate interests, or another permitted basis.
Data subjects can exercise rights involving confirmation, access, correction, portability, deletion, anonymization, blocking, information about sharing, consent withdrawal, and qualifying automated decisions.
The ANPD can investigate and impose corrective measures or sanctions. Controllers and operators may also face claims for material, moral, individual, or collective damages when statutory conditions are established.
Turn LGPD obligations into repeatable workflows.
Captain Compliance connects Brazilian Portuguese experiences, tracker controls, lawful-basis records, rights workflows, transfer governance, and incident evidence in one coordinated program.
Consent and preference management
Brazilian Portuguese banners with accept, reject, and customize controls. Purpose-specific consent, withdrawal, versioned consent receipts, geolocation-based experiences, and blocking rules for configured technologies.
Cookie and tracker monitoring
Detect cookies, pixels, SDKs, and scripts, identify third-party technologies, monitor new and changed trackers, and flag technologies firing outside the intended consent state. The LGPD does not state that every cookie always requires consent; the ANPD’s cookie guidance recognizes that consent and legitimate interests are both commonly relevant, while other legal bases may apply in appropriate circumstances.
Brazilian Portuguese privacy notices
Explain processing purposes, identify relevant legal bases, describe sharing and international transfers, publish data-subject rights, and provide encarregado contact information, with versions and changes documented.
Data-subject request workflows
Support confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, consent withdrawal, and automated-decision requests. A complete access response generally must be supplied within 15 days; not every right carries the same deadline.
Lawful-basis documentation
Record the purpose of processing, assign the relevant statutory basis, document legitimate-interest assessments, connect vendors and data categories, track retention and deletion rules, and preserve approvals and changes.
Impact assessments — RIPD
Relatório de Impacto à Proteção de Dados Pessoais. Document processing descriptions, risk identification, fundamental-rights analysis, safeguards, mitigation, ownership, and review evidence. The ANPD can require an RIPD in specified circumstances; not every processing activity automatically requires one.
International-transfer governance
Address adequacy decisions, standard contractual clauses, specific contractual clauses, binding corporate rules, and other permitted LGPD mechanisms under Resolution CD/ANPD No. 19/2024, with vendor and destination documentation, transfer records, and assessments.
Security incidents and accountability
Incident intake, risk and relevant-damage assessment, three-business-day deadline tracking, ANPD and data-subject notification, evidence and remediation records, escalation to the encarregado and management, and ongoing governance documentation.
One deployment for Brazil and your broader global program.
Detect trackers, collection points, vendors, technologies, and unexpected website changes. Decide by connecting every processing purpose to an appropriate legal basis, consent state, retention rule, and accountable owner. Demonstrate by preserving notices, consent receipts, assessments, rights responses, transfer records, incident decisions, and remediation evidence. Geolocation can help deliver a Brazil-specific experience, but geolocation alone does not determine whether the LGPD applies.
Book a LGPD privacy audit- Day 1 — Discover — Scan websites and identify cookies, trackers, forms, vendors, and data flows involving people located in Brazil
- Week 1 — Classify — Document processing purposes, data categories, sensitive data, legal bases, vendors, and international transfers
- Week 2 — Control — Configure Portuguese consent experiences, preference controls, blocking rules, and heightened safeguards for sensitive processing
- Week 3 — Publish — Deploy the privacy notice, cookie disclosures, rights-request channel, and encarregado contact information
- Week 4 — Operationalize — Implement data-subject requests, RIPDs, transfer records, incident workflows, and governance documentation
- Ongoing — Monitor — Detect tracker changes, review new vendors, update notices, reassess legal bases, and preserve evidence
From fragmented data handling to documented accountability.
- Unknown Brazilian website trackers
- English-only generic banner
- Consent treated as the only legal basis
- Rights requests handled through email
- No international-transfer inventory
- Encarregado information difficult to locate
- Incidents handled without deadline controls
- High-risk processing launched informally
- Continuously maintained tracker inventory
- Brazilian Portuguese consent experience
- Purpose-by-purpose lawful-basis records
- Verified and tracked request workflows
- Transfer mechanisms and vendors documented
- Published communication channel
- Three-business-day notification workflow
- Documented RIPDs, safeguards, and approvals
Brazil’s LGPD, answered plainly.
What is Brazil’s LGPD?+
Does the LGPD apply to companies outside Brazil?+
Does the LGPD apply because someone is a Brazilian citizen?+
Does the LGPD require consent for every cookie?+
What are the LGPD’s ten legal bases?+
What rights do Brazilian data subjects have?+
Does every organization need an encarregado or DPO?+
When must a security incident be reported?+
How can personal data be transferred outside Brazil?+
What penalties and civil claims can arise under the LGPD?+
Make LGPD accountability part of how your organization actually handles data.
Connect Brazilian Portuguese consent, tracker monitoring, legal bases, privacy notices, rights requests, impact assessments, international transfers, incidents, and evidence in one coordinated privacy program.
Book a Brazil privacy review Start for free