One-Line Definition
The Lei Geral de Proteção de Dados (LGPD) is Brazil's comprehensive data protection law — Law No. 13,709/2018 — that governs how organizations collect, process, store, and transfer personal data belonging to individuals in Brazil, regardless of where the organization itself is located.
Real-Life Analogy: The "Data Passport Control"
Imagine every piece of personal data in Brazil as a traveler passing through an international airport. Before any traveler (data) can move, the airline (data controller) must:
1. Show a valid reason for travel — a legal basis for processing.
2. Declare the destination — a specific, explicit purpose.
3. Pass through security — consent or another lawful ground, plus transparency to the traveler.
4. Have a return ticket — data minimization and deletion obligations.
5. Obey customs at both ends — rules apply whether the data stays in Brazil or is transferred abroad.
The LGPD is that entire airport authority. It doesn't ban travel — it regulates it. And critically, it controls *every flight*, even those operated by foreign carriers flying into Brazilian airspace (i.e., foreign companies processing Brazilian users' data).
Core Formula
The LGPD can be reduced to a working formula for compliance teams:
**LGPD Compliance = (Lawful Basis + Purpose Limitation + Data Subject Rights) × (Accountability + Security) − Unlawful Transfers**
In practice, this breaks into 10 legal bases for processing (Article 7), 18 data subject rights (Article 18), and mandatory breach notification within a reasonable timeframe (ANPD guidance points to 3 business days for serious incidents).
Key numbers to remember:
| Metric | Value |
|---|---|
| Law enacted | August 14, 2018 (Law 13,709/2018) |
| Effective date | September 18, 2020 |
| Maximum administrative fine | 2% of Brazilian group revenue, capped at R$50 million per infraction |
| Legal bases for processing | 10 |
| Data subject rights | 18 |
| ANPD created | 2019 (provisional), made permanent in 2020 |
Comparison with Related Terms
| Framework | Jurisdiction | Scope | Max Penalty | Key Distinction from LGPD |
|---|---|---|---|---|
| **LGPD** | Brazil | Any org processing Brazilian residents' data | 2% revenue / R$50M per violation | 10 legal bases; ANPD enforcement; extraterritorial like GDPR but with unique "legitimate interest" carve-outs |
| **GDPR** | EU/EEA | Any org processing EU residents' data | €20M or 4% global revenue | LGPD was modeled on GDPR but adds "credit protection" and "health" as sensitive categories |
| **CCPA/CPRA** | California, USA | For-profit businesses meeting thresholds | $2,500–$7,500 per violation | Opt-out model vs. LGPD's opt-in consent for most processing |
| **PIPL** | China | Orgs processing Chinese residents' data | Up to 5% of prior year revenue | Requires data localization for critical data; LGPD allows transfers with safeguards |
| **POPIA** | South Africa | Orgs processing South African data | Up to ZAR 10M or imprisonment | Similar GDPR lineage; LGPD has stronger ANPD enforcement teeth |
Use Cases
1. A U.S. SaaS company onboarding Brazilian customers.
Even with no physical presence in Brazil, if the platform collects names, emails, or usage data from Brazilian users, LGPD applies. The company must appoint a Data Protection Officer (DPO), publish a Portuguese-language privacy notice, and honor deletion requests within 15 days.
2. Cross-border data transfers for HR.
A German manufacturer with a São Paulo subsidiary wants to send employee payroll data to its Frankfurt HQ. LGPD requires either Standard Contractual Clauses (SCCs), Binding Corporate Rules, or explicit consent — plus a transfer impact assessment.
3. Marketing automation and consent.
A Brazilian e-commerce brand running email campaigns must obtain granular, revocable consent for marketing. Pre-checked boxes are invalid. Consent must be logged with timestamp, purpose, and scope.
4. Data breach response.
If a hacker exposes 10,000 customer records, the company must notify the ANPD and affected individuals within a reasonable period (ANPD's guidance: 3 business days for high-risk incidents), document the incident, and demonstrate remediation.
5. AI training datasets.
A fintech using Brazilian transaction data to train credit-scoring models must ensure a lawful basis (likely "credit protection" under Article 7, X), conduct a data protection impact assessment, and offer opt-out mechanisms for automated decisions.
Misconceptions
Misconception 1: "LGPD only applies to companies based in Brazil."
False. Article 3 explicitly applies to any organization processing data *in Brazil*, regardless of where the company is headquartered. If your website is accessible in Portuguese and collects Brazilian user data, you are in scope.
Misconception 2: "Consent is always required."
False. LGPD provides 10 legal bases — consent is just one. Legitimate interest, contract performance, legal obligation, and credit protection are equally valid. This mirrors GDPR but with Brazil-specific categories.
Misconception 3: "The ANPD is toothless."
False. Since becoming a permanent authority in 2020, the ANPD has issued fines, published guidelines, and collaborated with international regulators. Fines can reach R$50 million per infraction, and reputational damage in Brazil's active consumer-protection ecosystem is often worse.
Misconception 4: "LGPD is just GDPR in Portuguese."
False. While 70%+ of the text is GDPR-inspired, LGPD differs on: legal bases (10 vs. 6), breach notification timelines (reasonable vs. 72 hours), DPO requirements (broader), and the treatment of anonymized data (LGPD's definition is stricter). Treating them as identical creates compliance gaps.
Misconception 5: "Small businesses are exempt."
False. There is no blanket SME exemption. The ANPD may issue simplified rules for small businesses, but the law's core obligations apply to all controllers and processors.
Related Terms
- ANPD (Autoridade Nacional de Proteção de Dados) — Brazil's data protection authority, responsible for enforcement, guidance, and sanctions.
- Dado Pessoal — Personal data: any information relating to an identified or identifiable natural person.
- Dado Sensível — Sensitive data: racial/ethnic origin, religious belief, political opinion, health, biometrics, genetic data, and sexual orientation.
- Titular — Data subject: the individual to whom the personal data relates.
- Controlador / Operador — Controller / Processor: the entity deciding processing purposes vs. the entity processing on behalf of the controller.
- Encarregado (DPO) — Data Protection Officer: mandatory point of contact between controller, data subjects, and ANPD.
- Transferência Internacional de Dados — International data transfer: governed by Articles 33–36, requiring adequacy, SCCs, or consent.
- Relatório de Impacto à Proteção de Dados (RIPD) — Data Protection Impact Assessment: required for high-risk processing.
- GDPR — EU General Data Protection Regulation: the primary inspiration for LGPD.
- Marco Civil da Internet — Brazil's Internet Civil Rights Framework: complementary law governing internet use, often cited alongside LGPD.
Bottom line: The LGPD is not a checkbox exercise. It is a living compliance framework that treats personal data as a protected asset, imposes extraterritorial reach, and carries penalties significant enough to reshape how global companies architect their data operations in Latin America's largest market.