Privacy & Data Protection · Brazil
Lei Geral de Proteção de Dados (General Data Protection Law)
Brazil's general data protection law, closely modelled on the GDPR. It sets out lawful bases for processing, data subject rights and accountability obligations, enforced by the ANPD, Brazil's national data protection authority.
REGULATORAutoridade Nacional de Proteção de Dados (ANPD)
REGIONBrazil
EFFECTIVE18 September 2020
Who it applies to
- Organisations processing personal data of individuals in Brazil
- Both data controllers and data operators (processors)
- Organisations outside Brazil offering goods or services to people there
Key requirements
- A lawful basis for every processing activity
- Data Protection Impact Assessments (RIPD) for higher-risk processing
- Appointment of a data protection officer (Encarregado)
- Breach notification to the ANPD and affected individuals
- Accountability documentation demonstrating compliance
Maximum penaltyUp to 2% of Brazilian revenue per violation, capped at R$50 million per infraction
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates LGPD compliance
Continuous monitoring, evidence and reporting for LGPD — alongside every other framework you need to satisfy.