LGPD
acronymprivacygovernance & risk
Lei Geral de Proteção de Dados: Brazil's general data protection law (13.709/2018), governing personal data processing on GDPR-inspired principles with Brazilian teeth.
In force since 2020, sanctions since 2021, enforced by the ANPD; legal bases include consent and legitimate interest.
The LGPD is Brazil's general data protection law, in force since 2020 and closely modelled on the GDPR. It applies to any processing of personal data of people in Brazil, regardless of where the processing organization sits, which is the extraterritorial reach that makes it relevant to companies with no Brazilian presence.
The structure will look familiar to anyone who has worked with the European regime. Processing requires a legal basis, of which consent is only one and often not the most appropriate. Data subjects hold rights of access, correction, portability, and deletion. Controllers and operators have distinct obligations, and the ANPD is the supervisory authority with enforcement powers including fines calculated against Brazilian revenue.
The differences matter more than the similarities in practice. The Brazilian law lists more legal bases than the European one, including protection of credit, and it interacts with a large body of existing Brazilian consumer and civil law rather than replacing it. Treating an existing GDPR programme as automatically sufficient is the common mistake: the shape transfers, the specifics do not, and the supervisory authority is a different institution with its own priorities.