Data Protection Matters
← All privacy laws

Brazil

LGPD

General Personal Data Protection Law (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018)

Keywords

LGPDBrazilLei 13.709/2018personal datatitularcontroladoroperadorencarregadoANPDlegitimate interestconsentdata breachinternational transfersfinesRIPD
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Lei Geral de Proteção de Dados Pessoais (LGPD), Law No. 13.709 of 14 August 2018, is Brazil's comprehensive data protection law. It replaced a patchwork of sector rules with a single national framework, and it was heavily inspired by the EU's GDPR. Most of its provisions took effect in September 2020, and the administrative sanctions became enforceable in August 2021.

Who it applies to

The LGPD covers any processing of personal data by a person or organization, public or private, whatever the country of its headquarters or where the data is stored, provided that the processing takes place in Brazil, aims to offer goods or services to people in Brazil, or involves data collected in Brazil. It distinguishes the "controlador" (controller) from the "operador" (processor). Some uses are outside its scope, such as purely personal non-commercial use, journalism and, in large part, national security and criminal investigation.

Core principles

Processing must follow ten principles: purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability. In practice, organizations must collect only what they need for a stated, legitimate purpose, keep data accurate, protect it, and be able to show how they comply.

Every processing activity needs one of the ten legal bases listed in the law. These include consent, compliance with a legal obligation, performance of a contract, the regular exercise of rights in legal proceedings, protection of life or health, research, the legitimate interest of the controller or a third party, and credit protection. Sensitive personal data, such as health, biometrics, religion or political opinion, has a narrower list of permitted bases, and children's data has its own protections.

Individual rights

People (titulares) may ask a controller to confirm that it processes their data and to give them access to it. They may also ask to correct it, to anonymize, block or delete unnecessary or unlawfully processed data, to port it to another provider, to learn with whom it was shared, and to withdraw consent. People can also request review of decisions made solely by automated processing that affect their interests.

Key obligations

Controllers must keep records of their processing, apply security measures from the design stage, and appoint an "encarregado", the contact point for individuals and the regulator, whose identity must be published. The national authority may require a data protection impact report (RIPD) for higher-risk processing. A security incident that may cause relevant risk or harm to individuals must be reported to the authority and to the people affected within a reasonable period set by the authority.

International transfers

Personal data may leave Brazil only on specific grounds. These include transfer to a country or international body with an adequate level of protection, standard contractual clauses, binding corporate rules, approved certifications or codes of conduct, specific consent, and certain other cases listed in the law. The national authority issues the detailed rules, including approved contractual clauses.

Enforcement and penalties

The Autoridade Nacional de Proteção de Dados (ANPD) supervises and enforces the law, and individuals can also bring claims in court. Sanctions range from a warning to a fine of up to 2% of the company's revenue in Brazil, capped at R$50 million per infraction. The ANPD may also impose daily fines, publicize the infraction, block or delete the data involved, and suspend the processing activity.

The official text

The authoritative version is Lei nº 13.709/2018, published in Portuguese on the website of the Brazilian Presidency (Planalto), with later amendments incorporated in the compiled text. There is no official English version. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (Portuguese, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →