Back to Knowledge Hub

LGPD: Brazil's General Data Protection Law

·1 min read

Overview

Brazil's Lei Geral de Proteção de Dados (LGPD) took effect in September 2020. It can apply when processing occurs in Brazil, when goods or services are offered to people in Brazil or their data is processed there, or when personal data was collected in Brazil. The controller's headquarters can be elsewhere.

The LGPD is a distinct Brazilian framework administered by the ANPD; familiar GDPR concepts can be useful orientation, but the legal bases, rights, and procedures must be read on their own terms.

Key Principles

Purpose: Processing must be for legitimate, specific, and clearly communicated purposes.

Necessity: Only data strictly necessary for the stated purpose should be collected.

Transparency: Data subjects must receive clear and complete information about data processing.

Consent and Legal Bases

The LGPD provides ten legal bases for ordinary personal-data processing, including consent, contract, legal obligation, legitimate interests, and protection of credit. Consent is therefore not the default for every purpose. When used, it must be provided in writing or by another demonstrable means, relate to specific purposes, and be provable by the controller; generic authorizations are void.

Rights and revocation

People can request confirmation, access, correction, anonymization or deletion in relevant cases, information about sharing, and review-related remedies. Consent can be revoked at any time through a free and facilitated procedure. A website CMP can capture and communicate choices, while the broader rights workflow and processing inventory remain the controller's responsibility.

A
Artur WachelkaFounder & CEO

Building transparent consent infrastructure for the modern web.