EnglishPortuguês
Brazil flag

Brazil

Brazil Data Privacy Laws: LGPD Compliance Guide (2026)

Independently fact-checked against primary sources (last audited June 19, 2026). · 9 primary sources cited on this page. How we verify our legal content

Brazil Data Privacy Laws: LGPD Compliance Guide (2026)

Frequently Asked Questions

Does the LGPD apply to foreign companies that process data of people in Brazil?

Yes. The LGPD has explicit extraterritorial reach. It applies to any organization, regardless of where it is located, that processes personal data of individuals in Brazil, offers goods or services to people in Brazil, or collects data from individuals physically located in Brazil. Foreign companies must comply with the same requirements as Brazilian organizations, including appointing a DPO and establishing mechanisms for data subject rights.

What did Brazil's Constitutional Amendment EC 115/2022 change for data protection?

EC 115/2022, enacted on February 10, 2022, added personal data protection as an explicit fundamental right under Article 5, item LXXIX of Brazil's Federal Constitution. The amendment guarantees the right to data protection 'including in digital means.' It also gave the federal government exclusive jurisdiction to legislate on data protection, preventing states and municipalities from enacting conflicting rules. This constitutional footing strengthens the LGPD's authority and was cited as a key factor in the EU's decision to grant Brazil an adequacy decision in January 2026.

How does the LGPD credit protection legal basis work, and why is it unique?

The credit protection basis under Article 7(X) of the LGPD allows organizations to process personal data for credit scoring, creditworthiness assessments, and fraud prevention without obtaining consent. This legal basis reflects Brazil's extensive credit reporting system and the importance of credit access in the Brazilian economy. It is unique to the LGPD and has no direct equivalent in the GDPR, where credit-related processing typically relies on legitimate interest or legal obligation.

What changed with the EU-Brazil mutual adequacy decision in January 2026?

The mutual adequacy decision adopted on January 26, 2026 allows personal data to flow freely between Brazil and the EU (including EEA/EFTA countries) without additional transfer safeguards. Before this decision, organizations needed standard contractual clauses, binding corporate rules, or other approved mechanisms for every transfer. Now, transfers can occur directly under LGPD Article 33(I) and GDPR Article 45. The decision is reviewed every four years and excludes transfers for national security or criminal prosecution purposes.

What are Brazil's SCC requirements for international data transfers outside the EU?

Resolution CD/ANPD No. 19/2024, published August 23, 2024, introduced ANPD-approved Standard Contractual Clauses for international data transfers. The SCCs cover both controller-to-controller and controller-to-processor transfers. The 12-month grace period for implementing SCCs expired on August 23, 2025. Organizations transferring personal data to countries without an adequacy decision (i.e., most countries other than EU/EEA member states) must now have SCCs in place or face non-compliance. Binding Corporate Rules remain technically available but require ANPD pre-approval, and none had been approved as of mid-2025.

What are the penalties for violating the LGPD, and could they increase?

Current penalties include fines up to 2% of revenue in Brazil (capped at BRL 50 million per violation), daily fines, public disclosure of the infraction, data blocking or deletion, suspension of processing for up to six months, and total prohibition of data processing activities. Bill PL 4530/23, currently under consideration, proposes increasing the maximum fine to 20% of revenue with a cap of BRL 100 million per violation. The ANPD has imposed over BRL 98 million in total fines since 2023.

How does Brazil's breach notification rule differ from the GDPR's 72-hour requirement?

Under Resolution CD/ANPD No. 15/2024, controllers must notify the ANPD and affected data subjects within three business days of becoming aware that a security incident may result in risk or harm. The GDPR requires notification to the supervisory authority within 72 hours. A key difference is that the LGPD also requires direct notification to affected data subjects within the same three-day window, while the GDPR requires data subject notification only when there is a high risk to their rights and freedoms, with no specific deadline beyond 'without undue delay.'

What is the status of Brazil's AI bill PL 2338/2023?

The Brazilian Federal Senate approved Bill No. 2338/2023 on December 10, 2024. As of May 2026, the bill remained under review in the Chamber of Deputies, where a special committee was established on April 29, 2025 to analyze the legislation. The bill establishes a risk-based AI framework and designates the ANPD as the primary AI regulator. It has not yet been enacted into law. Until enacted, the ANPD regulates AI-related data processing under existing LGPD provisions.

Are small businesses exempt from the LGPD?

Small processing agents, as defined by Resolution CD/ANPD No. 2/2022, have reduced compliance obligations under the LGPD. This category covers microenterprises, small businesses, startups, and natural persons or legal entities whose data processing activities pose limited risk. The main practical exemption is from the mandatory DPO appointment requirement. However, small processing agents must still comply with the LGPD's substantive requirements, including legal basis identification, data subject rights, and breach notification. The ANPD's first enforcement action (Telekall, 2023) was against a small telecom company.

Updates

Independently fact-checked against the cited primary sources

Full audit-and-evolve refresh: added constitutional amendment section (EC 115/2022), AI Bill section (PL 2338/2023), updated international transfer section with Resolution CD/ANPD No. 19/2024 and SCC August 2025 deadline, expanded enforcement section with IAMSPE and TikTok cases, added LGPD vs GDPR comparison table, added internal links. Title and meta unchanged (strong existing signals). Word count expanded from ~3,850 to ~5,800.

Sources and References

  1. Lei Geral de Protecao de Dados (Law No. 13.709/2018)(planalto.gov.br).gov
  2. ANPD Official Website(gov.br).gov
  3. Constitutional Amendment EC 115/2022: Data Protection as Fundamental Right(diascarneiro.com.br)
  4. European Commission: EU-Brazil Data Adequacy Agreement(ec.europa.eu).gov
  5. Resolution CD/ANPD No. 15/2024: Breach Notification Requirements(gov.br).gov
  6. Resolution CD/ANPD No. 2/2022: Small Processing Agents(gov.br).gov
  7. Resolution CD/ANPD No. 4/2023: Sanctions Dosimetry Methodology(gov.br).gov
  8. Resolution CD/ANPD No. 19/2024: International Data Transfers and SCCs(mayerbrown.com)
  9. Law No. 15.211/2025: Digital Statute for Children and Adolescents (ECA Digital)(planalto.gov.br).gov
  10. Mayer Brown: End of Grace Period for Brazil SCCs (August 2025)(mayerbrown.com)
  11. Baker McKenzie: Brazil and EU Mutual Data Protection Adequacy Decision(bakermckenzie.com)
  12. Mayer Brown: A New Era for Personal Data Transfers (EU-Brazil)(mayerbrown.com)
  13. IAPP: ANPD Becomes Independent Regulatory Agency(iapp.org)
  14. Kasznar Leonardos: ANPD Second Penalty (IAMSPE)(kasznarleonardos.com)
  15. ICLG: Data Protection Laws and Regulations Brazil 2025-2026(iclg.com)
  16. Trench Rossi Watanabe: ANPD Priority Issues 2026-2027(trenchrossi.com)
  17. Library of Congress: Brazil Senate Advances AI Bill (2025)(loc.gov).gov
  18. Mattos Filho: Data Protection as Fundamental Right in Brazil(mattosfilho.com.br)
  19. Resolution CD/ANPD No. 15/2024: Breach Notification Requirements(gov.br).gov
Share: