Home › Law library › LGPD
BR
LGPD
Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018)
Sourced. Last verified 9 October 2026
Brazil Privacy
- Status
- In force. ANPD became a regulatory agency under Law 15,352/2026 (signed 25 Feb 2026).
- Who it applies to
- Any public or private processing, wherever the company is based, if processing happens in Brazil, aims to offer goods or services to or process data of people in Brazil, or the data was collected in Brazil.
- Size thresholds
- No size or revenue thresholds. Small processing agents (micro/small businesses, startups) get a simplified regime under ANPD Resolution 2/2022, unless they do high-risk processing.
- Regulator
- Agência Nacional de Proteção de Dados (ANPD)
- Breach or incident reporting
- Notify the ANPD (via its electronic form) and affected data subjects within 3 business days of learning of an incident that may cause relevant risk or damage (Resolution CD/ANPD 15/2024). Keep records of all incidents for at least 5 years. Deadlines doubled for small agents.
- Deadline to answer personal data requests
- Confirmation/access in simplified form immediately; complete declaration within 15 days of the request (Art. 19).
- Data protection officer
- Controllers must appoint a DPO (encarregado) and publish their identity and contact details, preferably on the website (Art. 41). Small processing agents without high-risk processing are exempt but must provide a contact channel.
- Local representative
- Being verified
- Sending data abroad
- Allowed only on Art. 33 grounds: adequacy, ANPD standard contractual clauses (adopted verbatim; 12-month adoption deadline from 23 Aug 2024), specific clauses, global corporate rules, specific consent, etc. EU and Brazil granted mutual adequacy in Jan 2026.
- Cookies and consent
- Needs a legal basis (consent or legitimate interest). ANPD cookie guide (Oct 2022): no pre-ticked non-essential cookies, offer an easy 'reject all' on the first banner layer, and keep consent-based cookies off by default.
- Maximum penalty
- Up to 2% of the company's (or group's) revenue in Brazil in the prior fiscal year, net of taxes, capped at R$50 million per infraction.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Identify a legal basis for each processing activity and record it.
- Appoint and publish a DPO (encarregado), unless exempt as a low-risk small agent.
- Answer access requests immediately (simplified) or within 15 days (complete).
- Report risky security incidents to the ANPD and affected people within 3 business days.
- Use ANPD standard contractual clauses or another Art. 33 mechanism for transfers abroad.
- Keep a record of all security incidents for at least 5 years.
- Set up cookie banners with a clear reject option and no pre-ticked boxes.
Recent changes
EU adequacy for Brazil adopted 26 Jan 2026; ANPD Res. 32/2026 recognized the EU (27 Jan 2026). Law 15,352/2026 (25 Feb 2026) made ANPD a regulatory agency and set ECA Digital in force from 17 Mar 2026. SCC adoption deadline (Res. 19/2024) passed Aug 2025.
Sources
- Primary source: https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm
- Second source: https://www.whitecase.com/insight-alert/mutual-adequacy-between-eu-and-brazil-new-era-transatlantic-data-transfers
- Regulator: Agência Nacional de Proteção de Dados (ANPD)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].