verified_user
Standardful
Homechevron_rightStandardschevron_rightLGPD
ActiveInternational Standardupdate Last Updated: Aug 2025

LGPD

Lei Geral de Proteção de Dados Pessoais — Brazil's General Data Protection Law (Law No. 13,709/2018)

apartmentPublishing Organization:Brazilian National Data Protection Authority (ANPD)

Standard Introduction

LGPD is an active standard published by Brazilian National Data Protection Authority (ANPD). It is commonly used across Technology, Finance & Banking, Retail, Healthcare, Services and applies in Brazil.

Use this page to review the official documentation, current status, and the certification or assessment bodies most commonly associated with LGPD.

public

Broad Territorial Scope

Applies to any organization that processes personal data of individuals in Brazil, regardless of where the organization is located — similar to GDPR's extraterritorial reach.

shield

Ten Legal Bases

Provides ten legal bases for data processing, including consent, contract, legal obligation, legitimate interests, credit protection, and protection of life — more than GDPR's six bases.

account_balance

ANPD Enforcement

The ANPD has evolved from moderate to very active enforcement, with fines totaling approximately BRL 98 million between 2023 and 2025 across healthcare, finance, and technology sectors.

list_alt Core Principles

  • Purpose — processing for legitimate, specific, and informed purposes
  • Adequacy — compatibility with the stated purposes
  • Necessity — limited to the minimum required
  • Free access — guarantee of easy and free consultation
  • Data quality — accuracy and up-to-date data
  • Transparency — clear information about processing
  • Security — technical and administrative measures to protect data
  • Non-discrimination — prohibition of processing for discriminatory purposes

Who Needs to Comply?

groups

Any public or private organization that processes personal data of individuals located in Brazil, or that collects data in Brazil, or that offers goods/services to individuals in Brazil — regardless of the organization's physical location.

Key Requirements

1

Legal Basis for Processing

Establish one of ten legal bases before processing personal data: consent, legal obligation, public policy, research, contract, exercise of rights, life protection, health protection, legitimate interest, or credit protection.

2

Data Protection Officer (DPO)

Appoint a Data Protection Officer (Encarregado) responsible for accepting complaints, providing guidance, and communicating with the ANPD. Contact information must be publicly available.

3

Data Subject Rights

Guarantee data subjects' rights including access, correction, anonymization, deletion, portability, information about sharing, and the ability to revoke consent.

4

International Data Transfers

Transfer personal data internationally only with adequate protections — Standard Contractual Clauses, binding corporate rules, adequacy decisions, or specific consent from the data subject.

5

Incident Reporting

Notify the ANPD and affected data subjects within a reasonable time of any security incident that may create risk or relevant harm. Provide details including the nature of data affected and mitigation measures taken.

Penalties & Enforcement

warning

Administrative fines up to 2% of the company's revenue in Brazil for the preceding fiscal year, capped at BRL 50 million (approximately USD 10 million) per infraction. Daily fines may also apply. Non-monetary sanctions include public disclosure of violations, data deletion orders, and partial or total bans on data processing activities.

Official Documentation

View All

Implementation Timeline

gavel
Aug 2018
LGPD enacted (Law No. 13,709/2018)
check_circle
Sept 2020
LGPD entered into force
warning
Aug 2021
Administrative sanctions provisions became enforceable
payments
July 2023
ANPD issues first administrative fine
update
Aug 2025
Grace period ends for Standard Contractual Clauses for international data transfers

Related Categories