verified_user
Standardful
首页chevron_right标准chevron_rightLGPD
有效国际标准update 最后更新:2025年8月

LGPD

Lei Geral de Protecao de Dados Pessoais(巴西通用数据保护法)

apartment发布组织:巴西国家数据保护局 (ANPD)

标准简介

LGPD 是由 巴西国家数据保护局 (ANPD) 发布的有效标准,常用于科技、金融银行、零售、医疗健康、服务业等行业,并适用于巴西等市场。

本页汇总了 LGPD 的官方文档、当前状态以及常见相关认证或评估机构,便于快速理解要求与落地路径。

public

Broad Territorial Scope

Applies to any organization that processes personal data of individuals in Brazil, regardless of where the organization is located — similar to GDPR's extraterritorial reach.

shield

Ten Legal Bases

Provides ten legal bases for data processing, including consent, contract, legal obligation, legitimate interests, credit protection, and protection of life — more than GDPR's six bases.

account_balance

ANPD Enforcement

The ANPD has evolved from moderate to very active enforcement, with fines totaling approximately BRL 98 million between 2023 and 2025 across healthcare, finance, and technology sectors.

list_alt Core Principles

  • Purpose — processing for legitimate, specific, and informed purposes
  • Adequacy — compatibility with the stated purposes
  • Necessity — limited to the minimum required
  • Free access — guarantee of easy and free consultation
  • Data quality — accuracy and up-to-date data
  • Transparency — clear information about processing
  • Security — technical and administrative measures to protect data
  • Non-discrimination — prohibition of processing for discriminatory purposes

Who Needs to Comply?

groups

Any public or private organization that processes personal data of individuals located in Brazil, or that collects data in Brazil, or that offers goods/services to individuals in Brazil — regardless of the organization's physical location.

Key Requirements

1

Legal Basis for Processing

Establish one of ten legal bases before processing personal data: consent, legal obligation, public policy, research, contract, exercise of rights, life protection, health protection, legitimate interest, or credit protection.

2

Data Protection Officer (DPO)

Appoint a Data Protection Officer (Encarregado) responsible for accepting complaints, providing guidance, and communicating with the ANPD. Contact information must be publicly available.

3

Data Subject Rights

Guarantee data subjects' rights including access, correction, anonymization, deletion, portability, information about sharing, and the ability to revoke consent.

4

International Data Transfers

Transfer personal data internationally only with adequate protections — Standard Contractual Clauses, binding corporate rules, adequacy decisions, or specific consent from the data subject.

5

Incident Reporting

Notify the ANPD and affected data subjects within a reasonable time of any security incident that may create risk or relevant harm. Provide details including the nature of data affected and mitigation measures taken.

Penalties & Enforcement

warning

Administrative fines up to 2% of the company's revenue in Brazil for the preceding fiscal year, capped at BRL 50 million (approximately USD 10 million) per infraction. Daily fines may also apply. Non-monetary sanctions include public disclosure of violations, data deletion orders, and partial or total bans on data processing activities.

官方文档

查看全部

实施时间线

gavel
2018年8月
LGPD enacted (Law No. 13,709/2018)
check_circle
2020年9月
LGPD entered into force
warning
2021年8月
Administrative sanctions provisions became enforceable
payments
2023年7月
ANPD issues first administrative fine
update
2025年8月
Grace period ends for Standard Contractual Clauses for international data transfers

相关分类