Compliance Brazil
Legal basis: Law 13.709/2018 (LGPD)
Data governance under Brazil's General Data Protection Law (LGPD) — consolidated legal text adapted to our compliance program.
THE PRESIDENT OF THE REPUBLIC: I hereby make known that the National Congress decrees and I sanction the following Law:
CHAPTER I — PRELIMINARY PROVISIONS
Art. 1. This Law provides for the processing of personal data, including by digital means, by a natural person or by a legal entity of public or private law, with the purpose of protecting the fundamental rights of freedom and privacy and the free development of the personality of the natural person. Sole paragraph. The general rules in this Law are of national interest and must be observed by the Union, the States, the Federal District and the Municipalities.
Art. 2. The discipline of the protection of personal data is grounded on: respect for privacy; informational self-determination; freedom of expression, information, communication and opinion; the inviolability of intimacy, honor and image; economic and technological development and innovation; free enterprise, free competition and consumer protection; and human rights, the free development of personality, dignity and the exercise of citizenship by natural persons.
Art. 3. This Law applies to any processing operation carried out by a natural person or legal entity of public or private law, regardless of the means, the country of its headquarters or the country where the data is located, provided that: (I) the processing is carried out in the national territory; (II) the activity aims to offer or supply goods or services to, or process the data of, individuals located in the national territory; or (III) the personal data was collected in the national territory.
Art. 4. This Law does not apply to the processing of personal data carried out: by a natural person for exclusively private and non-economic purposes; for exclusively journalistic, artistic or academic purposes; for the exclusive purposes of public safety, national defense, State security, or activities of investigation and repression of criminal offenses; or originating outside the national territory that is not subject to communication, shared use or international transfer with Brazilian processing agents, provided the country of origin affords an adequate level of protection.
Art. 5. Key definitions: personal data — information relating to an identified or identifiable natural person; sensitive personal data — data on racial or ethnic origin, religious conviction, political opinion, trade-union or religious/philosophical/political membership, health or sex life, genetic or biometric data; anonymized data; database; data subject; controller — party responsible for decisions on processing; operator — party that processes on the controller's behalf; DPO (encarregado) — the channel of communication between controller, data subjects and the National Data Protection Authority (ANPD); processing agents; processing; anonymization; consent; blocking; deletion; international data transfer; shared use of data; data protection impact report; research body; and national authority.
Art. 6. Processing activities must observe good faith and the following principles: purpose; adequacy; necessity; free access; data quality; transparency; security; prevention; non-discrimination; and accountability (demonstration of effective measures capable of proving compliance with data-protection rules).
CHAPTER II — PROCESSING OF PERSONAL DATA
Section I — Requirements for Processing Personal Data
Art. 7. Processing may only be carried out under one of the following legal bases: consent of the data subject; compliance with a legal or regulatory obligation; execution of public policy by the public administration; studies by a research body (with anonymization whenever possible); performance of a contract or preliminary procedures at the data subject's request; regular exercise of rights in judicial, administrative or arbitration proceedings; protection of life or physical safety; health protection by health professionals or authorities; legitimate interest of the controller or third party; and credit protection.
Art. 8. Consent under Art. 7(I) must be given in writing or by another means demonstrating the data subject's will; if in writing, it must appear in a clause distinct from other contractual clauses. The controller bears the burden of proving valid consent. Consent must refer to specific purposes (generic authorizations are void) and may be withdrawn at any time by a free and facilitated procedure.
Art. 9. The data subject has the right to facilitated access to clear information about the processing, including: specific purpose; form and duration; identification and contact of the controller; information on shared use and its purpose; responsibilities of the agents; and the data subject's rights (Art. 18).
Art. 10. The controller's legitimate interest may only ground processing for legitimate purposes considered from concrete situations, limited to the data strictly necessary, with transparency measures; the national authority may request a data protection impact report.
Section II — Processing of Sensitive Personal Data
Art. 11. Sensitive personal data may only be processed with specific and prominent consent for specific purposes, or, without consent, where indispensable for: compliance with a legal/regulatory obligation; shared processing needed to execute public policy; studies by a research body (anonymized when possible); regular exercise of rights; protection of life or physical safety; health protection by health professionals/authorities; or fraud prevention and the data subject's security in identification and authentication processes. Sharing sensitive health data to obtain economic advantage is prohibited, save for the exceptions expressly listed.
Art. 12. Anonymized data is not considered personal data, unless the anonymization process can be reversed using reasonable means, or where used to form the behavioral profile of an identifiable natural person.
Art. 13. In public-health studies, research bodies may access personal databases, which must be processed exclusively within the body and strictly for the study, kept in a controlled and secure environment, with anonymization or pseudonymization whenever possible; disclosure of results may in no case reveal personal data.
Section III — Processing of Children's and Adolescents' Personal Data
Art. 14. The processing of children's and adolescents' personal data must be carried out in their best interest. Children's data must be processed with specific and prominent consent from at least one parent or legal guardian; controllers must keep public information about the types of data collected and the procedures for exercising rights, must not condition participation in games or applications on the provision of unnecessary data, and must make reasonable efforts to verify that consent was given by the guardian. Information must be provided in a simple, clear and accessible manner suited to the child's understanding.
Section IV — Termination of Data Processing
Art. 15. Processing terminates when: the purpose is achieved or the data is no longer necessary; the processing period ends; the data subject so communicates, including by withdrawing consent; or the national authority so determines upon a violation.
Art. 16. Personal data must be deleted after the end of processing, retention being authorized only for: compliance with a legal/regulatory obligation; study by a research body (anonymized when possible); transfer to a third party under the Law's requirements; or the controller's exclusive use, with access by third parties prohibited and the data anonymized.
CHAPTER III — RIGHTS OF THE DATA SUBJECT
Art. 17. Every natural person is assured ownership of their personal data, with the fundamental rights of freedom, intimacy and privacy guaranteed.
Art. 18. The data subject may obtain from the controller, at any time and upon request: confirmation of the existence of processing; access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary, excessive or non-compliant data; portability to another provider; deletion of data processed with consent (save the exceptions of Art. 16); information on public and private entities with which data was shared; information on the possibility of refusing consent and its consequences; and withdrawal of consent. The data subject may also petition the national authority and consumer-protection bodies.
Art. 19–22. Confirmation of existence or access to data is provided immediately in a simplified format, or within 15 days by a full declaration. The data subject may request review of decisions taken solely on automated processing that affect their interests (including profiling); the controller must provide clear information on the criteria used, subject to trade and industrial secrecy. Data related to the regular exercise of rights may not be used to the data subject's detriment, and their interests may be defended in court, individually or collectively.
CHAPTER IV — PROCESSING OF PERSONAL DATA BY PUBLIC AUTHORITIES
Section I — Rules
Art. 23–27. Public legal entities must process personal data to fulfill their public purpose and legal competences, informing the hypotheses, legal basis and procedures in easily accessible channels (preferably their websites) and appointing a DPO. Public companies and mixed-capital companies operating in competition receive the same treatment as private entities. Data must be kept in an interoperable and structured format for shared use. Shared use by public authorities must serve specific public-policy purposes; transferring data to private entities is prohibited except in the listed hypotheses, and communication or shared use with private parties is reported to the national authority and depends on consent, save the exceptions.
Art. 29–30. Public entities must, at any time, provide specific information on the scope and nature of the data and the processing; the national authority may issue supplementary technical opinions and complementary rules for communication and shared use.
Section II — Liability
Art. 31–32. Where a public body violates this Law, the national authority may issue a notice with appropriate measures to cease the violation, and may request the publication of data protection impact reports and suggest the adoption of standards and best practices.
CHAPTER V — INTERNATIONAL DATA TRANSFER
Art. 33. International transfer of personal data is permitted only: to countries or international organizations affording an adequate level of protection; where the controller offers guarantees (specific contractual clauses, standard contractual clauses, global corporate rules, or seals, certificates and codes of conduct); for international legal cooperation; to protect life or physical safety; where authorized by the national authority; under international cooperation agreements; to execute public policy; with the data subject's specific and prominent consent; or where necessary under the bases of Art. 7 (II, V and VI).
Art. 34–36. The level of protection of the foreign country or organization is assessed by the national authority (considering the legislation, nature of the data, general principles, security measures and judicial/institutional guarantees). The content of standard contractual clauses and the verification of specific clauses, global corporate rules, seals, certificates and codes of conduct are defined by the national authority; changes to the guarantees must be communicated to it.
CHAPTER VI — PROCESSING AGENTS
Section I — Controller and Operator
Art. 37–40. The controller and operator must keep records of processing operations, especially where based on legitimate interest. The national authority may require the controller to prepare a data protection impact report. The operator must process according to the controller's instructions, and the controller verifies compliance. The national authority may provide for interoperability standards for portability, free access and security.
Section II — Data Protection Officer (DPO)
Art. 41. The controller must appoint a Data Protection Officer (encarregado), whose identity and contact details must be publicly and clearly disclosed (preferably on the controller's website). The DPO's duties include: receiving complaints and communications from data subjects, providing clarifications and taking action; receiving communications from the national authority; guiding employees and contractors; and other tasks defined by the controller or in complementary rules.
CHAPTER VII — SECURITY AND BEST PRACTICES
Section I — Security and Secrecy of Data
Art. 46–49. Processing agents must adopt security, technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication or dissemination. In the event of a security incident that may create risk or relevant damage to data subjects, the controller must notify the national authority and the affected data subjects within a reasonable time, describing the data involved, the risks, the measures taken and mitigating actions. Systems must be structured to meet security requirements, best practices and governance principles.
Section II — Best Practices and Governance
Art. 50–51. Controllers and operators may formulate rules of good practice and governance establishing conditions of organization, operating regime, procedures, security norms, technical standards, obligations, complaint and incident-handling actions, education measures, and internal supervision and risk-mitigation mechanisms — including a privacy governance program. The national authority encourages the adoption of technical standards that facilitate the data subject's control over their personal data.
CHAPTER VIII — SUPERVISION AND ADMINISTRATIVE SANCTIONS
Art. 52–54. Processing agents that violate this Law are subject, after administrative proceedings, to: a warning with a corrective deadline; a simple fine of up to 2% of revenue in Brazil in the previous fiscal year, capped at BRL 50 million per violation; a daily fine (subject to the same cap); public disclosure of the infraction; blocking of the personal data concerned; deletion of the personal data concerned; and, in the most severe cases, partial or total suspension of database operation and of processing activities. Sanctions are applied after an administrative procedure ensuring the right to a full defense, considering criteria such as the seriousness of the fact, the agent's good faith, the advantage obtained, cooperation, and the adoption of a governance program.
CHAPTER IX — THE ANPD AND THE NATIONAL COUNCIL (CNPD)
Art. 55-A to 58-B. The National Data Protection Authority (ANPD) is created as the body responsible for overseeing, implementing and enforcing compliance with this Law throughout the national territory, with technical and decision-making autonomy. Its duties include ensuring data protection, drawing up guidelines for the National Policy, supervising and applying sanctions, and promoting knowledge of data-protection norms. The National Council for Personal Data Protection and Privacy (CNPD) proposes strategic guidelines and prepares annual reports.
CHAPTER X — FINAL AND TRANSITIONAL PROVISIONS
Art. 59–65. Agents that cause material, moral, individual or collective damage in violation of this Law are obliged to redress it. This Law does not override other applicable protective legislation (e.g., the Consumer Protection Code and the Internet Civil Framework). The rights and principles herein apply to procedures and systems already existing at the time of entry into force. This Law entered into force 24 months after its official publication, with the administrative-sanction provisions (Arts. 52–54) taking effect as of August 1, 2021.
The legally authoritative full text is in Portuguese and is published on the official Brazilian government portal (Planalto).
Access the Original Full Text (Planalto — LGPD)