Country:巴西 · Data Compliance
Medium confidenceUpdated 2026-08-03Handbook

Brazil · Data Compliance

Brazilian personal data protection is governed by the General Data Protection Law (LGPD, Lei 13.709/2018), enforced by ANPD, with a maximum fine of R$50 million per infraction. Key obligations: processing must have a legal basis, a Data Protection Officer (encarregado/DPO) must be designated, a Data Protection Impact Assessment (DPIA) must be conducted for high risk, data subject rights must be guaranteed, and cross-border transfers must meet adequacy, Standard Contractual Clauses (SCC), or another lawful mechanism. ANPD Resolution No. 19/2024 establishes the SCC standard model, with a transition period ending 2025-08-23; from 2026-01 the EU–Brazil mutual adequacy decision takes effect, facilitating EU/Brazil data flows. Chinese enterprises operating in Brazil, with apps and SaaS, must comply upfront.

Key points

Procedure

  1. Data inventory: map the personal data flow (collection, purpose, sharing, cross-border).
  2. Determine the legal basis and draft the privacy policy and Records of Processing (ROP).
  3. Designate a DPO (encarregado) and publish contact details.
  4. Cross-border transfer: assess applicability of adequacy/SCC, sign the ANPD Resolution No. 19/2024 SCC model or adopt another mechanism.
  5. Conduct a DPIA for high-risk processing; establish a security incident response and reporting process.
  6. Maintain compliance updates and training within the ANPD regulatory framework.

Hard requirements

Costs

Compliance system build: approx. R$10,000–R$100,000 (by scale, including DPO/advisor).SCC cross-border transfer: ANPD model free, but requires legal review and localization.Violation fines: cap R$50 million per infraction, plus possible order to cease processing.DPIA and audit: advisor fee by complexity.⏱ ⏱ Timeline:Data inventory 2–4 weeks; policy drafting and DPO designation 2–4 weeks; SCC signing and cross-border mechanism 2–6 weeks; ongoing maintenance.

⚠ Common risks

  • No DPO designated or published, violating basic LGPD obligations.
  • Cross-border transfer without a lawful mechanism (e.g., transferring directly to China without SCC) penalized by ANPD.
  • Security incident not reported, leading to fines and reputational loss.
  • Missing privacy policy and records increases inspection risk.
  • Misjudging the scope of adequacy, violating EU/Brazil flow rules.
  • Unanswered data subject rights requests trigger complaints and fines.
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese enterprises operating in Brazil that collect or process Brazilian personal data, including apps, SaaS, e-commerce, fintech, and local hiring (employee data processing); covers the full LGPD compliance flow.

Prerequisites

  • Identified the types and flows of personal data processed.
  • Clarified whether cross-border transfer to China/third countries is involved.
  • Configured a compliance owner and legal counsel.
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data Inventory and Flow Map
Map the collection, purpose, sharing, and cross-border flow of personal data; identify high-risk processing (sensitive data, large scale).
Data compliance2–4 weeksInternal/AdvisorData map + ROPBasis for the subsequent legal basis and DPIA.
Penalty:Lack of clarity leaves processing without a basis.
2Legal Basis and Policy Drafting
Determine a legal basis for each processing type (consent/contract/legitimate interest) and draft the privacy policy and Records of Processing (ROP).
Legal/Compliance2–4 weeksAdvisor feePrivacy policy + ROPPrivacy policy must be in Portuguese and easy to understand.
Penalty:Processing without a legal basis can be fined and halted.
3Designate and Publish DPO
Designate an encarregado (Data Protection Officer) and publish contact details and duties on the website and via ANPD channels.
Management1–2 weeksInternalDPO publicationExplicitly required by LGPD.
Penalty:Absence is a basic violation.
4Cross-Border Transfer Mechanism (SCC)
For data transferred to China/third countries, assess adequacy (the 2026-01 EU–Brazil mutual recognition does not directly cover China), and sign the ANPD Resolution No. 19/2024 SCC model or adopt another lawful mechanism.
Legal2–6 weeksLegal review feeSCC agreementTransition period ended 2025-08-23; must already be in place now.
Penalty:Cross-border without a mechanism can be fined and transfer halted.
5DPIA and Security Measures
Conduct a DPIA for high-risk processing and implement technical and organizational security measures such as encryption and access control.
Security/Compliance2–4 weeksTools/AdvisorDPIA reportRetain for inspection.
Penalty:High risk without DPIA aggravates penalties.
6Incident Response and Ongoing Compliance
Establish a security incident reporting process; report major breaches to ANPD and data subjects; conduct regular training and review.
ComplianceOngoingInternalIncident log + trainingANPD may inspect proactively.
Penalty:Cover-up brings heavy fines (cap R$50 million).

✅ Self-check list

⚠ Common pitfalls

Cross-border transfer to China without SCC.影响:ANPD penalty + transfer halt.规避:Sign the ANPD Resolution No. 19/2024 SCC model.
No DPO designated/published.影响:Basic violation.规避:Mandatorily appoint an encarregado and publish it.
Security incident not reported.影响:Fine up to R$50 million.规避:Establish a reporting SLA and drills.
Misusing the adequacy decision.影响:Violation for flows to third countries.规避:The 2026 EU–Brazil mutual recognition does not cover China; use SCC instead.
Privacy policy missing Portuguese.影响:Non-compliance and complaints.规避:Publish a readable Portuguese version.

📅 Ongoing post-incorporation obligations

  • Continuously maintain the ROP, privacy policy, and SCC, updating with business changes.
  • Periodic DPIA review and employee training.
  • Report major security incidents to ANPD and subjects as required by law.

🔗 Official portals

📎 Source:ANPD (National Data Protection Authority, Autoridade Nacional de Proteção de Dados)
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.