Country:巴西 · Data Compliance
Brazil · Data Compliance
Brazilian personal data protection is governed by the General Data Protection Law (LGPD, Lei 13.709/2018), enforced by ANPD, with a maximum fine of R$50 million per infraction. Key obligations: processing must have a legal basis, a Data Protection Officer (encarregado/DPO) must be designated, a Data Protection Impact Assessment (DPIA) must be conducted for high risk, data subject rights must be guaranteed, and cross-border transfers must meet adequacy, Standard Contractual Clauses (SCC), or another lawful mechanism. ANPD Resolution No. 19/2024 establishes the SCC standard model, with a transition period ending 2025-08-23; from 2026-01 the EU–Brazil mutual adequacy decision takes effect, facilitating EU/Brazil data flows. Chinese enterprises operating in Brazil, with apps and SaaS, must comply upfront.
Key points
- LGPD (Lei 13.709/2018) is Brazil's foundational data protection law, enforced by ANPD, with a fine cap of R$50 million per infraction.
- An encarregado (DPO) must be designated and contact details published via ANPD channels.
- Processing must have a legal basis (consent, contract, legitimate interest, etc.) and guarantee data subject rights to access/deletion.
- Cross-border transfer mechanisms: adequacy decision, SCC (ANPD Resolution No. 19/2024 model, transition to 2025-08-23), binding corporate rules, etc.
- From 2026-01 the EU–Brazil mutual adequacy takes effect, facilitating bilateral data flows.
- High-risk processing requires a DPIA; security incidents must be reported to ANPD and data subjects.
Procedure
- Data inventory: map the personal data flow (collection, purpose, sharing, cross-border).
- Determine the legal basis and draft the privacy policy and Records of Processing (ROP).
- Designate a DPO (encarregado) and publish contact details.
- Cross-border transfer: assess applicability of adequacy/SCC, sign the ANPD Resolution No. 19/2024 SCC model or adopt another mechanism.
- Conduct a DPIA for high-risk processing; establish a security incident response and reporting process.
- Maintain compliance updates and training within the ANPD regulatory framework.
Hard requirements
- Have and document a legal basis for processing.
- Designate an encarregado (DPO) and publish it via ANPD channels.
- Draft a privacy policy, Records of Processing (ROP), and a data subject rights response mechanism.
- Cross-border transfer must have a lawful mechanism (adequacy/SCC/other).
- Adopt technical and organizational security measures; report major incidents to ANPD.
- Complete a DPIA for high-risk processing.
Costs
Compliance system build: approx. R$10,000–R$100,000 (by scale, including DPO/advisor).SCC cross-border transfer: ANPD model free, but requires legal review and localization.Violation fines: cap R$50 million per infraction, plus possible order to cease processing.DPIA and audit: advisor fee by complexity.⏱ ⏱ Timeline:Data inventory 2–4 weeks; policy drafting and DPO designation 2–4 weeks; SCC signing and cross-border mechanism 2–6 weeks; ongoing maintenance.⚠ Common risks
- No DPO designated or published, violating basic LGPD obligations.
- Cross-border transfer without a lawful mechanism (e.g., transferring directly to China without SCC) penalized by ANPD.
- Security incident not reported, leading to fines and reputational loss.
- Missing privacy policy and records increases inspection risk.
- Misjudging the scope of adequacy, violating EU/Brazil flow rules.
- Unanswered data subject rights requests trigger complaints and fines.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises operating in Brazil that collect or process Brazilian personal data, including apps, SaaS, e-commerce, fintech, and local hiring (employee data processing); covers the full LGPD compliance flow.
Prerequisites
- Identified the types and flows of personal data processed.
- Clarified whether cross-border transfer to China/third countries is involved.
- Configured a compliance owner and legal counsel.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data Inventory and Flow Map Map the collection, purpose, sharing, and cross-border flow of personal data; identify high-risk processing (sensitive data, large scale). | Data compliance | 2–4 weeks | Internal/Advisor | Data map + ROP | Basis for the subsequent legal basis and DPIA. Penalty:Lack of clarity leaves processing without a basis. |
| 2 | Legal Basis and Policy Drafting Determine a legal basis for each processing type (consent/contract/legitimate interest) and draft the privacy policy and Records of Processing (ROP). | Legal/Compliance | 2–4 weeks | Advisor fee | Privacy policy + ROP | Privacy policy must be in Portuguese and easy to understand. Penalty:Processing without a legal basis can be fined and halted. |
| 3 | Designate and Publish DPO Designate an encarregado (Data Protection Officer) and publish contact details and duties on the website and via ANPD channels. | Management | 1–2 weeks | Internal | DPO publication | Explicitly required by LGPD. Penalty:Absence is a basic violation. |
| 4 | Cross-Border Transfer Mechanism (SCC) For data transferred to China/third countries, assess adequacy (the 2026-01 EU–Brazil mutual recognition does not directly cover China), and sign the ANPD Resolution No. 19/2024 SCC model or adopt another lawful mechanism. | Legal | 2–6 weeks | Legal review fee | SCC agreement | Transition period ended 2025-08-23; must already be in place now. Penalty:Cross-border without a mechanism can be fined and transfer halted. |
| 5 | DPIA and Security Measures Conduct a DPIA for high-risk processing and implement technical and organizational security measures such as encryption and access control. | Security/Compliance | 2–4 weeks | Tools/Advisor | DPIA report | Retain for inspection. Penalty:High risk without DPIA aggravates penalties. |
| 6 | Incident Response and Ongoing Compliance Establish a security incident reporting process; report major breaches to ANPD and data subjects; conduct regular training and review. | Compliance | Ongoing | Internal | Incident log + training | ANPD may inspect proactively. Penalty:Cover-up brings heavy fines (cap R$50 million). |
✅ Self-check list
⚠ Common pitfalls
Cross-border transfer to China without SCC.影响:ANPD penalty + transfer halt.规避:Sign the ANPD Resolution No. 19/2024 SCC model.
No DPO designated/published.影响:Basic violation.规避:Mandatorily appoint an encarregado and publish it.
Security incident not reported.影响:Fine up to R$50 million.规避:Establish a reporting SLA and drills.
Misusing the adequacy decision.影响:Violation for flows to third countries.规避:The 2026 EU–Brazil mutual recognition does not cover China; use SCC instead.
Privacy policy missing Portuguese.影响:Non-compliance and complaints.规避:Publish a readable Portuguese version.
📅 Ongoing post-incorporation obligations
- Continuously maintain the ROP, privacy policy, and SCC, updating with business changes.
- Periodic DPIA review and employee training.
- Report major security incidents to ANPD and subjects as required by law.
🔗 Official portals
📎 Source:ANPD (National Data Protection Authority, Autoridade Nacional de Proteção de Dados)
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.