Don’t do SECURITY. Do business SECURELY.

Brazil’s LGPD comes into force

Brazil’s General Data Protection Law, the LGPD, is now in force, bringing GDPR-style obligations to organisations processing Brazilians’ data.

Brazil’s Lei Geral de Proteção de Dados (LGPD) comes into force today, establishing a comprehensive, GDPR-style data protection regime.

Key points

  • Applies to processing in Brazil, processing to offer goods or services to people in Brazil, and data collected in Brazil.
  • Ten legal bases for processing, with enhanced protections for sensitive data.
  • Controllers must appoint a data protection officer (encarregado).
  • Security measures and incident notification to the ANPD and data subjects are required.
  • Administrative sanctions, including fines of up to 2% of Brazilian revenue, apply from August 2021.

The LGPD has extraterritorial reach, so UK organisations with Brazilian customers, staff or suppliers need to extend privacy programmes, notices and transfer mechanisms to cover it.

Source: Lei nº 13.709/2018 – LGPD (Planalto)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights